Nothing is downloaded during the install. Python, its packages and (for
single) Node.js are in
the bundle, so the server needs no internet access and no build tools of its own.What the server needs
- Debian 12 or Ubuntu 22.04 / 24.04 / 26.04, on the CPU the bundle is for, with systemd, and root.
- PostgreSQL 15 or newer, with a database and a user that owns it.
- Redis 6 or newer, or Valkey, which speaks the same protocol on the same port.
- DNS for the API’s domain, and a web server with TLS in front (Apache/Virtualmin or nginx).
/opt/fireflomust not exist yet — the installer refuses a server that already has one.
Ubuntu 26.04. Debian 12 and Ubuntu 22.04 / 24.04 are the releases the bundle is tested on; on 26.04 it
installs the same way, because the bundle brings its own Python and the installer only requires a
Debian-family system. Two things differ there:
- The archive may offer Valkey in place of Redis — hence the fallback above. It listens on
6379as Redis does, soREDIS_URLandREDIS_CACHE_URLstayredis://127.0.0.1:6379/…. - The system Python is newer than any earlier release’s; nothing in OMNI uses it.
Install
1
Copy the bundle over and check it
2
Write the answers
--env-file, install.sh asks for the first six instead.3
Run the installer
omni user, installs into /opt/fireflo/releases/<release>, writes
/opt/fireflo/shared/.env with generated secrets, runs the migrations, starts the services and waits
for the API to report healthy.4
Back up the settings file
5
Put HTTPS in front
Proxy the API’s domain to Webhooks from the gateway arrive at this domain, so it must be reachable from the gateway.
127.0.0.1:8200. The bundle’s api/deploy/virtualmin-proxy.conf is the
Apache version. For nginx:6
Create the first staff user
What it runs
The panel on Vercel
On anapi-vercel bundle, panel/ is ready to deploy as it is — the modules are already in it. From
any machine with the bundle unpacked:
- Add the panel’s domain in Vercel (Settings → Domains). It must be the
PANEL_DOMAINyou gave the installer: the API only accepts the browser from that origin, and anything else shows as CORS errors. - Put the function region next to the API server (Settings → Functions).
Connecting it to the gateway
- Platform → Products: turn on SMS for the plans that should have it. A channel is only on for plans whose product enables it.
- Enter the gateway account in the SMS channel’s settings.
- Optionally turn on bulk callbacks on the gateway for that account, so its receipts arrive hundreds
to a request (gateway 0.11.3 or newer; see releases):
smsg.callback.bulk.accounts=<account>. - Send one test message and watch it reach Delivered.
Upgrading
FireFlo supplies a new bundle. It must carry at least the channels and plugins the server runs./opt/fireflo/current, restarts the services and waits for health. /opt/fireflo/shared/.env is
kept as it is.
- If the new release isn’t healthy within 90 seconds, the server switches back to the release that was running and restarts on it. Migrations are not reversed; they only add.
- The last three releases are kept.
- A bundle that leaves out a module the server runs is refused: its menus, pages, webhooks and jobs
would go (its data would stay).
./upgrade.sh --allow-removewhen that is the intent.
api-vercel, deploy the new bundle’s panel too, so it matches the API. The Vercel variables stay:
Rolling back by hand
omni-panel on a single server.