Skip to content

Server Provisioning & Setup

When provisioning a new VPS or performing a disaster recovery rebuild from bare Ubuntu 24.04 LTS, the automated bootstrap script setup-vps.sh installs all essential runtimes, tunes kernel limits, and provisions the directory hierarchy.


πŸš€ Automated Bootstrapping (setup-vps.sh)

1. Prerequisites

  • Fresh Ubuntu 24.04 LTS server instance.
  • Root SSH access via public key.
  • A public IPv4 address assigned (191.218.165.149).

2. Execution

Connect via SSH and run the setup script:

Terminal window
ssh root@191.218.165.149
# Clone the infrastructure repository
mkdir -p /opt
git clone https://github.com/PA-IDEAS/planovi-vps.git /opt/vps-stack
cd /opt/vps-stack
# Make bootstrap executable and run
chmod +x setup-vps.sh
./setup-vps.sh

πŸ“‹ What setup-vps.sh Configures

The script automates several operational phases:

Phase 1: Package Updates & Security Hardening

  • Runs apt-get update && apt-get upgrade -y.
  • Installs utilities: curl, wget, git, htop, ufw, jq, ca-certificates, gnupg, net-tools.
  • Configures UFW firewall:
    • Port 22 (SSH) - LIMIT
    • Port 80 (HTTP) - ALLOW
    • Port 443 (HTTPS) - ALLOW
    • Default incoming: DENY, default outgoing: ALLOW.

Phase 2: Docker Engine Installation

  • Installs the official Docker CE repository and GPG signing keys.
  • Installs docker-ce, docker-ce-cli, containerd.io, docker-buildx-plugin, docker-compose-plugin.
  • Enables and starts docker.service on boot.

Phase 3: Directory Hierarchy Initialization

Creates application repositories under /opt/vps-apps:

Terminal window
mkdir -p /opt/vps-apps/{webpage,microservices,flutter-app,converters,backend}/{prod,dev}
mkdir -p /opt/vps-stack/{backups,cloudflare-ssl,supabase/functions}

Phase 4: Kernel Tuning & Cron Jobs

  • Copies sysctl-tuning.conf to /etc/sysctl.d/99-planovi-vps.conf and runs sysctl --system.
  • Installs the nightly database backup and 5-minute health check jobs in root’s crontab:
    0 2 * * * /opt/vps-stack/scripts/backup_databases.sh > /dev/null 2>&1
    */5 * * * * /opt/vps-stack/scripts/check-health.sh > /dev/null 2>&1

πŸ”‘ Post-Provisioning Steps

  1. Deploy SSL Certificates: Place Cloudflare origin certificate and private key into /opt/vps-stack/cloudflare-ssl/:
    • fullchain.pem
    • privkey.pem
    • planovi-device-ca.pem
  2. Inject Environment Variables: Create /opt/vps-stack/.env using credentials retrieved from PA Management.
  3. Launch Docker Services:
    Terminal window
    cd /opt/vps-stack
    docker compose up -d --build
  4. Verify Container Health:
    Terminal window
    docker compose ps
    curl -k https://127.0.0.1/