Skip to main content
Installs and upgrades the gateway. The control panel has its own installer — fireflo-panel-install.

The five verbs

“Packages” means the installer’s own dependencies, not the services FireFlo talks to. It installs curl, openssl, rsync, python3 and the PostgreSQL client — never a PostgreSQL server, never a broker, and never Node. On a bare host, run setup.sh first.
install refuses when a configuration directory already exists, rather than minting a second pair of operational tokens over the top of the first. If you have configuration but no service, the verb you want is service, not install.That refusal keys on $CONF_DIR/fireflo.env, so it does not fire when you install the same tenant at a different path. Such a run gets as far as generating a second pair of tokens before the unit step refuses on the name collision. Remove the old install first — see Removing a tenant.
There is no uninstall verb. Removal is manual, and a tenant is more units than it looks: the gateway writes fireflo-<name>.service plus a -logclean.timer and -logclean.service pair.

Options worth knowing

Layout and identity

Both generated units mount a tmpfs over /home and bind only the one virtualhost back in, so a gateway cannot see any other customer’s home directory. That is a namespace, not a permission: the directory’s own mode still decides who may enter it, which is why --user matters above.
Every flag takes a space-separated value. --vhost=/home/acme is rejected as an unknown option rather than parsed.

Configuration and database

Behaviour

Also fireflo-install fail2ban, which turns blocking on for an install that already exists — the same step, reachable without reinstalling.--with-fail2ban edits host security configuration, and grants the control panel one narrow sudo rule. That is why it is opt-in rather than something an upgrade turns on: a jail that arrives by surprise is how an install starts refusing its own customers.Fill in the never-ban list before you rely on any of it. A ban is on an address, and an address usually carries a whole customer — see Blocking abusive clients.

Running it

--dry-run shows less than you might expect. It cannot report what a package manager would pull in, or what a migration would find in a database it has not connected to. Read it as “the decisions this script would make”, not “everything that would change on this host”.

What it does not install

The control panel. That is fireflo-panel-install, and on a fresh host you run both. --log-retain-days installs a daily systemd timer that deletes rotated logs, never touching the five live ones. Installing by hand means arranging that yourself — see Logging. See Install in one command for the walkthrough.