Server Provisioning & Setup
When provisioning a new VPS or performing a disaster recovery rebuild from bare Ubuntu 24.04 LTS, the automated bootstrap script setup-vps.sh installs all essential runtimes, tunes kernel limits, and provisions the directory hierarchy.
π Automated Bootstrapping (setup-vps.sh)
1. Prerequisites
- Fresh Ubuntu 24.04 LTS server instance.
- Root SSH access via public key.
- A public IPv4 address assigned (
191.218.165.149).
2. Execution
Connect via SSH and run the setup script:
ssh root@191.218.165.149
# Clone the infrastructure repositorymkdir -p /optgit clone https://github.com/PA-IDEAS/planovi-vps.git /opt/vps-stackcd /opt/vps-stack
# Make bootstrap executable and runchmod +x setup-vps.sh./setup-vps.shπ What setup-vps.sh Configures
The script automates several operational phases:
Phase 1: Package Updates & Security Hardening
- Runs
apt-get update && apt-get upgrade -y. - Installs utilities:
curl,wget,git,htop,ufw,jq,ca-certificates,gnupg,net-tools. - Configures UFW firewall:
- Port 22 (SSH) -
LIMIT - Port 80 (HTTP) -
ALLOW - Port 443 (HTTPS) -
ALLOW - Default incoming:
DENY, default outgoing:ALLOW.
- Port 22 (SSH) -
Phase 2: Docker Engine Installation
- Installs the official Docker CE repository and GPG signing keys.
- Installs
docker-ce,docker-ce-cli,containerd.io,docker-buildx-plugin,docker-compose-plugin. - Enables and starts
docker.serviceon boot.
Phase 3: Directory Hierarchy Initialization
Creates application repositories under /opt/vps-apps:
mkdir -p /opt/vps-apps/{webpage,microservices,flutter-app,converters,backend}/{prod,dev}mkdir -p /opt/vps-stack/{backups,cloudflare-ssl,supabase/functions}Phase 4: Kernel Tuning & Cron Jobs
- Copies
sysctl-tuning.confto/etc/sysctl.d/99-planovi-vps.confand runssysctl --system. - Installs the nightly database backup and 5-minute health check jobs in rootβs
crontab:0 2 * * * /opt/vps-stack/scripts/backup_databases.sh > /dev/null 2>&1*/5 * * * * /opt/vps-stack/scripts/check-health.sh > /dev/null 2>&1
π Post-Provisioning Steps
- Deploy SSL Certificates:
Place Cloudflare origin certificate and private key into
/opt/vps-stack/cloudflare-ssl/:fullchain.pemprivkey.pemplanovi-device-ca.pem
- Inject Environment Variables:
Create
/opt/vps-stack/.envusing credentials retrieved from PA Management. - Launch Docker Services:
Terminal window cd /opt/vps-stackdocker compose up -d --build - Verify Container Health:
Terminal window docker compose pscurl -k https://127.0.0.1/