Deployment Options

Delinea Credentials Cache can be deployed in three ways: installed on Windows and hosted in IIS, installed on Linux as a systemd service behind an Apache HTTP Server reverse proxy, or run as a Docker container on any host. All three options provide the same API endpoints and the same Swagger UI, and all three are configured with the same settings (see Configuring Delinea Credentials Cache).

Comparison

  Windows (IIS) Linux (Apache HTTP Server) Docker Container
Hosting IIS application on Windows Server systemd service on Ubuntu or RHEL, exposed through an Apache HTTP Server reverse proxy Docker on any host OS (Windows, Linux, or macOS)
Runtime ASP.NET Core 10.0 Hosting Bundle installed on the host aspnetcore-runtime-10.0 package installed on the host Included in the container image; nothing to install on the host
Configuration appsettings.json file appsettings.json file Environment variables (-e flags on docker run)
Certificate management Windows certificate store; HTTPS binding in IIS Host OS certificate files; TLS terminated by Apache HTTP Server Mounted into the container through Docker volumes; TLS terminated by Kestrel
Restart after a configuration change Recycle the IIS application pool sudo systemctl restart credcache.service docker restart, or re-run docker run with new -e values
Best for Persistent server deployments in environments that already run IIS Persistent server deployments in environments that already run Linux and Apache HTTP Server Portable, repeatable deployments; environments that already use containers; running several instances on one host

How to Choose

Whichever option you choose, review Prerequisites first. For guidance on how many instances to run and where to place them, see Architecture.