|
There is no Java and no Tomcat on our shared hosting servers, and they cannot be installed there. A Java application needs a process of its own, permanently running, with memory reserved for it: that means a VPS or a dedicated server with administrator access, which we do sell. This article is written for that case.
|
Apache Tomcat is the server that runs Java web applications. It looks nothing like PHP: instead of files the server executes on each request, there is one program that starts once, stays in memory, and answers on a port of its own.
Before you start
| 1 |
Choose the operating system with your head. A distribution with long term support saves you a reinstall not far down the road. See which operating system to choose.
|
|
| 2 |
Have administrator access and know how to log in. If you have not taken the first steps on the server yet, start with first steps with your VPS.
|
|
| 3 |
Check which Java version your chosen Tomcat requires. The Apache Tomcat project publishes that mapping on each release page. Do not guess: the wrong pairing starts up and then fails later, in production.
|
|
| 4 |
Decide who is looking after this in a year. An unmanaged VPS is yours end to end: the updates, the security and the three in the morning restarts. See managed or unmanaged VPS.
|
|
The install, step by step
| 1 |
Install a Java from the distribution package manager, not one downloaded by hand. That way it gets security updates along with the rest of the system, which is half the job done. Confirm afterwards with java -version.
|
|
| 2 |
Create a user just for Tomcat, with no shell. The service runs as that identity, and if it is ever abused, whoever gets in has nowhere to go.
|
|
| 3 |
Download Tomcat from the Apache project site, and only from there. Published beside the file are checksums and signatures: verify at least the checksum before you unpack.
|
|
| 4 |
Unpack it into a folder of its own, for example under /opt. A symbolic link pointing at the current version saves you work at the next upgrade: you move the link and you are done.
|
|
| 5 |
Give the folder to the user you created, and make the programs under bin executable.
|
|
| 6 |
Create a system service. That is what makes Tomcat start on its own when the machine reboots, and what gives you one command to start, stop and check it. The service file names the Java path, the Tomcat path and the user.
|
|
| 7 |
Enable and start the service, then check its status. A service that starts and dies a second later reports a failure: the reason is in the logs.
|
|
| 8 |
Confirm it is actually listening. A command listing the listening ports shows Tomcat on the port you chose. If it is not there, it did not start, whatever the service says.
|
|
|
The logs always tell the truth. Everything Tomcat does at startup is written into the logs folder of the installation, in the main output file. Before searching the internet, read the last twenty lines of that file: in the overwhelming majority of cases the answer is sitting there in plain words.
|
Three things not to do
|
Do not run Tomcat as administrator. It is the most tempting shortcut and the most expensive: any flaw in the application becomes a flaw in the whole machine. If it «only starts as root», what is wrong is the folder permissions, and that is what you fix.
|
|
Do not open Tomcat’s port to the world. The usual port of a fresh install is extremely well known and is scanned around the clock. The right way is to leave Tomcat listening inside the machine only and put a web server in front of it, with the certificate. That is the next article: configuring Tomcat.
|
|
Do not leave the install as it came. The sample and administration applications that ship in the box are the first place everybody knocks. Either delete them or lock them down, and locking them down is in the next article.
|
The rest of the hygiene of running your own server, which applies to Tomcat as much as to anything, is in keeping your VPS or dedicated server secure.
|
Need a server with administrator access to stand a Java application up? Tell us what it needs.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $9.99/mo See plans |