---
title: "π¦ Ring2All Platform - Deployment Topologies & Integrator Roadmap"
description: "Master deployment guide and roadmap for installing Ring2All PBX, Ring2All SBC, and Ring2All BSS across single-server and distributed topologies"
---
> Complete master deployment guide and roadmap for system integrators deploying the **Ring2All Platform** (PBX, SBC, and BSS) across all supported architectures on Debian 13 (Trixie).
---
## πΊοΈ Integrator Deployment Suite
Ring2All provides modular, production-ready installation paths tailored to each organizational tier:
```mermaid
flowchart TD
subgraph Suite["Ring2All Production Topologies"]
Single["π₯οΈ Single Server All-in-One
(Small Business & Lab Deployments)"]
Dist["π’ Distributed Multi-Server Cluster
(Patroni PostgreSQL 17 + FreeSWITCH N+1)"]
WebLB["π Web Cluster & Load Balancing
(Cloudflare Orange Cloud + HAProxy)"]
SBC["π‘οΈ Ring2All SBC Deployment
(Kamailio 6.1 + RTPEngine 12.5 + WireGuard)"]
BSS["π³ Ring2All BSS (Carrier Billing)
(Real-Time OCS + Customer Storefront)"]
end
Single -.->|Scale Out| Dist
Dist <--> WebLB
SBC <==|Encrypted WireGuard Mesh| Dist
SBC <-->|Sub-millisecond OCS Auth| BSS
Dist <-->|CDR & Balance Sync| BSS
```
---
## π Dedicated Step-by-Step Installation Guides
| Deployment Environment | Target Scope | Key Components | Direct Link |
| :--- | :--- | :--- | :--- |
| **π₯οΈ Single Server (All-in-One)** | POC, Lab, Small & Mid Businesses (up to 2,500 ext / 400 calls) | All 11 PBX packages, PostgreSQL 17, FreeSWITCH 1.11+, Nginx, Let's Encrypt | π **[Single Server Guide](single-server.mdx)** |
| **π’ Distributed Multi-Server Cluster** | Large Enterprise & Telco (10,000β100,000+ ext / 15,000+ calls) | 3-node Patroni DB, GlusterFS/S3 shared recordings, FreeSWITCH N+1 cluster, local HAProxy | π **[Distributed Cluster Guide](distributed-cluster.md)** |
| **π Web Cluster & Load Balancing** | High-availability Web GUIs & REST APIs | Decoupled Web nodes, Cloudflare Load Balancers, SSL termination, Sticky Session routing | π **[Web Cluster Guide](web-cluster-load-balancing.md)** |
| **π‘οΈ Ring2All SBC Deployment** | Perimeter SIP Security & NAT Traversal Gateway | Kamailio 6.1+, RTPEngine 12.5+, Pike anti-flood, WireGuard mesh to PBX core | π **[Ring2All SBC Guide](sbc-deployment.md)** |
| **π³ Ring2All BSS (Billing & OCS)** | Carrier Monetization, Real-time Rating & Customer Store | Fastify 5 OCS engine, prepaid customer wallets, Stripe payments, customer self-care portal | π **[Ring2All BSS Guide](bss-deployment.md)** |
---
## ποΈ Architectural Topologies at a Glance
### 1. Single Server All-in-One
All softswitch applications, FreeSWITCH telephony core, and PostgreSQL 17 database run on a single machine. Nginx acts as the front-facing reverse proxy dispatching traffic to Web frontends (`/admin`, `/portal`, `/switchboard`), REST API (`:3000`), and WebSocket telemetry (`:3001`).
- **Best For**: Rapid deployments, lab testing, small businesses (< 500 extensions).
- **Setup Time**: < 10 minutes via the one-command automated script `install-softswitch.sh`.
### 2. Enterprise Distributed Multi-Server Cluster
Every functional layer is decoupled across dedicated physical or cloud virtual machines:
- **Database Layer**: 3-node PostgreSQL 17 cluster orchestrated by Patroni and Etcd for Raft consensus with automatic sub-30s failovers.
- **Shared Storage Layer**: 3-way replicated GlusterFS pool (or S3-compatible object storage) ensuring tenant recordings and audio prompts are instantly synchronized across all nodes.
- **Telephony Execution Layer (N+1)**: Stateless FreeSWITCH 1.11+ nodes connecting to the database via local HAProxy / PgBouncer loopback proxies. Add nodes horizontally as call volumes scale without modifying tenant configs.
### 3. Ring2All SBC Perimeter Gateway
Shields your core telephony cluster with zero public IP exposure:
- **Kamailio 6.1+**: Handles SIP registration, RFC 3263 SRV/NAPTR discovery, dispatcher load balancing across PBX nodes, and DDoS protection via the Pike module.
- **RTPEngine 12.5+**: High-performance kernel-based media proxy handling symmetric NAT traversal and WebRTC transcoding without CPU strain.
- **WireGuard Mesh**: PBX nodes connect from private subnets (`192.168.10.x`) to the SBC via encrypted WireGuard transit tunnels (`10.9.0.0/24`), preventing internet SIP scanners from reaching FreeSWITCH.
### 4. Ring2All BSS Carrier Billing & Customer Storefront
Provides the commercial monetization layer:
- **Separation of Concerns**: Back-office rate decks and margins (`softswitch-bss-web`) remain on internal management networks, while the customer storefront (`softswitch-bss-client`) is exposed to the public DMZ edge.
- **Real-Time OCS**: Queries prepaid balances and rate tables in < 2ms, authorizing outbound calls via Kamailio or FreeSWITCH before bridge establishment.
---
## π Hardware Sizing Matrix
| Deployment Tier | Extensions | Concurrent Calls | vCPU | RAM | Storage | Topology Recommendation |
| :--- | :--- | :--- | :--- | :--- | :--- | :--- |
| **Small / Lab** | < 500 | ~50 | 4 vCPU | 8 GB | 100 GB SSD | Single Server All-in-One |
| **Medium Business** | ~2,500 | ~400 | 8 vCPU | 16 GB | 250 GB SSD | High-Spec Single Server or 2-Node |
| **Enterprise** | ~10,000 | ~1,500 | 16 vCPU | 32 GB | 500 GB NVMe | 3-Node Distributed Cluster |
| **Service Provider** | ~50,000 | ~7,500 | Distributed | Distributed | 1+ TB SAN/S3 | Full Distributed (5+ Telephony Nodes + SBC Cluster) |
| **Carrier Grade** | 100,000+ | 15,000+ | Distributed | Distributed | Multi-TB | Patroni DB HA + N+1 PBX Nodes + Dual Active-Active SBCs + BSS DMZ |
---
import { Tabs, TabItem } from '@astrojs/starlight/components';
## π¦ Official System Repository Setup
All Ring2All packages are distributed through official, cryptographically signed APT repositories:
```bash
# Install system prerequisites
apt update && apt install -y curl gnupg2 lsb-release
# Add Ring2All GPG signing key
mkdir -p /etc/apt/keyrings
curl -fsSL https://repo.softswitchone.com/gpg.key | gpg --dearmor -o /etc/apt/keyrings/ring2all.gpg
# Register official repository
echo "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt trixie main" > /etc/apt/sources.list.d/ring2all.list
# Update package index
apt update
```
```bash
apt update && apt install -y curl gnupg2 lsb-release
mkdir -p /etc/apt/keyrings
curl -fsSL https://repo.softswitchone.com/gpg.key | gpg --dearmor -o /etc/apt/keyrings/ring2all.gpg
echo "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt bookworm main" > /etc/apt/sources.list.d/ring2all.list
apt update
```
```bash
sudo apt update && sudo apt install -y curl gnupg2 lsb-release
sudo mkdir -p /etc/apt/keyrings
curl -fsSL https://repo.softswitchone.com/gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/ring2all.gpg
echo "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt noble main" | sudo tee /etc/apt/sources.list.d/ring2all.list
sudo apt update
```
---
## π¦ Modular Debian Package Catalog
The Ring2All ecosystem is packaged into distinct, modular components:
### 1. Ring2All PBX Packages
- **`softswitch-all`**: Master metapackage deploying the complete PBX platform.
- **`softswitch-db`**: PostgreSQL 17 database schemas, default migrations, and seed data.
- **`softswitch-api`**: Fastify 5 REST API daemon (Port 3000/3001).
- **`softswitch-monitoring-api`**: Real-time ESL telemetry & WebSocket hub (Port 3001/3500).
- **`softswitch-admin`**: Static React 18 administration portal + authoritative Nginx configuration.
- **`softswitch-portal`**: Static React 18 end-user self-service portal.
- **`softswitch-switchboard`**: Static React 18 operator console.
- **`softswitch-telephony`**: FreeSWITCH 1.11+ configuration, Lua routing scripts, dialplans, and AI engine.
- **`softswitch-music`**: Multi-rate Music on Hold WAV audio packages.
- **`softswitch-voiceguide-emma`**: English (US) system audio prompts.
- **`softswitch-voiceguide-paloma`**: Spanish (US/LATAM) system audio prompts.
### 2. Ring2All SBC Packages
- **`softswitch-sbc`**: Unified perimeter gateway package pulling Kamailio 6.1+, RTPEngine 12.5+, `sbc-api` (Port 3003), Nginx web console, WireGuard VPN hub, and nftables rulesets.
### 3. Ring2All BSS Packages
- **`softswitch-bss-all`**: Metapackage for single-server billing deployments.
- **`softswitch-bss-api`**: Fastify 5 OCS engine, customer REST API, Stripe webhooks, and billing daemon (Port 3002).
- **`softswitch-bss-web`**: React 18 back-office billing administrative console.
- **`softswitch-bss-client`**: React 18 customer-facing self-care store & wallet portal.
---
## π Master Network & Firewall Matrix
| Port | Protocol | Layer / Service | Scope | Allowed Sources |
| :--- | :--- | :--- | :--- | :--- |
| **22** | TCP | SSH Administration | Perimeter / Management | Restricted Admin IPs / VPN |
| **80 / 443** | TCP | HTTP / HTTPS (Web Portals & APIs) | Public / Edge | Public Internet (or Cloudflare Orange Cloud βοΈπ§‘) |
| **5060** | UDP/TCP | SIP Signaling (Kamailio SBC) | Public Edge | Public Internet (Cloudflare Grey Cloud βοΈπ©Ά Only) |
| **5061** | TCP | SIP TLS Signaling (Kamailio SBC) | Public Edge | Public Internet (Cloudflare Grey Cloud βοΈπ©Ά Only) |
| **16384β32768** | UDP | RTP Audio Media (RTPEngine) | Public Edge | Public Internet / Carrier IP ranges |
| **51820** | UDP | WireGuard Transit Mesh (`wg0`) | Inter-Server | PBX Telephony Nodes β SBC Hub |
| **5432** | TCP | PostgreSQL 17 Core | Internal LAN | Patroni Peers, DB Clients, HAProxy |
| **8008** | TCP | Patroni Health & REST API | Internal LAN | HAProxy Leader Checks |
| **2379 / 2380**| TCP | Etcd Raft Consensus | Internal LAN | PostgreSQL DB Nodes Only |
| **5000** | TCP | HAProxy Local Leader Write Proxy | Loopback (`127.0.0.1`) | Local API & FreeSWITCH Instances |
| **5001** | TCP | HAProxy Local Replica Read Proxy | Loopback (`127.0.0.1`) | Local API Instances |
| **6432** | TCP | PgBouncer Transaction Pooler | Loopback (`127.0.0.1`) | FreeSWITCH ODBC Connection Pool |
| **24007β24008**| TCP | GlusterFS Management Daemon | Internal LAN | Storage Nodes & Client Mounts |
| **49152β49251**| TCP | GlusterFS Storage Bricks | Internal LAN | Storage Nodes & Client Mounts |
---
## π Getting Started
Select the installation guide suited for your infrastructure:
- π₯οΈ **[Single Server All-in-One Installation](single-server.mdx)**
- π’ **[Distributed Multi-Server Cluster Step-by-Step Guide](distributed-cluster.md)**
- π **[Web Cluster & Load Balancing Guide](web-cluster-load-balancing.md)**
- π‘οΈ **[Ring2All SBC Perimeter Deployment Guide](sbc-deployment.md)**
- π³ **[Ring2All BSS (Billing & OCS) Deployment Guide](bss-deployment.md)**