Environment requirements

Minimum and recommended server parameters for deploying the on-premise version.

Deployment methodThe commands on this page apply to the Docker Compose delivery. Open the matching Kubernetes and Helm procedure.
Terms used in this guide
  • A reverse proxy accepts external requests and forwards them to MassAccess services.
  • Transport Layer Security (TLS) encrypts connections to the public address.
  • A health check confirms that a service is ready to handle requests.
  • Enrollment binds an installed instance to the created license.

System requirements

ComponentMinimumRecommended
OSLinux kernel 5.x+Ubuntu 22.04 / Debian 12
Docker Engine24.0+27.0+
Docker Composev2.24+v2.30+
InstallerBash, Python 3, curlBash, Python 3, curl
CPU4 cores8 cores
RAM8 GB16 GB
Disk50 GB SSD100 GB SSD
Internet100 Mbps1 Gbps

Public ports

The platform publishes three ports. The API and web panel ports are exposed externally only through a reverse proxy; the service port is not exposed externally.

PortPurposeAccess
10001API and webhook requestsOnly for the reverse proxy (not exposed directly)
10002Service checksNo public access required
10011Web panelOnly for the reverse proxy (not exposed directly)

Domain and TLS

To access the control panel and API over the internet, configure a public DNS domain pointing to the server's external IP and a valid TLS certificate on port 443 (reverse proxy). Incoming messenger traffic is delivered by the MassAccess platform and does not require a separate public domain or certificate from you.

Connectivity requirements

The product is not offline or air-gapped. Keep the documented outbound routes available for license heartbeat, signed usage metering, cloud billing, image delivery, and Telegram/MAX connectivity.