mirror of
https://gitlab.com/ArkHost/WHMCS-ArkHost-HetznerVPS.git
synced 2026-07-24 07:45:53 +02:00
per product cloud-init optional support
This commit is contained in:
@@ -12,6 +12,7 @@ WHMCS server module for Hetzner Cloud VPS management.
|
|||||||
|
|
||||||
**Advanced**
|
**Advanced**
|
||||||
|
|
||||||
|
- Cloud-init support for automated server configuration
|
||||||
- Floating IP management with reverse DNS
|
- Floating IP management with reverse DNS
|
||||||
- Backup creation and restoration
|
- Backup creation and restoration
|
||||||
- Firewall rule management
|
- Firewall rule management
|
||||||
@@ -60,6 +61,7 @@ WHMCS server module for Hetzner Cloud VPS management.
|
|||||||
- Datacenter: `fsn1`, `nbg1`, `hel1`, `ash`, `hil`, `sin`
|
- Datacenter: `fsn1`, `nbg1`, `hel1`, `ash`, `hil`, `sin`
|
||||||
- Backups: On/Off
|
- Backups: On/Off
|
||||||
- Create Floating IP: On/Off
|
- Create Floating IP: On/Off
|
||||||
|
- Cloud-Init YAML: Optional custom cloud-init configuration
|
||||||
|
|
||||||
**Custom Field (Required)**
|
**Custom Field (Required)**
|
||||||
|
|
||||||
@@ -189,6 +191,102 @@ This ensures proper key isolation and security for each customer.
|
|||||||
|
|
||||||
We're exploring secure implementations using cloud-init or per-server user data to enable SSH key management while maintaining proper isolation.
|
We're exploring secure implementations using cloud-init or per-server user data to enable SSH key management while maintaining proper isolation.
|
||||||
|
|
||||||
|
## Cloud-Init Support
|
||||||
|
|
||||||
|
Cloud-init allows automatic server configuration during first boot. Unlike project-level SSH keys, cloud-init user_data is per-server, ensuring proper isolation in multi-tenant environments.
|
||||||
|
|
||||||
|
**Configuration:**
|
||||||
|
|
||||||
|
1. Navigate to Setup → Products/Services → Products/Services
|
||||||
|
2. Edit your product → Module Settings tab
|
||||||
|
3. Find "Cloud-Init YAML (Optional)" textarea
|
||||||
|
4. Enter your cloud-init configuration in YAML format
|
||||||
|
5. Leave empty to skip cloud-init
|
||||||
|
|
||||||
|
**Common Use Cases:**
|
||||||
|
|
||||||
|
**1. Change APT Mirrors** (original use case - avoid Hetzner mirrors):
|
||||||
|
```yaml
|
||||||
|
#cloud-config
|
||||||
|
apt:
|
||||||
|
primary:
|
||||||
|
- arches: [default]
|
||||||
|
uri: http://de.archive.ubuntu.com/ubuntu/
|
||||||
|
```
|
||||||
|
|
||||||
|
**2. Add SSH Keys** (secure alternative to project-level keys):
|
||||||
|
```yaml
|
||||||
|
#cloud-config
|
||||||
|
users:
|
||||||
|
- name: admin
|
||||||
|
ssh_authorized_keys:
|
||||||
|
- ssh-rsa AAAAB3NzaC1yc2E... user@laptop
|
||||||
|
sudo: ALL=(ALL) NOPASSWD:ALL
|
||||||
|
shell: /bin/bash
|
||||||
|
```
|
||||||
|
|
||||||
|
**3. Install Docker:**
|
||||||
|
```yaml
|
||||||
|
#cloud-config
|
||||||
|
packages:
|
||||||
|
- docker.io
|
||||||
|
- docker-compose
|
||||||
|
|
||||||
|
runcmd:
|
||||||
|
- systemctl enable docker
|
||||||
|
- systemctl start docker
|
||||||
|
```
|
||||||
|
|
||||||
|
**4. Security Hardening:**
|
||||||
|
```yaml
|
||||||
|
#cloud-config
|
||||||
|
packages:
|
||||||
|
- fail2ban
|
||||||
|
- ufw
|
||||||
|
|
||||||
|
runcmd:
|
||||||
|
- ufw default deny incoming
|
||||||
|
- ufw default allow outgoing
|
||||||
|
- ufw allow 22/tcp
|
||||||
|
- ufw --force enable
|
||||||
|
- systemctl enable fail2ban
|
||||||
|
- systemctl start fail2ban
|
||||||
|
```
|
||||||
|
|
||||||
|
**5. Combined Configuration:**
|
||||||
|
```yaml
|
||||||
|
#cloud-config
|
||||||
|
apt:
|
||||||
|
primary:
|
||||||
|
- arches: [default]
|
||||||
|
uri: http://mirror.example.com/ubuntu/
|
||||||
|
|
||||||
|
users:
|
||||||
|
- name: admin
|
||||||
|
ssh_authorized_keys:
|
||||||
|
- ssh-rsa AAAAB3... admin@company
|
||||||
|
sudo: ALL=(ALL) NOPASSWD:ALL
|
||||||
|
|
||||||
|
packages:
|
||||||
|
- fail2ban
|
||||||
|
- ufw
|
||||||
|
- docker.io
|
||||||
|
|
||||||
|
runcmd:
|
||||||
|
- ufw allow 22/tcp
|
||||||
|
- ufw --force enable
|
||||||
|
- systemctl enable docker fail2ban
|
||||||
|
```
|
||||||
|
|
||||||
|
**Important Notes:**
|
||||||
|
|
||||||
|
- YAML must be valid syntax (use a YAML validator if unsure)
|
||||||
|
- If you don't start with `#cloud-config`, the module will add it automatically
|
||||||
|
- Cloud-init runs ONCE on first boot only
|
||||||
|
- Invalid YAML will cause provisioning to fail silently
|
||||||
|
- Maximum size: 32 KiB (Hetzner API limit)
|
||||||
|
- Documentation: https://docs.hetzner.cloud/#servers-create-a-server
|
||||||
|
|
||||||
## Screenshots
|
## Screenshots
|
||||||

|

|
||||||

|

|
||||||
|
|||||||
@@ -177,6 +177,20 @@ function ArkHostHetznerVPS_API(array $params) {
|
|||||||
$data['enable_ipv6'] = false;
|
$data['enable_ipv6'] = false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Handle Cloud-Init user_data if provided
|
||||||
|
$cloudInitYaml = ArkHostHetznerVPS_GetOption($params, 'cloud_init_yaml');
|
||||||
|
if ($cloudInitYaml && trim($cloudInitYaml) !== '') {
|
||||||
|
// Basic YAML validation - check if it starts with #cloud-config
|
||||||
|
$trimmedYaml = trim($cloudInitYaml);
|
||||||
|
if (strpos($trimmedYaml, '#cloud-config') !== 0) {
|
||||||
|
// Auto-prepend #cloud-config if missing
|
||||||
|
$cloudInitYaml = "#cloud-config\n" . $cloudInitYaml;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Pass as plain text - Hetzner API accepts user_data as plain string (max 32KiB)
|
||||||
|
$data['user_data'] = $cloudInitYaml;
|
||||||
|
}
|
||||||
|
|
||||||
// Handle SSH keys from custom field if needed
|
// Handle SSH keys from custom field if needed
|
||||||
// This would need to be implemented with a custom field
|
// This would need to be implemented with a custom field
|
||||||
break;
|
break;
|
||||||
@@ -988,6 +1002,13 @@ function ArkHostHetznerVPS_ConfigOptions() {
|
|||||||
'Description' => 'Automatically create a floating IP when provisioning this server (additional cost - billed by Hetzner).',
|
'Description' => 'Automatically create a floating IP when provisioning this server (additional cost - billed by Hetzner).',
|
||||||
'Type' => 'yesno',
|
'Type' => 'yesno',
|
||||||
),
|
),
|
||||||
|
'cloud_init_yaml' => array(
|
||||||
|
'FriendlyName' => 'Cloud-Init YAML (Optional)',
|
||||||
|
'Description' => 'Custom cloud-init configuration in YAML format (max 32KiB). Passed as user_data to Hetzner API during server creation. Leave empty to skip cloud-init. <a href="https://docs.hetzner.cloud/#servers-create-a-server" target="_blank">Documentation</a>',
|
||||||
|
'Type' => 'textarea',
|
||||||
|
'Rows' => '10',
|
||||||
|
'Cols' => '60',
|
||||||
|
),
|
||||||
);
|
);
|
||||||
|
|
||||||
try {
|
try {
|
||||||
|
|||||||
Reference in New Issue
Block a user