Deployment Overview of WHMCS on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu (based on package manager usage).
-
Privileges: Root or sudo access is required for all installation steps.
-
PHP Version: PHP 8.3 is required.
-
Database: MySQL server must be installed and running.
-
Domain/FQDN: A valid domain name pointing to the server IP is required for SSL certification via Certbot.
-
Ports: The following TCP ports must be open:
-
22(SSH) -
80(HTTP) -
443(HTTPS)
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a dynamically generated subdomain based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | whmcs |
| Domain | hostkey.in |
| Full template | whmcs{Server_ID}.hostkey.in |
File and Directory Structure¶
The application uses a split directory structure to separate web files from sensitive data and storage:
-
Web Root:
/var/www/html/whmcs(Contains the main application files). -
Data Storage (External):
/var/opt/whmcs/whmcs/storage(Symlinked to/var/www/html/whmcs/storage). -
Downloads Directory (External):
/var/opt/whmcs/whmcs/downloads(Symlinked to/var/www/html/whmcs/downloads). -
PHP Session Data:
/var/opt/whmcs/php/session. -
Nginx Configuration:
/etc/nginx/sites-available/whmcs. -
SSL Certificates:
/etc/letsencrypt/live/{whmcs_domain}/.
Application Installation Process¶
The installation follows a multi-step process involving dependency setup, database configuration, and file deployment:
-
System Dependencies: The system is updated to include essential packages such as
nginx,mysql-server,certbot,git, andunzip. -
PHP Environment Setup: PHP 8.3 and various extensions (
php-fpm,php-mysql,php-gd,php-intl, etc.) are installed. The IonCube Loader is manually downloaded, extracted, and configured as a PHP extension for both CLI and FPM. -
Database Setup: A MySQL database named
whmcs_dbis created with a dedicated userwhmcs_user. -
Application Deployment:
-
The application files are unpacked from a ZIP archive into
/var/www/html/whmcs. -
Configuration files are initialized by renaming
configuration.sample.phptoconfiguration.php. -
Specialized directories (
storageanddownloads) are created outside the web root in/var/opt/whmcs/whmcs/for security and then symlinked into the web root. -
Module Integration: The Hostkey Reseller Mod is cloned from a Git repository and its hooks, modules, and gateway callback files are copied into the appropriate WHMCS directories.
Access Rights and Security¶
Security is enforced through several layers:
-
User/Group Management: A dedicated
whmcsuser and group are created for system operations, while the web server (www-data) is granted ownership of the web root and specific data directories to ensure proper execution. -
Firewall (UFW): The Uncomplicated Firewall (UFW) is enabled with rules allowing traffic on ports 22, 80, and 443.
-
Nginx Security Rules:
-
Access to sensitive directories (
crons,resources,vendor,includes,storage) is denied via Nginx configuration. -
Hidden files (e.g.,
.env,.ht) are blocked. -
Files with specific extensions like
.tplor PHPUnit files are restricted from direct access.
Databases¶
The application uses a local MySQL instance for data persistence.
| Parameter | Value |
|---|---|
| Database Name | whmcs_db |
| Database User | whmcs_user |
| Connection Method | Localhost via Unix socket/TCP |
Custom Scripts and Additional Setup¶
The following custom actions are performed during the deployment:
-
Hostkey API Proxying: Nginx is configured to act as a reverse proxy for several endpoints (e.g.,
/auth.php,/eq.php,/net.php) pointing topanel.hostkey.ru. -
Control Panel Integration: A specific location block is created to proxy
/controlpanel.htmland its associated assets from the Hostkey panel. -
Cron Job Configuration: A system cron job is established to run the WHMCS maintenance script (
cron.php) every 5 minutes using the PHP CLI. -
External Asset Download: The file
controlpanel.htmlis downloaded frominvapi.hostkey.ruand placed in/opt/panel.
Application Update Instructions¶
To update the main application:
-
Manual Method: Replace the files in
/var/www/html/whmcswith the new version, ensuring that theconfiguration.phpfile is preserved and permissions are reset towww-data. -
Service Restart: After updating files, it is recommended to restart the PHP-FPM service to clear any opcode caches:
Location of Configuration Files and Data¶
| Type | Path |
|---|---|
| Main Application Config | /var/www/html/whmcs/configuration.php |
| Nginx Site Config | /etc/nginx/sites-available/whmcs |
| External Storage | /var/opt/whmcs/whmcs/storage |
| Downloads | /var/opt/whmcs/whmcs/downloads |
Available Ports for Connection¶
-
HTTP:
80(Redirected to HTTPS) -
HTTPS:
443
Starting and Stopping the Application¶
The application relies on Nginx and PHP-FPM. Use the following commands:
Nginx (Web Server):
-
Start:
systemctl start nginx -
Stop:
systemctl stop nginx -
Restart:
systemctl restart nginx
PHP-FPM:
- Restart:
systemctl restart php8.3-fpm