Linux server or VM
Install PNeX on Debian or Ubuntu — bare metal, a hypervisor or a cloud VM
Requirements
- Debian 12/13 or Ubuntu 22.04+, amd64 or arm64.
- 4 GB of RAM (8 GB recommended), 16 GB of free disk.
- Ports 80 and 443 free. Docker Engine and the compose plugin are installed when missing.
On a LAN (lab, plant, Proxmox or VirtualBox VM)
curl -fsSL https://raw.githubusercontent.com/Pnex/pnex-deploy/main/install.sh \
| sudo bash -s -- --admin-user [email protected]The server is named <hostname>.local (mDNS) and TLS uses a certificate
authority generated on the server, as on a Raspberry Pi. For a VM, use a
bridged network adapter so devices on the LAN reach it.
On a public server
With a DNS record pointing at the server, use Let's Encrypt:
curl -fsSL https://raw.githubusercontent.com/Pnex/pnex-deploy/main/install.sh \
| sudo bash -s -- --domain pnex.example.com --tls cloud \
--acme-email [email protected] --admin-user [email protected]No domain name? Build one from the public IP with sslip.io: the VM gets a Let's Encrypt certificate without any DNS to manage:
curl -fsSL https://raw.githubusercontent.com/Pnex/pnex-deploy/main/install.sh \
| sudo bash -s -- --domain sslip --ip 203.0.113.7 --tls cloud \
--acme-email [email protected] --admin-user [email protected]--ip is needed when the VM only sees a private address behind the provider's
NAT. Ports 80 and 443 must be open to the internet.
Walkthrough: a fresh cloud VM
A real install of 0.1.0-beta.2 on a fresh Ubuntu 26.04 VM with a public IP,
sslip.io and Let's Encrypt (download phases shortened, admin password masked).
The installer sets up Docker itself, then pulls the images, starts the stack and
checks its health:
Once it is done, pnexctl status lists the services, and the certificate served
on the sslip.io name is issued by Let's Encrypt:
The admin password is printed once at the end of the install. If you missed
it, read it back from the install's .env:
sudo grep PNEX_ADMIN_PASSWORD /opt/pnex/.envIt only seeds the account on the very first start: change it after the first
login (the value in .env is then no longer valid).
Options
| Flag | Purpose |
|---|---|
--profile raspi|server | memory tuning (auto: raspi under 6 GB of RAM) |
--storage fs|s3 | firmware and media on the database / a volume, or in a bundled RustFS |
--smtp-url … | outgoing mail for self-registration and password resets |
--version latest|0.1.0-beta.5 | the release to install: latest (default, last green main) or a published release, kept on upgrades |
--tag <image tag> | override the image tag alone (e.g. main-<sha>) |
install.sh --help lists everything; day-2 operations go through pnexctl
(status, logs, upgrade, backup, log-level).

