GolangTAK GitHub

GolangTAK documentation

GolangTAK is one program that runs your TAK server. You install it with one command, open its dashboard in a browser, and connect your devices with a QR code. This page walks through everything in plain steps.

Quick version: run the install command for your system, sign in to the dashboard with the password it prints, open Connect a device, and scan the QR code with ATAK or iTAK.

1. Install

Paste one command. It installs GolangTAK as a service that starts at boot, opens the firewall, creates the certificate authority and the administrator account, and tests every port before it finishes.

Linux, Raspberry Pi, cloud server, macOS

curl -fsSL https://raw.githubusercontent.com/grangedevgroup-code/TAK-Backend/main/GolangTAK/scripts/install.sh | sh

Windows (PowerShell)

irm https://raw.githubusercontent.com/grangedevgroup-code/TAK-Backend/main/GolangTAK/scripts/install.ps1 | iex

Linux without curl, and FreeBSD

wget -qO- https://raw.githubusercontent.com/grangedevgroup-code/TAK-Backend/main/GolangTAK/scripts/install.sh | sh
fetch -qo - https://raw.githubusercontent.com/grangedevgroup-code/TAK-Backend/main/GolangTAK/scripts/install.sh | sh

When it finishes it prints the dashboard address, the administrator user name and password, and a QR code for iTAK. Nothing else needs to be installed: no Docker, no database, no Java or Python.

Running on a cloud server? Also allow the ports in your provider's firewall or security group. The list is under Troubleshooting.

2. Sign in to the dashboard

  1. Open https://SERVER:8446 in a browser, using the address the installer printed. On a trusted network http://SERVER:8080 also works.
  2. Your browser warns about the certificate the first time, because the server made its own. Continue to the site, or set up a trusted certificate under Let's Encrypt.
  3. Sign in as admin with the printed password, then choose your own password when asked.

Lost the password? It stays in admin-password.txt in the data folder until you change it: /var/lib/golangtak on Linux, C:\ProgramData\GolangTAK on Windows.

The dashboard is in English, Spanish, French, German, Portuguese and Ukrainian. Change the language on the sign-in page or under My account. Turn on two-step sign-in there too.

3. Connect devices

Open Connect a device in the dashboard. Pick the user, then use whichever way suits the device.

ATAK

Settings, Network, Servers, Add, Scan QR, and scan the enrollment code. ATAK signs in and gets its own certificate. The code works once.

iTAK

Settings, Network, Servers, Connect with QR, and scan the iTAK code. Then sign in with the user name and password.

WinTAK

Download the connection package and import it, or add a server on port 8089 with Enroll for client certificate and Use authentication turned on.

Any device

Copy a connection package (a .zip) to the device and import it. ATAK: Import, Local SD. iTAK: Upload server package.

Other CoT software

Connect to TCP port 8087, SSL port 8089 with a certificate, UDP 8087, or CoT over WebSocket on port 8090.

Devices appear under Online now and on the Map. Units are drawn with MIL-STD-2525 symbols.

4. Users and groups

Give each person their own user under Users. Groups are channels: people see traffic only from the groups they share. Each user has groups they receive from and groups they send to.

  • Sign in with company accounts: Settings, Directory sign-in for LDAP or Active Directory.
  • Let people sign up themselves: Settings, Email and accounts, with optional approval and allowed email domains.
  • Scripts and tools use an API token from API tokens instead of a password.

6. Video

The video server is built in. Publish with rtsp://SERVER:8554/live/NAME, or from drone apps and OBS with rtmp://SERVER:1935/live/NAME?user=USER&pass=PASSWORD. Sign in with a GolangTAK user name and password.

Every stream appears in each TAK client's video list and on the dashboard's Video page, where it plays in the browser. Press Record on a stream, or record everything automatically under Settings, Video server. To relay an IP camera, add it as a pull source.

7. Voice

Mumble, Mumla and the TAK voice plugins connect to port 64738 with the same user name and password as TAK. Each group has its own channel, so people talk with the same team they share a map with.

8. Feeds and trackers

Turn feeds on under Settings, Data feeds, or add your own under Feeds and layers.

Aircraft and ships

From ADS-B exchanges (adsb.lol by default) and AISHub, or your own receivers: dump1090, readsb, tar1090, rtl_ais and AIS-catcher.

Phone trackers

Phones running Traccar Client report to port 5055, and every device on a Traccar server can be shown.

Meshtastic

Point gateway radios' MQTT setting at the server. Mesh positions and chat appear in TAK, and TAK traffic can go out to the mesh.

Sensors

CoT over TCP, TLS, UDP or multicast, each on its own port with its own groups.

Map layers

Tile, WMS and WMTS sources offered to TAK clients and missions.

9. Telegram

  1. Create a bot with @BotFather in Telegram and copy its token.
  2. Add the bot to your group and send /start there.
  3. Get the group's ID (bots such as @getidsbot show it; groups start with -100).
  4. Enter both under Settings, Telegram, save, and restart when asked.

Group messages appear in TAK's All Chat Rooms and the other way round, emergencies are posted to the group, and locations people share in Telegram show on the map.

10. Reach it from anywhere

ZeroTier

No port forwarding needed. Create a network at my.zerotier.com and add its ID to the install command. Devices running the ZeroTier app connect to the server's ZeroTier address.

Let's Encrypt

Have a domain name? Enter it under Settings, Let's Encrypt for a certificate browsers trust. Port 80 must be reachable.

Port forwarding

Forward 8089 for TAK devices and 8446 for enrollment and the dashboard. Add the others from the port list only if you use them.

curl -fsSL https://raw.githubusercontent.com/grangedevgroup-code/TAK-Backend/main/GolangTAK/scripts/install.sh | GOLANGTAK_ZEROTIER=NETWORK_ID sh

11. Files, missions and checklists

Data packages shared from devices appear under Files, where you can upload, send to devices or delete them. Missions (Data Sync) are shared collections of map items and files with subscribers, roles, invitations and change history. ExCheck checklists work with the ATAK and WinTAK plugins. Repeated objects (choose an item on the map and select Repeat) are sent to every device that connects.

Publish ATAK plugins through the built-in update server, and push settings to devices with device profiles, both under Plugins and profiles.

12. APIs and plugins

TAK Server API

The Marti API used by TAK clients and CloudTAK, including OAuth sign-in, missions, files, video, data feeds, certificates and users.

FreeTAKServer API

On port 19023: map objects, chat, presence, routes, emergencies, drones and sensor points, video, KML points, objects in a zone, repeated messages, data packages, missions, ExCheck, system users and federations. Send an API token as Authorization: Bearer TOKEN.

Server plugins

Your own programs run next to the server with their own API token, settings form and dashboard page. Install one with golangtak plugin install FOLDER|ZIP|URL. A Go SDK is included.

13. Commands

CommandWhat it does
golangtak statusService state, addresses and connected devices
golangtak user add NAMEAdd a user; user list, passwd, del and package work the same way
golangtak qr NAMEPrint a QR code for a device in the terminal
golangtak peer invite NAMEMake a link code for another GolangTAK; peer join CODE uses it
golangtak config set KEY VALUEChange a setting, for example config set address tak.example.org
golangtak logs -fFollow the server log
golangtak selftestCheck that every port answers
golangtak backupSave settings, users, certificates and missions to a zip file
golangtak zerotier join IDJoin a ZeroTier network
golangtak benchLoad test with simulated clients
golangtak help COMMANDEvery option of a command

On Linux and macOS put sudo in front of commands that change things.

14. Update, back up and remove

  • Update: run the install command again. Settings, users, certificates and data are kept.
  • Back up: Settings, Maintenance, Download backup, or golangtak backup.
  • Background jobs: data cleanup, certificate renewal and feeds are listed under Settings, Maintenance, where each can be run now or paused.
  • Remove: golangtak uninstall, or golangtak uninstall --purge to delete all data too.

15. Troubleshooting

A device cannot connect

Run golangtak selftest. If it passes, the problem is between the device and the server: a cloud firewall, a router, or the wrong address. Check the address under Settings, General.

Certificate errors

The server address changed? Use Settings, Maintenance, Renew the server certificate and enroll the device again.

People do not see each other

They are in different groups. Check both users' send and receive groups under Users.

Something stopped working

Open Logs in the dashboard, or run golangtak logs -f. Warnings are bold and errors highlighted.

Ports
PortUsed for
8089 TCPTAK devices with certificates (SSL)
8087 TCP and UDPTAK without encryption, and CoT datagrams
8446 TCPCertificate enrollment and the dashboard over HTTPS
8443 TCPTAK API with certificates (Data Sync, files, update server)
8080 TCPDashboard and API over HTTP
8090 TCPCoT over WebSocket
19023 TCPFreeTAKServer API
9000, 9001 TCPTAK Server federation version 1 and 2 (off by default)
8554, 1935 TCPVideo: RTSP and RTMP
64738 TCP and UDPVoice (Mumble)
1883 TCPMeshtastic MQTT (off by default)

Compared with OpenTAKServer and FreeTAKServer

Based on each project's own documentation. GolangTAK covers every feature listed for both, in one program.

FeatureGolangTAKOpenTAKServerFreeTAKServer
TCP and SSL streaming, CoT routingYesYesYes
TAK Protocol (protobuf)YesNot listedIn 2.x
Certificate authority made at installYesYesNo
Certificate enrollment, QR codesYesYesNo
Federation with TAK Server (v1 and v2)YesPlannedYes
Data packages, Data Sync, missionsYesYesYes
ExCheck checklistsYesComing soonYes
Video server built in, recording and playbackYesYes (MediaMTX)Separate
Voice server built inYesMumble sign-inSeparate
Groups and channels, LDAP / Active DirectoryYesYesIn 2.x
Two-step sign-in, email registrationYesYesNo
ADS-B and AIS, your own SDR receiversYesAPIs onlyNo
Traccar trackersYesPlannedNo
MeshtasticYesYesNo
TelegramYesNoIn 2.x
Plugin update server, device profilesYesYesNo
Server pluginsYesYesNo
FreeTAKServer REST APIYesNoYes
MIL-STD-2525 symbols, web mapYesYesYes
Let's Encrypt, ZeroTierYesYesNo
Dashboard languages6SeveralEnglish
InstallOne command, no dependenciesScript with Python, PostgreSQL, RabbitMQ, nginx, MediaMTXPython, or Docker / Ansible

GolangTAK is an independent open source project and is not affiliated with OpenTAKServer, FreeTAKServer, tak.gov or the TAK Product Center.