Skip to main content
Version: 1.0.0

Adminer on Aruba Cloud

Deploy Adminer — a lightweight, single-file PHP database administration tool — on Aruba Cloud using Terraform and cloud-init. This example provisions both the Adminer web interface and a ready-to-use managed MySQL DBaaS instance, so you can connect and start exploring your database immediately after terraform apply.

Provider version: arubacloud/arubacloud ~> 1.0 | Terraform: ≥ 1.9


Introduction​

Adminer is a full-featured database management tool contained in a single PHP file. Compared to phpMyAdmin it is lighter, faster to deploy, and just as capable for day-to-day DB administration tasks. This example provisions:

  • Apache2 + PHP 8.1 — the smallest viable stack for Adminer
  • Adminer.php downloaded directly from the official GitHub release
  • PHP database drivers for MySQL (php-mysql), PostgreSQL (php-pgsql), and SQLite (php-sqlite3)
  • Managed MySQL 8.0 DBaaS — a dedicated database instance with autoscaling storage
  • DBaaS user and database — ready to connect out of the box
  • Port 80 restricted to admin_cidr — Adminer is never exposed to the public internet

Security note: Adminer has no built-in rate limiting or IP restriction. Always set admin_cidr to your specific management IP (e.g. 203.0.113.42/32) and never deploy with the default 0.0.0.0/0 in production.


Architecture Overview​


Infrastructure Created​

ResourceName patternDescription
arubacloud_projectadminer-prodProject container
arubacloud_vpcadminer-prod-vpcVirtual Private Cloud
arubacloud_subnetadminer-prod-subnetSubnet
arubacloud_securitygroupadminer-prod-vm-sgVM security group
arubacloud_securitygroupadminer-prod-dbaas-sgDBaaS security group
arubacloud_securityruleadminer-prod-vm-sshSSH ingress (port 22)
arubacloud_securityruleadminer-prod-vm-admin-uiAdminer UI ingress (port 80)
arubacloud_securityruleadminer-prod-db-mysqlMySQL ingress from VM IP only (port 3306)
arubacloud_elasticipadminer-prod-vm-eipVM public IP
arubacloud_elasticipadminer-prod-dbaas-eipDBaaS public IP
arubacloud_blockstorageadminer-prod-boot20 GB boot disk (Performance)
arubacloud_keypairadminer-prod-keypairSSH public key
arubacloud_cloudserveradminer-prod-vmCloudServer VM
arubacloud_dbaasadminer-prod-dbaasManaged MySQL 8.0 instance
arubacloud_database—Default database inside the DBaaS
arubacloud_dbaasuser—DBaaS admin user
arubacloud_databasegrant—liteadmin grant on the default database

Estimated Monthly Cost​

ResourceSpecEst. cost/mo
CloudServer VMCSO1A2 — 1 vCPU / 2 GB~€9
Boot disk20 GB Performance~€3
VM Elastic IP—~€3
Managed MySQL DBaaSDBO2A8 — 20 GB~€30
DBaaS Elastic IP—~€3
Total~€48/mo

Billed hourly when billing_period = "Hour". Destroy the stack when not in use to avoid charges.


Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 1.0
  • An ArubaCloud account with OAuth2 API credentials

All other inputs (SSH key, passwords) have working defaults for try-out purposes.


Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret

Optional​

VariableDefaultDescription
app_name"adminer"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO1A2"CloudServer flavor
vm_image"LU22-001"Boot disk image (Ubuntu 22.04 LTS)
vm_disk_size_gb20Boot disk size in GB
ssh_public_key(example key)SSH public key content
ssh_cidr"0.0.0.0/0"CIDR for SSH — restrict in production
admin_cidr"0.0.0.0/0"CIDR for Adminer UI — always restrict
dbaas_flavor"DBO2A8"Managed MySQL DBaaS flavor
db_storage_gb20Initial DBaaS storage in GB
db_admin_user"dbadmin"DBaaS admin username
db_admin_password"K7m@P4z!L9"DBaaS admin password (see password note below)
db_name"adminer"Default database name
adminer_version"4.8.1"Adminer release version

Password note: The ArubaCloud DBaaS API receives passwords base64-encoded and stores that base64 string as the MySQL password. The value you set in db_admin_password is the Terraform variable; the actual MySQL password is its base64 encoding. Use terraform output -raw db_admin_password_mysql to retrieve the correct password to enter in Adminer.


Outputs​

OutputDescription
adminer_urlAdminer web interface URL
vm_public_ipPublic IP address of the VM
ssh_commandSSH command to connect to the VM
dbaas_hostPublic IP of the managed MySQL instance
db_admin_userDBaaS admin username
db_nameDefault database name
db_admin_password_mysqlActual MySQL password (base64 of db_admin_password) — sensitive, retrieve with terraform output -raw db_admin_password_mysql
adminer_connection_hintOne-line summary of connection parameters

Deployment Instructions​

1. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/adminer

2. Configure variables​

cp terraform.tfvars.example terraform.tfvars

Set your credentials. For a quick try-out, only the two OAuth2 credentials are required — everything else has defaults:

arubacloud_client_id = "your-client-id"
arubacloud_client_secret = "your-client-secret"

For production, also restrict access:

ssh_public_key = "ssh-ed25519 AAAA..."
ssh_cidr = "203.0.113.42/32"
admin_cidr = "203.0.113.42/32"
db_admin_password = "YourStrongPassword123!"

3. Deploy​

terraform init
terraform plan
terraform apply

Bootstrap takes approximately 8–10 minutes (DBaaS provisioning dominates).

4. Retrieve the MySQL password​

The actual MySQL password is the base64 encoding of db_admin_password:

terraform output -raw db_admin_password_mysql

5. Connect to the database​

terraform output adminer_url

Open the URL in your browser and fill in the Adminer login form:

FieldValue
SystemMySQL
Serverterraform output -raw dbaas_host
Usernameterraform output -raw db_admin_user
Passwordterraform output -raw db_admin_password_mysql
Databaseterraform output -raw db_name (or leave blank to list all)

Security Recommendations​

  1. Always restrict admin_cidr to your management IP. Adminer exposes database credentials in the browser and has no built-in brute-force protection.

  2. Do not store sensitive credentials in terraform.tfvars. Use environment variables or a secrets manager in automated deployments:

    export TF_VAR_arubacloud_client_id="..."
    export TF_VAR_arubacloud_client_secret="..."
    export TF_VAR_db_admin_password="..."
  3. Add HTTP Basic Auth for an extra authentication layer before Adminer loads:

    sudo htpasswd -c /etc/apache2/.htpasswd admin

    Add to /etc/apache2/sites-enabled/000-default.conf inside <VirtualHost>:

    <Directory /var/www/html>
    AuthType Basic
    AuthName "Restricted"
    AuthUserFile /etc/apache2/.htpasswd
    Require valid-user
    </Directory>

    Then: sudo systemctl reload apache2

  4. Use a VPN. Keep admin_cidr locked to your WireGuard or other VPN tunnel CIDR and access Adminer only over VPN.


Troubleshooting​

Adminer page not loading​

# Check Apache is running
ssh ubuntu@$(terraform output -raw vm_public_ip) "sudo systemctl status apache2"

# Check Adminer PHP file exists
ssh ubuntu@$(terraform output -raw vm_public_ip) "ls -la /var/www/html/adminer.php"

# Check cloud-init completed successfully
ssh ubuntu@$(terraform output -raw vm_public_ip) "sudo tail -30 /var/log/cloud-init-output.log"

Access denied when connecting in Adminer​

The ArubaCloud DBaaS API stores the base64 encoding of your db_admin_password as the MySQL password — not the raw value. Always use:

terraform output -raw db_admin_password_mysql

Cannot reach the DBaaS from the VM​

ssh ubuntu@$(terraform output -raw vm_public_ip)
nc -zv $(terraform output -raw dbaas_host) 3306

If the connection is refused, check that the dbaas_mysql security rule allows inbound TCP 3306 from the VM's elastic IP.


References​