07 / Reference · 7.5 Paths, ports and services The ports the server listens on, the systemd services, the system users and the paths CloudGround uses.
On this page
The values are those of an installation made with the installer. <id> is the site's number in
the panel, <domain> its domain.
Ports
Port Who listens From where Use 22/tcp sshd Internet SSH for root, SFTP and site shells 80/tcp nginx Internet certificate challenges, then a redirect to HTTPS 443/tcp nginx Internet the sites and the panel domain 443/udp nginx Internet HTTP/3, when nginx has the module 8443/tcp nginx Internet the panel by IP, with its own self-signed certificate, and Quarry at /quarry 3306/tcp MariaDB the server only the sites' databases 9080/tcp panel-api 127.0.0.1 onlythe WordPress connector: cache purge and health check
The installer never turns the firewall on. When it is already active, it opens the ports sshd listens
on, 80, 443, 443/udp and 8443 (see firewall ). From the panel you cannot close the
SSH ports, 80, 443 or 8443.
The panel has no TCP port of its own: nginx talks to it on the socket /run/cloudground/api.sock.
Services
systemd unit Runs as What it does cloudground-api.servicecloudgroundthe panel's API and interface cloudground-api.socket— opens /run/cloudground/api.sock for the API cloudground-agent.serviceroot, sandboxed the privileged work cloudground-php-cg-site-<id>.servicecg-site-<id>a site's PHP-FPM, in the slice cg-site-<id>.slice cloudground-update-guard.serviceroot transient, during a panel update nginx.serviceroot and www-data the web server mariadb.servicemysqlthe databases redis-server.service— not installed on a new server; a server upgraded from an earlier version keeps it switched off
Users and groups
Name What it is cloudgroundthe panel's user, without a shell cg-site-<id>a site's system user: owns its files, runs its PHP, signs in over SFTP cg-shell-<id>the site shell's login, with the same uid as cg-site-<id> cg-sftp-offgroup: its members can sign in over neither SSH nor SFTP site_<id>the default name of a site's primary MariaDB database and user, when you choose none (see database names and passwords )
The panel
Path Contents /usr/local/bin/panel-api, panel-agent, cgctl, cg-site-shellthe binaries /etc/cloudground/panel.envthe panel's and the agent's configuration /etc/cloudground/cgctl.envcgctl's configuration /etc/cloudground/agent.tokenthe secret shared by the panel and the agent /etc/cloudground/certs/the panel's certificates (panel.pem, panel-ip.pem), the fallback (fallback.pem) and uploaded ones (custom/) /var/lib/cloudground/state.dbthe panel's database /var/lib/cloudground/secret.keythe key that encrypts the database's secrets: back it up with the database /var/lib/cloudground-agent/the agent's working space and, after the first update, highest-release /var/lib/cloudground-agent/installed.jsonwhat the installer installed because it was missing: packages, repository, tools (read by cgctl uninstall --purge-packages) /var/lib/cloudground-agent/update-result.jsonthe outcome of the last update /var/lib/cloudground-agent/update-snapshots/the snapshots taken before an update, the newest three /var/lib/cloudground-agent/databases.jsonthe agent's record of which database and database user is which site's (see recover the database record ) /run/cloudground/agent.sockthe agent's socket /run/cloudground/shell.sockthe socket on which the agent takes the site shells' sessions /var/log/cloudground-install.logthe installer's log /root/cloudground-uninstall/after an uninstall: the panel's state, backup.env, README.txt (see uninstall CloudGround )
The sites
Path Contents /srv/sites/<domain>/the site's folder /srv/sites/<domain>/currentthe link to the live release, releases/<id> /srv/sites/<domain>/releases/the releases /srv/sites/<domain>/shared/what stays across releases: wp-config.php, uploads /srv/sites/<domain>/tmp/PHP's temporary files and sessions /var/log/cloudground/<domain>/access.log, error.log, php-error.log/var/cache/cloudground/<domain>/the page cache /etc/nginx/sites-enabled/<domain>.confthe vhost /etc/nginx/conf.d/cloudground-cache-<id>.confthe site's cache zone /etc/nginx/conf.d/cloudground-global.confnginx settings shared by every site /etc/cloudground-php/cg-site-<id>.confthe site's PHP-FPM configuration /run/cloudground/php/cg-site-<id>/php.sockthe site's PHP-FPM socket /etc/nginx/cloudground-auth/<domain>.htpasswda staging copy's password /etc/cron.d/ and /etc/cloudground/cron/the sites' scheduled tasks /etc/letsencrypt/live/<domain>/the site's certificate
Server
Path Contents /etc/mysql/mariadb.conf.d/99-cloudground.cnfMariaDB's configuration, calculated for the server /etc/sysctl.d/60-cloudground.confthe kernel settings /etc/ssh/sshd_config.d/10-cloudground-sftp.confchrooted SFTP for the sites /etc/ssh/sshd_config.d/11-cloudground-shell.confthe site shells' cg-shell-* logins, keys only /var/cache/cloudground/restic/restic's cache for the backup repository /etc/logrotate.d/cloudgroundrotation of the sites' logs /var/log/mysql/slow.logMariaDB's slow queries, over 1 second /etc/nginx/sites-enabled/cloudground-panel-bootstrap.confthe default servers on :80 and :443 and the panel on :8443 /etc/nginx/nginx.conf.cloudground-prenginx.conf as it was before the installer, put back by the uninstall/etc/letsencrypt/renewal-hooks/deploy/cloudground-reload-nginx.shreloads nginx after a certificate renewal /usr/local/bin/restic, wp, composerrestic, wp-cli and composer, at the versions the installer pins
Directories the installer creates
The installer creates these directories, or fixes their mode, on every run. "Unchanged" means an
existing directory keeps its owner, and a new one belongs to root.
Directory Mode Owner /srv/sites0755 unchanged /var/log/cloudground0755 unchanged /var/cache/cloudground0755 unchanged /var/lib/cloudground0750 cloudground:cloudground/var/www/cloudground-acme0755 unchanged /run/cloudground0755 unchanged /run/cloudground/php0755 unchanged /etc/cloudground-php0755 root:root/var/lib/cloudground-agent0700 root:root/var/lib/cloudground-agent/work0700 root:root/etc/cloudground0750 group cloudground /etc/cloudground/certs0750 group cloudground /var/lib/letsencrypt0755 unchanged /var/spool/cron0755 unchanged
/var/www/cloudground-acme is the web folder for certificate challenges. /var/lib/letsencrypt and
/var/spool/cron belong to certbot and cron: the installer creates them before they exist so that
the agent can start.
Next step
To see how these pieces work together, read the architecture .