π³ Part 14: Deploying Ring2All BSS (Carrier Billing, Real-Time OCS & Customer Store Portal) on Debian 13
Welcome to the fourteenth installment of our βDebian 13 Clustering & Distributionβ series. In previous guides, we covered the deployment of custom APT repositories, FreeSWITCH Class 5 nodes (Ring2All PBX), Kamailio Class 4 perimeter gateways (Ring2All SBC), and high-availability database clusters. In this guide, we complete the carrier ecosystem by deploying Ring2All BSS (Business Support System) on Debian 13 (Trixie). We will explore how modern telecom carriers decouple back-office billing operations from customer-facing storefronts, walk through single-server and distributed DMZ topologies, configure real-time Online Charging System (OCS) engines, and install the modular .deb packages (softswitch-bss-api, softswitch-bss-web, softswitch-bss-client, and softswitch-bss-all).
ποΈ Architectural Overview: The Carrier BSS Model
Section titled βποΈ Architectural Overview: The Carrier BSS ModelβIn Tier-1 and wholesale telecom architectures (such as PortaOne PortaBilling, Telnyx, Twilio, and Amdocs), the Business Support System (BSS) serves as the monetization and commercial intelligence engine. It translates raw network events (SIP INVITEs, Call Detail Records, RTP sessions) into monetized transactions, enforces prepaid balance limits in real time, and exposes customer self-service capabilities.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ TIER-1 CARRIER BSS TOPOLOGY βββββββββββββββββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββββββββββββ€β PUBLIC EDGE / DMZ β INTERNAL MANAGEMENT LAN ββ (Customer Portal / Store / Self-Care) β (BSS Admin / Real-Time OCS / Databases) ββ β ββ ββββββββββββββββββββββββββββββββββ β ββββββββββββββββββββββββββββββββββββββββββ ββ β softswitch-bss-client β β β softswitch-bss-web β ββ β (Customer Store / Portal) β β β (Back-Office Admin) β ββ β Host: store.carrier.com β β β Host: bss-admin.carrier.com β ββ βββββββββββββββββ¬βββββββββββββββββ β βββββββββββββββββββββ¬βββββββββββββββββββββ ββ β β β ββ β HTTPS REST API β β Local Reverse Proxy ββ βΌ β βΌ ββ ββββββββββββββββββββββββββββββββββ β ββββββββββββββββββββββββββββββββββββββββββ ββ β Nginx Edge Proxy / WAF β β β softswitch-bss-api β ββ β Allows ONLY: /api/client/* βββββΌββ>β (Fastify Core Engine) β ββ β Blocks: /api/v1/users, etc. β β β Listens: 127.0.0.1:3002 β ββ ββββββββββββββββββββββββββββββββββ β βββββββββββββββββββββ¬βββββββββββββββββββββ ββ β β ββ β βΌ ββ β ββββββββββββββββββββββββββββββββββββββββββ ββ β β PostgreSQL 17 HA Cluster β ββ β β (customers, wallets, rates, ocs_cdrs)β ββ β ββββββββββββββββββββββββββββββββββββββββββ βββββββββββββββββββββββββββββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββββββββββββββCore Tenets of the Ring2All BSS Architecture:
Section titled βCore Tenets of the Ring2All BSS Architecture:β- Separation of Admin and Storefront:
- Back-Office Admin (
softswitch-bss-web): Confined to internal management subnets or secure VPNs. Telecom operators manage rate decks, customer accounts, telecom nodes (Ring2All SBC / PBX), and wholesale carrier margins. - Customer Self-Care Store (
softswitch-bss-client): Exposed to the public internet or DMZ. Subscribers purchase VoIP subscription plans, order virtual DID telephone numbers, top up their prepaid wallet using Stripe, and review real-time CDR usage.
- Back-Office Admin (
- Zero Database Exposure at the Perimeter:
- The customer portal is a 100% client-side React 18 Single Page Application (SPA). It never contains direct PostgreSQL database credentials or network access.
- DMZ Perimeter Reverse Proxy Filtering:
- The customer edge reverse proxy passes only authenticated customer endpoints (
/api/client/*) and public branding metadata, while aggressively issuing403 Forbiddenfor administrative routes (/api/v1/users,/api/v1/telecom-nodes,/api/v1/firewall,/api/v1/mcp-roles).
- The customer edge reverse proxy passes only authenticated customer endpoints (
- Real-Time Online Charging System (OCS):
- Evaluates call authorization, balance verification, and destination pricing using high-speed in-memory caching (Redis) and sub-millisecond PostgreSQL rating queries.
π¦ Modular Debian Package Breakdown
Section titled βπ¦ Modular Debian Package BreakdownβRing2All BSS is distributed via four decoupled Debian packages:
| Package Name | Function | Staging Path | Dependencies |
|---|---|---|---|
softswitch-bss-api |
Fastify 4 / Node.js 22 OCS rating engine, customer API, billing daemon, background CDR synchronizer | /var/www/softswitch/bss/api |
nodejs (>= 22), postgresql-client |
softswitch-bss-web |
React 18 administrative back-office web application | /var/www/softswitch/bss/web |
nginx |
softswitch-bss-client |
React 18 customer-facing self-care store & billing portal | /var/www/softswitch/bss/client |
nginx |
softswitch-bss-all |
Metapackage for single-server all-in-one deployments | N/A | Depends on the 3 packages above |
π Deployment Topologies
Section titled βπ Deployment TopologiesβTopology A: Single-Server All-in-One Deployment
Section titled βTopology A: Single-Server All-in-One DeploymentβIdeal for small to mid-sized telecom operators. The API daemon, Admin UI, and Customer Store run on the same Debian 13 host:
- Admin UI: Accessed at
https://bss.carrier.com(or port 443). - Customer Store: Accessed at
https://bss.carrier.com:8443(or dedicated virtual hoststore.carrier.com). - BSS API: Runs locally on
127.0.0.1:3002, reverse-proxied by Nginx.
Topology B: Distributed Multi-Server DMZ Deployment
Section titled βTopology B: Distributed Multi-Server DMZ DeploymentβRecommended for enterprise carriers and public cloud environments:
- Server 1 (Internal LAN / Billing Core):
- Runs
softswitch-bss-api,softswitch-bss-web, and PostgreSQL 17. - Not reachable directly from the public internet. Accessible only via corporate VPN or WireGuard tunnel.
- Runs
- Server 2 (Public Edge / DMZ Store):
- Runs
softswitch-bss-clientand Nginx. - Serves static assets for the Customer Store and proxies
/api/client/across the internal network to Server 1.
- Runs
π οΈ Installation Step-by-Step (Debian 13)
Section titled βπ οΈ Installation Step-by-Step (Debian 13)βStep 1: System Preparation & Prerequisites
Section titled βStep 1: System Preparation & PrerequisitesβOn your target Debian 13 server, install foundational dependencies:
sudo apt updatesudo apt install -y curl wget gnupg2 openssl nginx postgresql-clientEnsure Node.js 22 LTS is available:
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -sudo apt install -y nodejsStep 2: Database Initialization
Section titled βStep 2: Database InitializationβRing2All BSS uses PostgreSQL 17 with the ss_billing database. Connect to your database cluster or local PostgreSQL instance:
# Create the billing database and assign permissionssudo -u postgres psql << 'EOF'CREATE DATABASE ss_billing;GRANT ALL PRIVILEGES ON DATABASE ss_billing TO ss_db_user;\c ss_billingCREATE EXTENSION IF NOT EXISTS "uuid-ossp";CREATE EXTENSION IF NOT EXISTS "pgcrypto";EOFEnsure /etc/softswitch/db-credentials contains the connection parameters:
sudo mkdir -p /etc/softswitchcat << 'EOF' | sudo tee /etc/softswitch/db-credentialsDB_HOST=127.0.0.1DB_PORT=5432DB_USER=ss_db_userDB_PASSWORD=Letacla01EOFsudo chmod 600 /etc/softswitch/db-credentialsStep 3: Installing the Ring2All BSS Packages
Section titled βStep 3: Installing the Ring2All BSS PackagesβFrom your configured Ring2All APT repository, install the complete suite:
# For an All-in-One server:sudo apt updatesudo apt install -y softswitch-bss-all
# OR for a separated DMZ Customer Store server:# sudo apt install -y softswitch-bss-clientDuring package installation, the softswitch-bss-api post-installation script automatically:
- Verifies the database connection and seeds the complete BSS schema (customers, wallets, plans, rate cards, subscriptions, and transactions).
- Generates a cryptographically secure
JWT_SECRETin/etc/softswitch/bss-api.env. - Activates and starts the
softswitch-bss-api.servicesystemd daemon.
Step 4: Verifying the API Service
Section titled βStep 4: Verifying the API ServiceβInspect the background daemon:
sudo systemctl status softswitch-bss-apiTest the internal health check endpoint:
curl -s http://127.0.0.1:3002/healthExpected Output:
{"status":"ok","timestamp":"2026-09-11T23:00:00.000Z"}π Nginx Reverse Proxy & DMZ Perimeter Hardening
Section titled βπ Nginx Reverse Proxy & DMZ Perimeter Hardeningβ1. Back-Office Admin Configuration (/etc/nginx/sites-available/softswitch-bss-web)
Section titled β1. Back-Office Admin Configuration (/etc/nginx/sites-available/softswitch-bss-web)βserver { listen 80; server_name bss-admin.carrier.com; return 301 https://$host$request_uri;}
server { listen 443 ssl default_server; http2 on; server_name bss-admin.carrier.com;
ssl_certificate /etc/nginx/ssl/nginx.crt; ssl_certificate_key /etc/nginx/ssl/nginx.key;
# Core BSS Fastify API Proxy location /api/ { proxy_pass http://127.0.0.1:3002; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection 'upgrade'; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; }
# Admin Web SPA location / { root /var/www/softswitch/bss/web; index index.html; try_files $uri $uri/ /index.html; }}2. Customer Store DMZ Configuration (/etc/nginx/sites-available/softswitch-bss-client)
Section titled β2. Customer Store DMZ Configuration (/etc/nginx/sites-available/softswitch-bss-client)βIn a decoupled DMZ setup, the Customer Store Nginx configuration enforces perimeter security:
server { listen 443 ssl; http2 on; server_name store.carrier.com;
ssl_certificate /etc/nginx/ssl/nginx.crt; ssl_certificate_key /etc/nginx/ssl/nginx.key;
# ββ CARRIER PERIMETER FILTER: BLOCK ADMINISTRATIVE APIS ββ location ~* ^/api/(v1/)?(users|telecom-nodes|firewall|mcp|system|database|backups|migrations) { return 403 '{"error":"Forbidden: Administrative APIs are not accessible via customer perimeter"}'; add_header Content-Type application/json; }
# ββ ALLOWED CUSTOMER APIS PROXY ββ location /api/ { # If API is on a remote internal server, specify its IP: http://10.10.0.5:3002 proxy_pass http://127.0.0.1:3002; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection 'upgrade'; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; }
# Customer Store SPA location / { root /var/www/softswitch/bss/client; index index.html; try_files $uri $uri/ /index.html; }}Enable both sites and reload Nginx:
sudo ln -sf /etc/nginx/sites-available/softswitch-bss-web /etc/nginx/sites-enabled/sudo ln -sf /etc/nginx/sites-available/softswitch-bss-client /etc/nginx/sites-enabled/sudo nginx -t && sudo systemctl reload nginxπ Interconnecting with Ring2All SBC & Ring2All PBX
Section titled βπ Interconnecting with Ring2All SBC & Ring2All PBXβRing2All BSS acts as the central financial arbiter between your Session Border Controllers (Ring2All SBC) and Class 5 Media Servers (Ring2All PBX):
βββββββββββββββββββββββββββββββββ β Ring2All BSS β β (Rating, Wallet, Plans) β βββββββββ¬ββββββββββββββββ¬ββββββββ β β SIP LCR & OCS Balance β β Tenant & Extension Sync βΌ βΌ βββββββββββββββββββββββ βββββββββββββββββββββββ β Ring2All SBC β β Ring2All PBX β β (Kamailio 6.x) β β (FreeSWITCH 1.11.x) β βββββββββββββββββββββββ βββββββββββββββββββββββ- Ring2All SBC Integration:
- In the BSS Admin UI under Telecom Nodes, register your Ring2All SBC node (
http://10.9.0.1:3003or public IP). - The OCS automatically syncs customer prepaid balances to Kamailio memory tables (
htable), preventing calls when balances are exhausted.
- In the BSS Admin UI under Telecom Nodes, register your Ring2All SBC node (
- Ring2All PBX Integration:
- Register your FreeSWITCH Class 5 nodes (
http://10.9.0.2:3000). - When a customer purchases an extension or phone line in the Customer Store, Ring2All BSS automatically issues REST calls to Ring2All PBX to provision the tenant and extension.
- Register your FreeSWITCH Class 5 nodes (
- Stripe Payment Gateway:
- In
/etc/softswitch/bss-api.env, add your Stripe production credentials:Terminal window STRIPE_SECRET_KEY=sk_live_...STRIPE_WEBHOOK_SECRET=whsec_... - Restart the daemon:
sudo systemctl restart softswitch-bss-api. Customers can immediately add funds with credit cards.
- In
π Diagnostics & Troubleshooting
Section titled βπ Diagnostics & Troubleshootingβ| Issue | Verification Command | Solution |
|---|---|---|
| API wonβt start | journalctl -u softswitch-bss-api -n 50 --no-pager |
Verify DATABASE_URL in /etc/softswitch/bss-api.env and ensure PostgreSQL is running. |
| Customer Store shows 403 on API | tail -f /var/log/nginx/softswitch_bss_client_error.log |
Verify you are not invoking administrative routes from the store front. |
| CORS errors in multi-server setup | Check CORS_ORIGINS in /etc/softswitch/bss-api.env |
Add the client portal domain to the allowed origins list. |
| Stripe webhooks failing | curl -X POST http://127.0.0.1:3002/api/v1/client/payments/webhook |
Ensure STRIPE_WEBHOOK_SECRET matches your Stripe Dashboard endpoint configuration. |
You now have a production-ready, carrier-grade Ring2All BSS platform deployed on Debian 13 (Trixie), with secure separation between your internal administrative control plane and your public-facing customer self-care store.

