Skip to main content
Installs and upgrades the control panel, which serves both the operator screens and the customer portal.
The panel edits configuration and reads call records. It is not on the message path: a panel that is down costs you the ability to make changes, not the ability to send.Install it after the gateway. The gateway owns the database schema; the panel only reads and writes rows in it.

The five verbs

install asks for what it needs first and changes nothing until you agree.

Why passwd exists as a verb

There is no user table. OPERATOR_USERNAME and OPERATOR_PASSWORD in panel.env are the whole operator account. passwd is therefore the supported way to change it — it rewrites the environment file and restarts the unit in one step, rather than leaving you to edit a file the installer otherwise promises never to replace.

Layout

--tenant is the point of the shared vocabulary: the same word names the same instance to the gateway installer. One name per customer, two products. The three directory flags still win over either scheme.
--vhost alone keeps an older flat meaning, so panels already installed under /home/<name> are reached exactly as before — an upgrade must not relocate a running install. For a new tenant that is almost never what you want: it puts the panel in PATH/{app,conf,data} while the gateway sits in PATH/gateway, and update --tenant NAME then no longer finds the panel. Give both flags together.
Flags take space-separated values. --vhost=/home/acme is rejected as an unknown option.

What it derives, and the one thing it does not

Given the gateway’s conf directory (--gateway-conf-dir), the installer derives three things rather than asking you to copy them: both operational tokens, the read-only database connection, and the ops URL. The ops URL is built from that gateway’s recorded FIREFLO_OPS_PORT, so an instance on a non-default --ops-port needs no second flag here. It was once assumed to be 9000, and the symptom of getting it wrong is “Could not reach the gateway: fetch failed” on every page showing live state — which reads as the gateway being down rather than as the panel looking at the wrong port.
--config-url is never derived. The read-write connection to the configuration tables is the one that can change what customers are charged, so it is always stated rather than inferred. Without it the panel reports every configuration domain as not editable, rather than failing at the first save.Passed as a flag it puts the database password in shell history and in ps output. Omit it and the installer prompts instead — and that prompt accepts the literal word same, meaning “reuse the connection just derived from the gateway”, which is correct whenever one role owns the tenant’s database.
See Installing the control panel for the walkthrough and Control panel environment for every variable it writes.