Hi Christian,
Thanks for trying out ERPNext. Replies inline
On Fri, Sep 19, 2014 at 10:15 AM, Christian th...@gmail.com wrote:
Hi All
First off I would like to say congratulations on what looks to be a very
good product so far. I recently installed ERPnext from scratch on a virtual
box ubuntu 14.04 x64 vm which was quite easy as I have been a linux user for
a few years. My only problem was when I restarted the service at the end of
the guide and went to the web page it was not available but a a reboot and a
2 min wait solved that issue. Not sure as to why it took so long for the
service to start.
I would like to use the product on a VPS in Australia so your commercial
package would be the best option for me as I don’t want to be updating the
apps / bench constantly, technical capacity is not here issue but the time
definitely is. My questions specifically regards security, your access and
management of the updates.
As this VPS would only be for ERPnext, with regards to the commercial
support package ($599 per year) would you take care of the firewall and
other various security measures required on a web facing server ?
Commercial support is for only functional queries (with one time setup
at the moment). For deployment/production support, there’s another
plan, https://frappe.io/buy/production-support which might be too much
for you if you’re not looking into multitenancy.
Yes, commercial support is good if you want to upgrade to new features
at your own pace. Although we would be able to support you only for
the latest version.
With regards to access most on line tutorial for security of VPS suggest
removing SSH root access via password and using public and private keys
instead. Do you support this or use this method or do you have advice on
this ?
Would you require the only root user or can we add an ERPnext admin user
that has root access ?
Yes, we recommend doing minimum possible things as root. We’re fine
with you disabling the root user login via ssh and making an erpnext
user with sudo access. Would be great if you configure the security
part and then handover the server to us for installation.
Finally updates. Do you have a schedule for updates to the apps / bench ie
daily weekly monthly etc… ?
Also do you update the OS at the same time or is this our responsibility ?
The bench has a feature to auto update via a cron job but it’s
disabled at the moment. It is possible though.
Once I get it up and running I would be happy to make a video or write a
guide on setting up a vps in preparation for a commercial ERPnext install.
If you do not supply any if the security updates maybe your security people
could advise me on best practice and I could include this in the guide.
Thanks 
–
Pratik
erpnext