Skip to main content
Version: Next

NGINX on Aruba Cloud

Deploy NGINX as a web server or reverse proxy on Aruba Cloud using Terraform and cloud-init. This example provisions a production-ready NGINX instance with a default static site and optional automatic HTTPS via Certbot and an ACME provider such as Actalis ACME Certificates or Let's Encrypt.

Provider version: arubacloud/arubacloud ~> 1.0 | Terraform: ≥ 1.9


Introduction​

NGINX is a high-performance HTTP server, reverse proxy, and load balancer. This example provisions a minimal VM running NGINX with:

  • NGINX installed from Ubuntu 22.04 official packages
  • A default static HTML site served from /var/www/html
  • Ports 80 (HTTP) and 443 (HTTPS) open to web_cidr
  • Optional automatic HTTPS via Certbot when domain and certbot_email are set (use --server to select an ACME provider such as Actalis ACME Certificates or Let's Encrypt)

After deployment, replace the default site with your own content or additional server {} blocks for virtual hosting or reverse proxying.


Architecture Overview​


Infrastructure Created​

ResourceName patternDescription
arubacloud_projectnginx-prodProject container
arubacloud_vpcnginx-prod-vpcVirtual Private Cloud
arubacloud_subnetnginx-prod-subnetBasic subnet
arubacloud_securitygroupnginx-prod-vm-sgSecurity group
arubacloud_securityrulenginx-prod-vm-sshSSH ingress
arubacloud_securityrulenginx-prod-vm-httpHTTP ingress TCP 80
arubacloud_securityrulenginx-prod-vm-httpsHTTPS ingress TCP 443
arubacloud_elasticipnginx-prod-vm-eipVM public IP
arubacloud_blockstoragenginx-prod-boot20 GB boot disk (Performance)
arubacloud_keypairnginx-prod-keypairSSH public key
arubacloud_cloudservernginx-prod-vmCloudServer VM

Estimated Monthly Cost​

ResourceSpecEst. cost/mo
CloudServer VMCSO1A2 — 1 vCPU / 2 GB~€9
Boot disk20 GB Performance~€3
Elastic IP—~€3
Total~€15/mo

Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 1.0
  • An ArubaCloud account with OAuth2 API credentials
  • An SSH key pair
  • (For HTTPS) A domain name with an A record pointing to the VM's Elastic IP

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content

Optional​

VariableDefaultDescription
app_name"nginx"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO1A2"CloudServer flavor
vm_image"LU22-001"Boot disk image (Ubuntu 22.04 LTS)
vm_disk_size_gb20Boot disk size in GB
ssh_cidr"0.0.0.0/0"CIDR for SSH — restrict in production
web_cidr"0.0.0.0/0"CIDR for HTTP/HTTPS — typically 0.0.0.0/0 for public sites
domain""Domain name for ACME HTTPS via a provider such as Actalis or Let's Encrypt (DNS must point to VM first)
certbot_email""Email for Let's Encrypt notifications (required with domain)

Outputs​

OutputDescription
http_urlHTTP URL of the web server
https_urlHTTPS URL (only valid when domain and certificate are configured)
vm_public_ipPublic IP address of the VM
ssh_commandSSH command to connect to the VM

Deployment Instructions​

1. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/nginx

2. Configure variables​

cp terraform.tfvars.example terraform.tfvars

For HTTP-only deployment, only credentials and SSH key are required. For HTTPS:

domain = "example.com"
certbot_email = "admin@example.com"

Important: The DNS A record for domain must already point to the VM's Elastic IP before you apply. To get the IP first, run terraform apply without domain, note the vm_public_ip output, set your DNS record, then re-apply with domain set.

3. Deploy​

terraform init
terraform plan
terraform apply

Bootstrap takes approximately 1–2 minutes (3–5 minutes with Let's Encrypt).

4. Access the site​

terraform output http_url

5. Deploy your content​

ssh ubuntu@$(terraform output -raw vm_public_ip)
# Replace the default page:
sudo cp my-site/* /var/www/html/

Customisation​

Serving a second site (virtual hosting)​

Create a new site config and enable it:

sudo tee /etc/nginx/sites-available/mysite.conf << 'EOF'
server {
listen 80;
server_name mysite.example.com;
root /var/www/mysite;
index index.html;
location / { try_files $uri $uri/ =404; }
}
EOF
sudo ln -s /etc/nginx/sites-available/mysite.conf /etc/nginx/sites-enabled/
sudo nginx -t && sudo systemctl reload nginx

Reverse proxy​

Replace the location / block:

location / {
proxy_pass http://127.0.0.1:8080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}

Security Recommendations​

  1. Restrict ssh_cidr to your management IP. SSH on 0.0.0.0/0 is acceptable for a quick start, but exposes the VM to brute-force attacks.

  2. Enable HTTPS for any production site. Set domain and certbot_email to get a free certificate via an ACME provider such as Actalis ACME Certificates or Let's Encrypt. HTTP-only should only be used for internal or development sites.

  3. Keep NGINX updated. Ubuntu's unattended-upgrades handles security patches automatically if enabled. Check with sudo unattended-upgrades --dry-run.


Troubleshooting​

NGINX not starting​

sudo nginx -t
sudo systemctl status nginx
sudo journalctl -u nginx -n 30

ACME certificate not issued​

# Check DNS propagation first:
dig +short A example.com

# Re-run certbot manually:
sudo certbot --nginx -d example.com -m admin@example.com --non-interactive --agree-tos --redirect

Common causes: DNS A record not yet propagated, port 80 blocked by web_cidr, or domain mistyped.


References​