📦 Ring2All Platform - Deployment Topologies & Integrator Roadmap
Complete master deployment guide and roadmap for system integrators deploying the Ring2All Platform (PBX, SBC, and BSS) across all supported architectures on Debian 13 (Trixie).
🗺️ Integrator Deployment Suite
Section titled “🗺️ Integrator Deployment Suite”Ring2All provides modular, production-ready installation paths tailored to each organizational tier:
flowchart TD
subgraph Suite["Ring2All Production Topologies"]
Single["🖥️ Single Server All-in-One<br/>(Small Business & Lab Deployments)"]
Dist["🏢 Distributed Multi-Server Cluster<br/>(Patroni PostgreSQL 17 + FreeSWITCH N+1)"]
WebLB["🌐 Web Cluster & Load Balancing<br/>(Cloudflare Orange Cloud + HAProxy)"]
SBC["🛡️ Ring2All SBC Deployment<br/>(Kamailio 6.1 + RTPEngine 12.5 + WireGuard)"]
BSS["💳 Ring2All BSS (Carrier Billing)<br/>(Real-Time OCS + Customer Storefront)"]
end
Single -.->|Scale Out| Dist
Dist <--> WebLB
SBC <==|Encrypted WireGuard Mesh| Dist
SBC <-->|Sub-millisecond OCS Auth| BSS
Dist <-->|CDR & Balance Sync| BSS
📚 Dedicated Step-by-Step Installation Guides
Section titled “📚 Dedicated Step-by-Step Installation Guides”| Deployment Environment | Target Scope | Key Components | Direct Link |
|---|---|---|---|
| 🖥️ Single Server (All-in-One) | POC, Lab, Small & Mid Businesses (up to 2,500 ext / 400 calls) | All 11 PBX packages, PostgreSQL 17, FreeSWITCH 1.11+, Nginx, Let’s Encrypt | 📖 Single Server Guide |
| 🏢 Distributed Multi-Server Cluster | Large Enterprise & Telco (10,000–100,000+ ext / 15,000+ calls) | 3-node Patroni DB, GlusterFS/S3 shared recordings, FreeSWITCH N+1 cluster, local HAProxy | 📖 Distributed Cluster Guide |
| 🌐 Web Cluster & Load Balancing | High-availability Web GUIs & REST APIs | Decoupled Web nodes, Cloudflare Load Balancers, SSL termination, Sticky Session routing | 📖 Web Cluster Guide |
| 🛡️ Ring2All SBC Deployment | Perimeter SIP Security & NAT Traversal Gateway | Kamailio 6.1+, RTPEngine 12.5+, Pike anti-flood, WireGuard mesh to PBX core | 📖 Ring2All SBC Guide |
| 💳 Ring2All BSS (Billing & OCS) | Carrier Monetization, Real-time Rating & Customer Store | Fastify 5 OCS engine, prepaid customer wallets, Stripe payments, customer self-care portal | 📖 Ring2All BSS Guide |
🏛️ Architectural Topologies at a Glance
Section titled “🏛️ Architectural Topologies at a Glance”1. Single Server All-in-One
Section titled “1. Single Server All-in-One”All softswitch applications, FreeSWITCH telephony core, and PostgreSQL 17 database run on a single machine. Nginx acts as the front-facing reverse proxy dispatching traffic to Web frontends (/admin, /portal, /switchboard), REST API (:3000), and WebSocket telemetry (:3001).
- Best For: Rapid deployments, lab testing, small businesses (< 500 extensions).
- Setup Time: < 10 minutes via the one-command automated script
install-softswitch.sh.
2. Enterprise Distributed Multi-Server Cluster
Section titled “2. Enterprise Distributed Multi-Server Cluster”Every functional layer is decoupled across dedicated physical or cloud virtual machines:
- Database Layer: 3-node PostgreSQL 17 cluster orchestrated by Patroni and Etcd for Raft consensus with automatic sub-30s failovers.
- Shared Storage Layer: 3-way replicated GlusterFS pool (or S3-compatible object storage) ensuring tenant recordings and audio prompts are instantly synchronized across all nodes.
- Telephony Execution Layer (N+1): Stateless FreeSWITCH 1.11+ nodes connecting to the database via local HAProxy / PgBouncer loopback proxies. Add nodes horizontally as call volumes scale without modifying tenant configs.
3. Ring2All SBC Perimeter Gateway
Section titled “3. Ring2All SBC Perimeter Gateway”Shields your core telephony cluster with zero public IP exposure:
- Kamailio 6.1+: Handles SIP registration, RFC 3263 SRV/NAPTR discovery, dispatcher load balancing across PBX nodes, and DDoS protection via the Pike module.
- RTPEngine 12.5+: High-performance kernel-based media proxy handling symmetric NAT traversal and WebRTC transcoding without CPU strain.
- WireGuard Mesh: PBX nodes connect from private subnets (
192.168.10.x) to the SBC via encrypted WireGuard transit tunnels (10.9.0.0/24), preventing internet SIP scanners from reaching FreeSWITCH.
4. Ring2All BSS Carrier Billing & Customer Storefront
Section titled “4. Ring2All BSS Carrier Billing & Customer Storefront”Provides the commercial monetization layer:
- Separation of Concerns: Back-office rate decks and margins (
softswitch-bss-web) remain on internal management networks, while the customer storefront (softswitch-bss-client) is exposed to the public DMZ edge. - Real-Time OCS: Queries prepaid balances and rate tables in < 2ms, authorizing outbound calls via Kamailio or FreeSWITCH before bridge establishment.
📋 Hardware Sizing Matrix
Section titled “📋 Hardware Sizing Matrix”| Deployment Tier | Extensions | Concurrent Calls | vCPU | RAM | Storage | Topology Recommendation |
|---|---|---|---|---|---|---|
| Small / Lab | < 500 | ~50 | 4 vCPU | 8 GB | 100 GB SSD | Single Server All-in-One |
| Medium Business | ~2,500 | ~400 | 8 vCPU | 16 GB | 250 GB SSD | High-Spec Single Server or 2-Node |
| Enterprise | ~10,000 | ~1,500 | 16 vCPU | 32 GB | 500 GB NVMe | 3-Node Distributed Cluster |
| Service Provider | ~50,000 | ~7,500 | Distributed | Distributed | 1+ TB SAN/S3 | Full Distributed (5+ Telephony Nodes + SBC Cluster) |
| Carrier Grade | 100,000+ | 15,000+ | Distributed | Distributed | Multi-TB | Patroni DB HA + N+1 PBX Nodes + Dual Active-Active SBCs + BSS DMZ |
📦 Official System Repository Setup
Section titled “📦 Official System Repository Setup”All Ring2All packages are distributed through official, cryptographically signed APT repositories:
# Install system prerequisitesapt update && apt install -y curl gnupg2 lsb-release
# Add Ring2All GPG signing keymkdir -p /etc/apt/keyringscurl -fsSL https://repo.softswitchone.com/gpg.key | gpg --dearmor -o /etc/apt/keyrings/ring2all.gpg
# Register official repositoryecho "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt trixie main" > /etc/apt/sources.list.d/ring2all.list
# Update package indexapt updateapt update && apt install -y curl gnupg2 lsb-releasemkdir -p /etc/apt/keyringscurl -fsSL https://repo.softswitchone.com/gpg.key | gpg --dearmor -o /etc/apt/keyrings/ring2all.gpgecho "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt bookworm main" > /etc/apt/sources.list.d/ring2all.listapt updatesudo apt update && sudo apt install -y curl gnupg2 lsb-releasesudo mkdir -p /etc/apt/keyringscurl -fsSL https://repo.softswitchone.com/gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/ring2all.gpgecho "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt noble main" | sudo tee /etc/apt/sources.list.d/ring2all.listsudo apt update📦 Modular Debian Package Catalog
Section titled “📦 Modular Debian Package Catalog”The Ring2All ecosystem is packaged into distinct, modular components:
1. Ring2All PBX Packages
Section titled “1. Ring2All PBX Packages”softswitch-all: Master metapackage deploying the complete PBX platform.softswitch-db: PostgreSQL 17 database schemas, default migrations, and seed data.softswitch-api: Fastify 5 REST API daemon (Port 3000/3001).softswitch-monitoring-api: Real-time ESL telemetry & WebSocket hub (Port 3001/3500).softswitch-admin: Static React 18 administration portal + authoritative Nginx configuration.softswitch-portal: Static React 18 end-user self-service portal.softswitch-switchboard: Static React 18 operator console.softswitch-telephony: FreeSWITCH 1.11+ configuration, Lua routing scripts, dialplans, and AI engine.softswitch-music: Multi-rate Music on Hold WAV audio packages.softswitch-voiceguide-emma: English (US) system audio prompts.softswitch-voiceguide-paloma: Spanish (US/LATAM) system audio prompts.
2. Ring2All SBC Packages
Section titled “2. Ring2All SBC Packages”softswitch-sbc: Unified perimeter gateway package pulling Kamailio 6.1+, RTPEngine 12.5+,sbc-api(Port 3003), Nginx web console, WireGuard VPN hub, and nftables rulesets.
3. Ring2All BSS Packages
Section titled “3. Ring2All BSS Packages”softswitch-bss-all: Metapackage for single-server billing deployments.softswitch-bss-api: Fastify 5 OCS engine, customer REST API, Stripe webhooks, and billing daemon (Port 3002).softswitch-bss-web: React 18 back-office billing administrative console.softswitch-bss-client: React 18 customer-facing self-care store & wallet portal.
🔒 Master Network & Firewall Matrix
Section titled “🔒 Master Network & Firewall Matrix”| Port | Protocol | Layer / Service | Scope | Allowed Sources |
|---|---|---|---|---|
| 22 | TCP | SSH Administration | Perimeter / Management | Restricted Admin IPs / VPN |
| 80 / 443 | TCP | HTTP / HTTPS (Web Portals & APIs) | Public / Edge | Public Internet (or Cloudflare Orange Cloud ☁️🧡) |
| 5060 | UDP/TCP | SIP Signaling (Kamailio SBC) | Public Edge | Public Internet (Cloudflare Grey Cloud ☁️🩶 Only) |
| 5061 | TCP | SIP TLS Signaling (Kamailio SBC) | Public Edge | Public Internet (Cloudflare Grey Cloud ☁️🩶 Only) |
| 16384–32768 | UDP | RTP Audio Media (RTPEngine) | Public Edge | Public Internet / Carrier IP ranges |
| 51820 | UDP | WireGuard Transit Mesh (wg0) |
Inter-Server | PBX Telephony Nodes ↔ SBC Hub |
| 5432 | TCP | PostgreSQL 17 Core | Internal LAN | Patroni Peers, DB Clients, HAProxy |
| 8008 | TCP | Patroni Health & REST API | Internal LAN | HAProxy Leader Checks |
| 2379 / 2380 | TCP | Etcd Raft Consensus | Internal LAN | PostgreSQL DB Nodes Only |
| 5000 | TCP | HAProxy Local Leader Write Proxy | Loopback (127.0.0.1) |
Local API & FreeSWITCH Instances |
| 5001 | TCP | HAProxy Local Replica Read Proxy | Loopback (127.0.0.1) |
Local API Instances |
| 6432 | TCP | PgBouncer Transaction Pooler | Loopback (127.0.0.1) |
FreeSWITCH ODBC Connection Pool |
| 24007–24008 | TCP | GlusterFS Management Daemon | Internal LAN | Storage Nodes & Client Mounts |
| 49152–49251 | TCP | GlusterFS Storage Bricks | Internal LAN | Storage Nodes & Client Mounts |
🚀 Getting Started
Section titled “🚀 Getting Started”Select the installation guide suited for your infrastructure:

