# Supported Operating Systems

## Overview

WHost uses an OS abstraction layer to support both Debian and RHEL-based distributions. All OS-specific operations are routed through `core/os_commands.py`, ensuring consistent behavior across platforms.

---

## Supported Distributions

WHost ships with a deliberately narrow OS matrix. The installer
(`installer/lib/detect_os.sh`) **rejects every other release with `exit 1`**
before it installs anything, rather than printing a soft warning. It accepts
Ubuntu 22.04 and 24.04 (no other Ubuntu release, older or newer) and version
9 of AlmaLinux, Rocky Linux and CentOS Stream; Debian 12 is recognised but
refused, and Red Hat Enterprise Linux itself is not on the list. The
agent's compiled modules need CPython 3.12 (see *Agent Python runtime*
below), which Debian 12 does not package; older releases such as Debian 11
and the RHEL 8 family also ship system libraries (Python, `libmodsecurity3`)
older than the stack is built for.

### Debian Family

| Distribution | Version | Codename | Status |
|-------------|---------|----------|--------|
| Ubuntu | 22.04 LTS | Jammy Jellyfish | Fully Supported (Python 3.12 via deadsnakes PPA) |
| Ubuntu | 24.04 LTS | Noble Numbat | Fully Supported |
| Debian | 12 | Bookworm | Not installable in the 1.0 line (no Python 3.12 package); returns with the multi-ABI build |

### RHEL Family

| Distribution | Version | Status |
|-------------|---------|--------|
| AlmaLinux | 9 | Fully Supported |
| Rocky Linux | 9 | Fully Supported |
| CentOS Stream | 9 | Fully Supported |

The installer switches SELinux to Permissive on these systems — see
[SELinux on the RHEL family](installation.md#selinux-on-the-rhel-family).

---

## OS-Specific Differences

### Package Management

| Operation | Debian/Ubuntu | RHEL/Alma/Rocky |
|-----------|--------------|-----------------|
| Install | `apt-get install -y` | `dnf install -y` |
| Remove | `apt-get remove -y` | `dnf remove -y` |
| Update index | `apt-get update -y` | `dnf makecache --refresh` |

### Web Server

| Component | Debian/Ubuntu | RHEL/Alma/Rocky |
|-----------|--------------|-----------------|
| Apache package | `apache2` | `httpd` |
| Apache user | `www-data` | `apache`, a member of the `nginx` group when nginx runs in front (account homes and PHP-FPM sockets belong to that group) |
| Apache config | `/etc/apache2/sites-available/` | `/etc/httpd/conf.d/` |
| Enable site | `a2ensite` | None — files in `conf.d/` are loaded as they are |
| Nginx config | `/etc/nginx/sites-available/` + `sites-enabled/` | `/etc/nginx/conf.d/` |

### PHP-FPM

| Component | Debian/Ubuntu | RHEL/Alma/Rocky |
|-----------|--------------|-----------------|
| Package name | `php8.4-fpm` | `php84-php-fpm` (Remi repo) |
| Service name | `php8.4-fpm` | `php84-php-fpm` |
| Config path | `/etc/php/8.4/fpm/` | `/etc/opt/remi/php84/` |
| Pool directory | `/etc/php/8.4/fpm/pool.d/` | `/etc/opt/remi/php84/php-fpm.d/` |
| Account pool socket | `/run/php/php-fpm-<account>-8.4.sock` | `/run/php/php-fpm-<account>-8.4.sock`; the folder is declared in `/etc/tmpfiles.d/whost-php-fpm.conf` |
| Shared pool (phpMyAdmin, webmail) | `www`, runs as `www-data` on `/run/php/php8.4-fpm.sock` | `www`, written by the installer to run as `nginx` on `/run/php/php8.4-fpm.sock` |

### Firewall

| Component | Debian/Ubuntu | RHEL/Alma/Rocky |
|-----------|--------------|-----------------|
| Firewall | UFW | firewalld |
| Allow port | `ufw allow 80/tcp` | `firewall-cmd --permanent --add-port=80/tcp` |
| Close port (remove the allow rule) | `ufw delete allow 80/tcp` | `firewall-cmd --permanent --remove-port=80/tcp` |
| Reload | `ufw reload` | `firewall-cmd --reload` |

### Service Management

All distributions use `systemctl` for service management. Service names may differ:

| Service | Debian/Ubuntu | RHEL/Alma/Rocky |
|---------|--------------|-----------------|
| Web server | `apache2` / `nginx` | `httpd` / `nginx` |
| Database | `mariadb` | `mariadb` |
| DNS | `pdns` | `pdns` |
| Mail | `postfix`, `dovecot` | `postfix`, `dovecot` |
| Redis (Rspamd's store) | `redis-server` | `redis` |
| FTP | `pure-ftpd-mysql` | `pure-ftpd` |

### Other Paths

| Resource | Debian/Ubuntu | RHEL/Alma/Rocky |
|----------|--------------|-----------------|
| PowerDNS config | `/etc/powerdns/pdns.conf` | `/etc/pdns/pdns.conf` |
| Certbot | `certbot` (apt) | `certbot` (EPEL) |
| Pure-FTPd | `pure-ftpd-mysql` (apt) | `pure-ftpd` (EPEL) |
| Let's Encrypt webroot | `/var/www/letsencrypt` | `/var/www/letsencrypt` |

---

## OS Detection

WHost automatically detects the operating system at startup by parsing `/etc/os-release`. The detection provides:

- **family:** `debian` or `rhel`
- **distro:** Specific distribution name (e.g., `ubuntu`, `almalinux`)
- **version:** Full version string (e.g., `22.04`, `9.4`)
- **codename:** Release codename (e.g., `jammy`, `noble`)
- **pkg_manager:** Package manager command (`apt` or `dnf`)
- **cgroup_version:** `2` on hosts with cgroup v2, which per-account resource limits need

This information is used throughout the codebase to make OS-appropriate decisions without hardcoding distribution-specific logic in service layers.

---

## Agent Python runtime

The agent's protected modules are compiled for **CPython 3.12** and only load
under that interpreter. The installer therefore uses:

| OS | Interpreter used for `/opt/whost/venv` |
|----|------------------------------------------|
| Ubuntu 24.04 | system `python3` (3.12) |
| AlmaLinux / Rocky / CentOS Stream 9 | `python3.12` from AppStream (installed by the installer; system `python3` stays 3.9) |
| Ubuntu 22.04 | `python3.12` from the deadsnakes PPA, added by the installer |
| Debian 12 | the distribution ships 3.11 only and no 3.12 package exists; **not installable in this release** |

The service unit starts the agent and its integrity preflight with the venv's
interpreter, so a different default `python3` on the system does not affect the
agent; the interpreter the venv was created from (for example `python3.12` on
AlmaLinux) has to stay installed.

---

**Developed by [WISECP LLC.](https://wisecp.com)**
**Contact:** hello@wisecp.com
