> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.jambonz.org/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.jambonz.org/_mcp/server.

# Post-Install Steps

# Overview

Once you have deployed jambonz on VM-based infrastructure such as AWS EC2, you will need to create
some DNS records and enable HTTPS for the web portal.

# Create DNS records

The output of the deployment will have included the IP addresses of the Web/Monitoring server and the SBC server.

> **Note**
>
> On a jambonz mini, these will be the same IP address since it is a single server deployment.

Using the DNS name that you specified during deployment (e.g. `my-domain.example.com`), create the following DNS A records:

**Pointing to WebServerIP:**

* `my-domain.example.com`
* `api.my-domain.example.com`
* `grafana.my-domain.example.com`
* `public-apps.my-domain.example.com` *(cloud-image deployments only)*

**Pointing to SbcServerIP:**

* `sip.my-domain.example.com` *(cloud-image deployments only)*

> **Note**
>
> **bare-metal / Debian package installs** only require the first three records (`my-domain`, `api.`, `grafana.`). The `public-apps.` and `sip.` subdomains are used by the cloud-image (AMI) deployments and aren't proxied through nginx in the Debian package — SIP traffic on a mini install reaches drachtio directly at the host's public IP, and the `public-apps` demo content is served from the main portal vhost.

# Enable HTTPS for the portal

SSH into the Web/Monitoring server as the `jambonz` user and install TLS certificates:

```bash
ssh -i <your-ssh-keypair> jambonz@<WebServerIP>

# Install certbot and the nginx plugin (you may already have this)
sudo apt-get install -y certbot python3-certbot-nginx

# Generate TLS certs for the portal vhosts
sudo certbot --nginx \
  -d my-domain.example.com \
  -d api.my-domain.example.com \
  -d grafana.my-domain.example.com
```

> **Note**
>
> **Cloud-image (AMI) deployments only** — after running certbot, edit `~/apps/webapp/.env` to set `VITE_API_BASE_URL` to the `https://` URL, then rebuild and restart the webapp:
>
> ```bash
> cd ~/apps/webapp && vi .env
> npm run build && pm2 restart webapp
> ```
>
> This step is **not** required for the bare-metal / Debian package install. The webapp in the Debian package falls back to `window.location.protocol` at runtime, so it picks up HTTPS automatically once certbot finishes.

# First time login

Now log into the portal for the first time.

The user is `admin`. The initial password depends on how you deployed:

* **Cloud-image (AMI) deployments**: the password was listed in the outputs from the deployment script.
* **Bare-metal / Debian package installs**: the initial password is `admin`.

You will be prompted to change the password on first login.

> **Note**
>
> The initial grafana login is admin/admin.