Prerequisites
Before installing flexFS, verify that your server meets the following requirements. These apply to both Enterprise and Community editions.
Operating System
Section titled “Operating System”FlexFS requires a Linux host on one of the following architectures:
| Architecture | Kernel identifier |
|---|---|
| x86-64 (Intel/AMD) | x86_64 / linux/amd64 |
| ARM 64-bit | aarch64 / linux/arm64 |
Any modern Linux distribution is supported (Ubuntu, Debian, RHEL, Rocky, Amazon Linux, etc.) as long as it runs a 64-bit kernel with FUSE support.
Required Software
Section titled “Required Software”The server installers check for these dependencies at startup and abort if any are missing. Without them, you can still set up the servers by hand from their component pages (for example, Metadata Server Setup); the Enterprise: First Mount and Community: First Mount pages cover manual installation of the mount client.
| Dependency | Purpose | Check |
|---|---|---|
curl | Downloads binaries and validates license keys | command -v curl |
systemctl | Manages flexFS services via systemd | command -v systemctl |
The mount client needs a FUSE helper (fusermount3, or fusermount as a fallback) only for mounts started without root or CAP_SYS_ADMIN, and on systems whose /etc/mtab is a regular file; a root mount on a current system talks to the kernel directly. If neither fusermount3 nor fusermount is present, the mount client installer script installs FUSE3 via apt-get, dnf, or yum, enables the EPEL repository when yum cannot find the fuse3 package, and aborts if neither helper is present afterward. You can also install it manually:
sudo apt-get update && sudo apt-get install -y fuse3sudo dnf install -y fuse3sudo yum install -y https://dl.fedoraproject.org/pub/archive/epel/7/x86_64/Packages/e/epel-release-7-14.noarch.rpmsudo yum install -y fuse3On CentOS 7 and Amazon Linux 2, fuse3 is available only from EPEL 7. Both distributions have reached end of life (CentOS 7 on June 30, 2024, Amazon Linux 2 on June 30, 2026), and EPEL 7 is served only from the Fedora archive; the EPEL release package above (the same URL on x86-64 and ARM) configures the repository to use it. CentOS 7’s default package mirrors are offline, so its repository files must point at the CentOS Vault archive (vault.centos.org) before yum can install anything. When the mount client installer enables EPEL, it leaves the EPEL repository enabled.
The Enterprise server installer additionally requires sqlite3, which it uses to read from the admin server’s local database during setup. Like FUSE3, the installer installs it automatically via the system package manager, and aborts if none is available.
Root Access
Section titled “Root Access”Both the server installer and mount client installer must be run as root (sudo). The scripts check for uid 0 and exit if not running with elevated privileges. The Community server installer asks you to accept its license agreement before this check; the other installers check first. The installers set everything up under root’s home folder (/root/.flexfs), with the servers as root systemd services and mounts in /etc/fstab.
Running the servers and the mount client directly does not require root: any user can run them with credentials in that user’s home folder (see, for example, Metadata Server Setup and Mounting without root).
Cloud Account and Bucket
Section titled “Cloud Account and Bucket”You need an object storage bucket on one of the supported cloud providers:
| Provider | Storage API | Example bucket path |
|---|---|---|
| Amazon Web Services | S3 | s3://<bucket> |
| Google Cloud Platform | GCS | gs://<bucket> |
| Microsoft Azure | Azure Blob | https://account.blob.core.windows.net/container |
| Oracle Cloud Infrastructure | OCI Object Storage | oci://<bucket> |
S3-compatible storage services (MinIO, Wasabi, Ceph RGW, etc.) are also supported through the S3 API with a custom endpoint.
Authentication
Section titled “Authentication”On a cloud VM, the servers can reach the bucket with the identity attached to the host: an IAM instance role (AWS), an attached service account (GCP), a managed identity (Azure), or an instance principal (OCI). The installer offers this when the host is on the chosen provider’s cloud and that cloud’s native storage API is used. Otherwise, have these ready:
| Storage API | Credentials |
|---|---|
| S3 (including S3-compatible services) | Access key ID and secret access key |
| GCS | Service account key file (JSON) |
| Azure Blob | Storage account name and access key |
| OCI Object Storage | User OCID, tenancy OCID, API key fingerprint, and API private key file (PEM) |
For S3, GCS, and OCI, the installer can instead use credentials already configured for root, such as /root/.aws/credentials, /root/.config/gcloud/application_default_credentials.json, or /root/.oci/config. GCS HMAC keys work only through the S3 API. With a managed identity and no custom endpoint, the installer still asks for the storage account name, because it forms the default service URL. See Amazon S3, Google Cloud Storage, Azure Blob Storage, and Oracle Cloud Infrastructure for details.
See the Cloud IAM Setup guide for step-by-step instructions on configuring instance roles, attached service accounts, managed identities, and instance principals for each cloud provider.
Network Requirements
Section titled “Network Requirements”FlexFS services communicate over TCP. Ensure the following ports are reachable by any host that will mount the filesystem.
Enterprise Edition
Section titled “Enterprise Edition”| Default Port | Service | Protocol | Purpose |
|---|---|---|---|
| 443 | admin.flexfs | HTTPS | Admin API, mount client installer, auto-update |
| 8443 | meta.flexfs | TLS/RPC | Metadata operations |
| 9443 | proxy.flexfs | HTTPS | Block caching proxy (if enabled) |
Community Edition
Section titled “Community Edition”| Default Port | Service | Protocol | Purpose |
|---|---|---|---|
| 443 | free.flexfs | HTTPS | Admin API, mount client installer, auto-update |
| 8443 | meta.flexfs | TLS/RPC | Metadata operations |
Outbound Access
Section titled “Outbound Access”The server host needs outbound HTTPS access to:
- Your cloud provider’s object storage endpoints (for reading and writing blocks)
get.flexfs.io(for downloading binaries during installation and auto-updates)stat.flexfs.io(Enterprise only, from the admin server host: license validation during installation, then ongoing usage reporting and license renewal)
Mount client hosts need outbound access to the admin/free server, the metadata server, the proxy server (if one is configured), and the object storage endpoint. Mount clients reach object storage directly even when a proxy is configured: some block operations always go direct, and reads and writes fall back to object storage when no proxy group is reachable or a proxy request fails.
Next Steps
Section titled “Next Steps”Once your environment meets these prerequisites, proceed to the installation guide for your edition: