Before the installer runs
Use a dedicated supported Linux host or virtual machine. Decide the public management hostname, SIP hostname and media address before generating certificates.
A production install must not reuse example passwords, development secrets or loopback-only port mappings.
- Reserve TCP 443, SIP UDP/TCP/TLS ports, WSS and the configured RTP range.
- Create forward and reverse DNS where the carrier requires it.
- Confirm NTP, outbound HTTPS and a backup destination independent from the PBX host.
- Document the emergency service address and validated caller identity.
Preflight and first run
The supported installer performs host, port, storage and dependency checks before it changes the system. It generates unique secrets and stores only references in the runtime configuration.
The first-run wizard creates the platform owner, default tenant, timezone and certificate policy, then applies versioned database migrations.
Acceptance gate
Do not treat a successful container start as production acceptance. Register two endpoints and exercise internal, inbound, outbound, emergency and remote-hangup paths.
- Confirm two-way RTP and final BYE propagation.
- Download a SIP diagnostic and, when licensed, a PCAP for one test call.
- Create a backup and restore it into a clean disposable environment.
- Save carrier, emergency and rollback evidence with the installation record.