> For the complete documentation index, see [llms.txt](https://docs.roboflow.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.roboflow.com/deployment/self-hosted/inference-server/install/linux.md).

# Install on Linux

The easiest way to start the correct container for your machine, with good default settings (a cache volume and a secure, non-privileged execution mode), is to let the CLI choose and start it with `inference server start`. [Install Docker](https://docs.docker.com/engine/install/) first:

```bash
pip install inference-cli
inference server start
```

## Manually starting the container

If you want more control over the container settings, start it yourself.

{% tabs %}
{% tab title="CPU" %}
The core CPU Docker image includes support for OpenVINO acceleration on x64 CPUs via onnxruntime. Heavy models like SAM2 may run too slowly (dozens of seconds per image) to be practical; if you need them, use a CUDA-capable GPU.

The primary use cases for CPU inference are processing still images (for example NSFW classification of uploads or document verification) or infrequent sampling of frames from a video (for example occupancy tracking of a parking lot).

To get started with CPU inference, use the `roboflow/roboflow-inference-server-cpu:latest` container.

```bash
sudo docker run -d \
    --name inference-server \
    --read-only \
    -p 9001:9001 \
    --volume ~/.inference/cache:/tmp:rw \
    --security-opt="no-new-privileges" \
    --cap-drop="ALL" \
    --cap-add="NET_BIND_SERVICE" \
    roboflow/roboflow-inference-server-cpu:latest
```

{% endtab %}

{% tab title="GPU" %}
The GPU container adds hardware acceleration on cards that support CUDA via NVIDIA-Docker. Follow the [NVIDIA Container Toolkit installation guide](https://docs.nvidia.com/datacenter/cloud-native/container-toolkit/latest/install-guide.html), then add `--gpus all` to the `docker run` command:

```bash
sudo docker run -d \
    --name inference-server \
    --gpus all \
    --read-only \
    -p 9001:9001 \
    --volume ~/.inference/cache:/tmp:rw \
    --security-opt="no-new-privileges" \
    --cap-drop="ALL" \
    --cap-add="NET_BIND_SERVICE" \
    roboflow/roboflow-inference-server-gpu:latest
```

{% endtab %}

{% tab title="TensorRT" %}
With the GPU container you can optionally enable [TensorRT](https://developer.nvidia.com/tensorrt), NVIDIA's model optimization runtime. It greatly increases your models' speed at the expense of a heavy compilation and optimization step (sometimes 15+ minutes) the first time you load each model.

Enable TensorRT by adding `TensorrtExecutionProvider` to the `ONNXRUNTIME_EXECUTION_PROVIDERS` environment variable.

```bash
sudo docker run -d \
    --name inference-server \
    --gpus all \
    --read-only \
    -p 9001:9001 \
    --volume ~/.inference/cache:/tmp:rw \
    --security-opt="no-new-privileges" \
    --cap-drop="ALL" \
    --cap-add="NET_BIND_SERVICE" \
    -e ONNXRUNTIME_EXECUTION_PROVIDERS="[TensorrtExecutionProvider,CUDAExecutionProvider,OpenVINOExecutionProvider,CPUExecutionProvider]" \
    roboflow/roboflow-inference-server-gpu:latest
```

{% endtab %}
{% endtabs %}

## Docker Compose

If you use Docker Compose for your application, the equivalent YAML is:

{% tabs %}
{% tab title="CPU" %}

```yaml
version: "3.9"

services:
  inference-server:
    container_name: inference-server
    image: roboflow/roboflow-inference-server-cpu:latest

    read_only: true
    ports:
      - "9001:9001"

    volumes:
      - "${HOME}/.inference/cache:/tmp:rw"

    security_opt:
      - no-new-privileges
    cap_drop:
      - ALL
    cap_add:
      - NET_BIND_SERVICE
```

{% endtab %}

{% tab title="GPU" %}

```yaml
version: "3.9"

services:
  inference-server:
    container_name: inference-server
    image: roboflow/roboflow-inference-server-gpu:latest

    read_only: true
    ports:
      - "9001:9001"

    volumes:
      - "${HOME}/.inference/cache:/tmp:rw"

    deploy:
      resources:
        reservations:
          devices:
            - driver: nvidia
              count: all
              capabilities: [gpu]

    security_opt:
      - no-new-privileges
    cap_drop:
      - ALL
    cap_add:
      - NET_BIND_SERVICE
```

{% endtab %}

{% tab title="TensorRT" %}

```yaml
version: "3.9"

services:
  inference-server:
    container_name: inference-server
    image: roboflow/roboflow-inference-server-gpu:latest

    read_only: true
    ports:
      - "9001:9001"

    volumes:
      - "${HOME}/.inference/cache:/tmp:rw"

    deploy:
      resources:
        reservations:
          devices:
            - driver: nvidia
              count: all
              capabilities: [gpu]

    environment:
      ONNXRUNTIME_EXECUTION_PROVIDERS: "[TensorrtExecutionProvider,CUDAExecutionProvider,OpenVINOExecutionProvider,CPUExecutionProvider]"

    security_opt:
      - no-new-privileges
    cap_drop:
      - ALL
    cap_add:
      - NET_BIND_SERVICE
```

{% endtab %}
{% endtabs %}

{% hint style="info" %}
Roboflow Enterprise plans add [a Helm chart](https://github.com/roboflow/inference/tree/main/inference/enterprise/helm-chart) for Kubernetes deployments, networking solutions for OT networks, and customized support and installation packages. [Contact the sales team](https://roboflow.com/sales) to learn more.
{% endhint %}

## Next steps

* [Run a model](/deployment/self-hosted/self-hosted.md#run-a-model) against your new server.
* [Docker configuration options](/deployment/self-hosted/inference-server/configuration/docker-configuration.md) for ports, caching, and model limits.
* [Securing a self-hosted server](/deployment/self-hosted/inference-server/configuration/security.md) before you expose it beyond localhost.
