🚀 Kurulum & Sistem Yönetim Kılavuzu 🚀 Installation & Administration Guide 🚀 Installations- & Administrationshandbuch
AiPBX; Asterisk 22, MariaDB 11, Nginx L4, Apache 2.4, Go Chat motoru ve Coturn TURNS servisini tek bir otomatik betikle (install.sh) 5 dakikada kurup çalışır hale getirir.
AiPBX automates the entire stack (Asterisk 22, MariaDB 11, Nginx L4, Apache 2.4, Go Chat, Coturn TURNS) with zero hardcoded credentials in under 5 minutes via install.sh.
AiPBX automatisiert den gesamten Software-Stack (Asterisk 22, MariaDB 11, Nginx L4, Apache 2.4, Go-Chat, Coturn TURNS) ohne feste Passwörter in unter 5 Minuten mit install.sh.
1. Sistem Gereksinimleri & Donanım Boyutlandırma 1. System Requirements & Hardware Sizing 1. Systemanforderungen & Hardware-Dimensionierung
| Param | Minimum (Test / Geliştirme) Minimum Specs (Dev / Test) Minimalanforderung (Test) | Önerilen Prodüksiyon (50-200 Dahili) Production Recommended (50-200 Ext) Produktion (50-200 Nebenstellen) |
|---|---|---|
| OS | Ubuntu Server 22.04 / 24.04 LTS (x86_64) | Ubuntu 24.04 LTS or RHEL / Rocky Linux 9 |
| CPU | 2 vCPU | 4 vCPU+ (Intel Xeon / AMD EPYC / Ryzen) |
| RAM | 2 GB | 4 GB – 8 GB RAM |
| Storage | 15 GB SSD | 50 GB+ NVMe SSD (for CDR Call Recordings) |
| Network | Static Local IP | Static Public IPv4 & Pointed FQDN Domain |
2. Anahtar Teslim Otomatik Kurulum (Turnkey Install) 2. Turnkey Automated Installation 2. Schlüsselfertige automatische Installation
bash — Ubuntu Server
# 1. Clone repository
git clone https://github.com/mahirgul/AiPBX.git /opt/aipbx
cd /opt/aipbx
# 2. Run automated installer as root
sudo bash install.sh
Kurulum Betiğinin Otomatik Yaptığı İşlemler: What the Installer Automates: Automatisierte Installationsschritte:
- Paket Kurulumları: Asterisk 22, Apache 2.4, Nginx L4 Stream, MariaDB 11, PHP 8 ve tüm uzantıları, Go, Coturn ve Fail2ban kurulur.
- Dinamik Kriptografik Parolalar: Kodda hiçbir sabit parola bırakılmaz; veritabanı kullanıcıları, Asterisk AMI ve coturn için 32 karakterlik rastgele güçlü şifreler üretilir.
- Otomatik SSL Sertifikası: Alan adınız (FQDN) girildiğinde Let's Encrypt Certbot ile gerçek SSL sertifikası alınır veya SAN yerel SSL üretilir.
- Veritabanı Şeması: Phinx migration ve seed tabloları yüklenerek varsayılan yönetici hesabı oluşturulur.
- Parola Kasası: Üretilen tüm şifreler yalnızca root'un okuyabileceği
/root/aipbx-credentials.txt(chmod 600) dosyasına kaydedilir.
- Stack Provisioning: Installs Asterisk 22, Apache 2.4, Nginx L4 Stream, MariaDB 11, PHP 8 with extensions, Go compiler, Coturn, and Fail2ban.
- Dynamic Cryptographic Passwords: Generates unique 32-character random secrets for MariaDB users, AMI, coturn, and admin portal.
- Automated TLS Provisioning: Interactively prompts for FQDN domain and obtains free Let's Encrypt certificates via Certbot (or generates self-signed SAN SSL).
- Schema Migrations: Executes Phinx database migrations and seeds initial admin accounts.
- Credential Safe: Prints complete terminal summary and writes protected credentials to
/root/aipbx-credentials.txt(chmod 600).
- Software-Pakete: Installiert Asterisk 22, Apache 2.4, Nginx L4 Stream, MariaDB 11, PHP 8 mit Erweiterungen, Go, Coturn und Fail2ban.
- Dynamische Passwörter: Erzeugt sichere 32-stellige Zufallspasswörter für Datenbank, AMI, Coturn und Webportal.
- Automatische SSL-Zertifikate: Richtet Let's Encrypt via Certbot für Ihre Domain ein (oder generiert SAN-Self-Signed SSL).
- Datenbank-Migrationen: Führt Phinx-Migrationen aus und richtet Standard-Benutzer ein.
- Passwort-Tresor: Speichert alle Zugangsdaten geschützt in
/root/aipbx-credentials.txt(chmod 600).
3. Ağ ve Güvenlik Duvarı Port Tablosu 3. Network Ports & Firewall Table 3. Netzwerk-Ports & Firewall-Tabelle
| Port | Protocol | Kullanım AmacıService / PurposeDienst / Verwendungszweck | Dışa Açılmalı mı?Inbound WAN AccessWAN-Freigabe |
|---|---|---|---|
| 443 | TCP | Nginx L4 ALPN Stream (Web, WebRTC WSS, Coturn TURNS) | Required / Zorunlu |
| 80 | TCP | HTTP -> HTTPS Redirect & Let's Encrypt ACME HTTP-01 | Required / Zorunlu |
| 10000 - 20000 | UDP | Asterisk RTP Voice Streams (Audio Packets) | Required / Zorunlu |
| 5060 | UDP / TCP | SIP Hardware Desk Phones & Telecom Trunks | Optional (If using hardware SIP) |
| 5061 | TCP | SIP TLS (Encrypted desk phones) | Optional |
| 5038 | TCP | Asterisk Manager Interface (AMI - Web Portal) | NO (127.0.0.1 Local Only) |