Ornate PBX Version 1.0.0-dev · build 202609281733

Install Ornate PBX

Start with a new server that has only the operating system installed. Everything else — Asterisk, the panel, the database, certificates, firewall and background services — is installed by the installer.

Requirements

Log in to the server

Log in via SSH to the server.

If you are using a private key to log in, the SSH command would be:

ssh -i path_to_your_private_key root@yourIpAddress

If you are using a password to log in, the SSH command would be:

ssh root@yourIpAddress

Update the system

Before running the installer, update the system and install the required packages.

export DEBIAN_FRONTEND=noninteractive NEEDRESTART_MODE=a
apt update && apt -y -o Dpkg::Options::=--force-confold upgrade && apt -y install curl wget sudo

If the update installed a new kernel, run reboot, wait a minute and log in again.

Run the installer

Run the installer with your preferred setup.

The installer downloads Ornate PBX, checks it and prints a link like http://yourIpAddress:8800/?t=…. Open it in your browser:

The setup page uses TCP port 8800. If your provider has its own firewall (security group), open 8800 during the setup, or use the SSH tunnel the installer prints. You can close SSH once the link is shown. Keep the link private.

After the install

Ports

The installer sets up the server's firewall. If your provider has its own firewall, open the same ports there.

PortUse
22/tcpSSH
80, 443/tcp, 443/udpPanel, apps, WebRTC, certificate renewal
5080/udp+tcp, 8060/tcpSIP for phones and softphones
10000–20000/udpCall audio (RTP)
3478/udp+tcp, 5349/tcp, 30000–31000/udpTURN for apps and browsers behind strict NAT
5060Closed, except for addresses allowed under Panel → SIP firewall (carriers)
8800/tcpWeb setup only, closed when the setup is closed

What gets installed

PartDetails
Webnginx, PHP 8.4-FPM with all needed extensions, Composer, Let's Encrypt with automatic renewal
DataPercona Server 8.4 (MySQL), Redis
TelephonyAsterisk 22 LTS built from source (PJSIP realtime over ODBC, G.722, WebRTC), coturn (TURN)
VoicePiper neural text-to-speech, espeak, ffmpeg and sox
BackgroundSupervisor: FastAGI, queue worker, Reverb, AMI listener, Node.js push server; cron scheduler
Securityufw firewall, fail2ban against SIP password guessing, SIP firewall sync
Toolornate-pbx: status, doctor, backup, restore, update, reconfigure

Update an installed server

A database backup is made first.

If something fails

Everything is logged to /var/log/ornate-pbx-install.log. Fix the cause (usually DNS or a closed port) and run the installer again: finished steps are skipped. Let's Encrypt needs the host name to point to the server before the install.

Release ornate-pbx-1.0.0-dev-202609281733.tar.gz · 3.0M · 28 Sep 2026, 17:33 UTC
SHA256 66b8f811796659e680c08f930fad727cd90b2d9b8015c477593b8223ef1280c8