---
title: "Coriolis STACKIT Installer"
description: "The Coriolis STACKIT Installer reproducibly deploys a Cloudbase Coriolis appliance from an OVA with image normalization, networking, DNS, and TLS automation."
scfAsset:
  managed: false
  category: "software"
  external: true
  tags: ["design-and-mobilize", "design", "relocate", "coriolis", "deployment", "automation", "ova", "vm"]
  maintainers:
    - user: "lukas.weberruss"
source_url: "https://framework.stackit.cloud/migration/assetcontainer/stackit/coriolis-stackit-installer/"
source_file: "docs/migration/assetcontainer/stackit/coriolis-stackit-installer.mdx"
---

## Overview

The Coriolis STACKIT Installer deploys a Cloudbase Coriolis appliance from an OVA into a STACKIT
project. A single Go binary validates the appliance and target placement, prepares a reusable
STACKIT image, provisions the runtime infrastructure, and bootstraps access without Terraform, the
STACKIT CLI, a serial console, or manual Web Console steps.

This asset covers appliance deployment and life cycle-safe reruns. Cloudbase Coriolis provides the
actual migration and disaster recovery capabilities used after the appliance is ready.

<LinkCard
  title="Cloudbase Coriolis"
  description="Review the migration, replication, and disaster recovery capabilities of the deployed product."
  href="/migration/assetcontainer/cloudbase/cloudbase-coriolis/"
/>

## What the installer automates

- **OVA inspection and placement validation**: Reads OVF metadata, calculates the OVA SHA-256, and
  rejects incompatible disk sizing, availability zones, or machine types before image upload.
- **Image normalization**: Streams the VMDK to a temporary STACKIT helper VM, converts it through
  RAW to QCOW2, installs the STACKIT Server Agent offline, and imports a reusable image.
- **Image reuse and sharing**: Discovers normalized images by OVA hash, resumes interrupted imports,
  and supports project-specific, organization-wide, or central image-project sharing.
- **STACKIT infrastructure**: Creates or reuses the network, security group, appliance VM, public
  IP, DNS record, and supporting resources from declarative YAML settings.
- **Bootstrap and exposure**: Configures the hostname and appliance administrator password through
  Run Command, then provides direct HTTPS with ACME DNS-01 or optional TLS termination through a
  STACKIT Application Load Balancer.
- **Repeatable execution**: Reuses matching infrastructure, generated credentials, and current
  certificates on subsequent runs and returns a structured JSON result for downstream automation.

## Inputs and outputs

Typical inputs are:

- a STACKIT service-account key and target project ID;
- the target STACKIT region;
- a supported Cloudbase Coriolis OVA;
- a YAML configuration based on the repository example.

The successful result contains the resolved image, network, server, security group, public IP, and
login details as JSON. When configured to print a generated appliance password, route stdout
directly into a protected secret store instead of retaining it in terminal or build logs.

## Recommended workflow

<Steps>
1. Build the binary with `make check`, or use a suitable prebuilt binary when one is available.
2. Copy the example YAML, add project-specific values, and protect the service-account key and any fixed password.
3. Run `--dry-run` to validate configuration, OVA metadata, sizing, and the resolved deployment plan without cloud changes.
4. Run `--check-cloud` to validate authentication, placement, and optional DNS or load-balancer access, then verify quotas separately.
5. Run the deployment, store its JSON result securely, and repeat the same command to confirm that resources are reused.
</Steps>

## Prerequisites

- **Operator workstation**: Requires the installer binary, read access to the OVA, outbound HTTPS
  to STACKIT APIs, and temporary outbound TCP/22 to the helper VM during a new image import. Building
  from source requires Go 1.25 or newer.
- **Service-account permissions**: Automatic Run Command activation requires the `Project Editor`
  role. The selected workflow also needs read and write access to its IaaS, Server Agent, DNS, and
  optional load-balancer and certificate resources.
- **Quota and connectivity**: The first import temporarily uses a helper VM, two data volumes, a
  public IP, a security group, and a key pair in addition to the final image and appliance resources.
- **OVA format**: The OVA must be TAR-based and contain exactly one OVF and one referenced virtual
  disk. The current installer supports one appliance disk.
- **Storage performance**: The documented default uses `storage_premium_perf12` for appliance and
  normalization volumes because conversion, image upload, migration, and backup paths create
  sustained I/O load.

## Security and operational boundaries

- The appliance security group opens only TCP/443 by default. The STACKIT Server Agent uses an
  outbound management channel and does not need an ingress rule.
- A new OVA import temporarily permits TCP/22 to the helper VM from `0.0.0.0/0`. Access requires a
  one-time key and a host key pinned through Server Agent. Rerun or clean up promptly after a failed
  import because helper resources may remain for recovery.
- Direct TLS keeps the private key on the appliance. The optional Application Load Balancer covers
  only the HTTPS web path and does not proxy every Coriolis migration or worker connection.
- Existing servers, failed VMs, security-group rules, and licensed appliance state are never
  deleted or replaced implicitly.

## Limitations

- The installer is not a Coriolis upgrade tool and does not migrate licenses, projects, endpoints,
  transfer state, or application data to a new appliance.
- A new OVA creates a new normalized image but never replaces an existing stateful server
  automatically.
- `--check-cloud` validates access and placement but does not reserve resources or replace a full
  quota check.
- Adopting an existing server can change its hostname, administrator password, or TLS configuration
  when the corresponding management features are enabled. Back up a licensed production appliance
  before first adoption.

## References

<CardGrid>
  <LinkCard
    title="Coriolis STACKIT Installer repository"
    href="https://github.com/stackitcloud/coriolis-stackit-installer"
  />
  <LinkCard
    title="Getting started"
    href="https://github.com/stackitcloud/coriolis-stackit-installer/blob/main/docs/en/getting-started.md"
  />
  <LinkCard
    title="Technical prerequisites"
    href="https://github.com/stackitcloud/coriolis-stackit-installer/blob/main/docs/en/prerequisites.md"
  />
  <LinkCard
    title="Configuration reference"
    href="https://github.com/stackitcloud/coriolis-stackit-installer/blob/main/docs/en/configuration.md"
  />
  <LinkCard
    title="Network and security"
    href="https://github.com/stackitcloud/coriolis-stackit-installer/blob/main/docs/en/security.md"
  />
</CardGrid>
