Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
For a new Tomcat 10 installation on Debian 12 or 11, target the Tomcat 10.1 branch: Tomcat 10.0 is superseded. Install Debian’s tomcat10 package for the simplest systemd-managed setup, or use Apache’s binary archive when you need a newer upstream release or a custom installation. Tomcat 10.1 requires Java 11 or later. Before migrating an application from Tomcat 9, check its dependencies: Tomcat 10 uses jakarta.* APIs in place of the older javax.* APIs.
This guide covers both installation methods, service and port checks, WAR deployment, basic security, upgrades, and common failures. Use one method at a time; Debian’s package paths and service name differ from those of an upstream archive installation.
Before you install: choose a Tomcat 10.1 method
Tomcat 10.1 is the current stable Tomcat 10 branch. Tomcat 10.0 is end-of-life, so do not use an old tutorial that installs it for a new deployment. Apache’s download page listed Tomcat 10.1.57 on July 3, 2026; that version will change, so check the official Tomcat 10 download page before using version-specific commands. Tomcat 10.1 implements Jakarta Servlet 6.0 and requires Java 11 or newer. See Apache’s version overview and Tomcat 10.1 migration notes.
Recommended Free Tools
| Method | Choose it when | Trade-off |
|---|---|---|
Debian tomcat10 package |
You want Debian to manage files, service integration, and package updates. | The packaged release and filesystem layout may differ from Apache’s latest archive and upstream tutorials. |
| Apache binary archive | You need a specific upstream release, a custom path, or multiple Tomcat installations. | You manage release verification, service configuration, permissions, updates, and rollback. |
Tomcat 10 is not a drop-in replacement for Tomcat 9. Applications or libraries that depend on javax.servlet or related Java EE APIs may need migration to jakarta.servlet and related Jakarta APIs. Confirm application and dependency compatibility before scheduling a production upgrade.
#1 Best Overall
Check Debian and Java prerequisites
Confirm the operating system and architecture, and check available memory and disk space before installing:
cat /etc/os-release
uname -m
free -h
df -h /
Tomcat 10.1 needs Java 11 or later. A headless runtime is enough for most servers that only run applications; use a JDK if the server must compile code or needs development tools. Debian’s default headless runtime is a convenient choice:
sudo apt update
sudo apt install -y default-jre-headless
java -version
To select Java 17 explicitly, if it is available in your configured Debian repositories, install openjdk-17-jre-headless. Java 17 is an example, not Tomcat’s minimum requirement. Do not assume a particular Java installation path; detect it when configuring an upstream systemd service.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Option A: install Debian’s Tomcat package
1. Check availability and install
Debian 12 (Bookworm) provides the tomcat10 package. On Debian 11, check your configured repositories rather than assuming a package version or availability:
apt-cache policy tomcat10
apt-cache madison tomcat10
If APT offers the package, install it with the runtime:
sudo apt update
sudo apt install -y default-jre-headless tomcat10
Optional packages include tomcat10-admin, tomcat10-docs, tomcat10-examples, and tomcat10-user. Install only what you need. In particular, do not add administration applications to a public production server unless there is a specific requirement. Debian’s Bookworm package page lists the package and related components.
2. Start the service and check its status
sudo systemctl enable --now tomcat10
sudo systemctl status tomcat10
systemctl is-enabled tomcat10
systemctl is-active tomcat10
Enabling the service makes it start at boot; --now starts it immediately. If it fails, inspect its boot log:
sudo journalctl -u tomcat10 -b --no-pager
To follow new log messages while troubleshooting, run sudo journalctl -u tomcat10 -f.
3. Verify the HTTP connector
Tomcat’s default HTTP connector uses port 8080, although the installed configuration may have been changed. Check whether anything is listening and make a local request:
Rank #2
sudo ss -ltnp | grep ':8080'
curl -I http://127.0.0.1:8080/
A successful response confirms that the local HTTP endpoint answered; the precise status can vary with configuration. The default local URL and common startup issues are documented in Apache’s Tomcat 10.1 running instructions. If you intend to allow direct access from another machine, test http://SERVER_IP:8080/ after configuring the firewall. For production, prefer a reverse proxy with HTTPS and keep Tomcat’s connector private where possible.
4. Find Debian’s files and deploy a WAR
Debian packages do not use the same layout as an extracted Apache archive. Discover the installed paths instead of copying instructions for /opt/tomcat:
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchdpkg -L tomcat10 | grep -E '/webapps|server.xml|tomcat-users.xml'
dpkg -L tomcat10-common
systemctl cat tomcat10
Copy a WAR to the package-managed application directory shown by those commands. For example, if the installed layout identifies /var/lib/tomcat10/webapps/ as the deployment directory:
sudo cp myapp.war /var/lib/tomcat10/webapps/
sudo systemctl restart tomcat10
sudo journalctl -u tomcat10 -n 100 --no-pager
A file named myapp.war normally uses the /myapp context path, so its URL is typically http://SERVER_IP:8080/myapp/. A WAR named ROOT.war is typically deployed at the root path. Verify the application’s deployment and context in the logs; a copied file alone does not prove it started successfully.
Option B: install an Apache Tomcat 10.1 archive
Use this route if you need the upstream release or a custom layout. The commands below use Tomcat 10.1.57 as a version-specific example. Check Apache’s download page and substitute the current 10.1.x release before downloading.
1. Install prerequisites and create a service account
sudo apt update
sudo apt install -y openjdk-17-jre-headless curl ca-certificates
java -version
sudo groupadd --system tomcat
sudo useradd --system
--gid tomcat
--home-dir /opt/tomcat
--shell /usr/sbin/nologin
tomcat
The commands assume that neither the tomcat user nor group already exists. Check first and adapt them if you have an existing account. Run Tomcat as this dedicated, unprivileged user, not as root.
2. Download and verify the release
cd /tmp
curl -fLO https://dlcdn.apache.org/tomcat/tomcat-10/v10.1.57/bin/apache-tomcat-10.1.57.tar.gz
sha512sum apache-tomcat-10.1.57.tar.gz
Compare the SHA-512 output with the value Apache publishes for that exact archive. For stronger release verification, verify the matching OpenPGP signature against the release-manager key referenced by Apache. The signature filename, key, and checksum change with releases; get the current files and verification details from the official download page rather than reusing an old checksum or signature.
3. Extract the archive and set permissions
sudo tar -xzf apache-tomcat-10.1.57.tar.gz -C /opt
sudo ln -sfn /opt/apache-tomcat-10.1.57 /opt/tomcat
sudo chown -R tomcat:tomcat /opt/apache-tomcat-10.1.57
sudo chown -h tomcat:tomcat /opt/tomcat
sudo chmod +x /opt/apache-tomcat-10.1.57/bin/*.sh
sudo chmod -R o-rwx /opt/apache-tomcat-10.1.57
This is a straightforward ownership layout, not the strongest possible production separation. Apache recommends keeping server configuration and binaries protected from modification by the Tomcat process where practical, while granting that process write access only to the runtime and application locations it needs. Review the Tomcat security guidance before exposing a production service.
4. Create a systemd service
Find the Java home from the actual Java executable:
Rank #3
JAVA_HOME="$(dirname "$(dirname "$(readlink -f "$(command -v java)")")")"
printf '%sn' "$JAVA_HOME"
Use the printed path in the unit below, replacing the example value if it differs. Create /etc/systemd/system/tomcat.service:
sudo tee /etc/systemd/system/tomcat.service >/dev/null <<'EOF'
[Unit]
Description=Apache Tomcat 10
After=network.target
[Service]
Type=simple
User=tomcat
Group=tomcat
Environment="JAVA_HOME=/usr/lib/jvm/java-17-openjdk-amd64"
Environment="CATALINA_HOME=/opt/tomcat"
Environment="CATALINA_BASE=/opt/tomcat"
RuntimeDirectory=tomcat
RuntimeDirectoryMode=0750
ExecStart=/opt/tomcat/bin/catalina.sh run
SuccessExitStatus=143
Restart=on-failure
RestartSec=5
UMask=0027
[Install]
WantedBy=multi-user.target
EOF
Replace /usr/lib/jvm/java-17-openjdk-amd64 with the detected Java home. catalina.sh run keeps Tomcat in the foreground for systemd to supervise; do not use the backgrounding startup.sh command with this Type=simple unit.
Load the unit and start Tomcat:
sudo systemctl daemon-reload
sudo systemctl enable --now tomcat
sudo systemctl status tomcat
sudo journalctl -u tomcat -b --no-pager
curl -I http://127.0.0.1:8080/
For custom JVM options, create /opt/tomcat/bin/setenv.sh as an executable shell script. For example:
sudo tee /opt/tomcat/bin/setenv.sh >/dev/null <<'EOF'
#!/bin/sh
export CATALINA_OPTS="-Xms512m -Xmx1024m"
EOF
sudo chown tomcat:tomcat /opt/tomcat/bin/setenv.sh
sudo chmod 0750 /opt/tomcat/bin/setenv.sh
The heap values are examples only. Choose memory settings based on application needs, concurrency, JVM overhead, other processes, and available RAM; leaving too little memory for the operating system can cause its own failures.
Deploy applications and manage access
For either installation, deploy a WAR into the appropriate webapps directory, use a controlled CI/CD process, or configure an external application directory. Identify the actual directory first: Debian package paths differ from the upstream archive’s /opt/tomcat/webapps. In production, make deployments deliberate rather than relying on unrestricted automatic deployment. After every deployment, inspect the relevant service log and confirm the expected context path responds.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsThe Manager and Host Manager applications can deploy applications or change server configuration, so treat them as privileged management interfaces. Debian’s tomcat10-admin package is optional. If you need Manager, use long, randomly generated credentials, retain its IP restrictions or narrow them to a trusted management range, and access it over HTTPS or a private channel. A password alone does not make a publicly exposed Manager safe; Apache describes the risks and controls in its security guide.
For administration from a workstation without opening the service to the Internet, an SSH tunnel can forward a local port to the server:
ssh -L 8080:127.0.0.1:8080 user@SERVER_IP
Then visit http://127.0.0.1:8080/ locally. Do not weaken Manager’s IP restrictions by allowing every address just to clear a 403 error.
Network access and production security
For a short connectivity test, direct access might be http://SERVER_IP:8080/. Open that port only if direct HTTP access is intentional. If UFW is installed and in use, a direct-access rule is:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #4
sudo ufw allow 8080/tcp
For a typical production design, put an HTTPS reverse proxy such as Nginx or Apache in front of Tomcat, and bind or firewall Tomcat’s connector to localhost or a private network. Configure the proxy’s forwarded headers and, if the application needs them, WebSocket upgrades, upload limits, and suitable timeouts. Correct settings depend on the application’s paths and behavior; test uploads, streaming, and long-running requests rather than assuming one proxy configuration fits all. In that design, expose the proxy’s required public ports, not Tomcat’s 8080 port. Do not assume UFW is installed or enabled by default.
- Keep Debian, Java, and Tomcat updated through their respective release channels.
- Run Tomcat as a dedicated unprivileged user.
- Remove unused default applications, especially examples and management applications that are not needed. Inspect the actual installed directory before removing anything.
- Restrict Manager and Host Manager to a trusted management path; prefer an SSH tunnel or private network.
- Disable unused connectors, especially AJP if it is not required. AJP is not encrypted by itself and should be limited to trusted networks when used.
- Protect configuration, application secrets, and logs with appropriate ownership and permissions; do not solve permissions problems with world-writable access.
- Back up application data and configuration separately from replaceable Tomcat binaries.
For an upstream archive, inspect the default applications first:
sudo ls -la /opt/tomcat/webapps
Remove only applications you have confirmed are unnecessary. For example, these commands remove common optional applications from an upstream layout:
sudo rm -rf
/opt/tomcat/webapps/docs
/opt/tomcat/webapps/examples
/opt/tomcat/webapps/host-manager
/opt/tomcat/webapps/manager
Do not apply those paths to Debian’s package installation. Discover the package’s directories with dpkg -L tomcat10 | grep webapps and assess the effect before removing files. Apache also notes that the default ROOT application can disclose the Tomcat version; remove it only if you have a suitable replacement and have verified the application path.
Update or remove Tomcat
Debian package
APT-managed installations can receive available package updates with:
sudo apt update
sudo apt install --only-upgrade tomcat10
Review the service and application logs after an update, and check Apache’s migration notes for configuration changes between Tomcat 10.1 releases. If removing the package, stop and disable the service first, then inspect what will remain before removing configuration or application data:
sudo systemctl disable --now tomcat10
sudo apt remove tomcat10
Do not assume package removal should delete your applications or locally maintained configuration; back up anything you need and review package behavior before any purge or manual deletion.
Upstream archive
For an archive installation, download and verify the new 10.1.x release, stop Tomcat, preserve application data and configuration, and compare configuration files with the new release. Install the new version beside the old one, update the /opt/tomcat symlink, check ownership and runtime permissions, then start and test it. Keep the old directory until the new release has passed verification so you have a rollback path. Apache notes that configuration changes can be needed between 10.1 releases, particularly where CATALINA_HOME and CATALINA_BASE are separate; see the migration guide.
Free tools Windows power users keep installed
One-click scans. No signup required.
To remove an upstream service, first back up anything needed and stop it. Remove the service unit and installation only after confirming that the paths contain no required applications, configuration, or logs:
Best Value
sudo systemctl disable --now tomcat
sudo rm /etc/systemd/system/tomcat.service
sudo systemctl daemon-reload
Only then remove the relevant version directory and symlink if you are certain they are no longer needed. Remove the tomcat user and group only if no other service or retained files use them.
Troubleshooting
APT says there is no installation candidate
cat /etc/os-release
apt-cache policy tomcat10
grep -Rhv '^[[:space:]]*#' /etc/apt/sources.list /etc/apt/sources.list.d/ 2>/dev/null
sudo apt update
apt-cache policy tomcat10
Check that the host is actually Debian 11 or 12, repository configuration is correct, and metadata is current. Do not mix Debian 11 and Debian 12 repositories. If the package is unavailable or its version does not meet your needs, use the upstream archive rather than mixing releases.
Java version or path errors
java -version
systemctl show tomcat --property=Environment
systemctl show tomcat10 --property=Environment
A shell may select a different Java than the systemd service expects, particularly if multiple versions are installed. For an upstream unit, set JAVA_HOME to the detected runtime path. Debian users can inspect the selected Java with sudo update-alternatives --config java.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Port 8080 is already in use
sudo ss -ltnp | grep ':8080'
sudo lsof -nP -iTCP:8080 -sTCP:LISTEN
Stop or reconfigure the conflicting process, or change Tomcat’s HTTP connector in its active server.xml. Confirm that you are editing the configuration file used by the service, not a copy from another installation.
The service starts and then stops
sudo systemctl status tomcat
sudo journalctl -u tomcat -b --no-pager
For the Debian package, substitute tomcat10 as the unit name. For an upstream install, also test the configuration as the service user:
sudo -u tomcat /opt/tomcat/bin/catalina.sh configtest
Look for a wrong Java path, occupied port, malformed XML, incorrect CATALINA_HOME, unsupported JVM option, or insufficient write permission for runtime locations such as logs, temporary files, and work files.
Permission denied
sudo journalctl -u tomcat -b | grep -iE 'permission|denied|access'
For an upstream installation, test the specific runtime directories:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
sudo -u tomcat test -w /opt/tomcat/logs
sudo -u tomcat test -w /opt/tomcat/temp
sudo -u tomcat test -w /opt/tomcat/work
Correct ownership or narrowly grant the required write permission. Do not use chmod -R 777 on the installation.
The application deploys but returns 404
Check the context path, whether the WAR unpacked, the deployment log, required environment variables and database drivers, and the application’s compatibility. A Tomcat 9 application still using javax.* may fail on Tomcat 10.1 until it and its dependencies are migrated to Jakarta APIs. Inspect the last deployment messages with sudo journalctl -u tomcat10 -n 200 --no-pager for Debian, or use tomcat for the upstream unit.
Manager returns 403
Manager and Host Manager restrict client addresses by default. A 403 commonly means the requesting IP is not permitted by the application’s context configuration. Use a trusted management IP range or an SSH tunnel; do not allow all addresses as a shortcut.
Quick Recap
Quick verification checklist
java -versionreports Java 11 or newer.- The correct service is enabled and active:
tomcat10for Debian’s package, ortomcatfor the example upstream unit. - A local request to
http://127.0.0.1:8080/receives a response if the default connector remains enabled. - The service log confirms that the application deployed at the intended context path.
- Only intended public ports are reachable; Tomcat administration interfaces are not exposed to the public Internet.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

