Deployment Overview of LXD on Server¶
Prerequisites and Basic Requirements¶
The following requirements must be met for a successful deployment:
-
Operating System: Ubuntu 22.04 (jammy)
-
Privileges: Root or sudo access is required for installation and configuration.
-
Dependencies:
snapdandsquashfs-toolsmust be installed. -
Network Ports:
-
External HTTPS:
443 -
Internal LXD API/UI:
8443
FQDN of the final panel on the hostkey.in domain¶
The application uses a dynamic subdomain template for access via the hostkey.in domain.
| Parameter | Value |
|---|---|
| Prefix | lxd |
| Domain | hostkey.in |
| Full template | lxd{Server_ID}.hostkey.in |
Application installation process¶
The application is installed using the following method:
-
System Preparation: The system ensures that
snapdandsquashfs-toolsare present via the package manager. -
LXD Installation: LXD is installed as a snap package from the
5.21/stablechannel. If an older version exists, it is refreshed to the specified stable channel. -
User Configuration: The administrative user is added to the
lxdgroup to allow management via the command line. -
LXD Initialization: If no storage pools are detected, LXD is initialized with minimal default settings using the
/snap/bin/lxcd init --minimalcommand. -
UI and API Configuration:
-
The LXD User Interface (UI) is enabled or disabled based on configuration.
-
The LXD HTTPS address is configured to listen on port
8443. -
Firewall Setup: If the firewall management feature is enabled,
ufwis installed and configured to allow SSH and the LXD HTTPS port (8443/tcp).
Access Rights and Security¶
-
User Management: The designated admin user is granted membership in the
lxdgroup. -
Firewall (UFW):
-
If enabled,
ufwallowsOpenSSH. -
Port
8443/tcpis opened to allow access to the LXD API and UI. Access can be restricted to specific CIDR ranges if configured.
Docker Containers and Their Deployment¶
The deployment utilizes a Docker container for managing SSL certificates via Nginx.
Nginx Certbot Container
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Environment Variables:
-
CERTBOT_EMAIL:[email protected] -
Volumes:
-
nginx_secrets:/etc/letsencrypt(External volume for SSL certificates) -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d(Configuration mapping) -
Restart Policy:
unless-stopped
Custom Scripts and Additional Setup¶
The installation process performs several automated configuration steps:
-
Nginx Proxy Configuration: The deployment automatically modifies the Nginx configuration files located in
/data/nginx/user_conf.d/. It removes existingproxy_passdirectives and inserts a new directive to route traffic to the local LXD service viahttps://127.0.0.1:8443. -
Service Notification: The system communicates deployment stages (start, stage completion, and final deployment) to an external management API.
Application Update Instructions¶
To update the application components:
-
LXD Updates: Since LXD is managed via snap, updates can be performed using:
-
Docker Components: To update the Nginx Certbot container, navigate to
/root/nginxand execute:
Location of configuration files and data¶
| Component | Path |
|---|---|
| Nginx Configuration Directory | /root/nginx |
| Nginx User Configs | /data/nginx/user_conf.d/ |
| Nginx Environment File | /data/nginx/nginx-certbot.env |
| SSL Certificates (Docker Volume) | nginx_secrets |
Available ports for connection¶
-
443/tcp: External HTTPS access via the proxy.
-
8443/tcp: Internal LXD API and UI management.