Run it for your lab
One lab, one database.
BioManager runs on your own computer in two minutes, or on a server that the whole lab opens from any browser and phone. This page lays out every way to host it, what each costs, and exactly how to set it up. Most labs pay nothing.
Part one
Start here
App or server?
BioManager is the same program in both cases; what differs is where the database lives and who can reach it.
💻 The desktop app
For one person
Download for macOS, Windows or Linux, open it, and you're working. The database is a file on that computer, private to it. Nothing to install, nothing to run.
🌐 A lab server (the web version)
For a whole lab
One machine runs BioManager; everyone opens it in a browser — laptops, the computer in the mouse room, phones at the rack. Everyone sees the same records, live, and it backs itself up every night.
| Phones | Phones open a server, never a desktop app. Android: install the BioManager app (.apk) and type the server's address once; its Scan button reads cage cards. iPhone and iPad: open the server in Safari, tap Share → Add to Home Screen. It gets its own icon and opens full screen like an app; the camera scans cage cards. |
|---|---|
| Mixing | Start with the app on your laptop. When the lab joins, move the same database onto a server in one step: nothing is retyped. |
| Browsers | Any current Safari, Chrome, Edge or Firefox. Light and dark follow the system. |
Choose how
Three questions settle it:
- Just you? Use the desktop app (A). Done.
- Everyone in one building, on the same network? A lab computer on your network (B) works, or ask IT for a university server (C).
- People at home, on phones on mobile data, or across sites? A cloud VM with Tailscale (D) — private, free, and reachable anywhere. This is what we recommend for most labs. Only if you want an ordinary web address that works with no app at all, use your own domain (E).
| Who can reach it | Cost | Set-up | You need | |
|---|---|---|---|---|
| A · One computer | That computer only | Free | 2 min | Nothing |
| B · Lab computer on your network | Anyone on the lab or campus network (or VPN) | Free with a spare computer; a Mac mini or small PC is a one-off $300–600 | 1 hour | A computer that stays on; Docker |
| C · University server | Campus network and VPN | Often free; some IT departments charge | Depends on IT | A request to IT |
| D · Cloud VM + Tailscale recommended | Your lab, from anywhere, and no one else | Free (Oracle Cloud's Always Free VM + Tailscale's free plan), or about $5–7 a month for a paid VM | 1 hour | A cloud account; Tailscale on each device |
| E · Cloud VM + your own domain | Anyone who knows the address (they still need an account) | VM as in D, plus a domain, about $10–15 a year | 1–2 hours | A domain name |
Prices are what these services charged in September 2026; check before you sign up. Every server option (B–E) includes nightly backups, a weekly restore test and HTTPS.
host/load-image.sh fetches for you. No accounts or registries.Part two
Ways to run it
Five ways, from one computer to a cloud server the whole lab reaches from anywhere. Pick one in Choose how, then follow its steps.
A · One computer: the desktop app
- Download BioManager for your computer: macOS (Apple silicon or Intel), Windows or Linux.
- Mac: unzip, drag BioManager to Applications, then the first time right-click → Open → Open. Windows: extract the zip, open BioManager.exe, and at the warning choose More info → Run anyway. Linux: mark the AppImage executable and open it.
- Create your account and answer the set-up questions. See the user guide.
Your data lives outside the app (~/Library/Application Support/Biomanager/ on a Mac,
%APPDATA%\Biomanager\ on Windows, ~/.local/share/Biomanager/ on Linux), so updating
never touches it. Back that folder up with Time Machine or File History, and never keep it in Dropbox,
OneDrive, Google Drive or iCloud Drive: syncing corrupts databases.
A few people on one network can share one computer's lab without a server: Settings → Devices → Share this lab on the network makes it the lab's master copy, opened by the others at the address it shows. The computer must stay on, nothing is backed up nightly as on a server, and the connection isn't encrypted: fine on a lab network you trust, a server for anything more (Devices).
B · A lab computer on your network
Any computer that stays switched on can be the server: a Linux PC, an old desktop, or a Mac mini. The lab
opens it at an address like https://192.168.1.50. It can't be reached from outside your network
unless your campus VPN puts people inside it.
- Give the computer a fixed address. Ask IT for a fixed IP address or a DNS name for it (for example
biomanager.bio.youruni.edu), so the address never changes. Turn off sleep. - Install Docker. Linux:
curl -fsSL https://get.docker.com | sudo sh, thensudo usermod -aG docker $USERand log in again. Mac: install Docker Desktop (free for education and small organisations) or OrbStack, and set it to start at login. - Get the server bundle into
/opt/biomanager:sudo mkdir -p /opt/biomanager && sudo chown "$USER" /opt/biomanager curl -fsSL -o /tmp/biomanager-server.tar.gz \ https://github.com/gaspolymerase/biomanager/releases/latest/download/biomanager-server.tar.gz tar -xzf /tmp/biomanager-server.tar.gz -C /opt/biomanager cd /opt/biomanager/Biomanager/deploy host/load-image.sh # downloads the app for this machine (Intel or ARM) cp .env.example .env && chmod 600 .env - Fill in
.envwith a text editor (nano .env):
If IT gives you a certificate for the name, useDOMAIN=192.168.1.50 # or the DNS name IT gave you TLS=internal # BioManager makes its own certificate POSTGRES_PASSWORD=... # paste the output of: openssl rand -hex 24 TZ=America/New_York # your time zone BACKUP_DIR=/opt/biomanager/backups # better: a folder on a second diskTLS=filesinstead and put it incerts/server.crtandcerts/server.key: then skip step 7. - Start it:
docker compose up -d docker compose logs app | grep "setup code" - Create the admin account. Open
https://DOMAIN/registeron the server itself and enter the setup code from the last step. The first account is the lab's admin. - Trust its certificate on every device, once. Export it:
docker compose exec caddy cat /data/caddy/pki/authorities/local/root.crt > biomanager-root.crtand install that file:- Mac: double-click it, then in Keychain Access open it and set Trust → Always Trust.
- Windows: double-click → Install Certificate → Local Machine → Trusted Root Certification Authorities.
- iPhone/iPad: AirDrop or email it, install the profile under Settings → General → VPN & Device Management, then turn it on under Settings → General → About → Certificate Trust Settings.
- Android: Settings → Security → Encryption & credentials → Install a certificate → CA certificate.
- Let people in: allow incoming connections on port 443 in the computer's firewall, and send the lab the
address. On Linux, also install the watchdog and weekly updates:
sudo host/install.sh(in thedeployfolder).
BACKUP_DIR on a second disk, and
copy the backups somewhere else too — see Keeping the data safe.C · A university or department server
Many universities give labs a virtual machine on the campus network. Send IT this request:
“We'd like a small Linux VM (Ubuntu 24.04, 2 vCPU, 4 GB RAM, 40 GB disk) with Docker, a DNS
name such as biomanager.ourdept.university.edu, a TLS certificate for that name, and port 443 open
to the campus network and VPN. It runs BioManager, a lab database, in Docker containers.”
Then follow B from step 3 with TLS=files and IT's certificate in certs/. Nothing needs
to be installed on lab devices. If IT offers backups of the VM, take them — they're a welcome extra layer.
D · A cloud VM with Tailscale recommended
The server is a virtual machine in the cloud. Tailscale is a private network
between your lab's devices: the server has no open ports on the internet at all, yet from any Wi-Fi or
phone signal, lab members open it at a normal HTTPS address like https://biomanager.tail1234.ts.net,
with a real certificate and nothing to trust by hand.
| The VM | Oracle Cloud Always Free: an Ampere A1 VM (up to 4 cores and 24 GB memory) and 200 GB of disk, free for good. Or any Ubuntu 24.04 VM: Hetzner (about €4/month), DigitalOcean or AWS Lightsail (about $5–7/month). |
|---|---|
| Tailscale | Free on the Personal plan for small teams; beyond that, share just the server with each member's own free Tailscale account, which costs nothing either. |
| Each member | Installs Tailscale once (Mac, Windows, Linux, iPhone, Android) and signs in. |
1. Accounts
- Create a free Oracle Cloud account (a card is asked for to verify you; Always Free resources are never charged). Pick a home region near you: it can't be changed.
- Create a free Tailscale account, with a lab or personal Google, Microsoft or GitHub account.
- On your own computer, download the server
bundle, unpack it, and open
Biomanager/deploy/cloud-init.yamlin a text editor. You'll paste it in the next step.
2. Create the VM
- In Oracle Cloud: Compute → Instances → Create instance.
- Image: Canonical Ubuntu 24.04. Shape: Ampere VM.Standard.A1.Flex, 2 OCPUs and 12 GB (or 4 and 24). If Oracle says it's out of capacity, try again later or pick another availability domain.
- Networking: a new public subnet, with a public IPv4 address (needed only for the first SSH login).
- SSH keys: upload your public key (
ssh-keygen -t ed25519makes one; the.pubfile is the public half). - Advanced options → Management → Initialization script: paste the contents of
cloud-init.yaml. It installs Docker, Tailscale and security updates at first boot. - Create it and wait a few minutes. Optionally, in Billing, upgrade to Pay As You Go: Always Free stays free, and Oracle then never reclaims an idle free VM.
3. Put it on Tailscale
ssh ubuntu@<the VM's public IP>
ls /var/lib/biomanager-ready # exists once first-boot set-up has finished
sudo tailscale up --ssh --hostname=biomanager
Open the link it prints and sign in. Then, in the Tailscale admin console:
- Machines → biomanager → ⋯ → Disable key expiry (otherwise it drops off after 180 days);
- DNS: turn on MagicDNS and HTTPS Certificates. Note your tailnet name, like
tail1234.ts.net.
From now on, connect with ssh ubuntu@biomanager over Tailscale.
4. Start BioManager
curl -fsSL -o /tmp/biomanager-server.tar.gz \
https://github.com/gaspolymerase/biomanager/releases/latest/download/biomanager-server.tar.gz
tar -xzf /tmp/biomanager-server.tar.gz -C /opt/biomanager
cd /opt/biomanager/Biomanager/deploy
host/load-image.sh # downloads the app for this machine (Intel or ARM)
cp .env.example .env && chmod 600 .env
nano .env
DOMAIN=biomanager.tail1234.ts.net # biomanager + your tailnet name
TLS=tailscale
COMPOSE_FILE=compose.yaml:compose.tailscale.yaml
POSTGRES_PASSWORD=... # openssl rand -hex 24
TZ=America/New_York
BACKUP_DIR=/opt/biomanager/backups
docker compose up -d
docker compose ps # wait until app and backup say "healthy"
docker compose logs app | grep "setup code"
sudo host/install.sh # watchdog, weekly updates and phone alerts
On a device with Tailscale, open https://DOMAIN/register and create the admin account with the
setup code. install.sh prints an ntfy topic: subscribe to it in the
ntfy app to hear if the site, the backups or the disk ever need you.
5. Close the door
In Oracle Cloud, open the VM's subnet → Security list and delete the ingress rule for port 22. The server now has no open ports on the internet; SSH and the website both go over Tailscale.
6. Invite the lab
- Each member installs Tailscale and either joins your tailnet (Users → Invite) or — simpler at any size — you share only the server with their own Tailscale account: Machines → biomanager → Share.
- They open the address, choose Create account, and you approve them in Manage users.
- Phones: Tailscale app on, then the BioManager Android app, or Safari → Add to Home Screen on iPhone.
Someone outside the lab who needs a look for a few days doesn't need Tailscale: see guest passes.
E · A cloud VM with your own domain
Everyone reaches https://biomanager.yourlab.org with no app at all. The cost of that convenience:
the sign-in page is on the open internet. BioManager is built for it — new sign-ups wait for an admin, wrong
passwords are throttled, sessions end when a password changes, and a strict content security policy is on — but
use strong passwords, and consider sign-in with Google or Microsoft.
- Buy a domain from a registrar such as Cloudflare, Porkbun or Namecheap (or use a subdomain your department gives you).
- Create the VM as in D, steps 1–2 (Tailscale is optional; it's still the safest way to SSH in).
- At the registrar, add a DNS A record:
biomanager→ the VM's public IP. - In the cloud firewall (Oracle: the subnet's security list), allow inbound TCP 80 and 443 from anywhere. Port 80 is needed for Let's Encrypt to issue the certificate.
- Get the bundle and
.envas in D step 4, with:
thenDOMAIN=biomanager.yourlab.org TLS=acme ACME_EMAIL=you@yourlab.org # Let's Encrypt writes here before a certificate expiresdocker compose up -d. Caddy gets and renews the certificate by itself. - Create the admin account at
https://biomanager.yourlab.org/registerwith the setup code, and runsudo host/install.sh(in thedeployfolder).
Other routes
- Guest passes: in for a few days, no Tailscale
- On a Tailscale server (D), an admin can let someone outside the lab in temporarily. Make a code under
Guests in the account menu, then put the server on the internet with Tailscale Funnel:
sudo deploy/host/internet-access.sh on(the first time, Tailscale prints a link to allow Funnel). The guest openshttps://DOMAIN:8443/guestand enters the code; anyone else there sees only that code page.internet-access.sh offcloses it again. See the user guide. - Cloudflare Tunnel
- Like E, an ordinary address, but without opening any port:
cloudflaredon the server connects out to Cloudflare, and Cloudflare Access can require a lab email login before anyone even sees BioManager (free for up to 50 people). It needs a domain on Cloudflare. We haven't packaged it; the AI guide has notes for an assistant setting it up. - Without Docker
- BioManager is a Python web app (gunicorn) on PostgreSQL behind any HTTPS proxy, so it runs on a plain server too. Docker is what makes backups, updates and restores one command each, so we recommend it.
Part three
Once it's running
After it's running
- Set up the lab
- The admin's first sign-in opens the set-up survey: tick what the lab keeps and BioManager builds just those databases. See the user guide.
- People
- Sign-ups wait for approval in Manage users, where admins also make others admin, disable leavers and reset passwords, and give animal-facility staff the Animal care or Facility manager role (what each may do).
- Sign-in with Google, Microsoft or your institution
- Optional, each one a few lines in
deploy/.envand a restart (deploy/README.mdin the bundle has the steps). Your institution's own sign-in works through OpenID Connect (Okta, Keycloak, Azure AD, Shibboleth's OIDC plugin): register BioManager with your IT, redirect addresshttps://DOMAIN/auth/institution/callback, and setBIOMANAGER_OIDC_ISSUER,_CLIENT_ID,_CLIENT_SECRETandBIOMANAGER_OIDC_NAME(what the button says). A university that only speaks SAML (InCommon, eduGAIN) comes in through CILogon:BIOMANAGER_CILOGON_CLIENT_IDand_SECRET, andBIOMANAGER_CILOGON_IDPto go straight to your university. - Cage cards with QR codes
- On a server, a card's QR code opens that cage on any phone that can reach the server. A Zebra label printer on the lab's network can be sent labels straight from the server (how) when the server can reach it: a server in the cloud can't reach a printer in your lab, unless the printer is on Tailscale too.
- Alerts
- The ntfy topic from
install.shtells you if the site stops answering, a container stops, the disk fills, or backups stop.deploy/RUNBOOK.mdsays what to do for each. - Updates
- Security fixes for the operating system install nightly, and the containers refresh every Sunday. A new BioManager
version is three commands:
Yourcd /opt/biomanager/Biomanager/deploy docker compose exec backup backup.sh # a fresh backup first curl -fsSL -o /tmp/b.tar.gz https://github.com/gaspolymerase/biomanager/releases/latest/download/biomanager-server.tar.gz \ && tar -xzf /tmp/b.tar.gz -C /opt/biomanager && host/load-image.sh && docker compose up -d --build.envand backups are never in the bundle, so unpacking over it keeps them. The new version brings the database up to date as it starts; every release is tested upgrading a lab made by each earlier one.
Keeping the data safe
A colony's records are years of work. BioManager keeps several independent copies, so no single failure — a deleted VM, a dead disk, a stolen laptop, a bad update — loses them.
| 1 · Every night | The server backs up the database and uploaded files, checks each backup can be read, and keeps the last 30. Automatic on every server. |
|---|---|
| 2 · Every week | The newest backup is restored into a scratch database and checked, so you know the backups actually work — not just that they exist. Automatic. |
| 3 · Off-site | Encrypted copies in cloud storage, kept 30 days, 12 weeks and 24 months — and, with the
bucket's Object Lock on, safe from deletion even by someone who takes over the server. Backblaze B2's first 10 GB are free — years of a lab's backups.
One command: sudo deploy/host/offsite-setup.sh. |
| 4 · On every lab computer | The desktop app keeps its own copy of the whole lab: on the server,
Settings → Copies of the lab → Make a key for a computer; in that computer's desktop app, Settings → Keep a copy
of your lab server, the address and the key. While the app is open it takes a fresh copy every day, checks it
arrived whole, keeps the last 14 and mirrors every uploaded file. Admins see which computers hold a copy and how
fresh it is. Put the app on a few lab machines and the lab survives even losing the server and its off-site copies.
(Admins may allow members to keep copies too, in Lab setup.) An admin's Mac can also pull the server's own nightly
backups over SSH: deploy/mac/install.sh from the bundle. |
| 5 · Everyone | Every sheet has Export, a CSV of what it shows that opens in Excel; and Settings → Export my data downloads your own mice and plasmids as CSV with your notebook pages, any time. |
| 6 · Undo and history | Mistakes, not disasters: every bulk change can be undone from Batches, and the Audit log shows every edit, who made it and what it was before. |
Restoring is one command too, and never deletes what it replaces — see deploy/RUNBOOK.md.
Moving from the desktop app to a server
Everything you entered in the app comes along: records, history, IDs. The same steps rebuild a lost server from a
lab computer's copy: use the newest .db from its lab-copies/…/db folder instead, and its
uploads folder. Do it before the server's first start (the copy goes into an empty database):
- Quit the app, and copy its data folder (see A) to the server, for example with
scp, to/tmp/lab. - On the server, in the deploy folder, after
host/load-image.shand filling in.env:docker compose up -d db docker compose run --rm --no-deps -v /tmp/lab/biomanager.db:/import/lab.db:ro app \ sh -c 'python scripts/migrate-to-postgres.py /import/lab.db "$DATABASE_URL"' docker compose up -d docker compose cp /tmp/lab/uploads/. app:/data/uploads/ - Sign in with your existing account.
--dry-runafter the script name checks everything first and changes nothing.
On a running server, the master copy can also move to a desktop and back without these steps: an admin hands it over under Settings → Devices, and the desktop gives it back there. While a desktop holds it the server is read only and says where the lab is (Devices).
Part four
Help
Set it up with an AI assistant
An AI coding assistant with a terminal (Claude Code, Cursor, Codex and the like) can do most of D or E for you. We
keep a guide written for it — the facts, the exact commands, what to check after each step, and the safety rules — at
deploy-with-ai.md. Paste this to your assistant:
You stay in charge of the parts only you can do: creating the cloud and Tailscale accounts, approving sign-ins, and typing secrets. The guide tells the assistant to stop and ask at each of those.
Questions
- Is a free cloud VM really free?
- Oracle's Always Free resources carry no charge. The card is for identity; nothing is billed unless you create paid resources. Free-tier accounts' VMs can be reclaimed when idle for a week; upgrading the account to Pay As You Go stops that and still charges nothing for Always Free resources.
- Is Tailscale safe for lab data?
- Tailscale connects devices directly with WireGuard encryption; it can't read the traffic. The server is simply invisible to anyone not in your tailnet — a far smaller target than a public sign-in page.
- How big does the server need to be?
- A lab with tens of thousands of animals uses well under 1 GB of database. The smallest VMs are plenty.
- Can we run several labs on one server?
- Run one BioManager per lab (each its own folder and domain), or one for a whole facility, where each lab keeps its own databases.
- Who can help?
- Open an issue with what you're trying and where it stopped.