Coriolis STACKIT Installer
Last updated on
Overview
Section titled “Overview”The Coriolis STACKIT Installer deploys a Cloudbase Coriolis appliance from an OVA into a STACKIT project. A single Go binary validates the appliance and target placement, prepares a reusable STACKIT image, provisions the runtime infrastructure, and bootstraps access without Terraform, the STACKIT CLI, a serial console, or manual Web Console steps.
This asset covers appliance deployment and life cycle-safe reruns. Cloudbase Coriolis provides the actual migration and disaster recovery capabilities used after the appliance is ready.
Cloudbase Coriolis Review the migration, replication, and disaster recovery capabilities of the deployed product. Open pageWhat the installer automates
Section titled “What the installer automates”- OVA inspection and placement validation: Reads OVF metadata, calculates the OVA SHA-256, and rejects incompatible disk sizing, availability zones, or machine types before image upload.
- Image normalization: Streams the VMDK to a temporary STACKIT helper VM, converts it through RAW to QCOW2, installs the STACKIT Server Agent offline, and imports a reusable image.
- Image reuse and sharing: Discovers normalized images by OVA hash, resumes interrupted imports, and supports project-specific, organization-wide, or central image-project sharing.
- STACKIT infrastructure: Creates or reuses the network, security group, appliance VM, public IP, DNS record, and supporting resources from declarative YAML settings.
- Bootstrap and exposure: Configures the hostname and appliance administrator password through Run Command, then provides direct HTTPS with ACME DNS-01 or optional TLS termination through a STACKIT Application Load Balancer.
- Repeatable execution: Reuses matching infrastructure, generated credentials, and current certificates on subsequent runs and returns a structured JSON result for downstream automation.
Inputs and outputs
Section titled “Inputs and outputs”Typical inputs are:
- a STACKIT service-account key and target project ID;
- the target STACKIT region;
- a supported Cloudbase Coriolis OVA;
- a YAML configuration based on the repository example.
The successful result contains the resolved image, network, server, security group, public IP, and login details as JSON. When configured to print a generated appliance password, route stdout directly into a protected secret store instead of retaining it in terminal or build logs.
Recommended workflow
Section titled “Recommended workflow”- Build the binary with
make check, or use a suitable prebuilt binary when one is available. - Copy the example YAML, add project-specific values, and protect the service-account key and any fixed password.
- Run
--dry-runto validate configuration, OVA metadata, sizing, and the resolved deployment plan without cloud changes. - Run
--check-cloudto validate authentication, placement, and optional DNS or load-balancer access, then verify quotas separately. - Run the deployment, store its JSON result securely, and repeat the same command to confirm that resources are reused.
Prerequisites
Section titled “Prerequisites”- Operator workstation: Requires the installer binary, read access to the OVA, outbound HTTPS to STACKIT APIs, and temporary outbound TCP/22 to the helper VM during a new image import. Building from source requires Go 1.25 or newer.
- Service-account permissions: Automatic Run Command activation requires the
Project Editorrole. The selected workflow also needs read and write access to its IaaS, Server Agent, DNS, and optional load-balancer and certificate resources. - Quota and connectivity: The first import temporarily uses a helper VM, two data volumes, a public IP, a security group, and a key pair in addition to the final image and appliance resources.
- OVA format: The OVA must be TAR-based and contain exactly one OVF and one referenced virtual disk. The current installer supports one appliance disk.
- Storage performance: The documented default uses
storage_premium_perf12for appliance and normalization volumes because conversion, image upload, migration, and backup paths create sustained I/O load.
Security and operational boundaries
Section titled “Security and operational boundaries”- The appliance security group opens only TCP/443 by default. The STACKIT Server Agent uses an outbound management channel and does not need an ingress rule.
- A new OVA import temporarily permits TCP/22 to the helper VM from
0.0.0.0/0. Access requires a one-time key and a host key pinned through Server Agent. Rerun or clean up promptly after a failed import because helper resources may remain for recovery. - Direct TLS keeps the private key on the appliance. The optional Application Load Balancer covers only the HTTPS web path and does not proxy every Coriolis migration or worker connection.
- Existing servers, failed VMs, security-group rules, and licensed appliance state are never deleted or replaced implicitly.
Limitations
Section titled “Limitations”- The installer is not a Coriolis upgrade tool and does not migrate licenses, projects, endpoints, transfer state, or application data to a new appliance.
- A new OVA creates a new normalized image but never replaces an existing stateful server automatically.
--check-cloudvalidates access and placement but does not reserve resources or replace a full quota check.- Adopting an existing server can change its hostname, administrator password, or TLS configuration when the corresponding management features are enabled. Back up a licensed production appliance before first adoption.
References
Section titled “References”Asset historyAdded Sep 15, 2026LWUpdatedNo updates · 1 bar = 1 week i
- LWLukas WeberrußHead of STACKIT Cloud Migration Framework · STACKITOwner
Lukas WeberrußHead of STACKIT Cloud Migration Framework · STACKITOwnerActive 10 of the last 12 weeks · 47 updateswww.linkedin.com/in/lukas-weberruß-a360b081