]> git.proxmox.com Git - pmg-docs.git/blob - pmg-installation.adoc
bump version to 5.1-2
[pmg-docs.git] / pmg-installation.adoc
1 Installation
2 ============
3
4 {pmg} is based on Debian and comes with an installation CD-ROM
5 which includes a complete Debian ("stretch" for version 5.x) system as
6 well as all necessary {pmg} packages.
7
8 The installer just asks you a few questions, then partitions the local
9 disk(s), installs all required packages, and configures the system
10 including a basic network setup. You can get a fully functional system
11 within a few minutes. This is the preferred and recommended
12 installation method.
13
14 Alternatively, {pmg} can be installed on top of an existing Debian
15 system. This option is only recommended for advanced users since
16 it requires more detailed knowledge about {pmg} and Debian.
17
18 Using the {pmg} Installation CD-ROM
19 -----------------------------------
20
21 You can download the ISO from http://www.proxmox.com. It includes the
22 following:
23
24 * Complete operating system (Debian Linux, 64-bit)
25
26 * The {pmg} installer, which partitions the hard drive(s) with ext4,
27 ext3, xfs or ZFS and installs the operating system.
28
29 * Linux kernel
30
31 * Postfix MTA, ClamAV, Spamassassin and the {pmg} toolset
32
33 * Web based management interface for using the toolset
34
35 Please burn the downloaded ISO image to a CD or create a
36 xref:create_bootable_usb[bootable USB stick].
37
38 Then insert the installation CD-ROM on the physical host where you want
39 to install {pmg} and boot from that drive. Immediately afterwards you
40 can choose the following menu options:
41
42 image::images/installer/pmg-grub-menu.png[]
43
44 Install {pmg}::
45
46 Start normal installation.
47
48 Install {pmg} (Debug mode)::
49
50 Start installation in debug mode. It opens a shell console at several
51 installation steps, so that you can debug things if something goes
52 wrong. Please press `CTRL-D` to exit those debug consoles and continue
53 installation. This option is mostly for developers and not meant for
54 general use.
55
56 Rescue Boot::
57
58 This option allows you to boot an existing installation. It searches
59 all attached hard disks and, if it finds an existing installation,
60 boots directly into that disk using the existing Linux kernel. This
61 can be useful if there are problems with the boot block (grub), or the
62 BIOS is unable to read the boot block from the disk.
63
64 Test Memory::
65
66 Runs `memtest86+`. This is useful to check if your memory is
67 functional and error free.
68
69 You normally select *Install {pmg}* to start the installation.
70
71 image::images/installer/pmg-select-target-disk.png[]
72
73 First step ist to read our EULA (End User License Agreement). After
74 that you get prompted to select the target hard disk(s).
75
76 NOTE: By default, the complete server is used and all existing data is
77 removed.
78
79 The `Options` button lets you select the target file system, which
80 defaults to `ext4`. The installer uses LVM if you select `ext3`,
81 `ext4` or `xfs` as file system, and offers additional option to
82 restrict LVM space (see <<advanced_lvm_options,below>>)
83
84 If you have more than one disk, you can also use ZFS as file system.
85 ZFS supports several software RAID levels, so this is specially useful
86 if you do not have a hardware RAID controller. The `Options` button
87 lets you select the ZFS RAID level, and you can choose disks there.
88
89 image::images/installer/pmg-select-location.png[]
90
91 The next page just ask for basic configuration options like your
92 location, the time zone and keyboard layout. The location is used to
93 select a download server near you to speedup updates. The installer is
94 usually able to auto detect those setting, so you only need to change
95 them in rare situations when auto detection fails, or when you want to
96 use some special keyboard layout not commonly used in your country.
97
98 image::images/installer/pmg-set-password.png[]
99
100 You then need to specify an email address and the superuser (root)
101 password. The password must have at least 5 characters, but we highly
102 recommend to use stronger passwords - here are some guidelines:
103
104 - Use a minimum password length of 12 to 14 characters.
105
106 - Include lowercase and uppercase alphabetic characters, numbers and symbols.
107
108 - Avoid character repetition, keyboard patterns, dictionary words, letter or number sequences, usernames, relative or pet names, romantic links (current or past) and biographical information (e.g., ID numbers, ancestors' names or dates).
109
110 It is sometimes necessary to send notification to the system
111 administrator, for example:
112
113 - Information about available package updates.
114
115 - Error messages from periodic CRON jobs.
116
117 All those notification mails will be sent to the specified email
118 address.
119
120 image::images/installer/pmg-setup-network.png[]
121
122 The last step is the network configuration. Please note that you can
123 use either IPv4 or IPv6 here, but not both. If you want to configure a
124 dual stack node, you can easily do that after installation.
125
126 If you press `Next` now, installation starts to format disks, and
127 copies packages to the target.
128
129 image::images/installer/pmg-installation.png[]
130
131 Copying packages usually takes a few minutes. Please wait until that
132 is finished, then reboot the server.
133
134 Further configuration is done via the Proxmox web interface. Just
135 point your browser to the IP address given during installation
136 (https://youripaddress:8006).
137
138 image::images/screenshot/pmg-gui-login-window.png[]
139
140 . Login and upload subscription key.
141 +
142 NOTE: Default login is "root" and the root password is
143 defined during the installation process.
144
145 . Check the IP configuration and hostname.
146
147 . Check and save the Time Zone.
148
149 . Check your xref:firewall_settings[Firewall settings].
150
151 . Configure {pmg} to forward the incoming SMTP traffic to your Mail
152 server ('Configuration/Mail Proxy/Default Relay') - 'Default
153 Relay' is your e-mail server.
154
155 . Configure your e-mail server to send all outgoing messages through
156 your {pmg} ('Smart Host', port 26 by default).
157
158 For detailed deployment scenarios see chapter
159 xref:chapter_deployment[Planning for Deployment].
160
161 If the installation succeeds you have to route all your incoming and
162 outgoing e-mail traffic to the Mail Gateway. For incoming traffic you
163 have to configure your firewall and/or DNS settings. For outgoing
164 traffic you need to change the existing e-mail server configuration.
165
166
167 [[advanced_lvm_options]]
168 Advanced LVM Configuration Options
169 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
170
171 The installer creates a Volume Group (VG) called `pmg`, and additional
172 Logical Volumes (LVs) called `root` and `swap`. The size of
173 those volumes can be controlled with:
174
175 `hdsize`::
176
177 Defines the total HD size to be used. This way you can save free
178 space on the HD for further partitioning (i.e. for an additional PV
179 and VG on the same hard disk that can be used for LVM storage).
180
181 `swapsize`::
182
183 Defines the size of the `swap` volume. The default is the size of the
184 installed memory, minimum 4 GB and maximum 8 GB. The resulting value cannot
185 be greater than `hdsize/8`.
186
187 `minfree`::
188
189 Defines the amount of free space left in LVM volume group `pmg`.
190 With more than 128GB storage available the default is 16GB, else `hdsize/8`
191 will be used.
192 +
193 NOTE: LVM requires free space in the VG for snapshot creation (not
194 required for lvmthin snapshots).
195
196
197 ZFS Performance Tips
198 ~~~~~~~~~~~~~~~~~~~~
199
200 ZFS uses a lot of memory, so it is best to add additional RAM if you
201 want to use ZFS. A good calculation is 4GB plus 1GB RAM for each TB
202 RAW disk space.
203
204 ZFS also provides the feature to use a fast SSD drive as write cache. The
205 write cache is called the ZFS Intent Log (ZIL). You can add that after
206 installation using the following command:
207
208 zpool add <pool-name> log </dev/path_to_fast_ssd>
209
210
211 include::pmg-usbstick.adoc[]
212
213
214 Install {pmg} on Debian
215 -----------------------
216
217 {pmg} ships as a set of Debian packages, so you can install it
218 on top of a normal Debian installation. After configuring the
219 repositories, you need to run:
220
221 [source,bash]
222 ----
223 apt-get update
224 apt-get install proxmox-mailgateway
225 ----
226
227 Installing on top of an existing Debian installation looks easy, but
228 it presumes that you have correctly installed the base system, and you
229 know how you want to configure and use the local storage. Network
230 configuration is also completely up to you.
231
232 NOTE: In general, this is not trivial, especially when you use LVM or
233 ZFS.
234
235
236 [[pmg_package_repositories]]
237 Package Repositories
238 --------------------
239
240 All {debian} based systems use
241 http://en.wikipedia.org/wiki/Advanced_Packaging_Tool[APT] as package
242 management tool. The list of repositories is defined in
243 `/etc/apt/sources.list` and `.list` files found inside
244 `/etc/apt/sources.d/`. Updates can be installed directly using
245 `apt-get`, or via the GUI.
246
247 Apt `sources.list` files list one package repository per line, with
248 the most preferred source listed first. Empty lines are ignored, and a
249 `#` character anywhere on a line marks the remainder of that line as a
250 comment. The information available from the configured sources is
251 acquired by `apt-get update`.
252
253 .File `/etc/apt/sources.list`
254 ----
255 deb http://ftp.debian.org/debian stretch main contrib
256
257 # security updates
258 deb http://security.debian.org stretch/updates main contrib
259 ----
260
261 In addition, {pmg} provides three different package repositories.
262
263
264 {pmg} Enterprise Repository
265 ~~~~~~~~~~~~~~~~~~~~~~~~~~~
266
267 This is the default, stable and recommended repository, available for
268 all {pmg} subscription users. It contains the most stable packages,
269 and is suitable for production use. The `pmg-enterprise` repository is
270 enabled by default:
271
272 .File `/etc/apt/sources.list.d/pmg-enterprise.list`
273 ----
274 deb https://enterprise.proxmox.com/debian/pmg stretch pmg-enterprise
275 ----
276
277 As soon as updates are available, the `root@pam` user is notified via
278 email about the available new packages. On the GUI, the change-log of
279 each package can be viewed (if available), showing all details of the
280 update. So you will never miss important security fixes.
281
282 Please note that and you need a valid subscription key to access this
283 repository. We offer different support levels, and you can find further
284 details at {pricing-url}.
285
286 NOTE: You can disable this repository by commenting out the above line
287 using a `#` (at the start of the line). This prevents error messages
288 if you do not have a subscription key. Please configure the
289 `pmg-no-subscription` repository in that case.
290
291
292 {pmg} No-Subscription Repository
293 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
294
295 As the name suggests, you do not need a subscription key to access
296 this repository. It can be used for testing and non-production
297 use. Its not recommended to run on production servers, as these
298 packages are not always heavily tested and validated.
299
300 We recommend to configure this repository in `/etc/apt/sources.list`.
301
302 .File `/etc/apt/sources.list`
303 ----
304 deb http://ftp.debian.org/debian stretch main contrib
305
306 # PMG pmg-no-subscription repository provided by proxmox.com,
307 # NOT recommended for production use
308 deb http://download.proxmox.com/debian/pmg stretch pmg-no-subscription
309
310 # security updates
311 deb http://security.debian.org stretch/updates main contrib
312 ----
313
314
315 {pmg} Test Repository
316 ~~~~~~~~~~~~~~~~~~~~~
317
318 Finally, there is a repository called `pmgtest`. This one contains the
319 latest packages and is heavily used by developers to test new
320 features. As usual, you can configure this using
321 `/etc/apt/sources.list` by adding the following line:
322
323 .sources.list entry for `pmgtest`
324 ----
325 deb http://download.proxmox.com/debian/pmg stretch pmgtest
326 ----
327
328 WARNING: the `pmgtest` repository should (as the name implies) only be used
329 for testing new features or bug fixes.
330
331
332 SecureApt
333 ~~~~~~~~~
334
335 We use GnuPG to sign the `Release` files inside those repositories,
336 and APT uses that signatures to verify that all packages are from a
337 trusted source.
338
339 The key used for verification is already installed if you install from
340 our installation CD. If you install by other means, you can manually
341 download the key with:
342
343 # wget http://download.proxmox.com/debian/proxmox-ve-release-5.x.gpg -O /etc/apt/trusted.gpg.d/proxmox-ve-release-5.x.gpg
344
345 Please verify the checksum afterwards:
346
347 ----
348 # sha512sum /etc/apt/trusted.gpg.d/proxmox-ve-release-5.x.gpg
349 ffb95f0f4be68d2e753c8875ea2f8465864a58431d5361e88789568673551501ae574283a4e0492f17d79dc67edfb173a56a6304dea39e01f249ebdabc9f074a /etc/apt/trusted.gpg.d/proxmox-ve-release-5.x.gpg
350 ----
351
352 or
353
354 ----
355 # md5sum /etc/apt/trusted.gpg.d/proxmox-ve-release-5.x.gpg
356 511d36d0f1350c01c42a3dc9f3c27939 /etc/apt/trusted.gpg.d/proxmox-ve-release-5.x.gpg
357 ----
358
359