Install Ferry and create its user
Copy the two programs to the server and create a Linux user that runs only ferryd.
Run these commands on the server, in the folder that contains the two binaries. sudo runs each command as root.
Copy the binaries
sudo install -m 755 ferryd ferry /usr/local/bin/The two programs are now in /usr/local/bin. The file mode 755 lets each user run them.
Create the user
sudo useradd --system --create-home --home-dir /home/ferry --shell /usr/sbin/nologin --groups docker ferryThe user ferry is a system user. It is a member of the group docker.
Create the folders
sudo install -d -o ferry -g ferry -m 700 /var/lib/ferry /etc/ferry/var/lib/ferry is for the data. /etc/ferry is for the configuration. Only the user ferry can open them.
The group docker has the power of root
ferryd needs the Docker socket. For this reason the user is in the group docker. A member of this group has the same power as root on the server. Keep the account ferry for ferryd only.
If your services clone private repositories over SSH, put the key in /home/ferry/.ssh.