]> git.proxmox.com Git - pmg-docs.git/blame - pmg-installation.adoc
installation: add proxmox-mailgateway-container
[pmg-docs.git] / pmg-installation.adoc
CommitLineData
03c03402
DM
1Installation
2============
3
4{pmg} is based on Debian and comes with an installation CD-ROM
5which includes a complete Debian ("stretch" for version 5.x) system as
6well as all necessary {pmg} packages.
7
8The installer just asks you a few questions, then partitions the local
9disk(s), installs all required packages, and configures the system
10including a basic network setup. You can get a fully functional system
11within a few minutes. This is the preferred and recommended
12installation method.
13
14Alternatively, {pmg} can be installed on top of an existing Debian
15system. This option is only recommended for advanced users since
16it requires more detailed knowledge about {pmg} and Debian.
17
18Using the {pmg} Installation CD-ROM
19-----------------------------------
20
b2d388d4
DM
21You can download the ISO from http://www.proxmox.com. It includes the
22following:
03c03402
DM
23
24* Complete operating system (Debian Linux, 64-bit)
25
b2d388d4
DM
26* The {pmg} installer, which partitions the hard drive(s) with ext4,
27 ext3, xfs or ZFS and installs the operating system.
03c03402
DM
28
29* Linux kernel
30
31* Postfix MTA, ClamAV, Spamassassin and the {pmg} toolset
32
33* Web based management interface for using the toolset
34
b2d388d4
DM
35Please burn the downloaded ISO image to a CD or create a
36xref:create_bootable_usb[bootable USB stick].
37
38Then insert the installation CD-ROM on the physical host where you want
39to install {pmg} and boot from that drive. Immediately afterwards you
40can choose the following menu options:
03c03402
DM
41
42image::images/installer/pmg-grub-menu.png[]
43
44Install {pmg}::
45
46Start normal installation.
47
48Install {pmg} (Debug mode)::
49
50Start installation in debug mode. It opens a shell console at several
51installation steps, so that you can debug things if something goes
52wrong. Please press `CTRL-D` to exit those debug consoles and continue
53installation. This option is mostly for developers and not meant for
54general use.
55
56Rescue Boot::
57
58This option allows you to boot an existing installation. It searches
59all attached hard disks and, if it finds an existing installation,
60boots directly into that disk using the existing Linux kernel. This
61can be useful if there are problems with the boot block (grub), or the
62BIOS is unable to read the boot block from the disk.
63
64Test Memory::
65
66Runs `memtest86+`. This is useful to check if your memory is
67functional and error free.
68
dc69da07 69You normally select *Install {pmg}* to start the installation.
03c03402 70
dc69da07 71image::images/installer/pmg-select-target-disk.png[]
03c03402 72
dc69da07
DM
73First step ist to read our EULA (End User License Agreement). After
74that you get prompted to select the target hard disk(s).
03c03402
DM
75
76NOTE: By default, the complete server is used and all existing data is
77removed.
78
03c03402
DM
79The `Options` button lets you select the target file system, which
80defaults to `ext4`. The installer uses LVM if you select `ext3`,
81`ext4` or `xfs` as file system, and offers additional option to
82restrict LVM space (see <<advanced_lvm_options,below>>)
83
84If you have more than one disk, you can also use ZFS as file system.
85ZFS supports several software RAID levels, so this is specially useful
86if you do not have a hardware RAID controller. The `Options` button
87lets you select the ZFS RAID level, and you can choose disks there.
88
dc69da07
DM
89image::images/installer/pmg-select-location.png[]
90
91The next page just ask for basic configuration options like your
92location, the time zone and keyboard layout. The location is used to
93select a download server near you to speedup updates. The installer is
94usually able to auto detect those setting, so you only need to change
95them in rare situations when auto detection fails, or when you want to
96use some special keyboard layout not commonly used in your country.
97
98image::images/installer/pmg-set-password.png[]
99
100You then need to specify an email address and the superuser (root)
101password. The password must have at least 5 characters, but we highly
102recommend to use stronger passwords - here are some guidelines:
103
104- Use a minimum password length of 12 to 14 characters.
105
106- Include lowercase and uppercase alphabetic characters, numbers and symbols.
107
108- Avoid character repetition, keyboard patterns, dictionary words, letter or number sequences, usernames, relative or pet names, romantic links (current or past) and biographical information (e.g., ID numbers, ancestors' names or dates).
109
110It is sometimes necessary to send notification to the system
111administrator, for example:
112
113- Information about available package updates.
114
115- Error messages from periodic CRON jobs.
116
117All those notification mails will be sent to the specified email
118address.
119
120image::images/installer/pmg-setup-network.png[]
03c03402
DM
121
122The last step is the network configuration. Please note that you can
123use either IPv4 or IPv6 here, but not both. If you want to configure a
124dual stack node, you can easily do that after installation.
125
126If you press `Next` now, installation starts to format disks, and
dc69da07
DM
127copies packages to the target.
128
129image::images/installer/pmg-installation.png[]
130
131Copying packages usually takes a few minutes. Please wait until that
132is finished, then reboot the server.
03c03402
DM
133
134Further configuration is done via the Proxmox web interface. Just
135point your browser to the IP address given during installation
136(https://youripaddress:8006).
137
b5b01ac3
DM
138image::images/screenshot/pmg-gui-login-window.png[]
139
b2d388d4
DM
140. Login and upload subscription key.
141+
03c03402
DM
142NOTE: Default login is "root" and the root password is
143defined during the installation process.
144
b2d388d4
DM
145. Check the IP configuration and hostname.
146
147. Check and save the Time Zone.
148
149. Check your xref:firewall_settings[Firewall settings].
150
151. Configure {pmg} to forward the incoming SMTP traffic to your Mail
152server ('Configuration/Mail Proxy/Default Relay') - 'Default
153Relay' is your e-mail server.
154
155. Configure your e-mail server to send all outgoing messages through
303ee757 156your {pmg} ('Smart Host', port 26 by default).
b2d388d4
DM
157
158For detailed deployment scenarios see chapter
159xref:chapter_deployment[Planning for Deployment].
160
161If the installation succeeds you have to route all your incoming and
162outgoing e-mail traffic to the Mail Gateway. For incoming traffic you
163have to configure your firewall and/or DNS settings. For outgoing
164traffic you need to change the existing e-mail server configuration.
165
03c03402
DM
166
167[[advanced_lvm_options]]
168Advanced LVM Configuration Options
169~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
170
171The installer creates a Volume Group (VG) called `pmg`, and additional
172Logical Volumes (LVs) called `root` and `swap`. The size of
173those volumes can be controlled with:
174
175`hdsize`::
176
177Defines the total HD size to be used. This way you can save free
178space on the HD for further partitioning (i.e. for an additional PV
179and VG on the same hard disk that can be used for LVM storage).
180
181`swapsize`::
182
183Defines the size of the `swap` volume. The default is the size of the
184installed memory, minimum 4 GB and maximum 8 GB. The resulting value cannot
185be greater than `hdsize/8`.
186
03c03402
DM
187`minfree`::
188
2729e8b8 189Defines the amount of free space left in LVM volume group `pmg`.
03c03402
DM
190With more than 128GB storage available the default is 16GB, else `hdsize/8`
191will be used.
192+
193NOTE: LVM requires free space in the VG for snapshot creation (not
194required for lvmthin snapshots).
195
196
197ZFS Performance Tips
198~~~~~~~~~~~~~~~~~~~~
199
200ZFS uses a lot of memory, so it is best to add additional RAM if you
201want to use ZFS. A good calculation is 4GB plus 1GB RAM for each TB
202RAW disk space.
203
204ZFS also provides the feature to use a fast SSD drive as write cache. The
205write cache is called the ZFS Intent Log (ZIL). You can add that after
206installation using the following command:
207
208 zpool add <pool-name> log </dev/path_to_fast_ssd>
209
210
3372775f
DM
211include::pmg-usbstick.adoc[]
212
213
03c03402
DM
214Install {pmg} on Debian
215-----------------------
216
217{pmg} ships as a set of Debian packages, so you can install it
218on top of a normal Debian installation. After configuring the
219repositories, you need to run:
220
221[source,bash]
222----
223apt-get update
224apt-get install proxmox-mailgateway
225----
226
227Installing on top of an existing Debian installation looks easy, but
228it presumes that you have correctly installed the base system, and you
229know how you want to configure and use the local storage. Network
230configuration is also completely up to you.
231
232NOTE: In general, this is not trivial, especially when you use LVM or
233ZFS.
e3eaa56a
DM
234
235
5991f9eb
SI
236Install {pmg} as a Debian-based Container
237-----------------------------------------
238
239The full functionality of {pmg} can also run on top of a Debian-based LXC
240instance. In order to keep the set of installed software, and thus the
241necessary updates, minimal you can install the `proxmox-mailgateway-container`
242meta-package, after configuring the repositories. You need to run:
243
244[source,bash]
245----
246apt-get update
247apt-get install proxmox-mailgateway-container
248----
249
250Additionally a ready-to-use appliance-template is available in the Proxmox VE
251appliance manager in the category `mail`.
252
253
e3eaa56a
DM
254[[pmg_package_repositories]]
255Package Repositories
256--------------------
257
258All {debian} based systems use
259http://en.wikipedia.org/wiki/Advanced_Packaging_Tool[APT] as package
260management tool. The list of repositories is defined in
261`/etc/apt/sources.list` and `.list` files found inside
262`/etc/apt/sources.d/`. Updates can be installed directly using
263`apt-get`, or via the GUI.
264
265Apt `sources.list` files list one package repository per line, with
266the most preferred source listed first. Empty lines are ignored, and a
267`#` character anywhere on a line marks the remainder of that line as a
268comment. The information available from the configured sources is
269acquired by `apt-get update`.
270
271.File `/etc/apt/sources.list`
272----
273deb http://ftp.debian.org/debian stretch main contrib
274
aedc8192
SI
275deb http://ftp.debian.org/debian stretch-updates main contrib
276
e3eaa56a
DM
277# security updates
278deb http://security.debian.org stretch/updates main contrib
279----
280
281In addition, {pmg} provides three different package repositories.
282
283
284{pmg} Enterprise Repository
285~~~~~~~~~~~~~~~~~~~~~~~~~~~
286
287This is the default, stable and recommended repository, available for
288all {pmg} subscription users. It contains the most stable packages,
289and is suitable for production use. The `pmg-enterprise` repository is
290enabled by default:
291
292.File `/etc/apt/sources.list.d/pmg-enterprise.list`
293----
294deb https://enterprise.proxmox.com/debian/pmg stretch pmg-enterprise
295----
296
297As soon as updates are available, the `root@pam` user is notified via
298email about the available new packages. On the GUI, the change-log of
299each package can be viewed (if available), showing all details of the
300update. So you will never miss important security fixes.
301
302Please note that and you need a valid subscription key to access this
303repository. We offer different support levels, and you can find further
d2ae160b 304details at {pricing-url}.
e3eaa56a
DM
305
306NOTE: You can disable this repository by commenting out the above line
307using a `#` (at the start of the line). This prevents error messages
308if you do not have a subscription key. Please configure the
309`pmg-no-subscription` repository in that case.
310
311
312{pmg} No-Subscription Repository
313~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
314
315As the name suggests, you do not need a subscription key to access
316this repository. It can be used for testing and non-production
317use. Its not recommended to run on production servers, as these
318packages are not always heavily tested and validated.
319
320We recommend to configure this repository in `/etc/apt/sources.list`.
321
322.File `/etc/apt/sources.list`
323----
324deb http://ftp.debian.org/debian stretch main contrib
325
326# PMG pmg-no-subscription repository provided by proxmox.com,
327# NOT recommended for production use
328deb http://download.proxmox.com/debian/pmg stretch pmg-no-subscription
329
330# security updates
331deb http://security.debian.org stretch/updates main contrib
332----
333
334
335{pmg} Test Repository
336~~~~~~~~~~~~~~~~~~~~~
337
338Finally, there is a repository called `pmgtest`. This one contains the
339latest packages and is heavily used by developers to test new
340features. As usual, you can configure this using
341`/etc/apt/sources.list` by adding the following line:
342
343.sources.list entry for `pmgtest`
344----
345deb http://download.proxmox.com/debian/pmg stretch pmgtest
346----
347
348WARNING: the `pmgtest` repository should (as the name implies) only be used
349for testing new features or bug fixes.
350
351
352SecureApt
353~~~~~~~~~
354
355We use GnuPG to sign the `Release` files inside those repositories,
356and APT uses that signatures to verify that all packages are from a
357trusted source.
358
359The key used for verification is already installed if you install from
360our installation CD. If you install by other means, you can manually
361download the key with:
362
363 # wget http://download.proxmox.com/debian/proxmox-ve-release-5.x.gpg -O /etc/apt/trusted.gpg.d/proxmox-ve-release-5.x.gpg
364
365Please verify the checksum afterwards:
366
367----
368# sha512sum /etc/apt/trusted.gpg.d/proxmox-ve-release-5.x.gpg
369ffb95f0f4be68d2e753c8875ea2f8465864a58431d5361e88789568673551501ae574283a4e0492f17d79dc67edfb173a56a6304dea39e01f249ebdabc9f074a /etc/apt/trusted.gpg.d/proxmox-ve-release-5.x.gpg
370----
371
372or
373
374----
375# md5sum /etc/apt/trusted.gpg.d/proxmox-ve-release-5.x.gpg
376511d36d0f1350c01c42a3dc9f3c27939 /etc/apt/trusted.gpg.d/proxmox-ve-release-5.x.gpg
377----
378
379