Skip to content

Deployment Overview of LXD on Server

Prerequisites and Basic Requirements

The following requirements must be met for a successful deployment:

  • Operating System: Ubuntu 22.04 (jammy)

  • Privileges: Root or sudo access is required for installation and configuration.

  • Dependencies: snapd and squashfs-tools must be installed.

  • Network Ports:

  • External HTTPS: 443

  • Internal LXD API/UI: 8443

FQDN of the final panel on the hostkey.in domain

The application uses a dynamic subdomain template for access via the hostkey.in domain.

Parameter Value
Prefix lxd
Domain hostkey.in
Full template lxd{Server_ID}.hostkey.in

Application installation process

The application is installed using the following method:

  1. System Preparation: The system ensures that snapd and squashfs-tools are present via the package manager.

  2. LXD Installation: LXD is installed as a snap package from the 5.21/stable channel. If an older version exists, it is refreshed to the specified stable channel.

  3. User Configuration: The administrative user is added to the lxd group to allow management via the command line.

  4. LXD Initialization: If no storage pools are detected, LXD is initialized with minimal default settings using the /snap/bin/lxcd init --minimal command.

  5. UI and API Configuration:

  6. The LXD User Interface (UI) is enabled or disabled based on configuration.

  7. The LXD HTTPS address is configured to listen on port 8443.

  8. Firewall Setup: If the firewall management feature is enabled, ufw is installed and configured to allow SSH and the LXD HTTPS port (8443/tcp).

Access Rights and Security

  • User Management: The designated admin user is granted membership in the lxd group.

  • Firewall (UFW):

  • If enabled, ufw allows OpenSSH.

  • Port 8443/tcp is opened to allow access to the LXD API and UI. Access can be restricted to specific CIDR ranges if configured.

Docker Containers and Their Deployment

The deployment utilizes a Docker container for managing SSL certificates via Nginx.

Nginx Certbot Container

  • Image: jonasal/nginx-certbot:latest

  • Network Mode: host

  • Environment Variables:

  • CERTBOT_EMAIL: [email protected]

  • Volumes:

  • nginx_secrets:/etc/letsencrypt (External volume for SSL certificates)

  • /data/nginx/user_conf.d:/etc/nginx/user_conf.d (Configuration mapping)

  • Restart Policy: unless-stopped

Custom Scripts and Additional Setup

The installation process performs several automated configuration steps:

  • Nginx Proxy Configuration: The deployment automatically modifies the Nginx configuration files located in /data/nginx/user_conf.d/. It removes existing proxy_pass directives and inserts a new directive to route traffic to the local LXD service via https://127.0.0.1:8443.

  • Service Notification: The system communicates deployment stages (start, stage completion, and final deployment) to an external management API.

Application Update Instructions

To update the application components:

  • LXD Updates: Since LXD is managed via snap, updates can be performed using:

    snap refresh lxd --channel=5.21/stable
    

  • Docker Components: To update the Nginx Certbot container, navigate to /root/nginx and execute:

    docker compose pull && docker compose up -d
    

Location of configuration files and data

Component Path
Nginx Configuration Directory /root/nginx
Nginx User Configs /data/nginx/user_conf.d/
Nginx Environment File /data/nginx/nginx-certbot.env
SSL Certificates (Docker Volume) nginx_secrets

Available ports for connection

  • 443/tcp: External HTTPS access via the proxy.

  • 8443/tcp: Internal LXD API and UI management.

question_mark
Is there anything I can help you with?
question_mark
AI Assistant ×