Skip to main content
07 / Reference · 7.5

Paths, ports and services

The ports the server listens on, the systemd services, the system users and the paths CloudGround uses.

Type
Reference
Version
v0.1.0
Last verified
Unverified

The values are those of an installation made with the installer. <id> is the site's number in the panel, <domain> its domain.

Ports​

PortWho listensFrom whereUse
22/tcpsshdInternetSSH for root, SFTP and site shells
80/tcpnginxInternetcertificate challenges, then a redirect to HTTPS
443/tcpnginxInternetthe sites and the panel domain
443/udpnginxInternetHTTP/3, when nginx has the module
8443/tcpnginxInternetthe panel by IP, with its own self-signed certificate, and Quarry at /quarry
3306/tcpMariaDBthe server onlythe sites' databases
9080/tcppanel-api127.0.0.1 onlythe WordPress connector: cache purge and health check

The installer never turns the firewall on. When it is already active, it opens the ports sshd listens on, 80, 443, 443/udp and 8443 (see firewall). From the panel you cannot close the SSH ports, 80, 443 or 8443.

The panel has no TCP port of its own: nginx talks to it on the socket /run/cloudground/api.sock.

Services​

systemd unitRuns asWhat it does
cloudground-api.servicecloudgroundthe panel's API and interface
cloudground-api.socket—opens /run/cloudground/api.sock for the API
cloudground-agent.serviceroot, sandboxedthe privileged work
cloudground-php-cg-site-<id>.servicecg-site-<id>a site's PHP-FPM, in the slice cg-site-<id>.slice
cloudground-update-guard.serviceroottransient, during a panel update
nginx.serviceroot and www-datathe web server
mariadb.servicemysqlthe databases
redis-server.service—not installed on a new server; a server upgraded from an earlier version keeps it switched off

Users and groups​

NameWhat it is
cloudgroundthe panel's user, without a shell
cg-site-<id>a site's system user: owns its files, runs its PHP, signs in over SFTP
cg-shell-<id>the site shell's login, with the same uid as cg-site-<id>
cg-sftp-offgroup: its members can sign in over neither SSH nor SFTP
site_<id>the default name of a site's primary MariaDB database and user, when you choose none (see database names and passwords)

The panel​

PathContents
/usr/local/bin/panel-api, panel-agent, cgctl, cg-site-shellthe binaries
/etc/cloudground/panel.envthe panel's and the agent's configuration
/etc/cloudground/cgctl.envcgctl's configuration
/etc/cloudground/agent.tokenthe secret shared by the panel and the agent
/etc/cloudground/certs/the panel's certificates (panel.pem, panel-ip.pem), the fallback (fallback.pem) and uploaded ones (custom/)
/var/lib/cloudground/state.dbthe panel's database
/var/lib/cloudground/secret.keythe key that encrypts the database's secrets: back it up with the database
/var/lib/cloudground-agent/the agent's working space and, after the first update, highest-release
/var/lib/cloudground-agent/installed.jsonwhat the installer installed because it was missing: packages, repository, tools (read by cgctl uninstall --purge-packages)
/var/lib/cloudground-agent/update-result.jsonthe outcome of the last update
/var/lib/cloudground-agent/update-snapshots/the snapshots taken before an update, the newest three
/var/lib/cloudground-agent/databases.jsonthe agent's record of which database and database user is which site's (see recover the database record)
/run/cloudground/agent.sockthe agent's socket
/run/cloudground/shell.sockthe socket on which the agent takes the site shells' sessions
/var/log/cloudground-install.logthe installer's log
/root/cloudground-uninstall/after an uninstall: the panel's state, backup.env, README.txt (see uninstall CloudGround)

The sites​

PathContents
/srv/sites/<domain>/the site's folder
/srv/sites/<domain>/currentthe link to the live release, releases/<id>
/srv/sites/<domain>/releases/the releases
/srv/sites/<domain>/shared/what stays across releases: wp-config.php, uploads
/srv/sites/<domain>/tmp/PHP's temporary files and sessions
/var/log/cloudground/<domain>/access.log, error.log, php-error.log
/var/cache/cloudground/<domain>/the page cache
/etc/nginx/sites-enabled/<domain>.confthe vhost
/etc/nginx/conf.d/cloudground-cache-<id>.confthe site's cache zone
/etc/nginx/conf.d/cloudground-global.confnginx settings shared by every site
/etc/cloudground-php/cg-site-<id>.confthe site's PHP-FPM configuration
/run/cloudground/php/cg-site-<id>/php.sockthe site's PHP-FPM socket
/etc/nginx/cloudground-auth/<domain>.htpasswda staging copy's password
/etc/cron.d/ and /etc/cloudground/cron/the sites' scheduled tasks
/etc/letsencrypt/live/<domain>/the site's certificate

Server​

PathContents
/etc/mysql/mariadb.conf.d/99-cloudground.cnfMariaDB's configuration, calculated for the server
/etc/sysctl.d/60-cloudground.confthe kernel settings
/etc/ssh/sshd_config.d/10-cloudground-sftp.confchrooted SFTP for the sites
/etc/ssh/sshd_config.d/11-cloudground-shell.confthe site shells' cg-shell-* logins, keys only
/var/cache/cloudground/restic/restic's cache for the backup repository
/etc/logrotate.d/cloudgroundrotation of the sites' logs
/var/log/mysql/slow.logMariaDB's slow queries, over 1 second
/etc/nginx/sites-enabled/cloudground-panel-bootstrap.confthe default servers on :80 and :443 and the panel on :8443
/etc/nginx/nginx.conf.cloudground-prenginx.conf as it was before the installer, put back by the uninstall
/etc/letsencrypt/renewal-hooks/deploy/cloudground-reload-nginx.shreloads nginx after a certificate renewal
/usr/local/bin/restic, wp, composerrestic, wp-cli and composer, at the versions the installer pins

Directories the installer creates​

The installer creates these directories, or fixes their mode, on every run. "Unchanged" means an existing directory keeps its owner, and a new one belongs to root.

DirectoryModeOwner
/srv/sites0755unchanged
/var/log/cloudground0755unchanged
/var/cache/cloudground0755unchanged
/var/lib/cloudground0750cloudground:cloudground
/var/www/cloudground-acme0755unchanged
/run/cloudground0755unchanged
/run/cloudground/php0755unchanged
/etc/cloudground-php0755root:root
/var/lib/cloudground-agent0700root:root
/var/lib/cloudground-agent/work0700root:root
/etc/cloudground0750group cloudground
/etc/cloudground/certs0750group cloudground
/var/lib/letsencrypt0755unchanged
/var/spool/cron0755unchanged

/var/www/cloudground-acme is the web folder for certificate challenges. /var/lib/letsencrypt and /var/spool/cron belong to certbot and cron: the installer creates them before they exist so that the agent can start.

Next step​

To see how these pieces work together, read the architecture.

Was this page useful?
Edit this page ↗