Introduction
This section This topic is for system administrators. It describes how to install a new instance of PhixFlow.
Pre-conditions
Before installation starts it is assumed that all system pre-requisites have been completed as documented in PhixFlow System Planning, specifically that
- you have installed a database server,
- you have configured a database instance / schema and user / login credentials
- you have installed a (Linux or Windows) server to act as the web-application (webapp) host
and, optionally, that
- you have installed a Linux or Windows server to act as the reverse proxy / HTTPS proxy
Installation
...
Prerequisites
Your IT system must meet the PhixFlow Minimum System Requirements.
If you are setting up an installation of PhixFlow for evaluation, or a platform for development or testing that requires minimal planning, you can go straight into the installation process below.
If you are installing a large and/ or long-running installation of PhixFlow, please complete the planning steps described in Planning your PhixFlow System and Infrastructure Planning and Delivery.
Summary Installation Instructions
The pages in this topic guide you through a complete PhixFlow installation. A summary of the steps is:
Required or recommended | Page with details | Summary |
---|---|---|
Required | Install Java | Download and install Java. |
Required | Download and install the Apache Tomcat web-application (webapp) server. | |
Recommended | Install reverse proxy and configure HTTPS:
| Set up a reverse proxy to help manage the load on the PhixFlow server |
...
Download / Unpack PhixFlow
...
, offer secure connections over HTTPS, and help with certificate management for multiple instances of PhixFlow. | ||
Optional | This is only needed if you want to generate PDF versions of files to export or send via email (Configuring PDF Conversion) | |
Required | Unpack PhixFlow Release Package | If you do not already have the PhixFlow package to install, you can download |
...
it from our support FTP site. Please |
...
email support@phixflow.com. |
...
Log on to the webapp host and unpack |
...
the release package. |
Required |
...
...
Schema | Create a database user and tables. Populate the tables with initial configuration data and set the customer name. See also the details in Database URLs. | |
Optional | MS SQL Server Integrated Authentication | Enable server support for integrated user authentication. |
Required | Install the PhixFlow |
...
Webapp | Copy the PhixFlow webapp from the unpacked release package into Tomcat and configure it. |
...
Start PhixFlow
You should now be able to start Tomcat, start the PhixFlow client and login as the startup user (password: 'Startup').
System Configuration
Configure the directories under System Directories. See System Configuration for details.
The Temporary File Location is especially important as it is used when Exporting / Importing files.
Create Users
You should immediately create new users, including at least one administrator, then disable or delete the startup user.
Import Component Templates (if required)
Import the component templates file if this is your first PhixFlow instance.
See Import Templates and Formats for more information on when and how to install the templates.
Configure HTTPS
PhixFlow should always be configured to allow HTTPS connections to the webapp and to disable HTTP access.
Info | ||
---|---|---|
| ||
If you want to make your web server visible on the default ports (http: 80, https: 443) on Linux, we recommend using a reverse proxy. In this configuration, the reverse proxy runs as root, which allows it to use privileged ports (up to 1000), and forwards requests to the web server which runs as a non-privileged user (normally 'tomcat'), on non-privileged ports (above 1000). |
Warning | ||
---|---|---|
| ||
Do not run Tomcat as root on Linux as this constitutes a security risk. |
Reverse Proxy
We recommend using a reverse proxy to terminate the HTTPS session and to forward web requests using HTTP to the Tomcat server. This solution requires that the proxy and tomcat servers run on a private network (or on the same server), and that the tomcat server is not directly accessible by normal users.
To install a reverse proxy on Linux, see Install the 'pound' reverse proxy.
To configure IIS as a reverse proxy on Windows, see here.
Tomcat
It is also possible to configure HTTPS directly in tomcat.
Configure for Resilience (optional)
PhixFlow can be configured to have a hot stand-by webapp shadowing the active webapp, such that the standby webapp will automatically take over in the event that the active server fails.
See Configuring for Resilience for details.
Configure for Active Directory Users (optional)
PhixFlow can be configured to allow users to be validated against one or more Active Directory servers in addition to users that are defined locally within the PhixFlow database.
See Configure Active Directory Integration for details.
Configure for SAML / Single Sign-on Users (optional)
PhixFlow can be configured to allow users to be validated against a single SAML Identity Provider in addition to users that are defined locally within the PhixFlow database.
See Configure SAML Integration for details.
Other Resources
The following pages may contain additional useful resources.
...
Required | Configure a Keystore and Aliases | Create a keystore for the database credentials and their aliases. Configure the following files to use the keystore:
|
Required | Start PhixFlow and Configure | Check that the application is running by starting the client and logging in. Pre-version 11 The following credentials can be used, we recommend getting up an administration user to replace this user. username: startup password: Startup Post-version 11 The recommended minimum basic install will create a new user called admin. The password will be autogenerated and written to the ../tomcat/security.log file. It is strongly recommended that this password is changed immediately after installation. username: admin password: see security.log |
After Installation
Once PhixFlow is installed, see System Administration for details of the configuration steps required immediately after installation, as well as the ongoing configuration and maintenance tasks.