# OneStop for Ubuntu — 2.1.75-ubuntu.2 **Initial Ubuntu build: not yet qualified on Ubuntu hardware or a VM.** This package carries the cumulative 2.1.75 server and web interface. The Windows installers remain separate. Target: Ubuntu Server or Desktop **24.04 or 26.04 LTS, amd64/x86-64**, with systemd. ARM, containers and non-Ubuntu distributions are not supported by this installer. Use a test machine first. Allow at least 4 GB RAM, disk space for the application/scanner plus your library, and internet access to Ubuntu package repositories, npm and ClamAV definition mirrors. Node 24.21.0 and Caddy 2.11.4 Linux runtimes are included and checked against official manifests. The installer installs Ubuntu ClamAV packages and resolves locked Linux npm dependencies; **this is not an offline installer**. It does not download or execute a remote shell script. ## Install Extract the tar.gz, enter the extracted directory, and choose one mode: ```bash sudo bash install.sh # or, for a permanent public HTTPS hostname: sudo bash install.sh --mode public --origin https://files.example.com # or internal HTTPS using a private certificate authority: sudo bash install.sh --mode internal --origin https://files.example.internal ``` Local mode is accessible through the browser on the Ubuntu computer at http://localhost:3001 (or the next free port through 3010). It is not a remote HTTP service. For headless remote access use a permanent HTTPS hostname. Public DNS and inbound TCP 80/443 must reach this server. The installer does not change UFW, your router or an existing web server. Do not expose the backend or scanner ports. An existing service on 80/443 needs an administrator-planned proxy arrangement; do not terminate it to make setup pass. Internal clients need to trust the private root certificate in `/var/lib/onestop-proxy/certificates/pki/authorities/local/root.crt`; never distribute its private key. The script verifies packaged checksums, installs prerequisites, stages a separate application release and installs these units: - `onestop`: application, running as the unprivileged `onestop` account. - `onestop-scanner`: dedicated loopback ClamAV instance, running as Ubuntu's `clamav` account, using distribution-managed definitions. - `onestop-proxy`: optional HTTPS proxy, running as `onestop-proxy`. Ubuntu's `clamav-freshclam` service updates definitions; other installed ClamAV services are not stopped or repurposed. Scanner port 3310 is preferred; conflicts select another free port through 3399. Unavailable, stale or failed inspection blocks file operations. The service sandbox and Ubuntu AppArmor policy must allow the documented directories; investigate denial logs instead of disabling protection. ## First account and clients ```bash sudo cat /var/lib/onestop/setup-code.txt ``` Use this one-time installation code on the setup page to create the administrator. Only the administrator can create other accounts. Use existing browser credentials or registered passkeys afterwards. Register remote passkeys against the final HTTPS hostname. Windows Desktop Sync connects to the Ubuntu server through the same HTTPS pairing API. This Ubuntu-only package includes Windows Desktop Sync 2.1.7 and native Linux Desktop Sync 1.0.0 preview in Settings → Desktop & phones. The Linux client has a Tk desktop interface, bundled Linux Node runtime, desktop keyring credential storage, folder selection, pause/resume and optional login startup. It requires Ubuntu Desktop x64 with Python Tk and Secret Service; extract its download and follow its README. Closing its window stops sync; minimize it to continue. The Linux client has not yet been tested on Ubuntu. The existing Windows server installer is unchanged. Phone apps remain separate development builds, not store-qualified releases. The full web workspace is provided: Files, Photos, document line spacing and page controls, workbook tabs, Mail, Calendar, Tasks, Contacts, sharing and quotas. The backup panel detects the server platform and shows the Ubuntu backup command. ## Paths, upgrades and logs - Application: `/opt/onestop/current`, with preserved releases under `/opt/onestop/releases`. - Configuration, database, setup code and encryption key: `/var/lib/onestop`. - Encrypted files: `/var/lib/onestop/storage`. A dedicated local disk can be mounted there before first setup. Keep the database on a local filesystem. This first package does not offer arbitrary storage paths. - Proxy configuration: `/etc/onestop/Caddyfile`; certificates: `/var/lib/onestop-proxy`. - Scanner configuration: `/etc/clamav/onestop.conf`. - Installation log: `/var/log/onestop-install/install.log`. ```bash sudo systemctl status onestop onestop-scanner onestop-proxy sudo journalctl -u onestop -u onestop-scanner -u onestop-proxy --since today sudo journalctl -u clamav-freshclam --since today ``` Upgrade by extracting a newer package and running its installer. Existing origin, port, configuration fields, data and encryption keys are retained. Only OneStop's named units are stopped. A failed upgrade retains the prior code releases and data, but services may remain stopped: inspect the log. There is no automatic database downgrade or rollback. A configuration snapshot is not a full data backup. ## Encrypted backup and restore ```bash sudo bash /opt/onestop/current/tools/backup.sh create /mnt/backup/library.onebackup sudo bash /opt/onestop/current/tools/backup.sh restore /mnt/backup/library.onebackup /srv/onestop-restored ``` The tool prompts privately for a password of at least 16 characters. Backup stops the app/proxy for consistency and restarts the units it found running. Keep the backup and its password in separate protected locations. Restore authenticates the archive and writes only to a NEW directory, revoking restored sessions and device tokens. It does not overwrite the live library. Test restoration before relying on this deployment. Linux activation requires an administrator to place the restored library at the installed data path, correct its config storage path and ownership, and rerun the installer. Do not copy a Windows installation directory or config blindly into Linux; backup portability and migration need separate qualification. ```bash sudo bash /opt/onestop/current/tools/uninstall.sh --remove-services ``` Removal stops/removes only OneStop's units and retains all data, keys, certificates, code, OS accounts and Ubuntu packages. ## Validation limits Built from the current server source and verified runtime archives on Windows. Configuration/port selection and application behavior can be checked here, but native Linux dependency installation, systemd permissions, AppArmor, real HTTPS, reboot, upgrade and restore must be exercised on Ubuntu 24.04 and 26.04 before calling this production-qualified. Do not infer successful installation from the presence of files; require application and scanner health checks and then test the site from a client. References: https://caddyserver.com/docs/running ; https://ubuntu.com/about/release-cycle ; https://nodejs.org/dist/v24.21.0/SHASUMS256.txt ## Help and support Open Help & FAQs from OneStop navigation, Settings or the sign-in page. Please submit a help request if you run into any issues at Greenlyz Helpdesk: https://helpdesk.greenlyz.com. Include the version and redacted error text; never include credentials, recovery keys or private documents. Account creation and password resets remain the responsibility of your own server administrator. Installer terms: interactive setup displays the terms and requires typing ACCEPT. For unattended setup, read app/client/dist/ONESTOP-TERMS.txt first and explicitly pass --accept-terms 2026-09-23.1. Acceptance receipts stay in /var/lib/onestop/terms-acceptance.jsonl; they are not transmitted to Greenlyz. ## Smart library performance self-test After installation, run `bash /opt/onestop/current/tools/self-test.sh --output ./OneStop-self-test`. Add `--samples /path/to/test/photos --count 10` for read-only sample testing. No personal library changes are made. Local models and English OCR are bundled; CPU-only processing uses one visual-analysis job and up to two model threads. Enable Smart server library in Photos settings. This Ubuntu preview has not been installed or benchmarked on Linux.