Skip to content

Deploy a server in the cloud

Run your SpanDock Server on a cloud VM, so it's always on for the whole team. Clients reach it over the encrypted tunnel, so no inbound port and no public address are needed: the VM only connects out.

Pick one way:

WayBest forDownload
One paste (cloud-init)Any provider's console: DigitalOcean, Hetzner, Akamai, Vultr, AWS, Google Cloud, Azure…cloud-init.yaml
One commandA Linux machine you already haveinstall-server.sh
Terraform on AWSEC2, as codespandock-terraform-aws.zip
Terraform on Google CloudCompute Engine, as codespandock-terraform-gcp.zip
AnsibleFleets of hosts you managespandock-ansible.zip

The kits are also on GitHub, under the Apache 2.0 license: SpanDock/spandock-deploy.

Every way installs the same thing:

  • a spandock service account;
  • the release, checked against its published checksums;
  • a systemd service that restarts on failure.

The server keeps itself up to date when Install updates automatically is on in its settings.

What to choose

  • System: Ubuntu 24.04 or later, or Debian 13. SpanDock needs glibc 2.38 or later. x86-64 or ARM64.
  • Size: 2 vCPU, 4 GB of memory and 30 GB of disk suit up to about 50 developers. For a larger team or longer history, use the hardware calculator.
  • Network: outbound HTTPS. Nothing has to reach the machine; open SSH only if you want it.
ProviderA good start (2 vCPU, 4 GB)ARM option
AWSt3.mediumt4g.medium
Google Cloude2-mediumt2a-standard-1 or larger
AzureB2sB2pls v2
DigitalOceanBasic 2 vCPU / 4 GB—
HetznerCPX21CAX11
Vultr, Akamai2 vCPU / 4 GB shared CPU—

One paste: cloud-init

Create a VM with Ubuntu 24.04 and paste cloud-init.yaml into the user data field:

ProviderWhere to paste
DigitalOceanCreate Droplet → Advanced options → Add initialization scripts
HetznerAdd server → Cloud config
Akamai (Linode)Create Linode → Add User Data
VultrDeploy → Additional features → Cloud-Init User-Data
AWS EC2Launch instance → Advanced details → User data
Google CloudCreate instance → Advanced → Management → Metadata: key user-data, the file as value
AzureCreate a virtual machine → Advanced → Custom data

Then activate the server.

One command

On a Linux machine you already have:

curl -fsSL https://spandock.com/deploy/install-server.sh | sudo bash

It prints the activation link when it's done. Run it again at any time to repair or upgrade the install; your data and settings stay.

Options, as environment variables after sudo:

  • SPANDOCK_VERSION=v0.14.0: pin a release.
  • SPANDOCK_JOIN_CODE=…: join a hub as a satellite.

For example: curl -fsSL … | sudo SPANDOCK_VERSION=v0.14.0 bash.

Terraform on AWS

Download spandock-terraform-aws.zip. It creates one EC2 instance with:

  • Ubuntu 24.04;
  • an encrypted gp3 disk;
  • IMDSv2 required;
  • a security group with no inbound rule.
cp terraform.tfvars.example terraform.tfvars   # region, instance type, disk
terraform init && terraform apply

The activation output is a command that reads the instance's console and prints the activation link. Settings in variables.tf:

  • your own subnet;
  • an SSH key and an allowed address;
  • Graviton (architecture = "arm64");
  • a pinned version;
  • a satellite join code.

Terraform on Google Cloud

Download spandock-terraform-gcp.zip, or open it in Cloud Shell to run it from your browser, already signed in to your project. It creates one Compute Engine VM with Ubuntu 24.04, as a Shielded VM, and no firewall rule.

cp terraform.tfvars.example terraform.tfvars   # project, region, machine type, disk
gcloud auth application-default login
terraform init && terraform apply

The activation output reads the serial port and prints the activation link. On a network with Cloud NAT, set external_ip = false.

Ansible

Download spandock-ansible.zip for machines you already manage:

cp inventory.example.ini inventory.ini   # your hosts
ansible-playbook -i inventory.ini site.yml

The role checks the platform, installs the release, and installs and starts the service. For each new hub it prints the activation link. Running it again upgrades to spandock_version and keeps all data.

Activate the server

A new SpanDock Server is approved once, by you, on spandock.com. A few minutes after boot it prints a link. Open it on any device, sign in, check the code matches what the server shows, and approve. The license is then stored on the server, and restarts don't ask again.

Where to read the link:

WhereHow
Over SSHjournalctl -u spandock -f
AWSEC2 → the instance → Actions → Monitor and troubleshoot → Get system log, or the Terraform activation command
Google CloudThe instance → Serial port 1 (console), or the Terraform activation command
AzureThe VM → Help → Boot diagnostics → Serial log
OthersThe provider's web or recovery console

The code expires after a few minutes; the server then prints a new one by itself.

Add satellites

Satellites share the load and let clients fail over. They need Premium or Enterprise.

  1. On the hub, open Settings → Scaling → Add server and copy the join code. It works once, for 30 minutes.
  2. Create the new VM with the code:
    • cloud-init: put it in the SPANDOCK_JOIN_CODE='' part of the file;
    • one command: curl … | sudo SPANDOCK_JOIN_CODE='…' bash;
    • Terraform: join_code = "…";
    • Ansible: -e spandock_join_code=….

A satellite follows the hub's license, so it doesn't need its own activation. See Satellites and failover.

Where things live

WhatWhere
The program/var/lib/spandock/bin/spandock (owned by the service, so it can update itself)
Data and settings/var/lib/spandock/.config/
Service settings/etc/spandock/server.env
Logsjournalctl -u spandock
Healthcurl http://127.0.0.1:4318/healthz on the machine

Back up /var/lib/spandock (or snapshot the disk) to keep the history and settings.