# Home

Welcome to Antsle! This is the documentation for the Antsle Private Cloud.

### Contents

{% content-ref url="/pages/-LzInJisUw19bC6B1tKl" %}
[Get Started](/get-started/getting-started-with-edgelinux-software-only-version)
{% endcontent-ref %}

{% content-ref url="/pages/-LzInBCTAXf3u7Gcbq\_W" %}
[Antlets](/antlets/antlets)
{% endcontent-ref %}

{% content-ref url="/pages/-LzmMpf5Loyq2OBtQ3wB" %}
[Templates](/templates/templates)
{% endcontent-ref %}

{% content-ref url="/pages/-LzJiz556U6Q7zRS47jX" %}
[Networking](/networking/networking-overview)
{% endcontent-ref %}

{% content-ref url="/pages/-LzmVNrllw1DwstdaBXD" %}
[System](/system/antsle-distributed-storage)
{% endcontent-ref %}

{% content-ref url="/pages/-LzmXj9extl090tBJBkT" %}
[Troubleshooting](/troubleshooting)
{% endcontent-ref %}


# Antsle One Setup

Congratulations! You're a proud owner of the Antsle! 🎉

Setup is **easy**! Actually, it’s super easy. Here’s our **famous five minute installation** process:

### 1. Unpack your Antsle

![We hope your like your packaging!](/files/-LzJjYuyIeFNEMw48M_j)

### 2. Connect Power and Network

**Important:** Make sure you connect your LAN cable to the *correct LAN port* on the backside of the Antsle, as depicted.

![](/files/-LzJkBepBqWwTGdBiKvI)

![](/files/-LzJkHbej1I5Z1p2KUku)

Connect the other end of the LAN cable to a free LAN port on your router.

Power on your Antsle and allow a few minutes for the boot process.

![](/files/-LzJkTvkQmMe8Liuf9aZ)

### 3. Set up antMan

{% hint style="info" %}
Windows user? Install Bonjour Print Services or iTunes. [**See why.**](https://antsle.com/forum/topic/did-windows-10-update-1803-break-bonjour-local-addresses/)
{% endhint %}

Go to [**http://myantsle.local**](http://myantsle.local)

Login with username: 'root' and password: 'antsle'

![](/files/-LzmCKFV0G8OuwnU3VGn)

Trouble getting the login screen? Try adding port 3000 to the URL: Use **<http://.local:3000>**,\
or if you know the IP address: **<http://x.x.x.x:3000>**

#### On-boarding

You should now be presented with the on-boarding screen:

![](/files/93WXgWwHPPZP5Q0QwKWi)

Choose "New Antsle hardware" and follow the instructions.&#x20;

When prompted for your e-mail address enter the address you used to purchase your Antsle so that we can **verify your order**. If you need to use another email address for some reason, please contact support.

![](/files/zSlGRwhhmoaGKvrMWFfS)

You will receive an email with a list of Antsle serial numbers associated to your email. Enter the token for your serial number which is printed on the bottom of the antsle (also printed on the delivery note in the box with the antsle).

![](/files/aQ1VP1Wx2KlQtt3Inju6)

You'll be asked to register your device with antHill. antHill is a central account, hosted on Antsle which is used to link ownership of your physical servers to a single profile. antHill allows you to restore backups between servers and also is where you manage your subscriptions, or can get support.

![](/files/-MA8fpOzQmXRRBPOiaBY)

After you finish the onboarding process, wait a few minutes for antMan to restart, login again and you should now see the following:

![](/files/-MA8dTIzZffmWY7zN17n)

Use antMan™ (antlet manager) to create a few antlets.

{% hint style="info" %}
When your Antsle is on, it will periodically send a "heartbeat" signal to our servers so that you can see it in antHill. (You can turn this feature off in antMan Services once the Antsle is activated, if you so choose).
{% endhint %}

## **That’s it***,* **you are done!**&#x20;

*Go do great things with your private cloud!*  🙂

**Some exciting videos** are next! We invite you to watch our popular [FreedomCasts](http://go.antsle.com/freedomcasts). They will show you in an entertaining manner how **easy** it is to master some real-life situations with your new Antsle.

Problems? Check our [troubleshooting](/troubleshooting) page.&#x20;

It's also a best practice to configure your IPMI. See below.

### 4. IPMI (Optional)

{% hint style="info" %}
The IPMI port gives you remote access to the Antsle's console and the ability to power up/down the Antsle remotely. Please change the username and password as described below. Keep these credentials in a safe place as it is difficult to recover.

The default username/password is ADMIN/ADMIN.

Some Antsle one D models have a custom IPMI password that you can find on a sticker above the IPMI port on the back of your Antsle.
{% endhint %}

Out of the box, the IPMI shares the 'br0' interface (bottom left port in the group of four) and will obtain its own IP address from DHCP. This address is not seen in antMan. The address is displayed during the POST when booting the antsle. The single ethernet port above the two USB ports is a dedicated IPMI port and is configured in the BIOS setup of the Antsle. Once configured the IPMI can only be accessed via the dedicated IPMI port.

Connect a keyboard and monitor and boot the Antsle - this is only required for the initial configuration. When the Antsle begins to boot you will see the Supermicro splash screen. Watch for a message that says 'Press `<del>` to enter setup' - then hit `<del>`.<br>

Arrow over to the IPMI menu item.

![](/files/-LzmCqx6aC7XQSLOzjIo)

Select 'BMC network configuration' > 'Configuration Address source' > Static and set the static IP address information.

![](/files/-LzmCxLEgcBlLh5BDyTm)

Hit F4 to Save and Exit

Now you can open a browser and go to <http://x.x.x.x> (the IP address you set in the bios).\
\
Go to 'Configuration' > 'Users' to change the password and users for access to the IPMI.\
For console access, go to 'Remote Control' > 'iKVM/HTML5' or 'Remote Control' > 'Console Redirection' > 'Launch Console'

{% hint style="info" %}
You can ignore any messages asking to upgrade java.
{% endhint %}

In case you have any questions or comments, please [contact us](https://support.antsle.com/). Don’t hesitate, we’re friendly.


# Antsle Nano Setup

Getting started with the Antsle Nano

Congratulations! You're a proud owner of the Antsle Nano 🎉

## Get your Nano Ready

### &#x20;   **1. Unpack** your new Antsle Nano

### &#x20;   2. Use a LAN cable to **connect** the Antsle Nano with your router

### &#x20;  3. Double-check that the SD card is **inserted** properly

### &#x20;  4. Connect the **power** adapter

![](/files/-M1M3ygqZgknt-aZMkAE)

As soon as the Nano has power, it will automatically **boot up** - no need to press a power button.

## Log in to antMan and Register your Nano

{% hint style="danger" %}
**Do not disconnect power during first boot**

While booting for the first time, the Antsle Nano finishes the edgeLinux installation by itself. That process may take up to 15 minutes. During this time, please do not unplug the power chord or your Nano may fail to boot.
{% endhint %}

{% hint style="info" %}
Windows user? Install Bonjour Print Services or iTunes. ([**Read why**](https://antsle.com/forum/topic/did-windows-10-update-1803-break-bonjour-local-addresses/)**)**
{% endhint %}

Open a browser and go to `http://myantsle.local`

Login with username: 'root' and password: 'antsle'

![](/files/-LzmCKFV0G8OuwnU3VGn)

Trouble getting the login screen? Try adding port 3000 to the URL: Use **<http://.local:3000>**,\
or if you know the IP address: **<http://x.x.x.x:3000>**

#### On Boarding

You should now be presented with the on-boarding screen:

![](/files/93WXgWwHPPZP5Q0QwKWi)

Choose "New Antsle hardware" and follow the instructions.&#x20;

When prompted for your e-mail address enter the address used to purchase your Antsle so that we can **verify your order**. If you need to use another email address for some reason, please contact support.

![](/files/zSlGRwhhmoaGKvrMWFfS)

You will receive an email with a list of Antsle serial numbers associated to your email. Enter the token for your serial number which is printed on the delivery note which came in the box with the Nano.

{% hint style="warning" %}
If you see a table with more than one entry, look for a serial number that begins with \`3000-\` (the prefix used for Nanos) and enter the corresponding token. **DO NOT** use the same serial-number twice, or it will invalidate your license.
{% endhint %}

![](/files/aQ1VP1Wx2KlQtt3Inju6)

You'll be asked to register your device with antHill. antHill is a central account, hosted on Antsle which is used to link ownership of your physical servers to a single profile. antHill allows you to restore backups between servers and also is where you manage your subscriptions, or can get support.

![](/files/miR98qzOJvx9zSVaHILZ)

After you finish the onboarding process, wait a few minutes for antMan to restart, login again and you should now see the following:

### Last but not least...

AntMan will now show you the **dashboard** and you can start creating antlets! To make sure the installation was successful, you can go to Settings > System Information and review the serial number.

{% hint style="info" %}
We strongly advise you to change your root password after the setup is complete. To do that, click the user icon in the top right corner and go to Settings.
{% endhint %}

![Change your root password once the setup is complete](/files/-LzsA4WtxSu4d-9vqAZp)


# Antsle Two Setup

Congratulations! You're a proud owner of the Antsle! 🎉

Setup is **easy**! Actually, it’s super easy. Here’s our **famous five minute installation** process:

### 1. Unpack your Antsle

![](/files/-LzJjYuyIeFNEMw48M_j)

### 2. Connect Power and Network

**Important:** Make sure you connect your LAN cable to the *correct LAN port* on the backside of the Antsle, as labeled.

![](/files/-MAC3SAU79v8bchFkqjM)

Connect the other end of the LAN cable to a free LAN port on your router.

| Port             | Interface |
| ---------------- | --------- |
| Ethernet (upper) | br0       |
| SPF (left)       | br1       |
| Ethernet (lower) | br2       |
| SPF (right)      | br3       |

Power on your Antsle and allow a few minutes for the boot process.

###

### 3. Set up antMan

{% hint style="info" %}
Windows user? Install Bonjour Print Services or iTunes. [**See why.**](https://antsle.com/forum/topic/did-windows-10-update-1803-break-bonjour-local-addresses/)
{% endhint %}

Go to [**http://myantsle.local**](http://myantsle.local)

{% hint style="info" %}
Login with **Default Credentials** below.&#x20;

username: `root` \
password: `antsle`
{% endhint %}

![](/files/-LzmCKFV0G8OuwnU3VGn)

Trouble getting the login screen? Try adding port 3000 to the URL: Use **<http://.local:3000>**,\
or if you know the IP address: **<http://x.x.x.x:3000>**

#### On-boarding

You should now be presented with the on-boarding screen:

![](/files/93WXgWwHPPZP5Q0QwKWi)

Choose "New Antsle hardware" and follow the instructions.&#x20;

When prompted for your e-mail address enter the address you used to purchase your Antsle so that we can **verify your order**. If you need to use another email address for some reason, please contact support.

![](/files/zSlGRwhhmoaGKvrMWFfS)

You will receive an email with a list of Antsle serial numbers associated to your email. Enter the token for your serial number which is printed on the delivery note which came with the antsle.

![](/files/aQ1VP1Wx2KlQtt3Inju6)

You'll be asked to register your device with antHill. antHill is a central account, hosted on Antsle which is used to link ownership of your physical servers to a single profile. antHill allows you to restore backups between servers and also is where you manage your subscriptions, or can get support.

![](/files/-MA8fpOzQmXRRBPOiaBY)

After you finish the onboarding process, wait a few minutes for antMan to restart, login again and you should now see the antMan dashboard:

![](/files/-MA8dTIzZffmWY7zN17n)

Use antMan™ (antlet manager) to create a few antlets.

{% hint style="info" %}
When your Antsle is on, it will periodically send a "heartbeat" signal to our servers so that you can see it in antHill. (You can turn this feature off in antMan Services once the Antsle is activated, if you so choose).
{% endhint %}

## **That’s it***,* **you are done!**&#x20;

*Go do great things with your private cloud!*  🙂

**Some exciting videos** are next! We invite you to watch our popular [FreedomCasts](http://go.antsle.com/freedomcasts). They will show you in an entertaining manner how **easy** it is to master some real-life situations with your new Antsle.

Problems? Check our [troubleshooting](/troubleshooting) page.&#x20;

It's also a best practice to configure your IPMI. See below.

### 4. IPMI (Optional)

{% hint style="info" %}
The IPMI port gives you remote access to the Antsle's console and the ability to power up/down the Antsle remotely. Please change the username and password as described below. Keep these credentials in a safe place as it cannot be recovered.

The default username/password is admin/password.
{% endhint %}

The single ethernet port above the two USB ports is a dedicated IPMI port. The IPMI is configured in the BIOS setup of the Antsle.

Connect a keyboard and monitor and boot the Antsle (this is only required for the initial configuration).\
When the Antsle begins to boot you will see the Supermicro splash screen. Watch for a message that says 'Press `<del>` to enter setup' - then hit `<del>`.<br>

Arrow over to the IPMI menu item.

![](/files/-LzmCqx6aC7XQSLOzjIo)

Select 'BMC network configuration' > 'Configuration Address source' > Static and set the static IP address information.

![](/files/-LzmCxLEgcBlLh5BDyTm)

Hit F4 to Save and Exit

Now you can open a browser and go to <http://x.x.x.x> (the IP address you set in the bios).\
\
Go to 'Configuration' > 'Users' to change the password and users for access to the IPMI.\
For console access, go to 'Remote Control' > 'iKVM/HTML5' or 'Remote Control' > 'Console Redirection' > 'Launch Console'

{% hint style="info" %}
You can ignore any messages asking to upgrade java.
{% endhint %}

In case you have any questions or comments, please [contact us](https://support.antsle.com/). Don’t hesitate, we’re friendly.


# edgeLinux Installation

antMan runs on our lightweight edgeLinux OS. Once you've installed edgeLinux on your server you can then log into antMan.

{% hint style="success" %}
If you've come here because you are setting up an Antsle server you just bought, edgeLinux is already installed. You can read about how to [set up the](/setup) [Antsle one](/setup) or [Antsle Nano](/setup-nano) for the first time.
{% endhint %}

## **Install edgeLinux on Intel / AMD Architecture**

### **1. Install ISO**

### 2. Access antMan

### 3. Activate your Server on antHill

### 4. Use antMan

## **Install ISO**

#### 1. Put ISO onto USB

Download the ISO [**here**](https://antsle.com/products/antmanedgelinux/download/) or with your antHill account at [**anthill.com**](https://anthill.antsle.com/)

You will need a fresh USB stick with as much space as the size of the iso file.

You then want to use a flash image tool such as [Etcher](https://www.balena.io/etcher/), to flash the iso image to your USB (please note this will erase all data on the USB).

![](/files/-M7UcVT3zktSxvYCwhBf)

Once you have done that you can eject that and insert it into your bare-metal server/desktop/laptop. Your machine should ideally also have connection to the internet, preferably via ethernet.

**2. Boot from USB and Install**

Watch our video with instructions as you go through the installation: \
\
[**Watch the Install Video**](https://www.loom.com/share/3881ee11902f47eeb81d4f548f908096)[**.**](https://antsle.us16.list-manage.com/track/click?u=67fb0a69c97ce889a53356aaa\&id=b46e00d17d\&e=b1d793750b)&#x20;

{% hint style="danger" %}
Stop! Watch the video above. Really. It'll save you from making some common mistakes in the install.

Do not configure a static IP during the installation. You can configure a static IP address in the antMan management dashboard after installation.&#x20;
{% endhint %}

\
If you do not have a connected keyboard and monitor you may install via IPMI. Follow the instructions [here](https://docs.antsle.com/get-started/pages/-LzJj5WRFrHhxYSRuP7B#4.-ipmi-optional).

**3. Important Highlight from** [**Video**](https://www.loom.com/share/3881ee11902f47eeb81d4f548f908096)**: Partition Your Drives (See Minute 1:45)**

Make sure that your root partition is not too big. We recommend taking the default partitions created. Ideally it looks like the following&#x20;

* 512 or 1024 MB for boot (/boot)
* 16 GB for Root (/)

Leave the rest unpartitioned. The edgeLinux installer will use the unpartitioned space for the antlets zpool (zfs storage pool).&#x20;

**4. Log in Using your Root Password and complete the installation**&#x20;

Log in with the root password that you set up and you should see the installer continue to progress.

After this it will complete the installation and ask to reboot. &#x20;

Before logging in to antMan for the first time run the command `upgrade-antman` from the command line to make sure you are at the latest version.

## Access antMan

**Are you a Windows user? Install Bonjour Print Services or iTunes.** [**See why.**](https://antsle.com/forum/topic/did-windows-10-update-1803-break-bonjour-local-addresses/)\
\
You should be able to access antMan right now at <http://YOUR_IP:3000> or <http://myantsle.local>.\
\
You can use your web browser to control your Antsle server. (IE and Edge are NOT recommended).

Login with username: 'root' and the password you chose during installation.

![](/files/-LzmCKFV0G8OuwnU3VGn)

#### On-boarding

You should now be presented with the on-boarding screen:

![](/files/93WXgWwHPPZP5Q0QwKWi)

Choose "New install on my own hardware". If you are reinstalling edgeLinux on antsle hardware or on your own hardware, choose "Reinstall with existing serial number".

Follow the on-boarding instructions. After you finish the onboarding process, wait a few minutes for antMan to restart.

## Use antMan

Go to **http\://\<myantslename>.local**\
If you have an antsle.us subdomain use **https\://\<mysubdomain>.antsle.us**

Trouble getting the login screen? Try adding port 3000 to the URL: Use **http\://\<myantslename>.local:3000**,  or if you know the IP address: **<http://x.x.x.x:3000>**

![](/files/-LzmCPXNffqJKU4gB5Y0)

Use antMan™ (antlet manager) to create a few antlets.

{% hint style="info" %}
When your server is on, it will periodically send a "heartbeat" signal to our servers so that you can see it in antHill. (You can turn this feature off in antMan Services once the server is activated, if you so choose).&#x20;
{% endhint %}

## **That’s it***,* **you are done!**&#x20;

*Go do great things with your private cloud!*  🙂

**Some exciting videos** are next! We invite you to watch our popular [FreedomCasts](http://go.antsle.com/freedomcasts). They will show you in an entertaining manner how **easy** it is to master some real-life situations with your new Antsle.

Problems? Check our [troubleshooting](/troubleshooting) page or write <support@antsle.com>. <br>

## Optional: Install from .iso remotely via IPMI

{% hint style="info" %}
This assumes you are using the IPMI available in Antsle servers. Your experience may be different if you are using 3rd party hardware.&#x20;
{% endhint %}

1. [**Connect to the IPMI**](https://docs.antsle.com/setup#4-ipmi-optional)**.** You can view the Antsle server's console and power up/down the antsle from the IPMI - Remote Control > iKVM/HTML5.<br>
2. Mount the installation .iso from a CIFS share via the IPMI - Virtual Media > CD-ROM Image Enter the connection details to the Share/install.iso and 'Mount' it.<br>
3. Now you can power on the antsle via the iKVM/HTML5 and it should boot to the .iso You may need to hit F11 during POST to invoke the boot menu. Choose the Virtual CDROM.<br>
4. Run through the installer and follow the video from[ step 1](https://docs.antsle.com/get-started/getting-started-with-edgelinux-software-only-version#1-install-iso)

![](/files/-M8HswAI25GoKk-VyLNm)


# Installing edgeLinux on Oracle VirtualBox

Oracle VirtualBox is a free open-source software that allows one to run virtual machines.  You can run edgeLinux and antMan using VirtualBox.

1\) Download antMan from link below or from antHill:  <https://antsle.com/products/antmanedgelinux/download/#0>

2\) Oracle VirtualBox is available for several platforms and can be downloaded here:  <https://www.virtualbox.org/wiki/Downloads>

3\) After downloading Oracle VirtualBox, install on your platform and then create new Virtual Machine.

4\) Create new virtual machine by clicking on New button.  Select Linux for type and Fedora (64-Bit) for version. Click on Next.

![New Virtual Machine - VirtualBox](/files/-MDHnulEsZVIc49MD2Jj)

5\) Select at least 4,096MB or more for Memory. Click on Next.

6\) Select on "Create Virtual Disk now" and then click on Create.

7\) Select on VMDK (Virtual Machine Disk) and then click on Next. (Other formats may work but it's been tested and working on VMDK format).

8\) Click on "Dynamically allocated" and then click on Next.

9\) Allocate at least 100GB or more for virtual disk. Click on Create.

10\) Go to Settings on your virtual machine. Click on Storage. Click on CD-ROM. Select Choose a disk file...  Select edgeLInux-x.x.x.iso (where x.x.x is the current version). Click on OK.

![Storage Configuration - VirtualBox](/files/-MDHr032tCK7wHnjv67z)

11\) Click on Settings - System - Processor tab. Make sure that Enable PAE/NX and Enable Nested VT-x/AMD -V are selected. Click on OK.

![VirtualBox - System - Processor - Extended Features](/files/-ME5MWboAOcwuL6C3MPI)

12\) Click on the Start button. Follow directions to complete installation: <https://docs.antsle.com/get-started/getting-started-with-edgelinux-software-only-version>


# Log in to the edgeLinux OS

### Access the edgeLinux OS terminal

There are several ways you can access the edgeLinux OS terminal

* In AntMan (vers. 0.9.1)
* via SSH
* Connect a keyboard and monitor
* IPMI: see the setup [page](/setup)&#x20;
* Click the '>\_Console' link in the main menu.

{% tabs %}
{% tab title="Antman" %}
![](/files/-LzmF-Xgl7LY94DdLhek)

Prior to antMan 0.10.0 You are prompted to enter your root username.<br>

![](/files/-LzmF9MKV8UooaWBJgcJ)

Now you have access to the EdgeLinux command line.<br>

![](/files/-LzmFxwNxkIPcksKMLwO)
{% endtab %}

{% tab title="SSH" %}
You can SSH to the edgeLinux OS in the following ways

**Using the private IP address of the antsle**

```
ssh root@x.x.x.x
```

**Using antsle\_name.local**

```
ssh root@myantsle.local
```

replace 'myantsle' with the name of your antsle

**With an .antsle.us subdomain**

You can [get an antsle.us subdomain in antHill](https://docs.antsle.com/system/secure-https-access-to-antman)

```
ssh root@yoursubdomain.antsle.us
```

![](/files/-LzmHDkzpDBvVjKfQFvb)
{% endtab %}
{% endtabs %}

#### [Read the docs on accessing your antlets](/antlets/access-antlets)

### SSH Tools <a href="#ssh-tools" id="ssh-tools"></a>

In case you are not familiar with `ssh`, it's very easy to use with many [excellent tutorials](http://support.suso.com/supki/SSH_Tutorial_for_Linux) out there.

**MacOS and Linux**: SSH is built-in and run with the terminal\
**Windows**: For Windows you can use packages like [PuTTY](http://www.putty.org/) or [MobaXterm](https://mobaxterm.mobatek.net/).

![](/files/-LzmIbkPvUcJk1JSevrm)

Or try WSL, aka: Bash on Ubuntu on Windows. This seems to work well but will not resolve .local domain names.

### Want to access your antlets next? [Read the guide](/antlets/access-antlets). <a href="#caveats" id="caveats"></a>

### &#x20;<a href="#web-access-to-your-antlets" id="web-access-to-your-antlets"></a>


# Name Your Antsle/Nano

The default name used in edgeLinux is `myantsle` . If you have more than one antsle, nano or edgeLinux install on your own hardware, you will want to rename them.

There are two ways you can change the name.

From the [EdgeLinux command line](/get-started/log-in-to-the-edgelinux-os-and-antlets), run the command `name-antsle NEW_NAME`. Then logout and log back in to see the new name.

```
root@myantsle:~ # name-antsle huggybear
```

You can also change the name from your account at [anthill.antsle.com](https://anthill.antsle.com/) under:\
&#x20;    My Servers > Actions > Re-configure

Then you can use NEW\_NAME.local to access antMan and edgeLinux.


# Setting Up Your Tech Stack

We've compiled instructions for a few different platforms/apps to give an example of what's involved in getting started. The "principles" in the guides are often valid when setting up other software as well.&#x20;

[Gitlab](/get-started/setting-up-your-tech-stack/gitlab)\
[Jenkins](/get-started/setting-up-your-tech-stack/jenkins)\
[WordPress](/get-started/setting-up-your-tech-stack/wordpress)<br>


# WordPress

WordPress is the most commonly used Content Management System out there. In fact, one-third of the top 10 million websites (!!) are running … you guessed it … WordPress! And that for good reason. It’s fast, modular, and has a huge active community that develops every imaginable feature in form of a plugin.&#x20;

![](/files/-MCiQLKNA6PzyH3kkfO8)

### Create an antlet with the LEMP Stack Template

To get started with WordPress, we again [create a new antlet](/antlets/create-and-manage-antlet). This time, we use the LEMP-Stack template, as it comes preconfigured with all the software you need to run WordPress.

![](/files/-MCiiklk6iOA6LWVGIJp)

Now, you just need to copy in the Wordpress files.&#x20;

### Copy in the WordPress Files

An easy way to do that is with an FTP app. Just create a port forwarding rule to make a port on your Antsle redirect to port 22 on your WordPress antlet. Then use FileZilla or Transmit and connect to that port. Here's an example below.

![Screenshot from Transmit. You can see it's connecting to port 2210 on your Antsle.](/files/-MCiQjVHLj29_tNaslA9)

![Create a port forwarding rule that sends traffic to port 22 on your Wordpress antlet.](/files/-MCiQyi4u1r-mZlzRm7o)

In your FTP app, just navigate to the `/var/www/html` directory and place all the files from wordpress.org/download/ there.

Update the owner and permissions of the wordpress files with

`chown -R www-data:www-data /var/www/html`\
`chmod -R 755 /var/www/html`

All in all, that just adds 1 minute to the famous 5 minute WordPress installation.

### Access WordPress on your antlet

Now you can open your browser, [connect to your antlet](/templates/using-the-lemp-stack#2-set-up-access), and voila, you're in the Wordpress set up page.

To show the world what your Website is all about, [configure access via a domain name](/antlets/access-antlets#access-domain-name) like *<https://myawesomeblog.com>*.


# Gitlab

The installation instructions may become out of date at any time due to updates to Gitlab. Feel free to "Google it" as a supplement to this guide.

![](/files/-M-BWKNwPFukH4OanSKi)

**1. Setup CentOS antlet**

Login to antMan and spin up an CentOS-7 KVM antlet.

SSH into your Antsle then your CentOS antlet

```
ssh <username>@<hostname>.local
ssh root@10.1.1.<antlet-ip>
```

The default root password is `antsle`

Update the system:

```
yum update
```

At the time of this writing the latest stable CentOS is 7.6

**2. Make antlet Accessible**

Read the docs article on [accessing your antlets](/antlets/access-antlets).

**3. Install GitLab**

First lets install all the dependencies required for GitLab CE:

```
yum install -y curl openssh-server openssh-clients policycoreutils-python
```

Next lets setup the GitLab CE RPM repository:

```
curl -sS https://packages.gitlab.com/install/repositories/gitlab/gitlab-ce/script.rpm.sh |  bash
```

Now to install GitLab. If you are accessing GitLab via domain name add that as the url parameter like below:

```
EXTERNAL_URL=“http://gitlab.example.com” yum install -y gitlab-ce
```

If you are accessing GitLab via the private IP:

```
EXTERNAL_URL=192.168.0.105 yum install -y gitlab-ce
```

Now type in the domain name or the private IP into your web browser to see your new source control system!

For a private IP example:

```
http://192.168.0.105
```

**4. Configure GitLab**

When you go to your new GitLab you will need to set your password. Then login with the user `root` and that password.

If you want to change the IP or domain name that points to GitLab, edit the file:

```
/etc/gitlab/gitlab.rb
```

On the 13th line you will see something like:

```
external_url 'http://192.168.0.108'
```

Just edit the url to your new IP or domain. Then run:

```
gitlab-ctl reconfigure
```

**Congratulations! You now have GitLab running on your own Private Cloud.**

![GitLab running on your Antsle](/files/-M-BWfw8xQebfRyO0A0c)

Happy Pushing!


# Jenkins

The installation instructions may become out of date at any time due to updates to Jenkins. Feel free to "Google it" as a supplement to this guide.

![](/files/-LzrsNlIPXrj2jiA62aW)

**1. Setup Debian antlet**

Login to antMan and spin up an Debian LXC antlet.

![](/files/-Lzms5kgvodVjBWD2E7N)

If you are going to run your builds on this Jenkins antlet, which we will be in this tutorial, be sure to allocate the appropriate amount of RAM and vCPUs for your build.

SSH into your Antsle then your Debain antlet

```
ssh <username>@<hostname>.local
ssh root@10.1.1.<antlet-ip>
```

The default root password is `antsle`

Make sure you are on the latest version:

```
apt update
apt upgrade
```

At the time of this writing the latest stable Debian is 9.8

**2. Install Jenkins**

First, we need to install java on the antlet ad Jenkins is a Java application.

```
apt install openjdk-8-jdk
```

Import the GPG keys of the Jenkins repository

```
wget -q -O - https://pkg.jenkins.io/debian/jenkins.io.key | apt-key add -
```

When your key is imported, we want to add the Jenkins repository to the antlet

```
sh -c 'echo deb http://pkg.jenkins.io/debian-stable binary/ > /etc/apt/sources.list.d/jenkins.list'
```

Now lets update the package list and install the latest version of Jenkins

```
apt update
apt install jenkins
```

Start the Jenkins service and systemctl enable jenkins

```
systemctl start jenkins
```

We also want to have it automatically start on boot

```
systemctl enable jenkins
```

**3. Make Jenkins Accessible**

**1. Accessing by Domain Name**

If you want to access your Jenkins on a specific url (which is recommended) have a look at [our accessing antlets by domain name page](/antlets/access-antlets#access-domain-name).

**2. Accessing by Private IP**

We could also add a vNIC to the antlet in antMan so that the antlet can acquire a IP from our local network.

In antMan, click on the antlet, Go to “Virtual Network”, and click on “New virtual NIC”. Choose which physical interface you want it to route to, this will be br0 by default.

![](/files/-LzmsRa2ePKvLIoKZYXx)

Now stop the antlet, and start again.

Now ssh back into the antlet. Check the name of the new interface that we have assigned, its most likely `eth1`.

```
ifconfig -a
```

And use your favourite editor to edit the interfaces file.

```
nano /etc/network/interfaces
```

You might want to set it to a static IP, but thats particular to your network so we will just set it to dhcp here. Your file should now look like this:

```
auto lo
iface lo inet loopback

auto eth1
iface eth1 inet dhcp

auto eth0
iface eth0 inet dhcp
```

Restart the network.

```
service networking restart
```

Run the following command and Note the new local network IP that is assigned to to our new nic.

```
ip -4 -o addr show eth1 | awk '{print $4}' | cut -d "/" -f 1
```

You can now access Jenkins in your web browser with that IP on port 8080. For example:

```
http://192.168.0.105:8080
```

**3. Configure Jenkins**

It will then prompt you for the password initialAdminPassword which you can with the following command:

```
cat /var/lib/jenkins/secrets/initialAdminPassword
```

You can then go through the options of installing selected plugins, set up new accounts, etc.

Once you get to the "Instance Configuration" page you can put it in your domain if you it set up a domain above. If you are accessing it with the private IP, then just set that pre-populated IP.

**Congratulations! You now have Jenkins running on your own Private Cloud.**

![Jenkins running on your Antsle](/files/-M-BW8XGBIUQSb9cz54y)

To change the admin password, click on the "admin" dropdown on the top right. Then hit "Configure" on the left, and scroll down to change the password.

Happy Building!


# Antlets Overview

## LXC or KVM Antlets

Each antlet will give you a completely self-contained and isolated operating system. That way, an antlet emulates a complete physical server as closely as possible.

The basic choice you will make when creating a new antlet is whether you'll make it an LXC or a KVM antlet.

The general rule is: Make it an LXC antlet whenever possible. If you want to run Linux in your antlet, whatever flavor or distribution, pick LXC. LXC antlets are -- under the hood -- implemented as Linux containers, which are **way more efficient** than virtual machines using KVM.

An LXC antlet is not to be confused with a docker container. Docker's main aim is packaging applications, whereas Antsle's main aim is to provide virtual private servers, each of which look and feel like a dedicated, physical server.

The only situation you need to revert to KVM antlets is when the OS you want to run is not Linux, e.g. Windows or FreeBSD. In those cases, you can create a KVM antlet and run the OS of your choice in it. You can even [import](/templates/import-vm-images) VMs from other hypervisors such as VMware or Hyper-V.


# Create and Manage an Antlet

## Create your Antlet

In antMan, click the 'Create' button.&#x20;

![](/files/-LzsgBXFz_F1knxwKc9P)

It will ask you for the details:

![Fill in the Antlet info](/files/-LzIgvTsPOMgMCwP48N2)

| Field       | Description                                                                                                                                     |
| ----------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
| Name        | Enter a unique name for the new antlet                                                                                                          |
| Template    | Select a template from the list of templates. Click the 'Add more' option to download additional templates.                                     |
| RAM         | Select the amount of RAM                                                                                                                        |
| vCPUs       | Select the number of vCPUs                                                                                                                      |
| IP          | This is the last number in the IP address for this antlet. It will automatically populate with the next available address. The range is 10-210. |
| zPool       | Select the storage pool the antlet will be created in.                                                                                          |
| Compression | Turn compression on or off for an individual antlet. Compression is off by default.                                                             |

Click the "Create Antlet" button and the antlet will appear in the list of antlets.

![Congratulations! You just created your first Antlet 🎉](/files/-MhLDqBTghz2xkyA7xjo)

## Manage your Antlet

### Controlling the Antlet at a glance

In the antlet listing in antMan you can perform the following functions:

* Open the antlet details (click the name of the antlet)&#x20;
* Start, Stop, Reboot and Delete the Antlet
* Clone the Antlet
* Copy the Antlet to another server
* Pause or Force stop the Antlet
* Open the antlet VNC Console (KVM antlets only)

{% hint style="info" %}
Note: Reboot is an OS reboot of the antlet. The antlet itself does not Stop then Start.
{% endhint %}

![Start, Stop or Reboot your Antlets from the Overview-page](/files/-LzIj0hiDv4zaPYKtQa1)

### Clone your Antlet

A clone of your antlet is a separate antlet that contains a copy of your antlet's existing data.

To clone your antlet: \
From the Dashboard, click the `...` to open your antlet's actions. Select `Clone this antlet`.

![](/files/-M61ayWVjbJspKElcgrJ)

![Fill in the Clone info](/files/-M61ag1KqmhxzaSquQis)

| Field           | Description                                                                                                                                     |
| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
| New antlet name | Name of the cloned antlet                                                                                                                       |
| IP              | This is the last number in the IP address for this antlet. It will automatically populate with the next available address. The range is 10-210. |
| Compression     | Turn compression on or off for an individual antlet. Compression is off by default.                                                             |

Click `Create antlet` to clone your antlet.

### Copy your Antlet

{% hint style="info" %}
You can Copy your Antlets between Antsle servers in one click with a Grow or Scale plan. [See details](https://antsle.com/pricing).

Copying only works between similar platforms. Nano to Nano or antsle One/Two to antsle One/Two.&#x20;
{% endhint %}

You can quickly copy your Antlet from one Antsle server to another from your dashboard. The data present in the Antlet

To copy your antlet:

{% hint style="info" %}
Make sure the destination Antsle server is configured. See [this guide](/system/multi-node#add-a-node) to add an Antsle server for multi-node access.
{% endhint %}

From the Dashboard, click the `...` to open your antlet's actions. Select `Copy this antlet`.

![](/files/-M66uz7u57Jeu6cGGMiL)

![Fill in the Copy info](/files/-M66vApJlOIIqsQLFrHK)

| Field                            | Description                                                                                                                                                                    |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Destination Node                 | Antsle server where the Antlet will be moved                                                                                                                                   |
| Do you want to delete the VNICs? | Delete all existing VNICs. Doing so will prevent conflicts if VNICs are configured on both Antsle servers. This is recommended if you are using VNICs on either Antsle server. |

Click `Copy antlet`to copy the antlet. You will be able to see the progress of your copy in the `Jobs` menu on the top-right of the screen.

### Pause your Antlet

![](/files/-M7FIF7FRMjNL4Y_f75z)

When you pause your antlet it will consume no CPU and no I/O while paused but keeps the RAM.&#x20;


# Antlet Details

The antlet details contains several tabs to configure various options. Click the antlet name in the list of antlets to enter this dialog.

### General Tab

The General tab gives you some general information about the antlet - Creation date, storage info and the template it was created from.\
Here you can change the antlet attributes - **RAM**, **vCPUs**, **IP address**, add a **description** and set the **Autostart** property..

![Adjust the performance settings of your Antlet](/files/-LzIkG9bLdjO9k1sNFAS)

The **Storage limit** only applies to LXC antlets. By default an LXC antlet does not have a limit on its storage capacity. A KVM antlet will display the vDrive size in this field which can be changed in the Virtual Drives tab.

The **Description** field is a place to add notes about the antlet. This will be displayed in a popup when hovering the cursor over the antlet name in antMan.&#x20;

**Autostart** sets the antlet to automatically start when the Antsle boots up.

Click the 'Update properties' button if you make any changes. The antlet must be Stopped to edit the RAM, vCPUs or the IP address.


# Access Antlets

## Access Antlets Locally <a href="#access-antlets-local" id="access-antlets-local"></a>

If you setup an [antsle.us subdomain](/get-started/log-in-to-the-edgelinux-os-and-antlets#web-access-to-your-antlets) in antHill, you can use the antlet name with your subdomain,

```
antlet_name.subdomain.antsle.us
```

In either case, the antlet must have a web server installed and listening on port 80 (http), else you may get a '502 Bad Gateway' error.

See the [SSL (https)](/system/secure-https-access-to-antman) page for https access to an antlet.

## Access antlets via SSH

There are several ways you can SSH to your antlets

* From the edgeLinux terminal
* Direct to the antlet using a bridged NIC

### Access antlets from the terminal

Just login to Antsle's command line as shown in "[Log in to the edgeLinux OS](/get-started/log-in-to-the-edgelinux-os-and-antlets#access-the-edgelinux-os-terminal) then open a new SSH session into your antlet.  e.g. antlet has IP address 10.1.1.12

```
ssh root@10.1.1.12
```

The default username for all of our Linux templates is 'root', with the exception of the Ubuntu KVM template which has a default username 'ubuntu'.\
See the [Templates](/templates/templates#default-passwords) page for default passwords.

In this example we are not required to include the username 'root' because, if omitted, SSH will use the name of the currently logged in user. The terminal prompt shows that 'root' is currently logged in.

![](/files/-LzmIBc_bQRnbWfwCguC)

### Access antlets the IP address of a bridged NIC

If you have configured a [bridged virtual NIC](/networking/bridge) on an antlet you can SSH directly to the IP address of the bridged interface.

```
ssh root@192.168.1.63
```

### Access antlets via ProxyJump&#x20;

You can create an entry in your local SSH `config` file to make an SSH connection with a single command to an antlet with the ProxyJump keyword.

The 'config' file is located in HOME/.ssh/ directory

A typical entry looks like this where shazam is my antsle

```
Host shazam 
  HostName 192.168.1.33
  User root
```

This allows you to SSH to 192.168.1.33 with this command

```
ssh shazam
```

You can then use 'shazam' as a ProxyJump host to an antlet with a `config` entry like the following&#x20;

```
Host webserver1
  HostName 10.1.1.11
  User root
  ProxyJump shazam
```

In the example above, 10.1.1.11 is the IP address of the antlet and an entry for the host 'shazam' exists in the `config` file. Now you can start an SSH session to webserver1 with

```
ssh webserver1
```

To make things a bit easier, first copy your local ssh key to the antsle

```
ssh-copy-id root@192.168.1.33
or
ssh-copy-id shazam
```

## Access antlets with VNC Console

Create your antlet and start it up. Once started you'll see a button for quick access to your VNC Console

![](/files/-MCik-JkpN8cwRN627Ea)

A window will open up that directly displays your desktop. If you're using one of our prebuilt templates, just use the template's [default password](/templates/templates#default-passwords) to log in and you're ready to go.&#x20;

![](/files/-MCikjJuUsuyjhaZ8ozr)

{% hint style="info" %}
If you're running Windows, open the tab on the left side and click "special keys" you can then click the option for CTRL+ALT+DELETE which will allow you to type in your username and password.
{% endhint %}

## Web Access to your antlets

After having logged in via ssh, install all the software you want. Use package managers such as [apt-get](https://wiki.debian.org/apt-get) in debian or Ubuntu, [yum](https://fedoraproject.org/wiki/Yum) in CentOS or Fedora, or [pkg](https://www.freebsd.org/doc/handbook/pkgng-intro.html) in FreeBSD to install your software. To get started, you might try [this](https://lowendbox.com/blog/how-to-install-apache-mysql-php-lamp-stack-on-ubuntu-16-04/) guide or [this](http://code.tutsplus.com/articles/download-and-install-wordpress-via-the-shell-over-ssh--wp-24403) one.

To make the web apps installed in your antlets accessible, edgeLinux provides a [reverse proxy](https://en.wikipedia.org/wiki/Reverse_proxy) using a software package called [nginx](https://en.wikipedia.org/wiki/Nginx).

See how easy it is to get web access to your antlets:

* [Access antlets locally](/antlets/access-antlets#access-antlets-local)
* [Access antlets via domain name](/antlets/access-antlets#access-domain-name) (below)

## Access antlets by Domain Name

If you want to configure Antsle so that the world can access your antlets by domain name, e.g. myawesomesite.com, then this page will guide you through the steps to do that.

Before you start, you need to setup port forwarding in your router. That step is only needed once. You don’t need to do that for every new domain name and/or antlet. You can skip port forwarding altogether if you (a) only access antlets from your local LAN/WiFi or (b) you’re using a tunnelling solution.

After you’ve setup port forwarding in your router (once), it’s a three-step process:

1. Get a domain name.
2. Set the A record.
3. Connect domain with antlet.

Here are our instructions for each of these steps:

### Get a domain name <a href="#id-1-get-a-domain-name" id="id-1-get-a-domain-name"></a>

You can register your domain name, e.g. mysite.com, through any domain registrar of your liking, e.g. godaddy.com.

### Set the A record <a href="#id-2-set-the-a-record" id="id-2-set-the-a-record"></a>

Set the A record of your new domain to the public IP address of your home or office Internet connection. To check your IP address, just go to checkip.dyndns.org in your browser. Copy that IP address to your clipboard. The go to the portal of the registrar that you bought your domain from. In case you bought it from GoDaddy, see [here](https://www.godaddy.com/help/manage-dns-680) for help.

Go to “DNS settings” and find where to set the A record. Set it to the IP address that you found out earlier.

After you’ve changed the A record, please allow up to 48 hours to let that change propagate through all DNS server of the Internet. In many cases you will be able to use the new domain after two hours or so. It’s a good idea to restart your router a few hours after you’ve updated the A record, so that the router will pull the latest DNS information from the Internet.

Please keep in mind that this step works best when you have a static IP address from your ISP. Alternatively, you can use a dynamic DNS provider.

### HTTP Access with Domain Name <a href="#id-3-connect-domain-with-antlet" id="id-3-connect-domain-with-antlet"></a>

After steps 1 and 2 are done, any traffic for your domain will arrive in your router. The port forwarding in your router will send it onwards to your Antsle - forward ports 80 and 443 to the private IP address of the Antsle (displayed in antMan). The last step now is to tell the Antsle to connect the domain name to the antlet of your choice. In order to achieve that, follow these steps:

Login to your Antsle via `ssh root@antsle_name.local`.

Enter this command: `cd /etc/nginx/virtualhosts`.

Then enter this command: `nano mysite.com.conf`. Use your domain name, not `mysite.com`!

Paste this text into the file:

```
server {
    server_name www.mysite.com;
    rewrite ^ $scheme://mysite.com$request_uri redirect;
}
server {
    listen 80;
    server_name mysite.com;
    root /var/www;
    location / {
        proxy_read_timeout 300;
        proxy_connect_timeout 300;
        proxy_redirect off;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header X-Forwarded-Protocol $scheme;
        proxy_set_header X-Forwarded-Ssl off;
        proxy_set_header X-Url-Scheme $scheme;
        proxy_set_header X-Frame-Options SAMEORIGIN;
        proxy_pass http://10.1.1.10;
    }
}
```

Make sure to replace `mysite.com` with the your own domain name, and replace `10.1.1.10` with the IP address of the antlet you want to connect this domain name to.

The intent of the first 'server { ... }' block is to redirect URLs prefixed with www to a URL without it, e.g. '[www.mysite.com](http://www.mysite.com)' will redirect to 'mysite.com'. Many people always type a 'www' in the URL but is not part of many domain names.

If your domain name is prefixed with www or you are using some other subdomain like yoyo.mysite.com, you can delete the first 'server { ... }' block

```
server {
    server_name www.mysite.com;
    rewrite ^ $scheme://mysite.com$request_uri redirect;
}
```

and edit the second 'server { ... }' block with the full domain name.

```
server {
    listen 80;
    server_name yoyo.mysite.com;
    root /var/www;
    location / {
        proxy_read_timeout 300;
    ...
    }
}
```

Press `Ctrl-X` in nano, enter `Y` for Yes when asked if you want to save, and hit `Enter` for the file name.

Finally, enter this command: `service nginx restart`

You’re ready to go now. From anywhere in the world, mysite.com will lead you directly to your antlet now.

### HTTPS Access with Domain Name

To set up an ssl certificate for an antlet we have a couple of options

* Install the certificate in the antlet
* Use nginx proxy to handle the certificate

The first option requires the antlet to have a bridged NIC and be addressed directly. The traffic for each antlet/webserver would require a unique public IP address or use a unique port number for the router to direct the traffic to the correct antlet IP address. Here the certificate files are installed and handled by the antlet

The second option allows nginx to connect to the proper antlet based on the URL in the header of the request. This is desireable because you can forward traffic (at the router) for multiple sites to one IP address, the private IP address of the Antsle. The certificate files are installed and handled by nginx on the edgeLinux OS.

First create a directory for your certificate files on the edgeLinux OS.

```
mkdir -p /etc/ssl/certs/mycerts
```

Use SCP or SFTP to copy your certificate files to this directory.

Create and edit a new nginx virtualhosts configuration file for your domain name. Replace example.com with your domain name.

```
  nano /etc/nginx/virtualhosts/ssl.example.com.conf
```

Paste the following content into the file and replace 'example.com' with your domain name.

```
# SSL to antlet

# If you want to use your domain example.com in HTTPS mode (with SSL),
# rename this file to ssl.example.com.conf (from ssl.example.com.conf.HTTPS)
# Replace example.com with your domain name.
# Make sure you have your SSL certificate installed properly.
# The certificate files are not required to be in the directories presented here, but
# the path must be the correct path to your certificate files.

# The webserver on your antlet will listen on port 80 (http).
# Nginx on edgeLinux handles SSL (https).

# Redirect http://www.example.com to https://example.com
# If your domain name does include 'www' then remove this server block and use the full
# domain name in the last server block.
server {
  listen 80;
  server_name www.example.com;
  rewrite ^ https://example.com$request_uri redirect;
}

# Redirect http://... to https://...
server {
  listen 80;
  server_name example.com;
  rewrite ^ https://example.com$request_uri redirect;
}

# Redirect https://www... to https://example.com
# If your domain name does include 'www' then remove this server block and use the full
# domain name in the last server block.
server {
  listen 443 ssl;
  ssl_certificate /etc/ssl/certs/mycerts/example.com.crt;
  ssl_certificate_key /etc/ssl/certs/mycerts/example.com.key;
  server_name www.example.com;
  rewrite ^ $scheme://example.com$request_uri redirect;
}

# Think of the word 'example' in 'upstream example' as a variable name which is
# used in other server blocks. This name must be unique among all your .conf
# files. It is used in the two 'proxy_pass' lines in the next server block.
# If you change the upstream variable name then be sure to update the proxy_pass
# lines also.
upstream example {
  # Enter the IP address and port number of your antlet handling this domain
  server 10.1.1.10:80;
}

server {
  listen 443 ssl;
  ssl_certificate /etc/ssl/certs/mycerts/example.com.crt;
  ssl_certificate_key /etc/ssl/certs/mycerts/example.com.key;
  server_name example.com;
  root /var/www;

  location / {
    proxy_read_timeout      300;
    proxy_connect_timeout   300;
    proxy_redirect          off;
    proxy_buffers         4 256k;
    proxy_buffer_size       128k;
    proxy_busy_buffers_size 256k;

    proxy_set_header    Host                 $host;
    proxy_set_header    X-Real-IP            $remote_addr;
    proxy_set_header    X-Forwarded-For      $proxy_add_x_forwarded_for;
    proxy_set_header    X-Forwarded-Proto    $scheme;
    proxy_set_header    X-Forwarded-Protocol $scheme;
    proxy_set_header    X-Forwarded-Ssl      off;
    proxy_set_header    X-Url-Scheme         $scheme;
    proxy_set_header    X-Frame-Options      SAMEORIGIN;

    proxy_pass http://example;
  }

  location ~*  \.(jpg|jpeg|png|gif|ico|css|js|pdf|woff|woff2)(\?.*)?$ {
    expires 365d;
    add_header Cache-Control "public, max-age=315360000";
    access_log off;

    proxy_read_timeout      300;
    proxy_connect_timeout   300;
    proxy_redirect          off;
    proxy_buffers         8 24k;
    proxy_buffer_size       2k;

    proxy_set_header    Host                 $host;
    proxy_set_header    X-Real-IP            $remote_addr;
    proxy_set_header    X-Forwarded-For      $proxy_add_x_forwarded_for;
    proxy_set_header    X-Forwarded-Proto    $scheme;
    proxy_set_header    X-Forwarded-Protocol $scheme;
    proxy_set_header    X-Forwarded-Ssl      off;
    proxy_set_header    X-Url-Scheme         $scheme;
    proxy_set_header    X-Frame-Options      SAMEORIGIN;

    proxy_cache            STATIC;
    proxy_cache_valid      200  1d;
    proxy_cache_use_stale  error timeout invalid_header updating
                           http_500 http_502 http_503 http_504;

    proxy_pass http://example;

  }
}
```

Restart the nginx service

```
service nginx restart
```


# Virtual Drives

Our basic KVM templates come with just one virtual drive that contains the OS. That drive is limited in size. LXC antlets, on the other hand, can by default access all space available on the zpool it is created in.

You can create and manage your own virtual drives in order to give your antlet more space. You can create virtual drives on any of your zpools.

{% hint style="warning" %}
Currently antlet backups only backup virtual drives created on the same zpool as the antlet.\
Virtual drives only work with KVM antlets.&#x20;
{% endhint %}

### Add Virtual HDD <a href="#add-virtual-hdd" id="add-virtual-hdd"></a>

#### Create a new virtual disk in Antman

Enter the antlet details page by clicking the name of the antlet  &#x20;

![Click the antlet name](/files/-M-BXTC-rmKGB5ZxXNrj)

Select the 'Virtual Drives' tab

![Select the 'Virtual Drives' tab](/files/-M-BXeOm5W8MnPxqaQci)

Click 'Create New Disk' button and fill in the form

![For Windows antlets choose IDE](/files/-M38G_DbSqFI3-ZnQriH)

After the virtual drive is created, note the 'Target' name, 'vdb' in this case. This is the device name in Linux antlets.

![](/files/-M-Bj6FlaTJ26WJjztXm)

Stop and Start the antlet

![](/files/-M-Bj8kT_GaorJyS5F6o)

#### Format and mount the new disk

After creatng a new virtual disk, you will need to format the disk in the operating system of the antlet.

**- Linux antlets**

*Depending on the template you may need to install some packages*\
*Debian/Ubuntu:*

```
apt-get install cron
apt-get install nano
```

*CentOS:*

```
yum install cronie
yum install e2fsprogs
yum install nano
```

Use the `target` name of the disk as seen in the 'Virtual Drives' tab, e.g. 'vdb', to create the file system.\
A KVM antlet will have one virtual disk (vda) by default. An LXC antlet has no virtual disks by default.<br>

NOTE: The first disk in a KVM antlet is 'vda' and contains the operating system. Do not format this disk! It will erase the operating system.I will use 'vdb' for the following examples. Replace with your target name.

```
mkfs.ext4 /dev/vdb  
```

Create a directory to mount the vDrive to. This can be anywhere in your directory tree.

```
mkdir /mnt/disk2
```

Mount the vDrive

```
mount -t ext4 /dev/vdb /mnt/disk2
```

**Mount the vDrive automatically on reboot**

*If you are not familiar with the vim editor, use nano (you may need to install it).*

The `fstab` file contains a list of drives and their mount information.

```
nano /etc/fstab
```

Add the following line

```
/dev/vdb        /mnt/disk2     ext4    defaults        1       2
```

**- Windows antlets**

For Windows antles you can format your new disk in 'Disk Manager'. Right click in the unallocated space of the new disk and choose 'New Simple Volume...'

![Create simple volume on new vDrive](/files/-M-BXuizvaRLPS8uXzcJ)

Follow the prompts of the 'New Simple Volume Wizard'\
When complete your new virtual drive is ready for use.

![Create simple volume on new vDrive](/files/-M-BY1rUC0TS7VrwM4yW)

### Resize a Drive <a href="#resize-a-drive" id="resize-a-drive"></a>

**antMan 0.8.1a**\
With antMan 0.8.1a we can resize virtual drives from within antMan.

In the 'Virtual Drives' tab, click the drive 'Size'

![Resize drive in the Virtual Drives tab](/files/-M-BY9gxmqzMOsSla14-)

Enter the new size and click the green check button.<br>

![Resize drive in the Virtual Drives tab](/files/-M-BYDYVgS6wOm6yR_tK)

Now you can partition and format the additional drive space in the OS of the antlet.<br>

{% hint style="info" %}
Best practice is to shutdown the antlet before resizing the vDrive.  Specifically in Windows antlets, resizing while the antlet is running and then performing a 'rescan' in Disk Manager can corrupt the vDrive.
{% endhint %}

<br>

**Prior to antMan 0.8.1a**

To resize a drive we need to find the path to the virtual drive file.

First ssh to the Antsle. Then lets list the files in the antlets dirctory. The .qcow2 file extention represents a virtual drive.

```
ls /ZPOOL_NAME/ANTLET_NAME
```

Replace ZPOOL\_NAME with the name of the zpool you created the antlet on.\
The default zpool name is 'antlets' if you have the hdd addon the zpool could be 'hdd'

Then to increase its size run:

```
qemu-img resize /antlets/ANTLET_NAME/THE_FILE.qcow2 +100G
```

Adjust the last option to the size you want. This will add the specifed amount of drive space.<br>


# Backing Up Antlets

## **Important Prerequisites:**&#x20;

1. Check your settings tab in antMan, your version of antMan should should be 2.2.1 (or higher). Why is this important? **Any antlet backups taken before this version can not be restored on edgeLinux 2.0 and may have issues when restoring to another server.** If your antMan is not up to date then run *`upgrade-antman`* in your console before taking backups.<br>
2. Log in [antHill.antsle.com](https://anthill.antsle.com) and make sure that your server is activated and visible there. antHill is the central hub and will  allow you to restore backups across multiple Antsle servers.

{% hint style="info" %}
Healing only works between similar platforms. Nano to Nano or antsle One/Two to antsle One/Two.
{% endhint %}

## Getting Started

Your backups can be started and managed from the Backups tab under your antlet settings. &#x20;

![](/files/-M8Mf5p6e60a1Hr53EHI)

Your backups can be taken to the Antsle Cloud or self-managed storage. To back up your server just select Back Up Now and then choose your storage backend. Do the same to schedule daily backups (scheduled daily backups run every day at midnight).

![](/files/-M8MitK-k0Y5tg__nA6j)

## Backing Up to the Antsle Cloud

Every subscription with Antsle comes with a certain amount of free storage space for backups to the Antsle Cloud. It ranges from 10 GB to 5 TB. Additional storage is available for as low as $6.90/100GB/mo. You can see the details on our [pricing page](https://antsle.com/pricing).&#x20;

All data in the Antsle Cloud is encrypted via SSL when in flight and on the server side. Antsle handles key management and key protection for you with 256-bit Advanced Encryption Standard (AES-256).

## Backing Up to Self Managed Storage

{% hint style="success" %}
If backing up via SSH, be sure the antsle's public SSH key is in the the remote host 'authorized\_keys' file so that the SSH session will be automatically authenticated.
{% endhint %}

You can back up your antlet to a mounted storage volume or to another device in your local network. To learn how to mount external storage, view our docs articles on [**setting up a shared storage volume**](https://docs.antsle.com/system/access-a-network-share). You then need to either refer to your storage volume's file path or the ip address when taking a backup.&#x20;

![](/files/-M8MjhxCRIfV61wx36pa)

## Backing up your Virtual Drives

{% hint style="danger" %}
IMPORTANT: At this time, only drives within the same zpool as your antlet are backed up. \
\
That means if you have your antlet and virtual drives in **different** zpools you will need to move your virtual drive to the same zpool or use a different method to keep it backed up.
{% endhint %}

In the example below, both virtual drives will be included in the backup since they are in the same zpool. If you want to move the drive to the same zpool , download your drive as a .qcow2 file, choose the "import disk" button, then when you add it, choose the same zpool as your antlet.&#x20;

![](/files/-M8MkHYkGcitLPrU7oDb)

## Healing an *antlet* to Another Server

If your Antsle server goes down you will probably want to get your antlets back up and running on another server. You can have a second server on standby and all users with a Scale Plan can get free access to a dedicated server in the cloud up to 4 Cores, 8 GB of RAM, and 80 GB SSD for up to 2 weeks. Once you are in your new server:

1. Click on the *Heal antlets* tab on the left
2. Retrieve your antlet. That will copy it over to your server.
3. Restore your antlet. That makes the antlet available to start and manage in your antlets window.

![](/files/-M8MocdUhHU19CGP-Pim)

## Test Your Backups

For peace of mind  you can restore a backup as a clone by clicking the '...' options dropdown and select 'Restore as Clone'. Rather than restoring over the existing antlet, this will create a new antlet with a new name which you can test to verify a good backup.

## Antsle Cloud Backups: Specs and Details

### Security:&#x20;

All data is **encrypted** at rest with AES-256 bit **encryption** and  we use HTTPS standards to protect data during transfers. We use top tier storage providers to hold the data - such as AWS or Wasabi.

### **Availability and Transfer Speeds:**

We have multiple redundant and secure 10 Gbps Internet connections. This means blazing fast upload and download times (as long as your connection can keep up).&#x20;

Your data is stored in one location, it is not replicated across multiple data centers.


# Self-Managed Restoration (Beta)

We are currently working on an easier way to restore for self-managed backups for another machine.  For now, you can use these instructions for restoring your antlets from self-managed storage.

* Create a new antlet with any configuration and template but with a different name than the original antlet
* Click 'Backup Now'
* Click 'Import Self-Managed backup (Beta)'
* The Backup ID can be found in the backup file name
* Enter the path to the directory containing the backup file

```
root@myantsle: # ls /seagate/self-managed
backup_local_c7046d65-e5d6-43c9-bcb0-1bb46f03ef42.zfs.gz
```

![](/files/-MHrJsKv4Zf3SUojEZ3Z)

* After the backup is retrieved, click the 'Restore' button
* Enter the name of the antlet being restored - this will create a new antlet from the backup
* Select the correct antlet 'Type' of the backed up antlet - LXC or KVM
* Click the 'Create antlet' button
* Delete the antlet used to facilitate the restore.

{% hint style="info" %}
If restoring a backup from edgeLinux 0.x.x to edgeLinux 2.x.x, upgrade to antMan version 3.3.1 or greater.\
If you  'Delete' or 'Delete local' the self-managed backup, either of these will delete the backup file.&#x20;
{% endhint %}


# Templates Overview

Our list of pre-built templates is ever-growing. See the current list below. \
Check back soon, we're constantly adding new templates.

### Templates

#### Linux (LXC)

| Name          | Type | Description                | antsle One | nano |
| ------------- | ---- | -------------------------- | ---------- | ---- |
| CentOS-7.1    | LXC  | CentOS 7.1                 | yes        | yes  |
| Debian8.5     | LXC  | Debian 8.5 Jessie          | yes        | no   |
| debian        | LXC  | Debian 8.2 Jessie          | yes        | no   |
| Debian-10     | LXC  | Debian 10 Buster           | yes        | yes  |
| Debian-11     | LXC  | Debian 11 Bullseye         | yes        | yes  |
| Fedora        | LXC  | Fedora LXC Version 28      | yes        | no   |
| Kali          | LXC  | Kali 2016.1                | yes        | no   |
| Kali2020      | LXC  | Kali 2020                  | yes        | yes  |
| LEMP Stack    | LXC  | LEMP Stack                 | yes        | yes  |
| Nagios Core   | LXC  | Nagios Core                | yes        | yes  |
| NextCloud     | LXC  | Nextcloud                  | yes        | yes  |
| Raspbian-10   | LXC  | Raspbian 10                | no         | yes  |
| Sandstorm     | LXC  | Sandstorm                  | yes        | no   |
| ubuntu-xenial | LXC  | Ubuntu 16.04 Xenial Xenus  | yes        | no   |
| Ubuntu-18.04  | LXC  | Ubuntu 18.04 Bionic Beaver | yes        | no   |
| Ubuntu 19.10  | LXC  | Ubuntu 19.10  Eoan Ermine  | yes        | yes  |
| Ubuntu 20.04  | LXC  | Ubuntu 20.04  Focal Fossa  | yes        | yes  |

#### Linux (KVM)

| Name         | Type | Description                | antsle One | nano |
| ------------ | ---- | -------------------------- | ---------- | ---- |
| CentOS-7     | KVM  | CentOS 7.2                 | yes        | yes  |
| Debian 10    | KVM  | Debian 10 Buster           | yes        | no   |
| Debian-11    | KVM  | Debian 11 Bullseye         | yes        | yes  |
| Fedora 28    | KVM  | Fedora KVM Version 28      | yes        | no   |
| Fedora 31    | KVM  | Fedora KVM Version 31      | no         | yes  |
| Kali         | KVM  | Kali 2016.1                | yes        | no   |
| Kali 2020    | KVM  | Kali 2020.2                | yes        | no   |
| Kali 2021    | KVM  | Kali 2021.2                | no         | yes  |
| OPNsense-21  | KVM  | OPNsense 21                | yes        | no   |
| Ubuntu-16.04 | KVM  | Ubuntu 16.04 Xenial Xenus  | yes        | no   |
| Ubuntu-18.04 | KVM  | Ubuntu 18.04 Bionic Beaver | yes        | yes  |
| Ubuntu 20.04 | KVM  | Ubuntu 20.04 Focal Fossa   | yes        | yes  |

#### Windows

| Name          | Type | Description                                                                                                                                                 |
| ------------- | ---- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Win2019StdGui | KVM  | Windows Server 2019 - Out of Box Desktop Experience. Includes virtio NIC and storage drivers. RDP enabled. The template does not include a Windows license. |
| Win2016StdGui | KVM  | Windows Server 2016 - Out of Box Desktop Experience. Includes virtio NIC and storage drivers. RDP enabled. The template does not include a Windows license. |
| Win2016       | KVM  | Windows Server 2016 Desktop Experience. The template does not include a Windows license.                                                                    |
| Win2012R2     | KVM  | Windows Server 2012 R2 Desktop Experience. The template does not include a Windows license.                                                                 |
| Win2012       | KVM  | Windows Server 2012 Desktop Experience. The template does not include a Windows license.                                                                    |
| Win10         | KVM  | Windows 10 Desktop Experience. You can access the Windows GUI via RDP. The template does not include a Windows license.                                     |
| Win10StdGui   | KVM  | Windows 10 Desktop Experience.  You can access the Windows GUI via RDP. The template does not include a Windows license.                                    |
| Win11StdGui   | KVM  | Windows 11 was built with TPM requirements bypassed. You can access the Windows GUI via RDP. The template does not include a Windows license.               |

Note: Currently Windows is not supported on the Nano.

### Default Passwords

#### Password to Antman

The default credentials to login to AntMan are

```
Username: root
Passowrd: antsle
```

If you change the password, it will be the same for both antman access as well as SSH access to the edgeLinux command line.

#### Password by Template

| Template                                                | Username                                                         | Password                                |
| ------------------------------------------------------- | ---------------------------------------------------------------- | --------------------------------------- |
| Windows 10                                              | antsle                                                           | antsleWin12                             |
| Windows 2016StdGui                                      | <p>You are prompted</p><p>for a password on</p><p>first boot</p> |                                         |
| Windows 2019StdGui                                      | <p>You are prompted</p><p>for a password on</p><p>first boot</p> |                                         |
| All other Windows                                       | Administrator                                                    | antsleWin12                             |
| Ubuntu KVM                                              | ubuntu                                                           | antsle (su and sudo with same password) |
| Kali2020 KVM                                            | antsle                                                           | antsle                                  |
| <p>All other templates</p><p>(Including Ubuntu LXC)</p> | root                                                             | antsle                                  |


# Install OS from .iso

With the introduction of antMan 0.9.0 we can install an operating system from an installation .iso.

First create a new antlet using the 'Blank-virtio - KVM' template for flavors of Linux or the 'Blank - KVM' template for other OS'es.

![Create a blank antlet](/files/-M-BZ56Ki3j_8dZKw7Ut)

Then enter the antlet details dialog by clicking the name of the antlet.

![Click on the Antlet-name](/files/-M-BZG5ngvjlsciVpd5o)

Select the 'Virtual Drives' tab and click the 'Import disk' button.

![Click import Disk to upload the ISO](/files/-M-BZNRdtPSYRsDkQB5j)

Upload the installation .iso file by dragging it to the drop zone and check the 'Add as CDROM' checkbox.

![Upload your custom ISO](/files/-M-BZYFgZqXCSMb_Ti0B)

When the upload is complete, click the 'Import' button. The new disk will now be displayed in the list.

![Check your disks](/files/-M-BZcGJJd3SBuqdE9vm)

Start your antlet and open the 'vnc Console' to run through the installation.

![Start the Antlet and check the VNC Console](/files/-M-BZjXbeWs-d-WiKtoQ)


# Import VM Images

Need to migrate from your current solution to Antsle? No problem!

You can drag & drop your existing VM files to antman, and they will be imported as a template. That means you can create as many antlets from it as you want.

Whether you're migrating from VirtualBox, VMware or Hyper-V, we can import many formats:

* .raw
* .bochs
* .cloop
* .cow
* .dmg
* .iso
* .qcow
* .qcow2
* .qed
* .vmdk
* .vpc
* .img
* .vhd
* .vhdx

A .vdi image (VirtualBox native format) must be converted to a raw .img format first by running the following command on the machine that hosts VirtualBox.

```
VBoxManage clonemedium abc.vdi abc.img --format RAW
```

replace 'abc' with the name of your .vdi image.

If you want to import OVA or OVF files, please convert them to qcow2 before importing. Information on how to do the conversion is readily available on the web, e.g. [here](https://edoceo.com/notabene/ova-to-vmdk-to-qcow2).

### Import VM Image <a href="#import-vm-image" id="import-vm-image"></a>

#### Select 'Templates' and the 'Import' tab

From here you can either drag and drop your VM file or select 'Path' from the Image Source field. If you select 'Path' you must supply a path to the VM file. The pop-out in the image below shows a path to an external USB drive connected to the Antsle which contains the VM image file.

![](/files/-LzstKgDmoZXGU88wCUn)

{% hint style="info" %}
Note: If the original VM booted with UEFI, a new antlet created from the imported template will not boot on the antsle.
{% endhint %}

#### Prior to antMan v2.x

**1. Click 'Manage Templates' in Antman**

![](/files/-LzsuNn968URa0o51WqM)

**2. In the Templates dialog click 'Import KVM/QEMU image' button**

![](/files/-LzsuZQZ1T_wVelzLVDt)

**3. Drag your image file into the Import Image dialog**

![](/files/-LzsuhjoI25DrRF5ULgl)

### Importing Virtual Drives

In case you have virtual drives attached to your VM being imported, and you want to import these virtual drives as well, here’s how to do it.

Let’s assume your drives are named `alice.vmdk` and `bob.vmdk`, and you want to attach them to antlet `Chris`.

Then just copy the virtual drive files to your Antsle.

On your Mac or Linux workstation, you can issue these commands:

```
ssh root@myantsle.local mkdir -p /antlets/Chris/antsle:volumes/
scp alice.vmdk bob.vmdk root@mayantsle.local:/antlets/Chris/antsle:volumes/
```

On Windows, you can use PuTTY and WinSCP instead.\
Or use [Filezilla with SFTP](https://docs.antsle.com/system/secure-ftp-sftp-access)

Then just edit the XML of your antlet `Chris`. See NOTE below before running the 'virsh edit' command.\
While logged in to the Antsle, for KVM antlets, run:

```
virsh edit Chris
```

if it’s an LXC antlet use the '-c lxc:///' option.

```
virsh -c lxc:/// edit Chris
```

NOTE: This will start a `vim` editor. If you are not familiar with vim, prefix the command with 'EDITOR=nano' to launch the nano text editor:

```
EDITOR=nano virsh edit Chris
```

Then find the \<devices> section in the XML. KVM antlets will have at least one \<disk> section inside the \<devices> section. LXC antlets by default do not have a \<disk> section.

Add a \<disk> block nested inside the \<devices> block for each virtual disk you are importing.\
Example:

```
<disk type='file' device='disk'>
      <source file='/antlets/Chris/antsle:volumes/alice.vmdk'/>
      <target dev='hda' bus='ide'/>
</disk>
<disk type='file' device='disk'>
      <source file='/antlets/Chris/antsle:volumes/bob.vmdk'/>
      <target dev='hdb' bus='ide'/>
</disk>
```

You might have to change the names `hda` and `hdb` so that there is no conflict with other drives.

Save the XML, restart your antlet and you’re ready to go!<br>


# Using the LEMP-Stack

Use the LEMP-Stack template to quickly spin up antlets that host your web-projects. The LEMP Stack features the following software, already installed and pre-configured:

* Debian 11
* Nginx 1.20.2
* MariaDB (MySQL) v10.5.12
* PHP 7.4.25

For easy database management, we pre-installed phpMyAdmin.

### 1. Create the antlet

First things first. Create a new antlet based on the `LEMP-Stack` template. If you do not know how to create antlets yet, please check out [this article](/antlets/create-and-manage-antlet).

### 2. Set up access

To make sure your antlet and the site running on it is reachable, you will need to configure access. We recommend three different ways to do it. Choose the one that suits your needs best.

{% tabs %}
{% tab title="Using a domain" %}
This is particurlarly helpful if you already have a domain that points to your edgeLinux server. Let's assume example.com is configured to point to your server. In that case, we want to create a subdomain, like myantlet.example.com that directly points to the antlet on your edgeLinux server. For that, we use the reverse proxy features in nginx. [You can find detailed set-up instructions here](https://docs.antsle.com/antlets/access-antlets#3-connect-domain-with-antlet)
{% endtab %}

{% tab title="Using Port Forwarding" %}
In this scenario, we access the address of our edgeLinux server, but specify a port that gets redirected to port 80 on the antlet. This is especially easy and quick to setup, and sufficient for most testing / developing scenarios. Once configured your can access the antlet at \<your-server-address>:XXXX where XXXX is a custom port of your choosing. [You can find detailed instructions on how to setup port forwarding here](https://docs.antsle.com/networking/port-forwarding)
{% endtab %}

{% tab title="Using a bridged NIC" %}
Configure a bridged network interface, to expose your antlet to your local network. By doing this, your antlet gets another IP address in the same network that your edgeLinux server is in (in addition to the 10.1.1.X address.) This method gives you full access to the antlet from your local network. [You can find detailed instruction on how to configure a bridged NIC here](https://docs.antsle.com/networking/bridge#configure-virtual-nic)
{% endtab %}
{% endtabs %}

### 3. Build your site

To get you started as fast as possible, we already pre-configured the antlet for you. When accessing the antlet with the method you configured, you see the php-info screen by default.

&#x20;If you have a static website you would like to serve, place it in the `/usr/share/nginx/html` directory. PHP files are automatically run. Checkout the default `index.php` for more info.

#### Using MariaDB and phpMyAdmin

The template comes with phpMyAdmin pre-installed. Navigate to the phpMyAdmin login screen by appending `/phpmyadmin` to your antlet's address (depending on the connection method you configured)

You can use it for creating, editing and deleting databases and their contents. By default, the database user is root and the password antsle. Use these credentials to authenticate with both phpMyAdmin and MariaDB (MySQL)

| Database Credentials |           |
| -------------------- | --------- |
| User                 | root      |
| Password             | antsle    |
| Hostname             | localhost |
| Port                 | 3306      |

Once logged in, click the `New` button in the sidebar to create a new databse. Choose a name and hit `Create`

![Create new Database](/files/-M3RRMdHFpDrZxyCUSAs)

Congrats, you can now use your created database with your website! 🎉

{% hint style="info" %}
**Note:** For anything other than local testing / developing we strongly recommend you change all default passwords!
{% endhint %}


# Using Nextcloud

Nextcloud is a suite of client-server software for creating and using file hosting services.  Nextcloud is functionally similar to Dropbox, Office 365 or Google Drive when used with its integrated office suite solutions Collabora Online or OnlyOffice. It can be hosted in the cloud or on-premise.

### 1. Create the antlet

Create a new antlet based on the `Nextcloud` template. If you don't know how to create antlets yet, please check out [this article](/antlets/create-and-manage-antlet).

### 2. Set up access

To make sure your antlet and the site running on it is reachable, you will need to configure access. We recommend three different ways to do it. Choose the one that suits your needs best.

{% tabs %}
{% tab title="Using a bridged NIC" %}
Configure a bridged network interface, to expose your antlet to your local network. By doing this, your antlet gets another IP address in the same network that your edgeLinux server is in (in addition to the 10.1.1.X address.) This method gives you full access to the antlet from your local network. You can find detailed instructions on how to configure a bridged NIC [here](https://docs.antsle.com/networking/bridge#configure-virtual-nic).

Add a configuration file for the bridged NIC using these commands:

Create file for the bridged NIC:  &#x20;

&#x20;   `nano /etc/network/interfaces.d/eth1`

Add the following contents:&#x20;

&#x20;   `auto eth1`\
`iface eth1 inet dhcp`&#x20;

Type CTRL+O to write. Type CTRL+X to exit.

Bring up the bridged NIC:

&#x20;    `ifup eth1`
{% endtab %}

{% tab title="Using Port Forwarding" %}
In this scenario, we will specify a port that gets redirected to port 80 on the antlet.  In this example, we are using the same port number (80) for source and destination. &#x20;

![An example of port forward](/files/-M_hI71bR8g7vSxBhMpW)

You can specify a different port if you'd like.  The source port should not be 3000 since this is used by antMan.

If you have multiple antlets running web servers listening on the same port, then you must create port forward rules with different source port numbers. &#x20;

You can find detailed instructions on how to setup port forwarding [here](https://docs.antsle.com/networking/port-forwarding).
{% endtab %}
{% endtabs %}

### 3. Connect to Nextcloud

If you used Bridged Networking above, then use this address in your browser to access Nextcloud:

&#x20; `http://bridge-nic-ip/nextcloud`

Where `bridge-nic-ip` is the private IP Address of your antlet that's on your network.

If you used Port Forwarding above, then use this address in your browser to access Nextcloud:

&#x20;   `http://myantsle.local/nextcloud`\
`http://antsle-private-ip/nextcloud`

Where `myantsle` is the host name of your antsle and `antsle-private-ip` is the private IP address of your antsle.

### 4. Logging into Nextcloud

Use the following default credentials for Nextcloud:

Username:  `root`  \
Password:  `antsle`

For using Nextcloud, you can refer to their documentation [here](https://docs.nextcloud.com/).


# Using OPNsense

OPNsense is an open-source operating system that was created from pfSense firewall software. You can use OPNsense template to create your own firewall.

### 1. Create the antlet

Create a new antlet based on the `OPNsense` template. If you don't know how to create antlets yet, please check out [this article](/antlets/create-and-manage-antlet).

### 2. Set up access

To make sure your antlet and the site running on it is reachable, you will need to configure access. We recommend three different ways to do it. Choose the one that suits your needs best.

{% tabs %}
{% tab title="Using a bridged NIC" %}
Configure a bridged network interface, to expose your antlet to your local network. By doing this, your antlet gets another IP address in the same network that your edgeLinux server is in (in addition to the 10.1.1.X address.) This method gives you full access to the antlet from your local network. You can find detailed instructions on how to configure a bridged NIC [here](https://docs.antsle.com/networking/bridge#configure-virtual-nic).

1\) Go to your antlet - **Virtual Network**.  Click on **+Virtual NIC**.  Select the interface and click on **Create**.<br>

![Create Bridged NIC](/files/-MjpPD802DQxu5yRYe6x)

2\) Click on **Delete** next to bblv (internal NIC).  Click on "I understand, delete the default Virtual NIC!"<br>

![Delete bblv (internal) NIC](/files/-MjpTrtvWsSzlDQ6Wo3_)

![Confirmation of Deletion of bblv (internal) NIC](/files/-MjpQDcFi0nz2MGzUWnL)

3\)  Start the antlet by pressing **Start**.
{% endtab %}

{% tab title="Using Port Forwarding" %}
In this scenario, we will specify a port that gets redirected to port 443 on the antlet.  Since antMan is being used on standard https port 443, we need to specify a different source port.  In this example, we are using 1443 for source port and 443 for destination port.<br>

![Port Forward Rule for OPNsense](/files/-MjpSBDu60AucrGHkt9x)

You can specify a different port if you'd like.  The source port should not be 3000 or 443 since these are being used by antMan.

If you have multiple antlets running web servers listening on the same port, then you must create port forward rules with different source port numbers. &#x20;

You can find detailed instructions on how to setup port forwarding [here](https://docs.antsle.com/networking/port-forwarding).
{% endtab %}
{% endtabs %}

### 3. Connect to OPNsense

f you used Bridged Networking above, then use this address in your browser to access OPNsense:

&#x20; `https://bridge-nic-ip`

Where `bridge-nic-ip` is the private IP Address of your antlet that's on your network.

If you used Port Forwarding above, then use this address in your browser to access OPNsense:

&#x20;   `https://myantsle.local:1443`\
`https://antsle-private-ip:1443`

Where `myantsle` is the host name of your antsle and `antsle-private-ip` is the private IP address of your antsle and port `1443` is the custom port we defined in Port Forwarding.

### 4. Logging into OPNsense

Use the following default credentials for Nextcloud:

Username:  `root`  \
Password:  `antsle`

For using OPNsense, you can refer to their documentation [here](https://docs.opnsense.org/system.html#).


# Networking Overview

If you're the Youtuber type, check out our video explaining networking with Antsle, and the easiest way to access your antlets.&#x20;

### [**Watch in Depth Video: Antsle's Networking & Easiest Way to Connect to Your antlets**](https://www.youtube.com/watch?v=E42I1tbAjJc)

![](/files/-MCiVPa2xBDhKp6Im9lr)

### Short Overview: For Those who Prefer to Read

To access the web software that you installed in your antlet, no configuration is necessary! Just navigate to `http://antletX.local`, where X is the last number of the antlet’s IP address. To access the antlet with IP address 10.1.1.42, e.g., just navigate to `http://antlet42.local`.

However, this will only work inside your local home network. The rest of this page will show you how to configure access to your antlets from the outside world.

There are three address spaces involved. See the diagram below.\
\
The Internet address space, shown in red in the diagram, uses IP adresses that are publicly accessible on the Internet. A remote user of the software in your antlets, called Alice in the diagram, is shown on top. The requests she sends find their way through the Internet to your home router.

![Antsle Network Overview](/files/-M-B_aCufPWJ6r_ekJL2)

Your router translates the Internet address space to a private address space, called a subnet, that is used to address devices in your home network. Common subnets used by router are 192.168.1.x or 192.168.0.x. By configuring port forwarding inside your router, the requests that Alice sent can find their way not only to your home router, but also onwards to your Antsle. In case you only want local access from inside your home network (shown as "You" in the diagram), you don't need any port forwarding in your router.

In order for Alice's request to finally reach a specific antlet, you can configure the nginx reverse proxy that comes with edgeLinux. This will work for "web" antlets, using HTTP or HTTPS. In case of non-HTTP antlets, you can configure a [libvirt forward](/networking/port-forwarding) to send the incoming requests to the specific antlets that will handle them.

Please read [Accessing antlets by domain name](/antlets/access-antlets#access-domain-name) in order to get your web-based antlet accessible from the outside world.


# Configure IP Addresses

The Network page allows you to configure IP addresses, default gateway, DNS and the antlets internal network IP address.&#x20;

![](/files/-MAn3byrwraa4v-Ta2no)

Click the 'Edit' button to configure the IP address of an interface. This is set to DHCP by default. To configure a static address select Static from the 'Type' dropdown and enter the IP address and mask in their respective fields.

![](/files/-MAmOwHc5o9Aq4HH3MGz)

If you configure a static IP address, scroll down and set the default gateway, choose the gateway interface and enter the DNS server addresses.&#x20;

![](/files/-MCSuRhkQ__5T-zvGp9q)

The 'Base IP' is the internal network address for the antlets - 10.1.1. by default. This network is an internal NAT'ed network and must be different than network the antsle is plugged into. When setting this field include the trailing period.

On this page you can also set an Http(s) proxy.

Click 'Save Network Defaults' and click the 'Restart Now' button if prompted. Log back into antMan within 30 minutes to confirm the new network configuration is good. If you do not confirm within 30 minutes the antsle roll back to the last configuration.


# Bridged Networking / Virtual NIC

#### Introduction <a href="#introduction" id="introduction"></a>

Bridged networking allows you to attach an additional virtual network interface to an antlet. This virtual NIC will connect to one of the physical ethernet ports on the rear of the Antsle by way of an internal bridge. Then the antlet can be accessed directly on the local LAN.

#### Antsle one, Antsle one Pro, Antsle one Ultra (sn# 100x-)

![](/files/-M-Ba5oaIuI5Eebjxz56)

| Ethernet port | Bridge name | Interface name | Speed       |
| ------------- | ----------- | -------------- | ----------- |
| Port 0        | br0         | enp0s20f0      | 10M/100M/1G |
| Port 1        | br1         | enp0s20f1      | 10M/100M/1G |
| Port 2        | br2         | enp0s20f2      | 10M/100M/1G |
| Port 3        | br3         | enp0s20f3      | 10M/100M/1G |

#### Antsle one D, Antsle one D+, Antsle one D Pro, Antsle one D Ultra (sn# 103x-)

![](/files/-M-Ba5oaIuI5Eebjxz56)

| Ethernet Port | Bridge name | Interface name | Speed       |
| ------------- | ----------- | -------------- | ----------- |
| Port 0        | br0         | eno1           | 10M/100M/1G |
| Port 1        | br1         | eno2           | 10M/100M/1G |
| Port 2        | br2         | eno3           | 10M/100M/1G |
| Port 3        | br3         | eno4           | 10M/100M/1G |

#### Antsle one XD, Antsle one XD Pro, Antsle one XD Ultra (sn# 101x-)

![](/files/-M-BaA4_bWPOzSlsxVxv)

| Ethernet port | Bridge name | Interface name | Speed       |
| ------------- | ----------- | -------------- | ----------- |
| Port 0        | br0         | eno1           | 10M/100M/1G |
| Port 1        | br1         | eno2           | 10M/100M/1G |
| Port 2        | br2         | eno3           | 1G/10G      |
| Port 3        | br3         | eno4           | 1G/10G      |

#### Antsle one XD

![](/files/-M-BaEZdWAA07EVaSLh8)

| Ethernet port | Bridge name | Interface name | Speed  |
| ------------- | ----------- | -------------- | ------ |
| Port 0        | br0         | eno3           | 1G/10G |
| Port 1        | br1         | eno4           | 1G/10G |

### Enable bridging <a href="#enable-bridging" id="enable-bridging"></a>

Ethernet port 0 is enabled for bridging by default. You can connect your antlets to this bridge port by configuring a 'Virtual NIC' in the antlet details page [(discussed later)](https://docs.antsle.com/networking/bridge#connect-antlet-directly-to-public-internet) - with no additional configuration here.

Navigate to the 'Network' page on antMan.\
&#x20;

![](/files/-LzmuAScp6yH10JXwgov)

![](/files/-LzmuVSZ0T2aTAVUvO5v)

**br0** is enabled by default and is your access to antman and to your antlets on the 10.1.1.x network. You should leave this enabled and connected to the LAN.

Note: Enabling an additional port is not necessary if you want your antlets bridged to the same local network as br0. When you configure a virtual NIC on an antlet you can choose this same port - br0. Your antlets and the Antsle can co-exist on this ethernet port. You can think of br0, br1... as internal switches that you can connect multiple antlets to in order to share the same physical port.

#### Enable another interface by checking its checkbox.

![](/files/-LzmupreECgAXFLdz9nT)

#### Click the 'Edit' button to configure DHCP or set a static address.

&#x20;**Important: Heed the DHCP warning about having a wired connection!**

![](/files/-M-BaLwb7q4_PnJjs_t7)

#### Restart the Antsle

Restart the Antsle and confirm the settings are good when it comes back up.\
If you cannot access antman after reboot, the Antsle will revert back to the last working configuration in {minutes}.

![](/files/-Lzmv2igJaANkDXY9RRI)

### Configure Virtual NIC <a href="#configure-virtual-nic" id="configure-virtual-nic"></a>

#### Enter the antlet details page

Click on the antlet name in antman.<br>

![Click on the antlet name](/files/-LzsxPkRP0OEAD5ut0aV)

#### Choose the 'Virtual Network' tab

Click 'New virtual NIC'<br>

![](/files/-M-BbZGAz9ckQ4G4CX59)

#### Choose a bridge/ethernet port

You can have multiple antlets on the same physical port. In this example I will leave it on br0.\
The 'Model' should be 'e1000' for Windows antlets or if the OS does not have virtio drivers. Any flavor of Linux should support VirtIO.

![](/files/-M-BbcRNViIpM1pVRjkO)

#### Click 'Create virtual NIC'

Now you have an additional Virtual NIC attached to this antlet and exposed to the network of the physical ethernet port.

![](/files/-M-BbetW2xkcht7NViZH)

#### Stop and Start the antlet.

Check the operating system of the antlet to configure the new NIC.\
See [Configure IP address](https://docs.antsle.com/bridgevnic/#configure-ip-address) to learn how to configure IP addresses for different operating systems.

![](/files/-M-Bbmd_5MQu_rGtYMH1)

### Connect antlet directly to public internet <a href="#connect-antlet-directly-to-public-internet" id="connect-antlet-directly-to-public-internet"></a>

Antsle is designed to [multiplex](https://docs.antsle.com/antlets/access-antlets#access-antlets-by-domain-name) all your virtual servers under a single public IP address. If you have the luxury of having multiple static public IP addresses from your ISP then you can connect an antlet directly to one of those addresses.

First connect the Antsle to the the public interface provided by your ISP. This could be the modem or a router port configured for 'bridge' mode.

Then create a virtual NIC in your antlet as [explained above](/networking/bridge#configure-virtual-nic) and assign it to the same interface that is connected to the public internet.

Configure the IP address in the antlet as [described below](https://docs.antsle.com/networking/bridge#configure-ip-address). Be sure and configure the correct subnet mask and gateway address.

Here is an example for Debian/Ubuntu. Be sure to place the configuration for eth1, the virtual NIC, before eth0 in the configuration file

*Adjust the addresses to your needs*

```
auto eth1
iface eth1 inet static
 address 70.168.1.105
 netmask 255.255.255.240
 gateway 70.168.1.1

auto eth0
iface eth0 inet dhcp
```

### Configure IP Address <a href="#configure-ip-address" id="configure-ip-address"></a>

After adding an additional network interface to an antlet you will need to configure the IP address in the operating system of that antlet.<br>

* [Debian/Ubuntu/Raspian](/networking/bridge#debianubuntu)
* [CentOS](/networking/bridge#centos)
* [Windows](/networking/bridge#windows)

#### Debian/Ubuntu/Raspian <a href="#debianubuntu" id="debianubuntu"></a>

**Connect to the antlet via ssh**

In this case it is best to ssh to the antlet from within antsleOS. See [Log in to your antlets](/get-started/log-in-to-the-edgelinux-os-and-antlets)

```
ssh myantsle.local
ssh 10.1.1.x
```

After enabling the new virtual NIC, ssh with the -p option no longer works but now you have direct access via the new IP address assigned to the virtual NIC.

**Get the interface name**

To list the interfaces run:

```
ip addr show
```

Your new NIC will most likely be called `eth1@if36`. We only need the `eth1` part.\
`eth0` should have the Antsle's internal 10.1.1.x address.

![](/files/-M-BbsTDgHhmCKD3oVG0)

**Edit configuration file**

*Debian and Ubuntu 16.04:*  Open the configuration file for editing with your preferred editor. Nano, Vi...\
For Ubuntu 16.04 KVM or ubuntu-xenial LXC

```
nano /etc/network/interfaces
```

To configure DHCP, add the following to the top of the configuration file

```
auto eth1
iface eth1 inet dhcp
```

For a Static IP address, add the following to the top of the configuration file\
*Adjust the addresses to your needs*

```
auto eth1
iface eth1 inet static
 address 192.168.1.105
 netmask 255.255.255.0
 gateway 192.168.1.1
 dns-nameservers 192.168.1.1
```

**Restart network service**

```
ifup eth1
```

#### ***Ubuntu 18.04 (netplan)***

Ubuntu 18.04 uses 'netplan' by default. Open the netplan .yaml configuration file with your preferred editor - Nano, Vi...\
For Ubuntu 18.04 KVM or LXC

```
nano /etc/netplan/50-cloud-init.yaml
or
nano /etc/netplan/10-lxc.yaml
```

To configure DHCP, add the interface (eth1 in this example) and enable 'dhcp' for the interface Here we are adding the 'eth1:' section

```
network:
  version: 2
  ethernets:
    eth0:
      dhcp4: true
    eth1:
      dhcp4: true
```

For a Static IP address, the interface section would look like this

```
eth1:
  dhcp4: false
  addresses:
    - 192.168.1.33/24
  gateway4: 192.168.1.1
  nameservers:
    addresses:
      - 192.168.1.1
      - 8.8.8.8
```

Be sure to use consistent indentation in the .yaml files\
Apply the changes with

```
netplan apply
```

Adjust the addresses to your needs\
I used the interface name 'eth1' in these examples but yours may be different.\
Yaml does allow items to use different syntax, e.g. 'lists' can use \[192.168.1.1, 8.8.8.8].

You can verify your changes by listing the interfaces again

```
ip addr show
```

.

#### CentOS <a href="#centos" id="centos"></a>

**Connect to the antlet via ssh**

In this case it is best to ssh to the antlet from within antsleOS. See [Log in to your antlets](/get-started/log-in-to-the-edgelinux-os-and-antlets)

```
ssh myantsle.local
ssh 10.1.1.x
```

After enabling the new virtual NIC, ssh with the -p option may no longer work, but now you have direct access via the new IP address assigned to the virtual NIC.

**Get the interface name of the new Bridged NIC**

To list the interfaces run:

```
ip addr
```

Your new NIC will most likely be called `eth1`.  Interface `eth0` should have the Antsle's internal 10.1.1.x address and the new bridged interface, `eth1` , may or may not have acquired an address from DHCP.

```
[root@antlet12 ~]# ip a s
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host
       valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
    link/ether b2:61:6e:73:6c:0c brd ff:ff:ff:ff:ff:ff
    inet 10.1.1.12/24 brd 10.1.1.255 scope global dynamic eth0
       valid_lft 3555sec preferred_lft 3555sec
    inet6 fe80::b061:6eff:fe73:6c0c/64 scope link
       valid_lft forever preferred_lft forever
3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
    link/ether 52:54:00:8a:05:c5 brd ff:ff:ff:ff:ff:ff
    inet 192.168.1.194/24 brd 192.168.1.255 scope global dynamic eth1
       valid_lft 86356sec preferred_lft 86356sec
```

**Configuration file**

In CentOS 7 the interface configuration file will be stored in

```
/etc/sysconfig/network-scripts/
```

Each NIC will have its own configuration file. These files are named ifcfg-NIC\_NAME\
You can list the configuration files with `ls -1 /etc/sysconfig/network-scripts/ifcfg-*`

```
[root@antlet12 ~]# ls -1 /etc/sysconfig/network-scripts/ifcfg-*
/etc/sysconfig/network-scripts/ifcfg-eth0
/etc/sysconfig/network-scripts/ifcfg-lo
```

Currently there is no configuration file for eth1. Open the configuration file in your favorite editor. If the file does not exist this command will create it.

```
nano /etc/sysconfig/network-scripts/ifcfg-eth1
```

**Configure static IP address**\
Edit the DEVICE, IPADDR, PREFIX, GATEWAY, and DNS1\
DEVICE is the interface name, `eth1`\
IPADDR is the static address you want to assign to this NIC\
PREFIX is the subnet mask number of bits (255.255.255.0 is 24 bits)\
GATEWAY is the gateway for this subnet\
DNS1 is your DNS server address\
DEFROUTE tells the system if you want this Gateway to be the default route. Set this to "no" in the configuration files for other interfaces

```
TYPE="Ethernet"
DEVICE="eth1"

ONBOOT="yes"
IPV4_FAILURE_FATAL="no"

BOOTPROTO="none"
IPADDR="192.168.1.12"
PREFIX="24"
GATEWAY="192.168.1.1"
DEFROUTE="yes"
DNS1="8.8.8.8"

```

**Restart network serverce**

```
systemctl restart network
```

#### Windows <a href="#windows" id="windows"></a>

To configure IP address setting on Windows, Open Control Panel\
Click Network and Internet link<br>

![](/files/-M-BcQuWYce3_QF1jMtO)

Click Network and Sharing Center<br>

![](/files/-M-BcT1v8PjJP5gesvcv)

Click Change Adapter Settings in the left column

![](/files/-M-BcV8DORnY09vvRxfs)

Rt Click the new adapter and choose Properties at the bottom of the context menu

![](/files/-M-BcXMby1a1ZmZvsnrF)

Choose Internet Protocol Version 4 (TCP/IPv4) from the center pane.\
Click the Properties button.<br>

![](/files/-M-BcZqgpjvZBh-ymjsV)

Configure to your needs.

![](/files/-M-BcbC9pbCwSyWt-9-v)

<br>


# Wifi on the Antsle Nano

{% hint style="info" %}
Setting up WiFi on the nano works and allows you to use the connection on a system level. However, it does not work as Interface in antMan, i.e. cannot be used to configure a bridged NIC. Since WiFi is generally less reliable and slower than Ethernet, it is generally not advised to use it.
{% endhint %}

You can easily configure a WiFi connection on the Antsle Nano using [wpa\_supplicant](https://linux.die.net/man/8/wpa_supplicant), which should be pre-installed on your Antsle Nano,  follow the steps below on the command line.

1. Edit `/etc/wpa_supplicant/wpa_supplicant.conf` and add a `network={…}` block to it.

Example:

```
ctrl_interface=/var/run/wpa_supplicant
ctrl_interface_group=wheel
network={
   ssid="MyNetwork"
   scan_ssid=1
   key_mgmt=WPA-PSK
   psk="topsecret"
}
```

| Field      | Description                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ssid       | Network name (as announced by the access point). An ASCII or hex string enclosed in quotation marks.                                                                                                                                                                                                                                                                                                                            |
| ssid\_scan | SSID scan technique; 0 (default) or 1. Technique 0 scans for the SSID using a broadcast Probe Request frame while 1 uses a directed Probe Request frame. Access points that cloak themselves by not broadcasting their SSID require technique 1, but beware that this scheme can cause scanning to take longer to complete.                                                                                                     |
| key\_mgmt  | <p>List of acceptable key management protocols; one or more of:</p><p>             WPA-PSK (WPA pre-shared key), WPA-EAP (WPA using EAP</p><p>             authentication), IEEE8021X (IEEE 802.1x using EAP authentication</p><p>             and, optionally, dynamically generated WEP keys), NONE (plaintext</p><p>             or static WEP keys).  If not set this defaults to "WPA-PSK</p><p>             WPA-EAP".</p> |
| psk        | WPA preshared key used in WPA-PSK mode.  The key is specified as 64 hex digits or as an 8-63 character ASCII passphrase.  ASCII passphrases are converted to a 256-bit key using the network SSID by the wpa\_passphrase utility.                                                                                                                                                                                               |

2\. Edit `/etc/sysconfig/wpa_supplicant` to make sure you add `-iwlan0` to specify the correct interface.

```
# Use the flag "-i" before each of your interfaces, like so:
#  INTERFACES="-ieth1 -iwlan0"
INTERFACES="-iwlan0"
# Use the flag "-D" before each driver, like so:
#  DRIVERS="-Dwext"
DRIVERS=""
# Other arguments
#   -u   Enable the D-Bus interface (required for use with NetworkManager)
#   -f   Log to /var/log/wpa_supplicant.log
#   -P   Write pid file to /var/run/wpa_supplicant.pid 
#        required to return proper codes by init scripts (e.g. double "start" action)
#        -B to daemonize that has to be used together with -P is already in wpa_supplicant.init.d
OTHER_ARGS="-P /var/run/wpa_supplicant.pid"
```

{% hint style="info" %}
The third line `INTERFACES="-iwlan0"` is the one that needs to be updated. If it is commented, uncomment that line.
{% endhint %}

3\. Restart the service by running `systemctl restart wpa_supplicant.service` .

4\. Run `wpa_cli -i wlan0` to start the wpa\_supplicant cli in interactive mode.

5\. Run `interface wlan0` in the wpa\_cli prompt.

6\. Wait a few seconds and check the status by running `status` at the wpa\_cli prompt. You should see the connection, like below.

```
> status
bssid=58:b6:33:7b:0c:6c
freq=5600
ssid=MyNetwork
id=0
mode=station
pairwise_cipher=CCMP
group_cipher=CCMP
key_mgmt=WPA2-PSK
wpa_state=COMPLETED
p2p_device_address=06:26:15:88:c9:22
address=c2:11:c6:b8:6e:9d
uuid=ca4813d9-409d-5033-8307-28cbc1b82b34
```

7\. Type `q` to quit `wpa_cli` .

You can now use the `wlan0` interface!

For more information on wpa\_supplicant, please refer to the manpage [here](https://www.daemon-systems.org/man/wpa_supplicant.conf.5.html).


# Port Forwarding

You can **skip this step** if:

1. You are using a tunneling solution in the antlet.
2. You are [accessing a web server on the antlet](/antlets/access-antlets) using the onboard nginx reverse-proxy

If, on the other hand, you want to access other services you’ve installed in your antlets, then port forwarding is one way to achieve this.

### Port Forwarding Rules

To start, navigate to the 'Port Forwarding' page from the sidebar.

#### Create a Port Forwarding Rule

A port forwarding rule will route traffic going through a specified port on your Antsle, called the *Source Port* to a specified port on a *Destination antlet* within your Antsle, called the *Destination Port.* &#x20;

To configure a port forwarding rule, click 'Add new' on the right-hand corner of the 'Port Forwarding Rules' table.

![](/files/-LzmzuJ36sS5CDmzzcbh)

Configure the port forwarding rule as below:

![](/files/-Lzn-1XAr2jQr2Y96jex)

| Field              | Description                                                                    | Values            |
| ------------------ | ------------------------------------------------------------------------------ | ----------------- |
| Protocol           | Specify the protocol of the traffic that will be allowed with this rule        | tcp, udp, or both |
| Source IP          | Private IP of the Antsle                                                       | Pre-populated     |
| Source Port        | Port on the Antsle where traffic will be routed to from outside the Antsle     |                   |
| Destination antlet | antlet where traffic will be routed to from the Source                         |                   |
| Destination Port   | Port on the destination antlet where traffic will be routed to from the Source |                   |
| Enabled?           | Toggle the port forwarding rule                                                |                   |

#### Enable a Port Forwarding Rule

Enabling a port forwarding rule takes a port forwarding rule configuration and actively routes the traffic. If left disabled, the port forwarding rule configuration will be saved, but the traffic will not be routed between the Antsle and the antlet.

To enable a port forwarding rule, click the checkbox as pictured below.

![](/files/-LznIzJJ53XwVmAvGOwa)

Then confirm by clicking 'Yes, enable this rule!'

![](/files/-LznJBBQflUXaVnGFARt)

#### Edit a Port Forwarding Rule

To make changes to the port forwarding rule configuration, click the 'Edit' button, as pictured below.

![](/files/-LznIts05ifJMNg5C1U8)

Make any changes as desired, and click 'Save Configuration'.

![](/files/-LznJ1jWPRXucXKCMe_y)

{% hint style="warning" %}
Although a Port Forwarding Rule is enabled, traffic may not reach the Destination antlet if the Destination Port is blocked by the antlet's firewall. In order to accept traffic coming into an antlet from your Antsle, you will need to open that port using a firewall tool appropriate for the antlet's OS (e.g. `firewalld` , `iptables`, `Windows Firewall`).
{% endhint %}

#### Delete a Port Forwarding Rule

Deleting a port forwarding rule will *permanently* remove the configuration from antMan.&#x20;

{% hint style="info" %}
If you would like to disable a port forwarding rule without removing the configuration, simply click the blue checkbox to disable the rule instead. Disabling the rule will prevent traffic from forwarding, while still keeping the configuration in case you need it for later.
{% endhint %}

To delete a port forwarding rule, click the 'Delete' button as pictured below.

![](/files/-LznImmy6J6efr6nzBD5)

Confirm deletion by clicking 'Yes, delete this rule!'

![](/files/-LznJ5yfKW8I7tA88HHd)

### Port Forwarding via 'hooks' file

If you do not have a plan that enables the port forwarding feature, then you can create a “libvirt hook”. This way, the port forwarding will be enabled when the antlet starts, and discarded when the antlet stops.

For that, ssh into your antsle and then issue these commands:

```
mkdir -p /etc/libvirt/hooks
cd /etc/libvirt/hooks
```

Now that you are in the /etc/libvirt/hooks directory, use your favorite text editor, such as vim or nano, to create a file named 'qemu' for port forwarding rules to KVM antlets. Name the file 'lxc' if creating port forwarding rules for LXC antlets. Add the contents shown below.&#x20;

```
#!/bin/bash
# update: 11/16/2018

antlet_type=`basename "$0"`

# Update the following variables to fit your setup
# Use an equal number of host and guest ports
antlet_name=Ansible
antlet_ipaddr=10.1.1.10
host_ipaddr=192.168.1.3
host_ports=( '3001' )
antlet_ports=( '3001' )


# Perform actions
if [ "${1}" = "${antlet_name}" ]; then
  echo `date` hook/${antlet_type} "antlet ${1}" "${2}" >>/var/log/libvirt/hook.log
fi
length=$(( ${#host_ports[@]} - 1 ))
if [ "${1}" = "${antlet_name}" ]; then
   if [ "${2}" = "stopped" ] || [ "${2}" = "reconnect" ]; then
       for i in `seq 0 $length`; do
               echo "`date` hook/${antlet_type} antlet $antlet_name Closing port ${host_ports[$i]} ->  ${antlet_ports[$i]} " >>/var/log/libvirt/hook.log
               iptables -t nat -D PREROUTING -d ${host_ipaddr} -p udp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -D FORWARD -d ${antlet_ipaddr}/32 -p udp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
               iptables -t nat -D PREROUTING -d ${host_ipaddr} -p tcp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -D FORWARD -d ${antlet_ipaddr}/32 -p tcp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
       done
   fi
   if [ "${2}" = "start" ] || [ "${2}" = "reconnect" ]; then
       for i in `seq 0 $length`; do
               echo "`date` hook/${antlet_type} antlet $antlet_name Mapping port ${host_ports[$i]} ->  ${antlet_ports[$i]} " >>/var/log/libvirt/hook.log
               iptables -t nat -A PREROUTING -d ${host_ipaddr} -p tcp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -I FORWARD -d ${antlet_ipaddr}/32 -p tcp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
               iptables -t nat -A PREROUTING -d ${host_ipaddr} -p udp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -I FORWARD -d ${antlet_ipaddr}/32 -p udp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
       done
   fi
fi
```

Please adapt these lines to your needs:

```
antlet_name=Ansible
antlet_ipaddr=10.1.1.10
host_ipaddr=192.168.1.3
host_ports=( '3001' )
antlet_ports=( '3001' )
```

* antlet\_name is the antlet name (case sensitve)
* antlet\_ipaddr is the IP address of the antlet as seen in antMan
* host\_ipaddr is the Private IP address of the antsle as seen in antMan
* host\_ports is the port number(s) of the request comming in to the antsle
* antlet\_ports is the target port number(s) of the service on the antlet

The host\_ports and antlet\_ports do not need to be the same:

```
host_ports=(  '13330' )
antlet_ports=( '3389' )
```

This can be used to forward traffic to multiple antlets listening on the same port by setting a unique host\_ports per antlet. This technique can also add a little security to well known ports.

You can add more ports if needed (use a space between port numbers)

```
host_ports=( ‘3389’ ‘4444’ ‘2211’)
antlet_ports=( '3389' '4444' '2211')
```

If you need to forward ports into additional antlets, just duplicate the code within the same hook file. An example could look like this:

```
#!/bin/bash
# update: 11/16/2018

antlet_type=`basename "$0"`

# Update the following variables to fit your setup
# Use an equal number of host and guest ports
antlet_name=Ansible
antlet_ipaddr=10.1.1.10
host_ipaddr=192.168.1.66
host_ports=( '3001' )
antlet_ports=( '3001' )


# Perform actions
if [ "${1}" = "${antlet_name}" ]; then
  echo `date` hook/${antlet_type} "antlet ${1}" "${2}" >>/var/log/libvirt/hook.log
fi
length=$(( ${#host_ports[@]} - 1 ))
if [ "${1}" = "${antlet_name}" ]; then
   if [ "${2}" = "stopped" ] || [ "${2}" = "reconnect" ]; then
       for i in `seq 0 $length`; do
               echo "`date` hook/${antlet_type} antlet $antlet_name Closing port ${host_ports[$i]} ->  ${antlet_ports[$i]} " >>/var/log/libvirt/hook.log
               iptables -t nat -D PREROUTING -d ${host_ipaddr} -p udp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -D FORWARD -d ${antlet_ipaddr}/32 -p udp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
               iptables -t nat -D PREROUTING -d ${host_ipaddr} -p tcp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -D FORWARD -d ${antlet_ipaddr}/32 -p tcp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
       done
   fi
   if [ "${2}" = "start" ] || [ "${2}" = "reconnect" ]; then
       for i in `seq 0 $length`; do
               echo "`date` hook/${antlet_type} antlet $antlet_name Mapping port ${host_ports[$i]} ->  ${antlet_ports[$i]} " >>/var/log/libvirt/hook.log
               iptables -t nat -A PREROUTING -d ${host_ipaddr} -p tcp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -I FORWARD -d ${antlet_ipaddr}/32 -p tcp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
               iptables -t nat -A PREROUTING -d ${host_ipaddr} -p udp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -I FORWARD -d ${antlet_ipaddr}/32 -p udp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
       done
   fi
fi


# Update the following variables to fit your setup
# Use an equal number of host and guest ports
antlet_name=lamp
antlet_ipaddr=10.1.1.15
host_ipaddr=192.168.1.66
host_ports=( '3306' '21' ) # Expose MySQL and FTP ports
antlet_ports=( '3306' '21' )

# Perform actions
if [ "${1}" = "${antlet_name}" ]; then
  echo `date` hook/${antlet_type} "antlet ${1}" "${2}" >>/var/log/libvirt/hook.log
fi
length=$(( ${#host_ports[@]} - 1 ))
if [ "${1}" = "${antlet_name}" ]; then
   if [ "${2}" = "stopped" ] || [ "${2}" = "reconnect" ]; then
       for i in `seq 0 $length`; do
               echo "`date` hook/${antlet_type} antlet $antlet_name Closing port ${host_ports[$i]} ->  ${antlet_ports[$i]} " >>/var/log/libvirt/hook.log
               iptables -t nat -D PREROUTING -d ${host_ipaddr} -p udp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -D FORWARD -d ${antlet_ipaddr}/32 -p udp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
               iptables -t nat -D PREROUTING -d ${host_ipaddr} -p tcp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -D FORWARD -d ${antlet_ipaddr}/32 -p tcp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
       done
   fi
   if [ "${2}" = "start" ] || [ "${2}" = "reconnect" ]; then
       for i in `seq 0 $length`; do
               echo "`date` hook/${antlet_type} antlet $antlet_name Mapping port ${host_ports[$i]} ->  ${antlet_ports[$i]} " >>/var/log/libvirt/hook.log
               iptables -t nat -A PREROUTING -d ${host_ipaddr} -p tcp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -I FORWARD -d ${antlet_ipaddr}/32 -p tcp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
               iptables -t nat -A PREROUTING -d ${host_ipaddr} -p udp --dport ${host_ports[$i]} -j DNAT --to ${antlet_ipaddr}:${antlet_ports[$i]}
               iptables -I FORWARD -d ${antlet_ipaddr}/32 -p udp -m state --state NEW,ESTABLISHED,RELATED --dport ${antlet_ports[$i]} -j ACCEPT
       done
   fi
fi
```

{% hint style="info" %}
IMPORTANT: Make sure there is no blank line before the first line (#!/bin/bash) Note: Only make edits to the hook file when the antlet is Stopped. Note: Windows uses different line endings than linux which are not compatible. You may get errors if you edit in a Windows text editor.
{% endhint %}

And make make the file executable:

```
chmod a+x qemu
chmod a+x lxc
```

When the hook file is first created you may need to reboot the antsle but is not required for future edits. Make edits to the hook file only when the antlet is Stopped.

If you have a second ethernet port enabled (br1, br2 or br3) and it has an IP address on the same network as br0. Use the host\_ipaddr of br0 when connecting to the antlet via the port.


# Load Balancing

If you want to:

1. Scale out your application across multiple antlets
2. Allow access to your antlet from the outside world
3. Route traffic from one antlet to another when one fails or hangs

then load balancing is perfect for you!

**Load Balancing** is a feature on antMan that lets you distribute outside traffic across a set of antlets, called **upstreams**. Each upstream typically accomplishes the same task (e.g. serve static web content, service API requests).&#x20;

{% hint style="info" %}
As each database technology has its own version of multi-node/clustering, utilize the multi-node/clustering functionality for that database rather than a load balancer.&#x20;
{% endhint %}

## Create Load Balancing Rule

Navigate to the "Load Balancing" page from the sidebar. On this page, you will see a table that will show high-level details of each load balancing rule.

![](/files/-M0KoEqVmb2ZyD_piqiH)

Click the "Create +" button, as shown below.

![](/files/-M0Oq3Hrrs5ZibOynX6R)

Fill out the form below, and click "Create Rule."&#x20;

![](/files/-M0Or7M6WD2m6qPVgDPP)

| Name         | Description                                                                                                                           |
| ------------ | ------------------------------------------------------------------------------------------------------------------------------------- |
| Server Name  | URL where you can access your upstreams. (e.g.`my-balanced-page.local`, `example.com`)                                                |
| Server Port  | Port where you can access your upstreams                                                                                              |
| Upstreams    | Applications that you are serving. These are usually copies of the same application served on different Antsle servers                |
| Backup only  | If selected, this upstream will only be used if the others are down                                                                   |
| Address      | Address of this upstream (e.g. `myserver.com`, `10.1.1.102:80`)                                                                       |
| Weight       | The amount of times the load balancer will route traffic to this upstream before moving to the next upstream in a round-robin fashion |
| Add Upstream | Add more upstreams as needed                                                                                                          |

Test your load balancer by repeatedly visiting the Server URL (e.g. `my-balanced-page.local`). As you repeatedly visit the URL, the load balancer will route the request to each of the different upstreams, taking into account the weight of each upstream.&#x20;

## Edit Load Balancing Rule

To make changes to a load balancing rule, click the "Edit" button as shown below:

![](/files/-M0Kr2tnbhotpCok1_uP)

Once confirmed, the changes will take place immediately.

## Delete Load Balancing Rule

To delete a load balancing rule, click the "Delete" button as shown below:

![](/files/-M0KqOnI-Rd7y4amm1wT)

Confirm deletion by clicking the button below that says "Yes, delete!"

![](/files/-M0KqPuMSUFmnIqBwLNw)


# SDN: Software Defined Networking

Dividing your Antsle's environment into isolated networks and creating trunk ports

{% hint style="info" %}
SDN is only available in edgeLinux 2.0.0 and later
{% endhint %}

## Internal vLANs

Creating a VLAN and adding antlets to it is an easy way to isolate different antlets into their own network environment within your Antsle server.&#x20;

A common reason for doing this is when you are doing things with those antlets that could adversely affect the others or their networking.&#x20;

To get started, **head over to the&#x20;*****SDN*****&#x20;tab on the left menu and hit create.**&#x20;

![](/files/-M93mKT4VPD0qt0W08km)

**Give your VLAN a name and a vLAN ID** (We'll discuss ID when creating a trunk). Do not connect it to an interface.

![](/files/-M93ni0cmHQOm9ZU3E7p)

**Add some antlets, and then connect them.** Voila. That's all.&#x20;

![](/files/-M93nwuxlcXKG4bImO8k)

This adds a new virtual NIC to those antlets. You will want to log into your antlets and give them a static IP that allows them to communicate in their isolated network.

{% hint style="success" %}
Your antlets are all created -- by default -- with a virtual NIC and connected to an internal natted network. This is what allows you to SSH into them from your Antsle's console, and allows them to communicate with each other.&#x20;

Your default NIC, **bblv**, will still be active (and your antlet not truly isolated) unless you delete it.
{% endhint %}

To truly isolate your antlets, you will need to remove the default, bblv NIC under the network tab. **This means you will only be able to access that antlet via the VNC console.** You can restore the default vNIC at any time.&#x20;

![](/files/-M93qfVFeE-v9637EKPe)

## Creating a Trunk

This is how you connect your vLAN (and the antlets in them) to "outside" networks, integrating it into virtual networks that may span many nodes (devices, servers, etc.).&#x20;

Creating a trunk happens automatically when you connect a vLAN to an interface (see image below).&#x20;

{% hint style="info" %}
Once you connect it to an interface (aka NIC or port) on your server, it becomes a trunk port. Creating a trunk port means that it will now send information about what vLAN the traffic is associated with and direct incoming traffic to the appropriate vLAN.&#x20;
{% endhint %}

![](/files/-M93s5dmp_ztMMXiP2qN)

If you are connected your vLAN to an external network you will want to give it the same vLAN ID (aka "tag") as the external network you are connecting it to.

Follow the process of adding antlets and you're done.&#x20;

## Mirroring

If you have a monitoring tool that you want to keep separate from a vLAN but still have it able to see all the internal traffic, just mirror one vLAN (the one with the traffic) to the other vLAN (the one with your monitoring tool).

![](/files/-M93wAfYkkH68hSl8xaX)


# Antsle Distributed Storage - ADS

If you want:

* Highly-available, resilient storage
* Access to your data across your Antsle servers
* Software that runs smoothly, even if portions of your cluster go down

then ADS is right for you!

### What You'll Need

* At least three Antsle servers with at least two drives each
* antMan Grow+ for each Antsle server
* 1G Ethernet switch with a connection to each Antsle server (Make sure to activate the NIC in the Networks page)

{% hint style="info" %}
Make sure that each Antsle server has a unique hostname, as the hostname plays an important part in uniquely identifying each node. i.e. Don't leave your antsle's name myantsle. See this guide to change the name of your Antsle server.
{% endhint %}

## ADS - Installation

Navigate to the Settings page.

![](/files/-M5c9Pgg1hpVujXGwLpL)

Under **Storage Settings** flip the switch for ADS.

![](/files/-MBGS-k6xEZHT2ezJgZe)

Follow the prompts through the configuration process

### Overview

![](/files/-MBGS8FC3etZoWSWuabt)

### &#x20;Select Nodes&#x20;

![](/files/-MBGSDa4H3FcmbHT8dBk)

**Add Node** - Add a node to the cluster.&#x20;

**Nodes**

| **Name** | Description                                                      |
| -------- | ---------------------------------------------------------------- |
| Node     | Name of the node                                                 |
| Include? | Select whether or not the node will be included into the cluster |

### Configure Nodes

![](/files/-MBGSIChBYhRi5R-8Nx3)

| Name       | Description                                                                                                                                              |
| ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Node       | Name of the node                                                                                                                                         |
| IP Address | IP Address ADS will use to make connections. The IP address selected should be the IP address assigned to the port connected to the 10G Ethernet switch. |
| Device     | Block device to be managed by ADS                                                                                                                        |

{% hint style="info" %}
The block device chosen will be wiped, so make sure that any important data on each block device selected is backed up. If the device chosen is used by ZFS to create a mirror, this mirror will be unset, and ADS will wipe and manage the drive. If the device chosen is an NVMe, the L2 Arch caching will be disabled, and ADS will manage the NVMe.
{% endhint %}

Once you've gone through the configuration steps, antMan will install ADS in the background. To check the status of the ADS installation, check the Jobs menu at the top-right of the screen.

{% hint style="warning" %}
Do not get an InstantSSL for any of the nodes in the ADS cluster as the nginx configuration will intercept the ADS cluster communication.

If you lose communication with antMan run the following command on the antsle's command line:

&#x20;   firewall-cmd --permanent --zone=public --add-port=3000/tcp
{% endhint %}

## ADS Drives

With ADS installed, you can create ADS Drives. **ADS Drives** are highly-available, distributed filesystems that can be mounted from multiple antlets. Saving data to this filesystem on any one antlet will be available for all other mounted antlets to access. Data in an ADS Drive will be available, even if some portion of the Antsle servers are down.

### Add ADS Drive

Click `+` Create to Create an ADS Drive

![](/files/-MBGTYAKAEJtpqw2idXi)

![](/files/-MBGTa6XRTg3XIfx50MJ)

| Name | Description                                                                                                                                               |
| ---- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Name | Name of the ADS Drive                                                                                                                                     |
| Size | Size of the ADS Drive. If 0 is chosen, no size limit will be configured, and ADS will store data on the ADS Drive until there is no more available space. |

### Edit ADS Drive

Click the `Edit` button to Edit an ADS Drive

![](/files/-MBGTgcjf8EfqOSgGdmx)

![](/files/-MBGTlaAWkzyToyDFmsJ)

| Name | Description                                                                                                                                               |
| ---- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Name | Name of the ADS Drive                                                                                                                                     |
| Size | Size of the ADS Drive. If 0 is chosen, no size limit will be configured, and ADS will store data on the ADS Drive until there is no more available space. |

### Delete ADS Drive

Click Delete to Delete an ADS Drive

![](/files/-MBGUG3PMw3FIJy6mUvz)

Click Yes, Delete this ADS Drive! to confirm deletion.

![](/files/-MBGUKAWOvgNKEAfoV6d)

### Mounting an ADS Drive

In order to mount an ADS Drive, an antlet must be able to access the ADS cluster. For example, if an ADS cluster is in the 192.168.0.0/24 subnet, then the antlet where you'd like to mount the ADS Drive must also be in that subnet. To accomplish this, see this guide on how to [create and configure a Virtual NIC](/networking/bridge).

After a Virtual NIC is configured, and the default gateway is set appropriately, you can mount the ADS Drive using the following command:

`mount -t ceph 192.168.0.9:6789:/test-drive /mnt/`

replacing:

| Example     | Description                                 |
| ----------- | ------------------------------------------- |
| 192.168.0.9 | IP address of any node in the cluster       |
| test-drive  | name of the ADS Drive you want to mount     |
| /mnt/       | mountpoint of your choice inside the antlet |


# Multi-Node

{% hint style="info" %}
You can access multi-node features with a Grow or Scale plan. [See details](https://antsle.com/pricing).
{% endhint %}

With multi-node features, you can view and manage your antlets all in one view.

### Add a Node

To add a node, click your node name on the sidebar, as shown below, and click "Add new node."

![](/files/-M0PeLrQNp66hDuc3ON4)

![](/files/-M0PeT1FJFaV-t7wPVw0)

Fill out the form below and click "Add node" to connect to the other node.

![](/files/-M0Peap1sDIGFS9dg6T9)

| Name         | Description                                                                                                                 |
| ------------ | --------------------------------------------------------------------------------------------------------------------------- |
| Host URL     | URL to connect to antMan on the node (e.g. `192.168.0.101:3000`, `https://example-node.antsle.us` , `http://example.local`) |
| Username     | Username on the  node                                                                                                       |
| Password     | Password for the Username                                                                                                   |
| Name (Alias) | The name you assign this node that will be displayed on antMan                                                              |

### Switch Nodes

Once configured, you should be able to see the alias of the new node when you click on the node name.

![](/files/-M0Pg_XzoLIDuUr8-Bj9)

To switch to that node, and view antlets on that node, click on the new node. You should see an alert like the one showed below.

![](/files/-M0PgqmIQYhWQQmFKmaK)

You will now be able to see antlets that are on the other node. You can manage the antlet just like you would if you were also on that node.

### See All Antlets

To see every antlet on all configured nodes, click "All antlets" like shown below.

![](/files/-M0PhOiFDCu6ddXYMzIT)

You can now manage all your antlets on all your configured nodes. Start, stop, reboot (and more) antlets across nodes with ease.

![](/files/-M0PiXVE_Z5-Y8s9YbVe)


# Secure (HTTPS) Access to Antman

### InstantSSL™: Easy https to antMan <a href="#easy-https-for-antman" id="easy-https-for-antman"></a>

With the introduction of antMan 0.9.1 we can set a subdomain to access antMan via https\://\<subdomain>.antsle.us

First we want to set the subdomain in antHill. We will assume you have activated your Antsle in antHill, if you have not take a look at the [release annoucement for 0.9.0](https://antsle.com/company/release-announcements/antman-0-9-0/). Once you login to antHill you should see your Antsle in your dashboard.

The under the subdomain column click "Get one!". You can then set the subdomain you want for this Antsle as long as its available. Lets say we set the subdomain to `aster`. After you submit the configuration you will be able to connect to antMan via <https://aster.antsle.us>!

![](/files/-MfYpauugG1esSs-F_xy)

{% hint style="info" %}
With InstantSSL configured, you can now securely access your antlets--just like antMan--via https. You can reach an https server on an antlet with the antlet name and antsle.us subdomain.&#x20;

e.g. if I have an antlet named 'webserver', you can securely access your antlet via *<https://webserver.aster.antsle.us>*
{% endhint %}

### Manual https to antMan <a href="#manual-https-to-antman" id="manual-https-to-antman"></a>

1. Obtain your domain name, SSL certificate files
2. Place the certificate files in the certs directory
3. Create a virtualhosts .conf file
4. Restart nginx

Note: If using a self-signed certificate, as I will in this example, your browser will show warnings because the certificate has not been signed by a trusted CA.\
Note: Replace *antman.mydomain.com* with your domain in the example configuration.

First lets create a new directory to store our certificate files

```
  mkdir -p /etc/ssl/certs/mycerts
```

Then copy your certificate files to the *mycerts* directory with [sftp (Filezilla)](/system/secure-ftp-sftp-access) or scp.\
For this example I will create a self-signed certificate.  You can skip creating the self-signed certificate if you already have your certificate.

```
  openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/certs/mycerts/antman-selfsigned.key -out /etc/ssl/certs/mycerts/antman-selfsigned.crt
```

You will be prompted with several questions. Enter your domain name when prompted for "Common Name"

```
Common Name (e.g. server FQDN or YOUR name) []: antman.mydomain.com
```

Create and edit a new nginx virtualhosts configuration file. The *.conf* extension is required.

```
  nano /etc/nginx/virtualhosts/ssl.antman.mydomain.com.conf
```

Paste the following content into the file.\
Replace *antman.mydomain.com* with your domain name on lines 9, 10 and 18.\
Replace the certificate *path/file* names if different on lines 16, 17, 46, 47, 92 and 93.

```
map $http_upgrade $connection_upgrade {
  default upgrade;
    ''      close;
}

# redirect http request
server {
  listen 80;
  server_name antman.mydomain.com;
  rewrite ^ https://antman.mydomain.com$request_uri redirect;
}

server {
  listen 443 ssl;
  ssl_certificate /etc/ssl/certs/mycerts/antman-selfsigned.crt;
  ssl_certificate_key /etc/ssl/certs/mycerts/antman-selfsigned.key;
  server_name antman.mydomain.com;
  root /var/www;

  location / {
    proxy_read_timeout      300;
    proxy_connect_timeout   300;
    proxy_redirect          off;

    proxy_set_header    Host                 $host;
    proxy_set_header    X-Real-IP            $remote_addr;
    proxy_set_header    X-Forwarded-For      $proxy_add_x_forwarded_for;
    proxy_set_header    X-Forwarded-Proto    $scheme;
    proxy_set_header    X-Forwarded-Protocol $scheme;
    proxy_set_header    X-Forwarded-Ssl      off;
    proxy_set_header    X-Url-Scheme         $scheme;
    proxy_set_header    X-Frame-Options      SAMEORIGIN;

    # Forward WebSocket.
    proxy_http_version  1.1;
    proxy_set_header    Upgrade              $http_upgrade;
    proxy_set_header    Connection           $connection_upgrade;

    proxy_pass http://127.0.0.1:3000;
  }
}

server {
  listen 6843 ssl;
  ssl_certificate /etc/ssl/certs/mycerts/antman-selfsigned.crt;
  ssl_certificate_key /etc/ssl/certs/mycerts/antman-selfsigned.key;
  root /var/www;

  location / {
    proxy_read_timeout      300;
    proxy_connect_timeout   300;
    proxy_redirect          off;

    proxy_set_header    Host                 $host;
    proxy_set_header    X-Real-IP            $remote_addr;
    proxy_set_header    X-Forwarded-For      $proxy_add_x_forwarded_for;
    proxy_set_header    X-Forwarded-Proto    $scheme;
    proxy_set_header    X-Forwarded-Protocol $scheme;
    proxy_set_header    X-Forwarded-Ssl      off;
    proxy_set_header    X-Url-Scheme         $scheme;
    proxy_set_header    X-Frame-Options      SAMEORIGIN;

    # Forward WebSocket.
    proxy_http_version  1.1;
    proxy_set_header    Upgrade              $http_upgrade;
    proxy_set_header    Connection           $connection_upgrade;

    proxy_pass http://127.0.0.1:6822;
  }
}

map $server_port $vnc_port {
    ~67(?<id>\d\d) 69$id;
}
server {
# These 'listen' lines are for the vncConsoles in antMan. If you will have more
# than 10 kvm antlets you can add more. Just increment the port number for each
# additional line.
  listen 6700 ssl;
  listen 6701 ssl;
  listen 6702 ssl;
  listen 6703 ssl;
  listen 6704 ssl;
  listen 6705 ssl;
  listen 6706 ssl;
  listen 6707 ssl;
  listen 6708 ssl;
  listen 6709 ssl;
  listen 6710 ssl;

  ssl_certificate /etc/ssl/certs/mycerts/antman-selfsigned.crt;
  ssl_certificate_key /etc/ssl/certs/mycerts/antman-selfsigned.key;
  root /var/www;

  location / {
    proxy_read_timeout      300;
    proxy_connect_timeout   300;
    proxy_redirect          off;

    proxy_set_header    Host                 $host;
    proxy_set_header    X-Real-IP            $remote_addr;
    proxy_set_header    X-Forwarded-For      $proxy_add_x_forwarded_for;
    proxy_set_header    X-Forwarded-Proto    $scheme;
    proxy_set_header    X-Forwarded-Protocol $scheme;
    proxy_set_header    X-Forwarded-Ssl      off;
    proxy_set_header    X-Url-Scheme         $scheme;
    proxy_set_header    X-Frame-Options      SAMEORIGIN;

    # Forward WebSocket.
    proxy_http_version  1.1;
    proxy_set_header    Upgrade              $http_upgrade;
    proxy_set_header    Connection           $connection_upgrade;

    proxy_pass http://127.0.0.1:$vnc_port;
  }
}
```

Restart the nginx service

```
service nginx restart
```

If working on the same local network as the antsle, the domain name must resolve to the private IP of the antsle.  If accessing remotely from the public internet, the domain name must resolve to your gateway/router public IP address and the router must forward port 443 to the antsle's private IP address.

### SSH Reverse Tunnel to antMan <a href="#ssh-reverse-tunnel-to-antman" id="ssh-reverse-tunnel-to-antman"></a>

SSH can be used to create a 'reverse tunnel' to antMan. The nice thing about this is the only configuration required is to create the port forwarding rule in the router. No additional nginx configuration or ssl certificates are required.

For example:

* router public IP: 2.2.2.2
* Antsle private IP: 192.168.1.3
* router is forwarding port 22 to the Antsle's private IP 192.168.1.3 port 22

We can run the following command from a remote location

```
ssh root@2.2.2.2 -L 3333:localhost:3000
```

The command maps a local port (3333 in this case) to the remote port (3000) via an ssh tunnel - antMan is listening on port 3000.\
Now you can enter the following url in your browser to open the remote antMan

```
http://localhost:3333
```

Using port 3333 is just an arbitrary choice. You can uses different local port numbers to connect to different antsle's e.g. 3333 for the San Diego Antsle and 4444 for the Dallas Antsle.

In the first example the standard ssh port is used (22). But you could forward a different port on the public side of your router. In this next example we will use port 44761 on the public side of the router.

* router is forwarding port 44761 to the Antsle's private IP 192.168.1.3 port 22

For this use the '-p' option to designate the target ssh port.

```
ssh -p 44761 root@2.2.2.2 -L 3333:localhost:3000
```

The url used in your browser to open antMan is the same as the first example.

To be able to open remote kvm antlet vncConsoles via antMan add these port mappings to the ssh command

```
ssh -p 44761 root@2.2.2.2 -L 3333:localhost:3000 -L 6900:localhost:6900 -L 6901:localhost:6901 -L 6902:localhost:6902
```

You can add as many '-L' mappings as you like. The first kvm antlet started will use port 6900 for its console. The second kvm antlet started will use port 6901... and so on.

### Manual https to antlets <a href="#https-to-antlets" id="https-to-antlets"></a>

To set up an ssl certificate for an antlet we have a couple of options

* Install the certificate in the antlet
* Use nginx proxy to handle the certificate

The first option requires the antlet to have a bridged NIC and be addressed directly. The traffic for each antlet/webserver would require a unique public IP address or use a unique port number for the router to direct the traffic to the correct antlet IP address. Here the certificate files are installed and handled by the antlet

The second option allows nginx to connect to the proper antlet based on the URL in the header of the request. This is desireable because you can forward traffic (at the router) for multiple sites to one IP address, the private IP address of the Antsle. The certificate files are installed and handled by nginx on the edgeLinux OS.

First create a directory for your certificate files on the edgeLinux OS.

```
mkdir -p /etc/ssl/certs/mycerts
```

Use SCP or SFTP to copy your certificate files to this directory.

Create and edit a new nginx virtualhosts configuration file for your domain name. Replace example.com with your domain name.

```
  nano /etc/nginx/virtualhosts/ssl.example.com.conf
```

Paste the following content into the file and replace 'example.com' with your domain name.

```
# SSL to antlet

# If you want to use your domain example.com in HTTPS mode (with SSL),
# rename this file to ssl.example.com.conf (from ssl.example.com.conf.HTTPS)
# Replace example.com with your domain name.
# Make sure you have your SSL certificate installed properly.
# The certificate files are not required to be in the directories presented here, but
# the path must be the correct path to your certificate files.

# The webserver on your antlet will listen on port 80 (http).
# Nginx on edgeLinux handles SSL (https).

# Redirect http://www.example.com to https://example.com
# If your domain name does include 'www' then remove this server block and use the full
# domain name in the last server block.
server {
  listen 80;
  server_name www.example.com;
  rewrite ^ https://example.com$request_uri redirect;
}

# Redirect http://... to https://...
server {
  listen 80;
  server_name example.com;
  rewrite ^ https://example.com$request_uri redirect;
}

# Redirect https://www... to https://example.com
# If your domain name does include 'www' then remove this server block and use the full
# domain name in the last server block.
server {
  listen 443 ssl;
  ssl_certificate /etc/ssl/certs/mycerts/example.com.crt;
  ssl_certificate_key /etc/ssl/certs/mycerts/example.com.key;
  server_name www.example.com;
  rewrite ^ $scheme://example.com$request_uri redirect;
}

# Think of the word 'example' in 'upstream example' as a variable name which is
# used in other server blocks. This name must be unique among all your .conf
# files. It is used in the two 'proxy_pass' lines in the next server block.
# If you change the upstream variable name then be sure to update the proxy_pass
# lines also.
upstream example {
  # Enter the IP address and port number of your antlet handling this domain
  server 10.1.1.10:80;
}

server {
  listen 443 ssl;
  ssl_certificate /etc/ssl/certs/mycerts/example.com.crt;
  ssl_certificate_key /etc/ssl/certs/mycerts/example.com.key;
  server_name example.com;
  root /var/www;

  location / {
    proxy_read_timeout      300;
    proxy_connect_timeout   300;
    proxy_redirect          off;
    proxy_buffers         4 256k;
    proxy_buffer_size       128k;
    proxy_busy_buffers_size 256k;

    proxy_set_header    Host                 $host;
    proxy_set_header    X-Real-IP            $remote_addr;
    proxy_set_header    X-Forwarded-For      $proxy_add_x_forwarded_for;
    proxy_set_header    X-Forwarded-Proto    $scheme;
    proxy_set_header    X-Forwarded-Protocol $scheme;
    proxy_set_header    X-Forwarded-Ssl      off;
    proxy_set_header    X-Url-Scheme         $scheme;
    proxy_set_header    X-Frame-Options      SAMEORIGIN;

    proxy_pass http://example;
  }

  location ~*  \.(jpg|jpeg|png|gif|ico|css|js|pdf|woff|woff2)(\?.*)?$ {
    expires 365d;
    add_header Cache-Control "public, max-age=315360000";
    access_log off;

    proxy_read_timeout      300;
    proxy_connect_timeout   300;
    proxy_redirect          off;
    proxy_buffers         8 24k;
    proxy_buffer_size       2k;

    proxy_set_header    Host                 $host;
    proxy_set_header    X-Real-IP            $remote_addr;
    proxy_set_header    X-Forwarded-For      $proxy_add_x_forwarded_for;
    proxy_set_header    X-Forwarded-Proto    $scheme;
    proxy_set_header    X-Forwarded-Protocol $scheme;
    proxy_set_header    X-Forwarded-Ssl      off;
    proxy_set_header    X-Url-Scheme         $scheme;
    proxy_set_header    X-Frame-Options      SAMEORIGIN;

    proxy_pass http://example;

  }
}
```

In the 'upstream' block replace the word 'example' with your domain name and enter the server IP address. For example if the domain name is 'antsle.com' and the antlet address is 10.1.1.32 and listening on port 8080, then the upstream block would look like this:

```
upstream antsle {
  # Enter the IP address and port number of your antlet handling this domain
  server 10.1.1.32:8080;
}
```

Replace the two occurrences of 'proxy\_pass <http://example>;' with the upstream name on lines 74 and 102

```
proxy_pass http://antsle
```

Restart the nginx service

```
service nginx restart
```


# Secure FTP (SFTP) Access

### Good News! <a href="#good-news" id="good-news"></a>

As of antman 0.5.0, you have SFTP access to your Antsle and each antlet by default! Just use any FTP client such as the popular [FileZilla](https://filezilla-project.org/)!

### SFTP to the Antsle <a href="#sftp-to-the-antsle" id="sftp-to-the-antsle"></a>

Just use the credentials shown in the table below. You can use FileZilla's QuickConnect function.

| **Field** | **Value**                          |
| --------- | ---------------------------------- |
| Host:     | {antsle domain name or IP address} |
| Username: | root                               |
| Password: | {yourpassword}                     |
| Port:     | 22                                 |

![](/files/-M-BctjLZQktuQJEvkN_)

Filezilla: When the SFTP protocol is chosen the port will default to 22 unless a different port number is entered. See example below.

### SFTP to a specific antlet <a href="#sftp-to-a-specific-antlet" id="sftp-to-a-specific-antlet"></a>

Note: if you [configured a bridged virtual NIC](/networking/bridge), the following method will not work. You can SFTP directly to the IP address configured on the bridged interface.

To access antlet with IP address 10.1.1.12, use these credentials:

| Field     | Example antlet 10.1.1.12 | antlet 10.1.1.{num}    |
| --------- | ------------------------ | ---------------------- |
| Host:     | sftp\://myantsle.local   | sftp\://myantsle.local |
| Username: | root                     | root                   |
| Password: | {yourpassword}           | {yourpassword}         |
| Port:     | 22012                    | 22000 + {num}          |

![](/files/-M-Bcw_RIN0yvYnsaaBc)

Enjoy!


# USB Drives

### USB Ports <a href="#usb-ports" id="usb-ports"></a>

#### Antsle one, Antsle one Pro, Antsle one Ultra

![](/files/-Lzsww5KxpxXfF7z2GeU)

#### Antsle one XD, Antsle one XD Pro, Antsle one XD Ultra

&#x20;Blue usb ports: usb 3.0.\
Black usb ports: usb 2.0.<br>

![](/files/-LzswzreCnyOT0h3IsTF)

**NOTE:** You must change the boot options in the system BIOS after adding a USB device. Upon the next restart, the Antsle will try to boot from the USB and fail. If you did not [configure IPMI](https://docs.antsle.com/setup/#5-ipmi-optional) you can connect a keyboard and monitor to the Antsle. Power up and hit \<Del> at the SuperMicro splash screen to enter the bios settings. Arrow over to the 'Boot' menu and select 'USB Device BBS Priorities' and set the boot option to 'disable' for the usb device. Save settings and exit.

There are three main ways to utilize external USB drives with the Antsle.

* Add Zpool storage
* Give an antlet exclusive access to a USB drive
* Mount USB storage in the edgeLinux file system

### Create Zpool on External USB Drive <a href="#create-zpool-on-external-usb-drive" id="create-zpool-on-external-usb-drive"></a>

You can use additional external USB storage for antlets and virtual drives.

First ssh to the Antsle

```
ssh root@myantsle.local 
```

To see the existing drives run

```
lsblk
```

The drives are named: sda, sdb...

Plug in your usb drive and run 'lsblk' again to see the name of the new drive - it should be the last drive in the list.\
Now we want to prepare the drive for zfs by removing the partitions on the drive. This will destroy all data on the USB drive!

```
parted -a optimal /dev/sdX
```

where 'sdX' is the name of your usb drive

```
mklabel gpt
```

this will warn, any data on the drive will be destroyed. If this is ok with you, answer Yes.\
then quit 'parted'

```
q
```

Now lets create a zpool on the drive

```
zpool create POOL_NAME -m /POOL_NAME /dev/sdX
zfs set atime=off POOL_NAME
zfs set compression=off POOL_NAME
```

Replace POOL\_NAME with a name to identify the new zpool.\
Replace 'sdX' with the actual drive name\
POOL\_NAME must be the same in each part of the commands. ex:

```
zpool create myusbdrive -m /myusbdrive /dev/sde
zfs set atime=off myusbdrive
```

Now you can refresh antman and create a new antlet or virtual drive on this zpool. You will see the new zpool in the 'zpool' dropdown.

### Create a Mirrored Zpool for Data Protection

If you want mirrored usb disks repeat the 'parted' steps for the second drive but run the following zpool commands.

```
zpool create POOL_NAME -m /POOL_NAME mirror /dev/sdX /dev/sdY
zfs set atime=off POOL_NAME
zfs set compression=off POOL_NAME
```

sdX and sdY need to be replaced by the actual drive names displayed in 'lsblk' Replace POOL\_NAME with the desired zpool name

You do not need to update /etc/fstab. zfs will take care of mounting the zpool if the Antsle is rebooted. Refresh antMan and you should see the new zpool.

### Remove a zpool <a href="#remove-a-zpool" id="remove-a-zpool"></a>

At the Antsle's command line list the zpools

```
zpool list
```

Then destroy the zpool

```
zpool destroy POOL_NAME
```

Remove the directory the zpool was mounted to

```
rm -rf /POOL_NAME
```

Now if you refresh antman and try to create a new antlet, the zpool dropdown will no longer list the usb zpool.

### USB Pass Through <a href="#usb-pass-through" id="usb-pass-through"></a>

Note: Currently USB Pass through only works with KVM antlets

USB Passthrough allows you to assign an external USB drive to a specific antlet. \
Enter the antlet details page by clicking the name of the antlet

![](/files/-LzsxPkRP0OEAD5ut0aV)

Then choose the 'USBs' tab and select your device.

![](/files/-LzsxTutfbpcxDTEx8D2)

Be sure to 'Stop' then 'Start' the antlet.

### Mount USB in the edgeLinux file system <a href="#mount-usb-in-the-edgelinux-file-system" id="mount-usb-in-the-edgelinux-file-system"></a>

This can be useful to store installation .iso files or store backups of other files without filling up the root '/' partition. List the existing drives with the command:

```
lsblk
```

The drives are named: sda, sdb... Find your device and partition number in the list. \
Create a directory to mount the USB in

```
mkdir -p /mnt/usb1
```

Mount the USB

```
mount /dev/sdXN /mnt/usb1
```

replace 'sdXN' with the device(X) and partition number(N) with those of your USB as seen in the 'lsblk' command.

Note: For edgeLinux 0.13 or prior, if you get an NTFS unknown file system error, you can install NTFS support with the command:\
emerge sys-fs/ntfs3g

Check that you can see the files on the USB with

```
ls /mnt/usb1
```

To make this mount persist after a reboot, we need to add the mount info to the 'fstab' file.\
First lets get the UUID and file system type from the USB drive using the `blkid` command. In this example the drive name is `sdc` as found in the `lsblk` command

```
blkid |grep sdc 
```

The output will include both the UUID and file system TYPE. The output may have other info like a LABEL.

```
/dev/sdc1: UUID="42AA6C2CAA6C1F23" TYPE="ntfs" PARTUUID="c129de7b-01"
```

We can now update the `/etc/fstab` file to mount the USB when booted.\
Make a backup of `/etc/fstab`and open it for editing

```
cp /etc/fstab /etc/fstab.bak
nano /etc/fstab
```

Add the following line to the end of the file using your UUID, mount point and file system type.

```
UUID=42AA6C2CAA6C1F23  /mnt/usb1  ntfs  noatime  0 2
```

To un-mount the USB (the command is 'u'mount not 'un'mount)

```
umount /mnt/usb1
```


# Docker Support

### Enable Docker service <a href="#enable-docker-service" id="enable-docker-service"></a>

The Docker service can be started in antMan via the Services page, accessible on the sidebar

![](/files/-Lzmx-4SOh7EkB5LKmgq)

From here you can start the Docker service. Check the 'Autostart' checkbox to have Docker start when the Antsle is rebooted.

![](/files/-LzmxCsRX_0kZLDTMGz6)

Docker can be run at the Antsle's command line. Simply connect to the [antsleOS via ssh](/get-started/log-in-to-the-edgelinux-os-and-antlets) and test docker by running dockers 'hello-world' image

```
docker run hello-world
```

This will download and run the 'hello-world' image in a container. It will print some text and exit.

```
Hello from Docker!
This message shows that your installation appears to be working correctly.

To generate this message, Docker took the following steps:
 1. The Docker client contacted the Docker daemon.
 2. The Docker daemon pulled the "hello-world" image from the Docker Hub.
 3. The Docker daemon created a new container from that image which runs the
    executable that produces the output you are currently reading.
 4. The Docker daemon streamed that output to the Docker client, which sent it
    to your terminal.
...
```

For more info on using docker please visit the [docker website](https://www.docker.com/)

### Kubernetes <a href="#kubernetes" id="kubernetes"></a>

Here's a guide on how to run an example service:

First, create (at least) two antlets out of the "Ubuntu 16.04 Kubernetes - KVM" template, and make sure hostnames are unique.

For our example, we're going to use Calico pod network, when running kubeadm init, you must run it like this: (use your network number)

```
sudo kubeadm init --pod-network-cidr=192.168.0.0/16
```

Then proceed with the output instructions and join the node as normal.

Next, you need to create the pod network, as we prepared it to use Calico, we run:

```
kubectl apply -f https://docs.projectcalico.org/v2.6/getting-started/kubernetes/installation/hosted/kubeadm/1.6/calico.yaml
```

Note: We have tested our changes with the Calico pod network, but it should work with other pod networks. Bare in mind that you must run some special flags for each when doing a kubeadm init. You can find the list of supported pod networks and their special flags here: <https://kubernetes.io/docs/setup/independent/create-cluster-kubeadm/#pod-network>

Now you should be able to run your services with type "NodePort", here's an example:

```
kubectl run hello-world --replicas=2 --labels="run=load-balancer-example" --image=gcr.io/google-samples/node-hello:1.0  --port=8080
kubectl expose deployment hello-world --type=NodePort --name=example-service
```

Then look for the node port:

```
kubectl describe services example-service
```

Look for the NodePort line, it should look like:

```
NodePort:                 <unset>  30588/TCP
```

The service should be accessible on this port, in our exmaple it would be:

```
curl http://127.0.0.1:30588
```

You need to use the IP address, for some reason using "localhost" won't work.

To call it from outside the antlet:

```
curl http://ANTLET_IP:30588
```

You should see an output like this:

```
Hello Kubernetes!ubuntu@kube-next-master3:~$
```

"Hello Kubernetes!" is the output of our example service.


# LDAP/SSO

The LDAP settings are in the 'Settings' page in antMan

![](/files/XDiOt5Cc7JJDxb4hKvdp)

* **Host:** URI of the LDAP server
* **Bind DN:** The LDAP object with permissions to look up authentication info
* **Password:** The Bind DNs password
* **Optional:** Choose an encryption protocol: TLS or SSL
* **Connect Timeout:** Set a connection timeout in milliseconds, e.g. 3000 = 3 seconds
* **Default OU:** Designate the Organizational Unit of the directory containing user info
* **Default DC:** The default Domain Components. e.g. if the domain is antsle.com then dc=antsle,dc=com


# antMan REST API

{% hint style="warning" %}
The antMan REST API may change at any time.&#x20;
{% endhint %}

You can view the swagger-ui using the following url

```
http://myantsle.local/swagger-ui
```

If you have renamed your Antsle, replace 'myantsle' in the URL with the name of your antsle - or the antsles private IP address.\
*The URL (localhost:4444) in the following images is unique to our lab setup. AntMan is actually listening on port 3000.*

![](/files/-M-BdxRZ6CTmN31CiMQQ)

First you need to authenticate and receive an access token

Open the 'auth' section

![](/files/-M-Be-9B4HPftfGnBqLe)

And open the /api/login section\
&#x20;Click in the 'Example Value' box to populate the 'Bodyxxx' field.\
Edit the values of the json object with your antlse's username and password.\
Click 'Try it out!'

![](/files/-M-Be254zmEkmgeOheC3)

This will give you an example cURL command to authenticate and retrieve an access token.\
The 'Response Body' field contains your access token

![](/files/-M-Be4VxjDcjuu_U76DY)

In subsequent calls you would add an 'Authorization' header to the cURL command with your access token.

```
--header 'Authorization: Token eyJhbGciO...'
```

```
curl -X POST --header 'Content-Type: application/json' --header 'Accept: application/octet-stream' --header 'Authorization: Token eyJhbGciO...' 
```


# The antMan Terraform Provider

Using antMan's REST API

{% hint style="warning" %}
The antMan Terraform Provider is only supported and maintained on the latest major release of edgeLinux: edgeLinux 2.0.  If you are still on edgeLinux 0.12 or earlier please read this guide for [migrating to the new OS.](https://docs.antsle.com/system/edgelinux-os-architecture#how-to-migrate-from-edgelinux-1-based-on-gentoo-to-edgelinux-2-0)
{% endhint %}

## Manage a Single Node

This is an example setup to manage one server (node) with Terraform. It's recommended you familiarize yourself with the workings of the antMan API first. To do that, read the article ["Rest API"](https://docs.antsle.com/rest/) and / or check out the swagger documentation on your server. The swagger documentation can be found under 'myantsle'.local:3000/swagger-ui.

### Installing the provider <a href="#installing-the-provider" id="installing-the-provider"></a>

The Antsle Terraform provider is based on the [Terraform OpenAPI Provider](https://github.com/dikhan/terraform-provider-openapi). You can download the [sample project here](https://github.com/antsle/antsle-terraform-provider-example/) to get started.

To install the binary, simply place it into your plugin directory - usually located under `~/.terraform.d/plugins/` - and add a configuration file called `terraform-provider-openapi.yaml`. In that file, define a new service called 'antsle' and include the URL to your server like so:

```
version: 1
services:
    antsle:
      swagger-url: https://<myantsle>.antsle.us/swagger.json
```

If you should not use SSL (only recommended for private local networks), add the following directly under your swagger-url: `insecure_skip_verify: true`.

After that, Antsle will be available as a provider in your Terraform-setup.

### Using Antsle as a provider <a href="#using-antsle-as-a-provider" id="using-antsle-as-a-provider"></a>

In your Terraform configuration files, specify the Antsle provider like so

```
provider "antsle" {
  apikey_auth = "Token eyJh..."
}
```

Notice that you'll need to provide a value for `apikey_auth`. This key will be used to authenticate all requests. To obtain your token, use the `/api/login` endpoint. Add the prefix `Token` to the returned value so your `apikey_auth` field looks like in the example above. Run `terraform init` to make the new provider available.

#### Managing resources <a href="#managing-resources" id="managing-resources"></a>

The provider exposes several resources to Terraform. Let's take a look at managing antlets. To create an antlet, simply make use of the resource `antsle_antlets` and specify the desired values like so:

```
resource "antsle_antlets" "antlet1" {
  dname = "antlet1"
  template = "Fedora.lxc"
  ram = 1024
  cpu = 1
  antlet_num = 33
  zpool_name = "antlets"
  compression = "lz4"
}
```

When running `terraform plan`, Terraform will check if the antlet exists and perform the appropriate action:

![](/files/-M-BeKJkbqyLYu0xJjOy)

## Manage Multiple Nodes <a href="#manage-multiple-nodes" id="manage-multiple-nodes"></a>

If you have multiple servers you'd like to manage with Terraform, you can register one provider for each server. Let's assume you have two servers running edgeLinux, server1 and server2. Download and install the provider like described in the single-node application. Once in your `~/.terraform.d/plugins/` directory, duplicate the provider. Make sure to follow this naming scheme: `terraform-provider-<servername>`. In our example, this would be terraform-provider-server1 and terraform-provider-server2.

Next, adjust your configuration accordingly. Like in a single-node application, create a file called `terraform-provider-openapi.yaml` - also in your plugins directory. Add an entry for each server and make sure the name of each service matches the `<servername>` of the corresponding plugin. Again, in our example the configuration would look like this:

```
version: 1
services:
  server1:
    swagger-url: https://server1.antsle.us/swagger.json
  server2:
    swagger-url: https://server2.antsle.us/swagger.json
```

After running `terraform init`, you can make use of each provider and their resources like described in the single-node example above. Only adjust the naming scheme to correspond to your configuration:

```
provider "server1" {
...
}

resource "server1_antlets" "antlet1" {
...
}
```


# Access Your HDD (or SSD) Add-on

The best way to access your HDD add-on or SSD add-on is to create [virtual drives](https://docs.antsle.com/drives/).

For LXC antlets, you have an additional option. You can enable your LXC antlet to access the add-on in its entirety.

Here's how it works:

Let’s assume the antlet that you want to use the HDD with is named TEST. Please replace the word TEST in the commands below with the actual name of your antlet! Please note: Currently, this only works when the antlet in question is of type LXC.

Login to your Antsle (not an antlet) via `ssh root@myantsle.local`. If needed, check the [default password](/get-started/log-in-to-the-edgelinux-os-and-antlets).

Then issue these commands:

`zfs create hdd/TEST`

`mkdir /antlets/TEST/hdd`

`mount --bind /hdd/TEST /antlets/TEST/hdd`

When you now log in to the antlet TEST, it will have mounted the HDD as `/hdd`.


# Setting Up Shared Storage Volume

How to access a network share

If you have a shared network volume like a NAS you can mount it directly in edgeLinux allowing you to read and write data to it. This is especially useful if you want to use it as a backup location for your antlets or simply want to access the data on the drive. These commands require the attached storage to be shared via smb. Most shared network volumes based on Linux or Windows use smb by default, but it may need to be enabled.

First, make sure you have a directory on your edgeLinux server where you can mount your shared network volume. To create one, simply type `mkdir -p /mnt/networkshare`. You can choose any path and folder name you'd like.

Once you have the folder on your Antsle, you'll also need the IP address of your network share plus the user and password to log in.

For our example, let's assume the IP address of your network share is 192.168.178.50 and your username simply user.

With that information, you can substitute the data in the command below:

`mount -t cifs -o username=user,password='P@sswrd123!' //192.168.178.50/remote-path /mnt/networkshare`

Make sure to substitute 'user' with the share's (e.g. NAS) username.  Use single quotes around the password.  Set the local path `/mnt/networkshare` to any (empty) directory on your Antsle.

![](/files/-M-BeV9kR_KgbNPzzukJ)

\
After running the command, the drive and it's contents will be available under the specified folder (in the example `/mnt/networkshare`). Now you can use the share to automatically save backups using antMan.


# edgeLinux OS

### Overview

edgeLinux OS is a type-1 [hypervisor](https://en.wikipedia.org/wiki/Hypervisor), specialized for the needs of Antsle. You can see the system requirements on the [download page](https://antsle.com/products/antmanedgelinux/download/).

It is based on CentOS and is a custom operating system with everything  that’s needed to manage your virtual servers. It orchestrates the networking, backups, storage, etc. It has zero overhead on top of that. The result is a blazing fast hypervisor.&#x20;

### Virtual Machines and Bare-Metal Containers

edgeLinux OS supports two types of virtualization to create your antlets. While each antlet is a complete Virtual Private Server (VPS), LXC antlets use OS-based virtualization, a.k.a. containerization (popularized by docker), whereas KVM antlets use hardware-based virtualization with QEMU and KVM. For most cases, use LXC-based antlets because they create the least overhead and save resources including electricity. In that way, your Antsle is a green datacenter.

### Storage

For storage, we use mirrored ZFS pools. ZFS is an advanced, feature rich file system designed to never allow any data loss or inconsistent state on the storage media. Combined with mirroring, our ZFS-based storage architecture offer excellent fault-tolerance and flexibility. We just thought your data is important – so we better keep it safe.

We use a ZFS pool (zpool) named “antlets” to store your antlets as well as the templates the antlets are created from. Try a `zfs list` or `zfs list -t all` to inspect the layout of ZFS file systems. The HDD add-on resides on a separate zpool named `hdd`.

Each antlet gets its own ZFS file system in the antlets pool, so it’s completely separated from the rest of the system (including other antlets). Mirroring, compression etc is all handled by ZFS inside edgeLinux OS and is completely transparant to the antlets themselves. In plain English: each and every antlet gets isolation, mirroring and compression for free, without having to take care of it in any way.

### Internal IP address assignment <a href="#internal-ip-address-assignment" id="internal-ip-address-assignment"></a>

We have an integrated, internal DHCP server in edgeLinux OS, and each antlet will pull it's IP address from that DHCP server - unless you [create a bridge](https://docs.antsle.com/bridgevnic/). This DHCP server will assign IP addresses based on Mac addresses:

```
b2:61:6e:73:6c:0a will receive 10.1.1.10
b2:61:6e:73:6c:0b will receive 10.1.1.11
b2:61:6e:73:6c:0c will receive 10.1.1.12
b2:61:6e:73:6c:0d will receive 10.1.1.13
...
```

In our pre-defined templates, we're always using those Mac addresses, and through our template XMLs we make sure that one of these MACs will be assigned.

## How to Migrate from edgeLinux 1 (based on Gentoo) to edgeLinux 2.0

{% hint style="info" %}
**This is a new migration process and currently in beta. We cannot guarantee that your system will be in the state that you left it previously or that all your antlets will run on your new installation.** \
\
This will not save any of the following:

* Custom configurations that you did to your Antsle server,&#x20;
* Your port forwarding rules
* Your snapshots
* Virtual drives that are not on the main antlets zpool (those need to be backed up separately).
  {% endhint %}

### Step 1 - Get your systems ready

Check your settings tab in antMan, your version of antMan should should be 2.2.1 (or higher). Why is this important? **Any antlet backups taken before this version can not be restored on edgeLinux 2.0.** If your antMan is not up to date then run *`upgrade-antman`* in your console before taking backups in step two.

Next log in to [antHill.antsle.com](https://anthill.antsle.com) and make sure that your server is activated and visible there. antHill is the central hub and will  allow you to restore backups across multiple Antsle servers.

### Step 2 - Back up any antlets that you want to keep

[**Watch this 1 minute video**](https://www.youtube.com/watch?v=65TCFU1RKGM) or read our [**docs article**](/antlets/backing-up-antlets) for a guide on how to back up and restore antlets. This tutorial assumes you will use the Antsle Cloud as your storage backend. \
\
Backups come with antMan Essential, Grow or Scale. You can see our plans and pricing [**here**](https://antsle.com/pricing). Once backups are enabled you can back up your antlets.

{% hint style="info" %}
If you have any templates you want to keep, just create an antlet out of them and back them up as well
{% endhint %}

{% hint style="danger" %}
Important note: If your antlet has a virtual drive on a different zpool that will not be included in the back up. Read our docs article on backing up antlets for workarounds.
{% endhint %}

### Step 3 - Do a fresh install of our OS

[**Download here**](https://antsle.com/products/antmanedgelinux/download/#0) and follow the [instructions in the docs for installation](/get-started/getting-started-with-edgelinux-software-only-version).

### Step 4 - Activate new Antsle Server

At the on-boarding screen, select “this is Antsle hardware” and follow the prompts. This will give your new installation the same serial number and license as the original.&#x20;

You must also register the Antsle on antHill when prompted in the on-boarding process. This will allow antHill to make the connection between your backups and this new server.

### Step 5 - Restore the backups to your new server

Restore backups from the "Heal antlets" section in antMan. Hop right over to the 0:45 time stamp at [this video](https://www.youtube.com/watch?v=65TCFU1RKGM) where we show you how to heal your antlets.


# Windows License

You may only use the Windows templates for evaluation purposes.

### Installing a license <a href="#installing-a-license" id="installing-a-license"></a>

Open a command line with administrative privileges (cmd or powershell)\
Execute the following:

```
DISM /online /Set-Edition:ServerStandard /ProductKey:XXXXX-XXXXX-XXXXX-XXXXX-XXXXX /AcceptEula
```

Where 'ServerStandard' is replace with your Edition and the XXXXX is replaced with a valid license key.

Generally our templates are for retail channel only. But it is possible that volume licencing method will work with no guarantee.


# antHill and Account Management

First things first. You gotta [register on antHill](https://anthill.antsle.com/#/signup) if you haven't already. You'll be asked to register when you log in to antMan for the first time. You can always [register now](https://anthill.antsle.com/#/signup) if you didn't do so before.&#x20;

Here are some important things you can do on your antHill account.

## Manage your Antsle ownership

You register your Antsle on [antHill](https://anthill.antsle.com) to claim ownership. This comes in handy when you have backups taken by one Antsle server that need to be restored to another. One way they sync up is through antHill recognizing the same owner on both servers.

If you ever sell or otherwise dispatch an Antsle server from your service, you should delete it from your antHill account.

## Get Support

You have a support portal on antMan where you can open a ticket...but what if you can't get to antMan? Log in to [antHill](https://anthill.antsle.com) and click the support button to get help.

## Manage your Subscriptions and Payment Methods

Head over to your billing account on [antHill](https://anthill.antsle.com). Here are some important actions you can take in your billing account.&#x20;

* Update billing address and payment methods
* See your billing history for subscriptions (this may not include server purchases from our ecommerce store)
* See your plan information and details
* Cancel your antMan subscription

![](/files/-MDTKIHHhdZeZErI5u36)

## &#x20;Assign Subscriptions to Your Servers

Click on the Subscriptions tab to see any available subscriptions and assign them to a server. Changing which server a subscription is assigned to can be done by sending a message to <support@antsle.com>. Just tell them the subscription (as seen in screenshot below) and the serial number of the server you would like to assign it to.&#x20;

![](/files/-MDTLWPXaj0R8Fl144rC)

## Instant SSL

Check out [this doc article](https://docs.antsle.com/system/secure-https-access-to-antman#easy-https-for-antman) on how to give your antlet a cool domain name via instant SSL.


# Troubleshooting

Here are some tips on how to resolve any problems that might arise.

## antHill Activation - Can't Find the Antsle

Here is a series of videos for trouble shooting anthill activation.

**1. Basic connectivity**

{% embed url="<https://www.youtube.com/embed/9YAUKbuTYHY?rel=0>" %}

Are you plugged into the correct ethernet port? The default ethernet port is 'br0' and is the only port enabled when new out of the box.

**2. antHill, enter SN# and password**

{% embed url="<https://www.youtube.com/embed/LH-3jtbt-bQ?rel=0>" %}

The SN# can be found on the bottom of your Antsle.

**3. Verify the root password**

{% embed url="<https://www.youtube.com/embed/A279IIF0Hc0?rel=0>" %}

**4. Check anthilld service and internet connectivity**

{% embed url="<https://www.youtube.com/embed/Y-zOEbioyPU?rel=0>" %}

## edgeLinux Rollback (for versions before 2.0)

If you need to roll back to the previous version after running an edgeLinux upgrade, follow these steps:

You'll need to create a bootable USB stick with the following image: <https://static-files.antsle.com:8443/edgeLinux/sysrec.iso>

Once you have the USB ready, connect a monitor, a keyboard and the USB stick; then boot from it.

Once in the sysrec OS, download the rollback shell script and execute. You can use the following commands to do so:

```
wget -c https://static-files.antsle.com:8443/edgeLinux/edgelinux-rollback.sh
chmod +x edgelinux-rollback.sh
./edgelinux-rollback.sh
```

After the script finishes, shutdown your server by executing:

```
shutdown -h now
```

Remove the USB stick, and boot normally. You should be able to access your previous environment before the upgrade.

## Cannot access antMan using **\<myantslename>**.local from a browser

#### Power

* Is the power LED on?
* Please check the power adapter is firmly plugged into Antsle's DC power connector and that the power button has been pressed to turn your Antsle on.

#### Ethernet Connection

* Is your ethernet cable plugged into the correct [ethernet port](/networking/networking-overview)?
* Is there a link light on the ethernet port and switch/router?
* Are you connected to the same subnet (same switch or vlan) as the Antsle?

#### .local name resolution

* Does your computer resolve the .local domain name to an IP address? Test with a ping which should return the private IP address of the Antsle.

```
ping antsle_name.local
```

* Windows does not resolve .local names by default. You may need to install Bonjour print services or iTunes:\
  <https://antsle.com/forum/topic/did-windows-10-update-1803-break-bonjour-local-addresses/>

#### URL's

* If you get google search results instead of antMan you may need to use 'http\://' in the url

```
http://antsle_name.local
```

* antMan is listening on port 3000, try

```
http://antsle_name.local:3000
```

* If you know the IP address of the Antsle, you can open antMan with:

```
http://x.x.x.x:3000
```

* You can find the IP address by connecting a keyboard and monitor to the Antsle and login as the root user. At the command line, run:

```
ifconfig br0
```

#### Firewall

* The avahi service (mDNS) on the Antsle is what advertises the .local names. It uses IP multicast address 224.0.0.251 and udp port 5353. Any chance you have a firewall blocking on your workstation or your router?

You can also try modifying your local [hosts file](/troubleshooting#hosts-file)

## InstantSSL not working

Here are the things to keep in mind regarding the InstantSSL. (antsle.us subdomains)

The InstantSSL domain name resolves to the private IP of the antsle as seen in the antMan dashboard (the IP on br0). If this IP is in a private IP address range, e.g. 10.x.x.x, 172.16.x.x thru 172.31.x.x or 192.168.x.x, then it cannot be reached from the public internet. Only from the local LAN.

Nginx on the edgeLinux OS handles the SSL cert and the connection to antMan. The Nginx service should be running. You can check with the command:

```
systemctl status nginx
systemctl status restart
```

The anthilld service queries the antHill database for the antsle.us domain name and handles installing the SSL cert and adding the nginx conifg file for the domain name. The anthilld service should be running

```
systemctl status anthilld
systemctl restart anthilld
```

The antsle must be able to communicate with the public internet?

```
ping -c3 8.8.8.8
ping -c3 google.com
ping -c3 anthill.antsle.com
```

The nginx config file that is created by anthilld is 'ssl.antsle.us.local.conf' and should exist in /etc/nginx/conf.d/

```
ls /etc/nginx/conf.d
```

## I cannot SSH into my Antsle

#### I don't know how to ssh from my Mac or Linux machine.

* On MacOS or Linux, you can launch the Terminal app.
* Run the 'ssh' command

```
ssh root@antsle_name.local
```

and enter your root password when prompted.\ <br>

#### I don't know how to ssh from my Windows PC.

* Install an ssh client on your PC, such as PuTTY or MobaXterm.
* Start a new ssh session, enter `antsle_name.local` as the host, `root` as the user name and use your root password.
* You can leave the port at the default setting (22).

## I cannot access my antlets

<http://antlet10.local> does not show the antlet.

You first need to install something in your antlet, e.g. Apache. See [FreedomCasts.com](https://docs.antsle.com/tshoot/freedomcasts.com)

Some antlets can take considerable time to start up, especially KVM antlets. So please wait a few minutes and try again.

I cannot SSH into my antlet.

Please make sure you've started the antlet and it is shown as Running in antman. Some antlets can take considerable time to start up, especially KVM antlets. So please wait a few minutes and try again.

Try to [SSH into antsle](https://docs.antsle.com/login/) first, and **from there** into your antlet.

Please make sure you're using the correct [port number](/get-started/log-in-to-the-edgelinux-os-and-antlets).

I get a 502 Bad Gateway error when connecting to an antlet?If you are trying to connect to an antlet according to the instructions in '[Access antlets Locally](/antlets/access-antlets#access-antlets-local)' e.g. <http://antlet10.local> , you must have some web server software installed and running on that antlet.

## No Available Templates are displayed

If the available templates list is empty and you have not downloaded all of our available templates, you may have an ad-blocker plugin in your browser.  Try creating an exception for antMan.

Refreshing the Templates page may cause this issue as well. Just navigate to another page and back again and the Available Templates will be populated again.

## USB Pass Through: Did not find USB device

The error: Internal error: Did not find USB device bus:X device:Y is displayed when starting an antlet with a USB Pass Through device.

The issue here is the USB device number will increment if the USB is removed and plugged back in. Or the USB has been removed before it was disabled in antMan.

To resolve this we need to edit the xml for the antlet. In antlet details in the USBs tab get the new device number for your USB. Then from the command line of the antsle: <https://docs.antsle.com/get-started/log-in-to-the-edgelinux-os-and-antlets>, Open the xml of the antlet for editing with

```
EDITOR-nano virsh edit ANTLET_NAME
```

Near the bottom you will find the '\<hostdev...' section. Edit the 'device=' number with the new device number. Or remove the entire `<hostdev...` section if the USB is no longer attached to the antsle.

```
<hostdev mode='subsystem' type='usb' managed='yes'>
    <source>
        <address bus='1' device='5'/>
    </source>
</hostdev>
```

Save and exit. Now the antlet should start.

## Importing VM files error

Wrong number of args (0) passed to: core/juxtThis error will occur if you delete all the templates from 'Manage templates'Getting error: Server responded with 0 codeIf running antsleOS version below 0.4.0 and antman 0.7.0, there is a 16GB limitation if you use <http://myantsle.local> URL.\
Look up your Private IP in antman, say it is 192.168.0.103. Then navigate to <http://192.168.0.103:3000> to access antman. With that URL, you should be able to import templates bigger than 16GB.

## antlets will not start: 'bblv' is not active

**Error: Requested operation is not valid: network 'bblv' is not active.**

The internal network (for the antlets) is a NAT'ed network and must be different than the LAN your antsle is connected to. We suggest using 10.1.1. for base-ip. If the LAN the antsle is connected to is using that same network address then the antlets base IP can be changed in antMan > Settings > Base IP.

The base IP can be set from the command line as well with the following command:

```
antsleOS-baseip set x.x.x.
```

replacing x.x.x. with a unique network address. Note, include the last '.'&#x20;

To start the 'bblv' network from the antlse's command line, run:

```
virsh net-start bblv
```

If you get an error referencing 'tun', run the following command:

```
echo 'modules="tun"' >> /etc/conf.d/modules
```

Reboot.\
You can check the status of the internal networks with:

```
virsh net-list --all
```

## Vnc Console

Mouse cursor not in sync with the display

If the antlet was running during the last upgrade, then you just need to Stop->Wait->Start the antlet; please note that clicking Reboot will not suffice, as it would just trigger Operating System level reboot and it won't reload any changes done on the domain definition.

There are many issues with IE, not recommended.

You can also try clearing your browser cache.

If the antlet was imported you may need to make a change to the xml definition\
First ssh to the Antsle and run:

```
EDITOR=nano virsh edit ANTLET_NAME
```

and add:

```
<input type='tablet' bus='usb'></input>
```

Before the `</devices>` tag near the bottom.

## Windows Server Essentials

Currently versions of Windows Server Essentials will not install on the Antsle.

## Ethernet ports layout and names

#### Antsle one, Antsle one Pro, Antsle one Ultra

![](/files/-M-Beu4k04SyZwGzIZtU)

| Ethernet port | Bridge name | Interface name | Speed       |
| ------------- | ----------- | -------------- | ----------- |
| Port 0        | br0         | enp0s20f0      | 10M/100M/1G |
| Port 1        | br1         | enp0s20f1      | 10M/100M/1G |
| Port 2        | br2         | enp0s20f2      | 10M/100M/1G |
| Port 3        | br3         | enp0s20f3      | 10M/100M/1G |

#### Antsle one XD, Antsle one XD Pro, Antsle one XD Ultra

![](/files/-M-BewaljmHNa9yktIy8)

| Ethernet port | Bridge name | Interface name | Speed       |
| ------------- | ----------- | -------------- | ----------- |
| Port 0        | br0         | eno1           | 10M/100M/1G |
| Port 1        | br1         | eno2           | 10M/100M/1G |
| Port 2        | br2         | eno3           | 1G/10G      |
| Port 3        | br3         | eno4           | 1G/10G      |

#### Antsle one XD

![](/files/-M-Bf-dgaTIAJERmcfRA)

| Ethernet port | Bridge name | Interface name | Speed  |
| ------------- | ----------- | -------------- | ------ |
| Port 0        | br0         | eno3           | 1G/10G |
| Port 1        | br1         | eno4           | 1G/10G |

## Hosts file

Modifying the local 'hosts' file can be useful for testing nginx domain name forwarding or if your machine is not working well with mDNS (resolving myantsle.local).The 'hosts' file on your local machine works like a local DNS. Your local machine will first check the local 'hosts' file to resolve a URL before making a DNS request. If the URL is found in the local 'hosts' file the IP address configured will be used and no DNS request will be made.

You can manually enter IP address to host name mappings in this file.

```
10.0.103.42     x.mycompany.com                     # company db server
192.168.1.74    ulab.mycompany.com     ulab         # test server
192.168.1.253   router2.mycompany.com  router2  r2  # internal router
192.168.1.4     myantsle.local         myantsle     # antsle
192.168.1.4     myantlet.com           myantlet     # antlet on antsle
```

The first column contains the IP address of the host.\
The second column contains the primary host name.\
The following columns are aliases.\
Anything following a '#' sign on a line is ignored (a comment).

On Windows, right click the icon to lauch NotePad and choose 'Run as Administrator'. Then open and edit the 'hosts' file which is located in

```
C:\Windows\System32\Drivers\etc\hosts
```

On Mac open a terminal and run nano with elevated privileges

```
sudo nano /private/etc/hosts
```

On Linux open a terminal and use nano or vi with elevated privileges

```
sudo nano /etc/hosts
```

In case you have any questions or comments, please [contact us](https://support.antsle.com/). Don’t hesitate, we’re friendly.


# Reset edgeLinux on a Pi or Antsle Nano


# Known Issues

**vncConsole clipboard does not work**

**Cloning an antlet with a virtual NIC clones the MAC address also**\
After cloning an antlet with a virtual NIC.. the virtual NIC on the new antlet will have the same MAC address of the original antlet virtual NIC.


# FAQs

## My RAM meter is showing higher usage than expected. Why?

Antsle's file system is based on ZFS which include powerful features to speed up your servers. It creates a very fast cache located in the server’s memory (RAM), called an ARC cache. The size of the ARC cache can range from **30% - 90% all of unused RAM.** It is released back to your *antlets* as soon as it's needed for other applications. \
\
ZFS prioritizes the content that is both used most frequently and common across your virtual machines (for example, if you have many *antlets* based on a single template). This speeds up as many of your *antlets* as possible. &#x20;

With the ARC cache your servers run faster but your RAM can look like it is always near MAX utilization. We are currently working on an update that will allow us to dynamically determine the amount of RAM being utilized for the ARC cache and deduct that from the total so you see your "true" RAM usage.

## IPMI Questions

#### How do I set up and access IPMI?&#x20;

Read [this article](https://docs.antsle.com/setup#4-ipmi-optional) in the docs

#### Do I run ethernet from the IPMI port to the router, or is the Ethernet cable not needed once the IPMI is configured properly?

The IPMI shares the connection as your Antsle on br0. It acquires an IP address from DHCP and no other cable is necessary. If you configure a static IP address in the BIOS, that address is applied to the dedicated IPMI port and is not shared with the br0 interface.

#### Can I access the IPMI at anytime or do I need to do this during the reboot?&#x20;

You can access the IPMI anytime even when the antsle is turned off.

#### Is this a LAN only access, or can I access from the outside using any network?

They will not be available over the internet unless you do a port-forward on your router.


# Protector Mode

Extra powers for cyber security professionals using antMan a fast and flexible test lab.

The *Protector Mode* is available to all users with antMan Grow or Scale. To enable Protector Mode, head over to settings in your left hand menu. Scroll down to preferences and toggle switch from `off` to `on`.

## Group Management for Antlets

The first new power that comes in Protector Mode is managing antlets as a group. You can select multiple antlets and perform common actions on them:&#x20;

1. Start
2. Stop
3. Restart
4. Delete
5. Take snapshot
6. Restore to last snapshot

![](/files/-M90a5Pa-_fwFGn3AChw)

The action you choose will only affect the applicable antlets. For example, if you choose `start`, it will start only the antlets that are stopped.

{% hint style="info" %}
The group rollback action takes each antlet  back by **one snapshot**, it does not take roll it back to the last group snapshot.
{% endhint %}

## What's Next for Protector Mode?

Here are some of the exciting new capabilities that are in the pipeline.&#x20;

* Create templates based off a group of antlets and their networking schema.&#x20;
* A community template hub where verified users can make their templates and group templates available to other Antsle users.


