docs/main/administration-guide/upgrade/enterprise-roll-out-checklist.mdx
This checklist is intended to serve as a guide to Enterprises who are rolling out Mattermost to thousands of users.
Much of the preparation work is focused on ensuring the environment is deployed and secured prior to onboarding users.
- Example project team members: Project Manager, Network Administrator, Database Administrator, Corporate Directory Administrator, Security & Compliance Administrator(s), User Support, User Champions, User Trainers
- Get buy-in from project team members and key stakeholders on the project charter
- Database, network, storage, log integrity
- Identify fields for log management tools (e.g. Splunk Enterprise event data)
- Network access, physical access, group controlled access
- Identify the list of users or groups who need administrative access for Mattermost System Console, Command Line Tools, and API privileges
- The Mattermost Marketplace is a service hosted by Mattermost that functions as a central place to store the current versions of available Mattermost integrations. See Enable Remote Marketplace documentation for details about required external network access.
- Mattermost supports external GIF providers. See GIF Commands configuration documentation for details about required external network access.
- Resource: https://docs.mattermost.com/deployment-guide/reference-architecture/application-architecture.html
- Resource: https://docs.mattermost.com/deployment-guide/deployment-guide-index.html
- Resource: https://docs.mattermost.com/administration-guide/scale/scaling-for-enterprise.html
- Resource: https://docs.mattermost.com/administration-guide/scale/high-availability-cluster-based-deployment.html
- Recommend using to test early configurations for database, authentication, file storage, Elasticsearch, prior to setting up high availability and load balancing
- Recommend configuring staging to be an identical replication of your production environment
Install Mattermost
Install the number of nodes based on your high availability requirements outlined in your production environment design
Recommendation: Use Kubernetes and the Mattermost Operator, with external supported external database and file storage solutions. This will also provide blue/green deployment, rolling upgrades, and canary builds
Install and configure database
Install the number of read and search replicas based on your high availability requirements outlined in your production environment design
(Optional) Set up configuration management via the database instead of a config file for high available environments
Install and configure File Storage
Install and configure proxy or load balancers
Note: If running Kubernetes and the Mattermost Operator, proxies will be created automatically.
Add SSL Cert
(Optional) Set up certificate-based authentication (CBA) for user or device-based authentication with a digital certificate
Configure SMTP for email notifications
Set up Elasticsearch (highly recommended if your organization anticipates over two million posts)
- Resource: https://docs.mattermost.com/administration-guide/configure/configuration-settings.html#environment-variables
- Upload your valid Enterprise License under Edition and License
- Ensure site URL is set appropriately for your production, dev and staging environments
- Add your database configuration to System Console > Environment > Database
- Add your Elasticsearch or AWS OpenSearch configuration to System Console > Environment > Elasticsearch
- Add your file storage system configuration to System Console > Environment > File Storage
- Add your proxy configuration to System Console > Environment > Image Proxy
- Add your SMTP configuration to System Console > Environment > SMTP
- Enable Push Notifications by adding your server to System Console > Environment > Push Notification Server
- Add your cluster configuration to System Console > Environment > High Availability
- Permissions Resource: https://docs.mattermost.com/administration-guide/onboard/advanced-permissions.html
- Guest Access Resource: https://docs.mattermost.com/administration-guide/onboard/guest-accounts.html
Load test production environment to verify that it will handle anticipated user load
Set up Prometheus and Grafana to monitor performance
Set up alerts in Grafana
Now that you have an environment in place, we recommend working through the following items in an iterative process. You may need to cycle through each of these topics multiple times to make adjustments to suit your organization as you onboard groups of users.
- Recommendation: Start with fewer teams in your early roll out
- Resource: https://docs.mattermost.com/end-user-guide/collaborate/channel-naming-conventions.html
- Recommendation: Add a “Support” channel for your users to escalate questions
- Resource: https://mattermost.com/marketplace/
- Resource: https://api.mattermost.com/
- Resource: https://academy.mattermost.com/
- Ensure you have set the site’s support URL to your own support team under System Console > Site Configuration > Customization
Resource: https://docs.mattermost.com/deployment-guide/desktop/desktop-app-deployment.html
(Optional) Use the MSI installer to install on Windows machines
Resource: https://docs.mattermost.com/deployment-guide/mobile/mobile-app-deployment.html
(Optional) Use an EMM provider
Recommendation: Use LDAP Group Sync to automate this process
- Train on using Mattermost
- Train on how to use integrations
- See “Roll Out to Groups of Users”
- Resource: https://mattermost.com/support/
- See the process below for escalating to Mattermost
- Resource: https://mattermost.com/marketplace/
- mmctl Command Line Tool Resource: https://docs.mattermost.com/administration-guide/manage/mmctl-command-line-tool.html
- Command Line Tools Resource: https://docs.mattermost.com/administration-guide/manage/command-line-tools.html
We recommend that you review your rollout on a cadence that matches your iterative approach to rolling out to users. Below are some areas to consider.
- Resource: https://docs.mattermost.com/administration-guide/manage/statistics.html
- Review: Total posts, total teams, total channels, total group chats, total direct chats, top channels, top teams
Identify additional tests and scans
(Optional) Enable Compliance Reporting
- Resource: https://mattermost.com/security-updates/