Deployment Overview of H-UI VPN Server on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the server must meet the following requirements:
-
Operating System: Ubuntu 22.04 (Jammy Jellyfish)
-
Privileges: Root or sudo access is required for package installation and service management.
-
Architecture Support: Compatible with
x86_64(amd64) andaarch64(arm64). -
Required Packages:
-
curl -
sqlite3 -
Docker (installed via the system's managed installation process)
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain generated based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | hui |
| Domain | hostkey.in |
| Full template | hui{Server_ID}.hostkey.in |
File and Directory Structure¶
The application uses several specific directories for its operation and configuration:
-
/usr/local/h-ui: Main installation directory containing the H-UI binary. -
/etc/systemd/system/h-ui.service: Systemd service unit file for managing the H-UI process. -
/root/nginx: Directory containing the Nginx Docker Compose configuration. -
/data/nginx/user_conf.d: Directory where Nginx configuration files are stored. -
/data/nginx/nginx-certbot.env: Environment file for Certbot settings.
Application Installation Process¶
The installation of H-UI is performed through a multi-step process involving binary deployment and system service configuration:
-
System Preparation: The server timezone is set to
Europe/Amsterdam, and the APT cache is updated. -
Binary Deployment: The latest H-UI binary is downloaded from GitHub based on the detected system architecture (
amd64orarm64) and placed in/usr/local/h-ui. -
Service Configuration: A systemd unit file is installed at
/etc/systemd/system/h-ui.service. This file is configured to run the H-UI binary on port8081with the correct timezone environment variable. -
Database Initialization and Security:
-
The service is started to allow the SQLite database to initialize.
-
Once the
.dbfile is detected in/usr/local/h-ui, a SQL command is executed viasqlite3to update the admin credentials. -
The default
sysadminaccount is updated with a new username (useradmin) and secure password hashes. -
Proxy Configuration: An Nginx container is deployed to handle SSL termination and proxy traffic to the application.
Access Rights and Security¶
-
Firewall/Ports:
-
External access is provided via port
443(HTTPS). -
Internal communication between the proxy and the application occurs on port
8081. -
Service Management: The H-UI application runs as a systemd service, ensuring it starts automatically upon system boot.
Databases¶
The application utilizes an embedded SQLite database for data storage.
-
Storage Location: Located within the
/usr/local/h-uidirectory (file ending in.db). -
Connection Method: The application manages the database internally; however, manual administrative tasks can be performed via
sqlite3.
Docker Containers and Their Deployment¶
The deployment includes a dedicated container for managing SSL certificates and reverse proxying.
| Container Name | Image | Ports | Volumes | Environment Variables | Restart Policy |
|---|---|---|---|---|---|
nginx | jonasal/nginx-certbot:latest | Host Network Mode | - nginx_secrets:/etc/letsencrypt- /data/nginx/user_conf.d:/etc/nginx/user_conf.d | [email protected] | unless-stopped |
Custom Scripts and Additional Setup¶
The deployment performs several automated configuration steps:
-
Architecture Mapping: Automatically detects if the system is
x86_64orarm64to pull the correct binary. -
Credential Injection: A script automatically updates the SQLite database to set up the administrative user (
useradmin) immediately after the first run of the application. -
Nginx Proxy Configuration: The deployment dynamically modifies Nginx configuration files in
/data/nginx/user_conf.d/to include aproxy_passdirective pointing tohttp://127.0.0.1:8081.
Application Update Instructions¶
To update the H-UI application, follow these steps:
-
Download the latest binary for your architecture from the official GitHub repository.
-
Replace the existing binary at
/usr/local/h-ui/h-uiwith the new version. -
Ensure the file has execution permissions (
chmod +x /usr/local/h-ui/h-ui). -
Restart the service to apply changes:
Location of configuration files and data¶
-
Application Binary:
/usr/local/h-ui/h-ui -
Database File: Located in
/usr/local/h-ui/*.db -
Nginx User Configs:
/data/nginx/user_conf.d/ -
Systemd Service:
/etc/systemd/system/h-ui.service
Available ports for connection¶
-
HTTPS (External):
443 -
HTTP (Internal/Localhost):
8081
Starting and Stopping the application¶
The application is managed via systemctl:
-
Start H-UI:
systemctl start h-ui -
Stop H-UI:
systemctl stop h-ui -
Restart H-UI:
systemctl restart h-ui -
Check Status:
systemctl status h-ui