Deployment Options
Delinea Credentials Cache can be deployed in three ways: installed on Windows and hosted in IIS, installed on Linux as a systemd service behind an Apache HTTP Server reverse proxy, or run as a Docker container on any host. All three options provide the same API endpoints and the same Swagger UI, and all three are configured with the same settings (see Configuring Delinea Credentials Cache).
Comparison
| Windows (IIS) | Linux (Apache HTTP Server) | Docker Container | |
|---|---|---|---|
| Hosting | IIS application on Windows Server | systemd service on Ubuntu or RHEL, exposed through an Apache HTTP Server reverse proxy | Docker on any host OS (Windows, Linux, or macOS) |
| Runtime | ASP.NET Core 10.0 Hosting Bundle installed on the host | aspnetcore-runtime-10.0 package installed on the host |
Included in the container image; nothing to install on the host |
| Configuration | appsettings.json file |
appsettings.json file |
Environment variables (-e flags on docker run) |
| Certificate management | Windows certificate store; HTTPS binding in IIS | Host OS certificate files; TLS terminated by Apache HTTP Server | Mounted into the container through Docker volumes; TLS terminated by Kestrel |
| Restart after a configuration change | Recycle the IIS application pool | sudo systemctl restart credcache.service
|
docker restart, or re-run docker run with new -e values |
| Best for | Persistent server deployments in environments that already run IIS | Persistent server deployments in environments that already run Linux and Apache HTTP Server | Portable, repeatable deployments; environments that already use containers; running several instances on one host |
How to Choose
-
Choose Windows (IIS) if your operations team already manages IIS and the Windows certificate store, or if you want to co-locate the cache with a Windows-based Distributed Engine. See Installing Delinea Credentials Cache on Windows.
-
Choose Linux (Apache HTTP Server) if your standard server platform is Ubuntu or RHEL and you prefer a native service managed with systemd. See Installing Delinea Credentials Cache on Linux.
-
Choose Docker if you want the fastest, most repeatable deployment, do not want to install a .NET runtime or a reverse proxy on the host, or need several instances side by side. See Deploying Delinea Credentials Cache as a Docker Container.
Whichever option you choose, review Prerequisites first. For guidance on how many instances to run and where to place them, see Architecture.