@@PRODUCT@@

Managing a server

A server has seven sections, and as of this round they are all in one bar at the top of the page — on every one of that server's screens. Wherever you are, you are one click from the other six.

Written for: Administrator

A server has seven sections, and as of this round they are all in one bar at the top of the page — on every one of that server's screens. Wherever you are, you are one click from the other six.

Servers → click the server.

Overview · Manage · Tools · Drop-ins · PHP policy · Mail delivery · Terminal

Before this, Tools, Drop-ins and the PHP policy were reachable only from the Quick actions block at the bottom of the server dashboard — six blocks of scrolling down, on a screen you were reading something else on. And every sub-screen had nothing but a back arrow: getting from the firewall to the tools meant going up and coming back down.

The seven sections, and what belongs in each

TabWhat for
OverviewOne Health block, the five meters, the charts, the biggest consumers and the tasks in flight.
ManageThe machine itself: SSH port, root keys, starting and stopping services, the platform switches (guest agent, trim), the profile, reboot and shutdown.
ToolsWhat the server carries beside its roles: git, Composer, WP-CLI, imapsync, a Node or Python series, Valkey, Docker.
Drop-insYour own service configuration on top of ours, per service.
PHP policyThe bounds this machine puts around customers' PHP settings.
Mail deliveryWhere this server's post went. Only on a machine with the mail role.
TerminalA root shell in the browser.

Statistics is deliberately not in the bar. That screen lives under Insights → Statistics rather than under the server; as a tab it would be a tab you press to lose the bar. It is the second button at the top right instead.

The screens that have no tab of their own — the firewall, the logs, the server advisor, integrations, infected files, addresses — draw the bar anyway, with nothing selected. So you can always leave them sideways instead of having to go up first.

The overview: one Health block

One block at the top of the overview answers "is this machine running?" once: a sentence with the counts in it, the first three things that need attention with their buttons on them, and one chip saying how many services are up. A service that is down is a line there with Start beside it, not a row in a list three blocks further down.

Behind the line All services, every check, and the advisor at the foot of the block stand every unit with its own restart button, and the door to the full server advisor. That is the same page, not a second view.

The same facts used to be in three places: the attention block, a counter reading "services 5/6" among the meters, and a list of every unit halfway down the page. The counter is gone and the list is behind the disclosure — no button disappeared, only the asking of one question three times.

What left the Quick actions block

The block at the bottom of the dashboard repeated four things that were already at the top right: the terminal, Configure server, Manage addresses and Statistics. Those are gone. Two more then moved to where their question lives: the logs now sit beside the task list they explain, and the server advisor behind the health block its findings come from. What remains in the block is what has no other door on that page and no closer neighbour either: the integrations, infected files, the firewall, the website firewall, and starting a rollout.

Choosing the webserver, and which LiteSpeed

The webserver choice appears in two places and they are now the same one: the add wizard (Servers → Add server) and the Configure server panel at the top right of the server dashboard.

Four choices, under their real names:

  • nginx + Apache — the default: nginx in front, Apache behind it for .htaccess.
  • nginx — nginx alone.
  • Apache — Apache alone.
  • LiteSpeed — and then a second choice:
  • OpenLiteSpeed (free) — installs on its own, no licence needed.
  • LiteSpeed Enterprise — licence required — .htaccess compatible and LSCache for every application, but it wants a serial.

Beside it is the LSCache switch, LiteSpeed's own page cache.

The fourth option used to read "OpenLiteSpeed", and the edition was never sent at all — so every LiteSpeed node came up on the free edition, licence or no licence.

A new server on LiteSpeed Enterprise

In the add wizard the panel asks for the serial as soon as you pick Enterprise. What happens then, in this order:

  1. The join code does not carry the Enterprise edition. It cannot: the installer looks for the licence on disk before it does anything, and the panel cannot reach a machine that has not enrolled yet. So the server comes up on nginx + Apache.
  2. As soon as the join is green, the panel puts the serial on the machine.
  3. Only then does it switch the webserver to LiteSpeed Enterprise.

You watch those two steps on their own card under the progress panel, with a Try again button if something goes wrong.

The serial never enters the panel's database. It exists in that one browser tab, goes straight to the server and lives there in /etc/corecp/secrets; the panel only ever shows its state. On the server itself it is the same pair of commands:

printf '%s' '<serial>' | corectl integration credential set litespeed --credential serial --stdin
corectl webserver set litespeed --edition lsws --lscache on

Close the tab before the join finishes and nothing is lost but the convenience: the server runs on nginx + Apache and you do the same two steps on that server's Integrations and Configure server screens.

Switching edition on an existing server

Only possible when the other edition is no longer there. The two share one server root (/usr/local/lsws) and cannot coexist, and removing an Enterprise install throws away a licence activation — which is not a decision a provider switch gets to make for you. So the server refuses the switch, and the explanation appears inside the panel, not on the page behind it.

Removing is done on the machine:

/usr/local/lsws/admin/misc/uninstall.sh     # Enterprise
apt purge openlitespeed                     # OpenLiteSpeed

When the server installs its own updates

Servers → the machine → Onderdelen, at the bottom. Everything above it on that tab is software the platform put there — the agent, the PHP builds, the database engine — and this is the other half of the same question: what the operating system puts there, and when.

Updates are off until you turn them on. A server that installs security updates at three in the morning is doing that because somebody decided it, not because it shipped that way.

  • Window — two times of day, for example 03:00-05:00. This is the promise you make to the customers on this machine about when it may restart. A window that wraps midnight is fine.
  • Security updates only — leaves everything else queued until you make time for it. The block shows how many packages are waiting either way.
  • Restarting — Tell me, do not restart is the default: when an update needs a reboot the server says so and waits for you. Restart inside the window lets it do it itself, inside the window and nowhere else.
  • Clean up afterwards — removes unused packages and old kernels. The running kernel and one fallback always stay, whatever you set.

CoreCP's own packages are held out of this stream, and the block says how many. They move through Onderdelen above and through releases, so an operating system update never brings you a new panel by accident.

Nothing installs before you have seen it

Update now and Clean up both open the server's own dry run first: this is what it would upgrade, this is which kernels would go. The button in that dialog is the real thing. A cleanup that would take three kernels off a machine and one that would take none look identical until you ask.

Inside the update dialog there is one more switch: Run now, outside the window. Without it the server waits for the window to open, and the dry run tells you so in as many words. Turning it on is you deciding to break the promise the window makes — which is why it is a switch you have to find rather than a checkbox on the button.

Both passes take as long as they take, so pressing the real button hands you a task to follow rather than a spinner.

Reboot required

When an update asks for a restart, a band appears saying so and naming the reason. Under Tell me, do not restart the server will not act on it: the restart is yours to schedule, from the same server's dashboard.

Retiring a server

A machine leaves eventually: the hardware is replaced, the contract ends, or a key has ended up somewhere it should not be. That is one button, under Danger zone on that server's page.

What happens, in this order:

  1. The certificate authority takes the certificate back. That is the step that lasts: without it the machine simply renews itself for another ninety days tomorrow morning.
  2. The panel stops talking to it. From the next connection on, this panel refuses that certificate — in seconds, not in ninety days.
  3. The other servers are given the list. Every machine that answers is told to refuse this certificate. Machines that were down get it later: the panel repeats the list every quarter of an hour.

The row in Servers stays, marked retired. That is deliberate: a year from now the audit log still has to know what stck7 was. The machine receives no new accounts, rollouts or waves.

Two things are typed before the button does anything: the server's name, so you are certain which one you are looking at, and why. The reason is not decoration — it goes in the audit log, in the message the administrator on call receives, and beside the certificate in the list below.

Customers still on the machine? Turn on Leave the certificate in place for now. The server drops out of the work rotation but stays trusted by the fleet, so websites and mailboxes can be moved off it calmly. Retire it again afterwards, without that choice.

On the machine itself the old certificate stays. While that machine is still running, corectl join --reset removes it. There is no hurry: every server in the fleet already refuses it.

What the fleet refuses

Security → Withdrawn certificates is the list: which machine, why, when and by whom, and when the certificate would have expired by itself. Usually it is empty, and that is the healthy state. The button beside it writes the list to every server straight away, for when you would rather not wait a quarter of an hour; that button is for administrators who see the whole fleet. With an assignment on a few servers you see the certificates of your own machines and one line saying how many more there are.

If a withdrawn certificate turns up again later — somebody boots an old machine, or somebody tries — the server remembers it and you hear about it within a quarter of an hour.

On a phone

The bar scrolls horizontally and nothing else does. At 390 pixels wide each of the seven screens fits without the page scrolling sideways, and the tab you are on is scrolled into view when you arrive by link or by ⌘K.

See also

  • Server settings and services — everything behind the Manage tab.
  • Tools on a server and Config drop-ins — the two tabs beside it.
  • Where a website is served — the server dashboard itself, meter by meter.
  • Integrations on a server — where licence keys live and what they are called.