Install Ornate PBX
Start with a new server that has only the operating system installed. Everything else — Asterisk, the panel, the database, certificates, firewall and background services — is installed by the installer.
Requirements
- Ubuntu 24.04 LTS (recommended), Ubuntu 22.04 LTS or Debian 12, x86_64 or arm64.
- At least 2 GB RAM and 15 GB disk (4 GB RAM and 50 GB disk for 100+ extensions).
- A host name (e.g.
pbx.example.com) with an A record pointing to the server's IP. - A server of its own: no CloudPanel, cPanel, Plesk or other PBX on it.
Log in to the server
Log in via SSH to the server.
If you are using a private key to log in, the SSH command would be:
ssh -i path_to_your_private_key root@yourIpAddress
If you are using a password to log in, the SSH command would be:
ssh root@yourIpAddress
Update the system
Before running the installer, update the system and install the required packages.
export DEBIAN_FRONTEND=noninteractive NEEDRESTART_MODE=a apt update && apt -y -o Dpkg::Options::=--force-confold upgrade && apt -y install curl wget sudo
If the update installed a new kernel, run reboot, wait a minute and log in again.
Run the installer
Run the installer with your preferred setup.
The installer downloads Ornate PBX, checks it and prints a link like http://yourIpAddress:8800/?t=…. Open it in your browser:
- the page checks the server (system, memory, disk, ports) and asks for the host name, admin email, company name and time zone;
- press Start installation and follow every step with a live log (20–40 minutes);
- at the end it shows the panel link, admin email and password. Press Close setup when you are done.
The installer asks for the host name and admin email, shows what it will install and asks to continue. The install takes 20–40 minutes, most of it building Asterisk. If the SSH connection drops, run sudo bash install.sh again: finished steps are skipped.
Answer the questions in advance (optional)
After the install
- Open
https://your-host-name/login, sign in and change the password under Account. The first password is also in/root/ornate-pbx-credentials.txt. - Add your carrier under Trunks and allow its IP under SIP firewall, then create extensions and routes.
- On the server:
ornate-pbx doctorchecks everything,ornate-pbx backup-schedule onturns on daily backups.
Ports
The installer sets up the server's firewall. If your provider has its own firewall, open the same ports there.
| Port | Use |
|---|---|
| 22/tcp | SSH |
| 80, 443/tcp, 443/udp | Panel, apps, WebRTC, certificate renewal |
| 5080/udp+tcp, 8060/tcp | SIP for phones and softphones |
| 10000–20000/udp | Call audio (RTP) |
| 3478/udp+tcp, 5349/tcp, 30000–31000/udp | TURN for apps and browsers behind strict NAT |
| 5060 | Closed, except for addresses allowed under Panel → SIP firewall (carriers) |
| 8800/tcp | Web setup only, closed when the setup is closed |
What gets installed
| Part | Details |
|---|---|
| Web | nginx, PHP 8.4-FPM with all needed extensions, Composer, Let's Encrypt with automatic renewal |
| Data | Percona Server 8.4 (MySQL), Redis |
| Telephony | Asterisk 22 LTS built from source (PJSIP realtime over ODBC, G.722, WebRTC), coturn (TURN) |
| Voice | Piper neural text-to-speech, espeak, ffmpeg and sox |
| Background | Supervisor: FastAGI, queue worker, Reverb, AMI listener, Node.js push server; cron scheduler |
| Security | ufw firewall, fail2ban against SIP password guessing, SIP firewall sync |
| Tool | ornate-pbx: status, doctor, backup, restore, update, reconfigure |
Update an installed server
A database backup is made first.
If something fails
Everything is logged to /var/log/ornate-pbx-install.log. Fix the cause (usually DNS or a closed port) and run the installer again: finished steps are skipped. Let's Encrypt needs the host name to point to the server before the install.