# Installation ## Docker Compose ```bash cp .env.example .env docker compose up --build ``` Change every secret in `.env` before using NexaFabric outside a local lab. ## Proxmox API Token Create a least-privilege Proxmox API token and start in read-only mode. NexaFabric can inventory clusters, nodes, VMs, LXCs, networks, and firewall state before any write workflows are enabled. Recommended initial scope: - Cluster inventory read - Node inventory read - VM and LXC config read - SDN and network read - Firewall read Enable write permissions only for a dedicated automation token after previews and approvals are working.