--- title: "🖥️ Single Server Installation Guide" description: "Documentation for Single Server" --- > Complete step-by-step guide for installing Ring2All PBX on a single server --- ## 🏛️ Architecture Diagram ```mermaid flowchart TB subgraph External["External Network"] Endpoints[SIP Phones & WebRTC Clients] PSTN[Carrier SIP Trunk Provider] end subgraph SingleServer["Single Server Infrastructure (Debian 13)"] Nginx["Reverse Proxy (Nginx 1.26+ SSL/TLS)"] subgraph Apps["Web Applications"] Admin["Ring2All Admin Web (:443)"] Portal["User Portal (:443/portal)"] Switch["Switchboard (:443/switchboard)"] BSS["Ring2All BSS (:443/billing)"] end subgraph BackendServices["Backend Services (Node.js 22 & Fastify 5)"] Api["Platform API (:3000)"] MonitorApi["Monitoring API (:3001)"] end subgraph Telephony["Telephony Core (FreeSWITCH 1.11+)"] Sofia["Sofia SIP Profile (UDP/TCP/TLS :5060)"] RTP["RTP Audio Media (UDP 16384-32768)"] Lua["Lua Routing Engine"] end subgraph Data["Database & Storage"] PG[("PostgreSQL 17 DB Engine")] Recordings[("Local Audio & Recordings (/var/lib/softswitch)")] end end Endpoints -->|SIP / WebRTC| Sofia Endpoints -->|HTTPS| Nginx PSTN -->|SIP Inbound/Outbound| Sofia PSTN -.->|Audio RTP| RTP Endpoints -.->|Audio RTP| RTP Nginx --> Admin Nginx --> Portal Nginx --> Switch Nginx --> BSS Nginx --> Api Nginx --> MonitorApi Admin --> Api Portal --> Api Switch --> MonitorApi BSS --> Api Api --> PG MonitorApi --> PG Telephony --> PG Telephony --> Recordings ``` --- ## 📋 Prerequisites ### Hardware Requirements | Component | Minimum | Recommended | High Performance | |-----------|---------|-------------|------------------| | **CPU** | 4 vCPU | 8 vCPU | 16+ vCPU | | **RAM** | 8 GB | 16 GB | 32+ GB | | **Storage** | 100 GB SSD | 250 GB SSD | 500+ GB NVMe | | **Network** | 100 Mbps | 1 Gbps | 10 Gbps | ### Software Requirements - **Operating System:** Debian 13 (Trixie) - 64-bit - **Network:** Static IP address configured - **Root Access:** Required for installation ### Capacity Reference | Configuration | Extensions | Concurrent Calls | |---------------|------------|------------------| | Minimum (4 vCPU, 8GB) | ~500 | ~50 | | Recommended (8 vCPU, 16GB) | ~2,500 | ~400 | | High Performance (16+ vCPU, 32GB+) | ~10,000 | ~1,500 | --- import { Tabs, TabItem } from '@astrojs/starlight/components'; ## ⚡ Option 1: Automated One-Command Installation (Recommended) For rapid all-in-one deployment on a clean Debian 13 (Trixie) server, run the official bootstrap installer as `root`: ```bash wget -O- https://repo.softswitchone.com/apt/install-softswitch.sh | bash ``` ### What this script performs automatically: 1. Configures Debian system prerequisites and DNS settings. 2. Installs Node.js 22 LTS, PostgreSQL 17, and security packages (`fail2ban`, `nftables`). 3. Registers the official Ring2All APT repository components (`base`, `core`, `devel`, `extras`, `audios`). 4. Installs the `softswitch-all` orchestrator meta-package, deploying all 10 core packages in correct dependency order. 5. Bootstraps databases, initializes system DSNs, and starts systemd services. --- ## 🛠️ Option 2: Step-by-Step Package Installation If you prefer installing individual packages or customizing dependencies: ### Step 1: Add Ring2All Repository ```bash # Install prerequisites apt update && apt install -y curl gnupg2 lsb-release # Add GPG key mkdir -p /etc/apt/keyrings curl -fsSL https://repo.softswitchone.com/gpg.key | gpg --dearmor -o /etc/apt/keyrings/ring2all.gpg # Add repository echo "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt trixie main" > /etc/apt/sources.list.d/ring2all.list # Update package list apt update ``` ```bash # Install prerequisites apt update && apt install -y curl gnupg2 lsb-release # Add GPG key mkdir -p /etc/apt/keyrings curl -fsSL https://repo.softswitchone.com/gpg.key | gpg --dearmor -o /etc/apt/keyrings/ring2all.gpg # Add repository echo "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt bookworm main" > /etc/apt/sources.list.d/ring2all.list # Update package list apt update ``` ```bash # Install prerequisites sudo apt update && sudo apt install -y curl gnupg2 lsb-release # Add GPG key sudo mkdir -p /etc/apt/keyrings curl -fsSL https://repo.softswitchone.com/gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/ring2all.gpg # Add repository echo "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt noble main" | sudo tee /etc/apt/sources.list.d/ring2all.list # Update package list sudo apt update ``` ### Step 2: Install Packages #### Quick Method (AIO Meta-Package): ```bash apt install -y softswitch-all ``` #### Granular Method (Individual Packages): ```bash # 1. Database (creates schemas, users, tables) apt install -y softswitch-db # 2. API Backend & Telemetry apt install -y softswitch-api softswitch-monitoring-api # 3. Web Frontends (Admin, Portal, Switchboard) & Authoritative Nginx config apt install -y softswitch-admin softswitch-portal softswitch-switchboard # 4. Telephony Core (FreeSWITCH 1.11+ & Lua Routing) apt install -y softswitch-telephony # 5. Audio Assets & Multilingual Voice Prompts apt install -y softswitch-music softswitch-voiceguide-emma softswitch-voiceguide-paloma # 6. (Optional) Ring2All BSS Carrier Billing & Storefront on same node apt install -y softswitch-bss-all ``` ### Step 3: Enable & Start Services ```bash # Database systemctl enable --now postgresql # Telephony Core systemctl enable --now freeswitch # Backend APIs systemctl enable --now softswitch-api systemctl enable --now softswitch-monitoring-api # Web Server (Nginx) systemctl enable --now nginx ``` **That's it!** 🎉 Your Ring2All PBX is now running. --- ## ✅ Post-Installation Verification ### Check Services Status ```bash # All services should show "active (running)" systemctl status postgresql systemctl status freeswitch systemctl status softswitch-api systemctl status softswitch-monitoring-api systemctl status nginx ``` ### Check Database Connection ```bash # Read generated credentials cat /etc/softswitch/db-credentials # Test connection (should show 6 databases) sudo -u postgres psql -c "\l" # Expected: ss_admin, ss_telephony, ss_cdr, ss_cc, ss_logs, freeswitch ``` ### Check Telephony Server ```bash # Enter Telephony Server CLI fs_cli # Check status (should show internal and external profiles) sofia status # Exit /exit ``` ### Access Web Interfaces | Interface | URL | Description | |-----------|-----|-------------| | **Admin Dashboard** | `https://your-server/admin` | System administration | | **User Portal** | `https://your-server/portal` | End-user self-service | | **Switchboard** | `https://your-server/switchboard` | Operator console | Default login: `admin` / *(check setup wizard or database)* --- ## 🔒 Firewall Configuration ```bash # Allow essential ports ufw allow 22/tcp # SSH ufw allow 80/tcp # HTTP (redirect to HTTPS) ufw allow 443/tcp # HTTPS ufw allow 5060/udp # SIP ufw allow 5060/tcp # SIP over TCP ufw allow 5061/tcp # SIP TLS ufw allow 16384:32768/udp # RTP media # Enable firewall ufw enable ``` --- ## 🔐 SSL Certificate (Let's Encrypt) ```bash # Install certbot apt install certbot python3-certbot-nginx # Obtain certificate (replace with your domain) certbot --nginx -d pbx.example.com # Auto-renewal is configured automatically systemctl status certbot.timer ``` --- ## ⚙️ Nginx Configuration The `softswitch-admin` package includes a default Nginx configuration. For customization: ```bash nano /etc/nginx/sites-available/softswitch ``` ```nginx server { listen 80; server_name _; # Redirect all HTTP to HTTPS return 301 https://$host$request_uri; } server { listen 443 ssl http2; server_name _; # SSL Certificates ssl_certificate /etc/ssl/certs/softswitch.crt; ssl_certificate_key /etc/ssl/private/softswitch.key; # Security headers add_header X-Frame-Options "SAMEORIGIN" always; add_header X-Content-Type-Options "nosniff" always; # API Backend (Node.js) location /api { proxy_pass http://127.0.0.1:3000; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection 'upgrade'; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } # WebSocket (Monitoring API) location /ws { proxy_pass http://127.0.0.1:3001; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $host; proxy_read_timeout 86400; } # Admin Dashboard location /admin { alias /var/www/softswitch/web; try_files $uri $uri/ /admin/index.html; } # User Portal location /portal { alias /var/www/softswitch/portal; try_files $uri $uri/ /portal/index.html; } # Switchboard Console location /switchboard { alias /var/www/softswitch/switchboard; try_files $uri $uri/ /switchboard/index.html; } # Root redirect to Admin location = / { return 302 /admin; } } ``` Apply changes: ```bash ln -sf /etc/nginx/sites-available/softswitch /etc/nginx/sites-enabled/ nginx -t && systemctl reload nginx ``` --- ## 📁 Credentials & Configuration Files | File | Description | |------|-------------| | `/etc/softswitch/db-credentials` | Database username and password | | `/etc/softswitch/api.env` | API environment variables | | `/etc/odbc.ini` | ODBC connections for Telephony Server | | `/etc/freeswitch/` | Telephony Server configuration | ### View Credentials ```bash cat /etc/softswitch/db-credentials ``` ``` # Softswitch Database Credentials # Generated: 2026-01-27 15:00:00 DB_USER=ss_db_user DB_PASSWORD=Xk9mN2pQ4rT7 DB_HOST=127.0.0.1 DB_PORT=5432 ``` --- ## 🔧 Resource Optimization Since all services share the same server, optimize resource allocation: ### PostgreSQL Tuning ```bash nano /etc/postgresql/17/main/postgresql.conf ``` ```ini # Memory (adjust based on available RAM) shared_buffers = 2GB # 25% of RAM effective_cache_size = 6GB # 75% of RAM work_mem = 32MB maintenance_work_mem = 512MB # Connections max_connections = 200 # WAL wal_buffers = 64MB checkpoint_completion_target = 0.9 ``` ### Telephony Server Tuning ```bash nano /etc/freeswitch/autoload_configs/switch.conf.xml ``` ```xml ``` --- ## 💾 Backup Strategy ### Automated Daily Backup Script Create `/opt/softswitch-backup.sh`: ```bash #!/bin/bash # Softswitch Single Server Backup Script BACKUP_DIR="/var/backups/softswitch" DATE=$(date +%Y%m%d_%H%M%S) RETENTION_DAYS=7 mkdir -p $BACKUP_DIR # Backup all databases for db in ss_admin ss_telephony ss_cdr ss_cc ss_logs ss_switchboard; do sudo -u postgres pg_dump $db | gzip > "$BACKUP_DIR/${db}_${DATE}.sql.gz" done # Backup Telephony Server configs tar -czf "$BACKUP_DIR/freeswitch_config_${DATE}.tar.gz" /etc/freeswitch # Backup recordings (if any) if [ -d "/var/lib/freeswitch/recordings" ]; then tar -czf "$BACKUP_DIR/recordings_${DATE}.tar.gz" /var/lib/freeswitch/recordings fi # Backup credentials cp /etc/softswitch/db-credentials "$BACKUP_DIR/db-credentials_${DATE}" # Remove old backups find $BACKUP_DIR -type f -mtime +$RETENTION_DAYS -delete echo "Backup completed: $BACKUP_DIR" ``` Enable and schedule: ```bash chmod +x /opt/softswitch-backup.sh # Add to cron (daily at 2 AM) echo "0 2 * * * root /opt/softswitch-backup.sh" >> /etc/crontab ``` --- ## 🔍 Troubleshooting ### Service Not Starting ```bash # Check logs journalctl -u softswitch-api -f journalctl -u freeswitch -f # Check ports ss -tlnp | grep -E '3000|3001|5060|5432' ``` ### Database Connection Issues ```bash # Test PostgreSQL sudo -u postgres psql -c "SELECT 1" # Check ODBC isql -v ss_telephony ss_db_user YOUR_PASSWORD ``` ### Telephony Server SIP Issues ```bash # Check SIP profiles fs_cli -x "sofia status" # Check registrations fs_cli -x "sofia status profile internal reg" # Debug SIP traffic fs_cli -x "sofia profile internal siptrace on" ``` ### Nginx 502 Bad Gateway ```bash # Check if API is running curl http://127.0.0.1:3000/api/health # Check API logs journalctl -u softswitch-api --since "5 minutes ago" ``` --- ## 📈 Scaling Up When your single server reaches capacity, consider: 1. **Vertical Scaling:** Upgrade CPU/RAM 2. **Database Separation:** Move PostgreSQL to dedicated server 3. **Distributed Deployment:** See [Distributed Installation Guide](distributed-overview.md) ### Capacity Indicators (Time to Scale) | Metric | Warning | Critical | |--------|---------|----------| | CPU Usage | > 70% sustained | > 85% | | RAM Usage | > 80% | > 90% | | Concurrent Calls | > 100 | > 150 | | Database Connections | > 150 | > 180 | --- ## 📊 Installation Summary | Component | Location | Port | |-----------|----------|------| | Admin Dashboard | `/var/www/softswitch/web` | 443 (/admin) | | User Portal | `/var/www/softswitch/portal` | 443 (/portal) | | Switchboard | `/var/www/softswitch/switchboard` | 443 (/switchboard) | | API | `/var/www/softswitch/api` | 3000 | | Monitoring WS | `/var/www/softswitch/monitoring-api` | 3001 | | PostgreSQL | System service | 5432 | | Telephony Server | `/etc/freeswitch` | 5060/5061 | | Credentials | `/etc/softswitch/db-credentials` | - | --- *Next: [Distributed Deployment Overview](distributed-overview.md)*