Author SHA1 Message Date
jknapp 6700ce27b8 Merge pull request 'Document Node.js as a backend option in switching-site-backend' (#13) from docs/node-backend-option into main
Build and deploy / deploy (push) Successful in 24s
2026-09-04 16:52:46 +00:00
jknapp 9f8d05eec8 Merge pull request 'Add how-to page: Manage SFTP SSH keys' (#12) from docs/manage-sftp-ssh-keys into main
Build and deploy / deploy (push) Successful in 49s
2026-09-04 16:52:39 +00:00
shadowdaoandClaude Sonnet 5 113c795c83 Document Node.js as a backend option when switching a site's container type
The "Switching your site's backend" page only covered PHP/PHP-FPM and the
LiteSpeed/OLS add-on tier. Node18/Node20/Node22 are also selectable in the
same Container Type dropdown, but weren't mentioned. Adds a Node.js section
covering the npm-start model, the auto-raised 512 MB memory floor, the
WebSocket/real-time checkbox, and that Node containers skip the shared
PHP-FPM/LiteSpeed placement choice — plus a capture script and screenshot
of the Edit Site modal with Node22 selected.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 09:50:08 -07:00
shadowdaoandClaude Sonnet 5 f1dac00138 Add how-to page for the new SFTP SSH key management feature
Documents the customer-facing SFTP SSH Keys page shipped in WHP 2026.09.11
(sidebar: Security → SFTP SSH Keys) — adding/removing SSH public keys that
authorize SFTP login alongside the account password, useful for teams
sharing one hosting account without sharing a password. Walked the live
page as the demo customer account and captured real redacted screenshots
(empty state, filled Add Key form, populated key list). Also documents a
non-obvious live-verified detail: the visible Comment column reflects the
key's own comment (ssh-keygen -C), not the separate Note field, which only
goes to the audit log. Cross-linked from Create a site.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 09:33:08 -07:00
jknapp 0e3ae941eb Merge pull request 'Add llms.txt for LLM-friendly site discovery' (#11) from add-llms-txt into main
Build and deploy / deploy (push) Successful in 31s
2026-08-03 02:51:19 +00:00
AnHonestHost DevandClaude Opus 5 1e3e0bd546 Add llms.txt for LLM-friendly site discovery
Publishes /llms.txt per the llmstxt.org convention: an H1, a summary
blockquote, an orientation paragraph, and H2 sections mirroring the
sidebar with links to every doc page (frontmatter titles and
descriptions, absolute URLs with trailing slashes), plus an Optional
section with the homepage and sitemap.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-02 19:51:05 -07:00
jknapp a28e20f881 Merge pull request 'chore: version-control the WHMCS KB redirect rules' (#10) from chore/save-whmcs-redirects into main
Build and deploy / deploy (push) Successful in 27s
2026-08-02 00:28:09 +00:00
AnHonestHost DevandClaude Opus 5 063f992516 chore: version-control the WHMCS KB redirect rules
These 301s live in .htaccess on secure.anhonesthost.com and existed only
on that server. WHMCS rewrites .htaccess during some updates, which would
silently drop them — every retired KB URL would start 404ing with nothing
in version control to restore from.

deploy/README.md documents where it installs, how to reinstall, and the
two traps: article/category IDs collide (only the trailing .html tells
them apart, so rule order is load-bearing) and the slug is ignored.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-01 17:27:59 -07:00
jknapp e4ea0484fd Merge pull request #9: port WHMCS KB articles to the dedicated KB
Build and deploy / deploy (push) Successful in 2m48s
Adds cPanel, Domains, Email, and Support sections so the WHMCS knowledgebase can be retired.
2026-08-01 22:11:04 +00:00
AnHonestHost DevandClaude Opus 5 b00a5fd8cf docs: add Email section — client setup + Baruwa retirement notice
Replaces the three Outlook 2016 articles (WHMCS 2, 3, 9 — ~62k views)
with one client-agnostic setup guide. Outlook 2016 went end of life in
October 2025, and the two archiving articles documented a feature the
current Outlook doesn't have.

Server settings are taken from the live autoconfig endpoint rather than
the old articles: IMAP 993/SSL, POP3 995/SSL, SMTP 587/STARTTLS, username
is the full address. cPanel settings verified against cpanel01.

Adds a Baruwa retirement notice covering the move to Proxmox Mail Gateway
in November 2026. Deliberately frames this as a platform change rather
than describing our current outbound filtering posture — see the PR
discussion.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-01 14:51:09 -07:00
AnHonestHost DevandClaude Opus 5 425f364f48 docs: add cPanel section; drop the outbound-filtering page
Adds a cPanel hosting section so cPanel customers have a correct
destination — previously this KB was WHP-only, so cPanel-specific
articles had nowhere to redirect to:

- cpanel/nameservers                        (WHMCS 5, 24k views)
- cpanel/free-ssl-certificate               (WHMCS 8, 18k views)
- cpanel/fix-a-403-error                    (WHMCS 6, 20k views)
- cpanel/wordpress-email-from-your-domain   (WHMCS 7, 25k views)

Rewritten rather than copied where the originals were wrong or thin:
- WordPress SMTP told customers to use port 25 unencrypted; now 587/TLS
  with 465 as the implicit-TLS alternative.
- The 403 article now says explicitly that loosening permissions to 777
  makes suEXEC refuse harder, since that's the instinctive wrong fix.
- AutoSSL gained the actual failure modes (CAA records, .htaccess
  redirects intercepting validation, domain not added to the account).

Also removes email/outbound-spam-filtering, added in the previous commit.
Outbound filtering via Baruwa has been disabled and Baruwa is being retired,
so the page describes a feature we no longer offer. It needs rewriting
around the Proxmox migration before it can ship.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-01 14:47:44 -07:00
AnHonestHost DevandClaude Opus 5 ee6b6af107 docs: port still-relevant WHMCS KB articles to the dedicated KB
First step of retiring the WHMCS knowledgebase in favour of
kb.anhonesthost.com. Ports the four articles that are still accurate and
product-agnostic, into three new top-level sections:

- domains/  — transferring a domain, flushing a local DNS cache
- email/    — why we filter outbound mail
- support/  — remote support via RustDesk

Content was refreshed rather than copied verbatim:
- RustDesk download links were pinned to 1.3.8; now point at /releases/latest
  (current is 1.4.9). API server switched to https, which the relay serves.
- macOS DNS flush gained the killall mDNSResponder step, without which the
  documented command usually appears to do nothing.
- The nameserver list was deliberately not ported — this KB points customers
  at Dashboard → Server Information instead of hardcoding per-server values.
- Added an anti-social-engineering warning to the remote-support page.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-01 14:36:30 -07:00
jknapp f0ec3395ab Merge pull request 'docs: link Bichon to its open-source project' (#8) from docs/bichon-opensource-link into main
Build and deploy / deploy (push) Successful in 24s
Reviewed-on: #8
2026-06-29 01:31:02 +00:00
23 changed files with 1324 additions and 6 deletions
+20
View File
@@ -19,6 +19,10 @@ export default defineConfig({
'/whp/reference/': '/whp/reference/service-hostnames/', '/whp/reference/': '/whp/reference/service-hostnames/',
'/whp/add-ons/': '/whp/add-ons/overview/', '/whp/add-ons/': '/whp/add-ons/overview/',
'/whp/admin/': '/whp/admin/overview/', '/whp/admin/': '/whp/admin/overview/',
'/domains/': '/domains/transferring-a-domain-to-us/',
'/support/': '/support/remote-support/',
'/cpanel/': '/cpanel/nameservers/',
'/email/': '/email/set-up-your-email-client/',
}, },
vite: { vite: {
resolve: { resolve: {
@@ -85,6 +89,22 @@ export default defineConfig({
}, },
], ],
}, },
{
label: 'cPanel hosting',
items: [{ autogenerate: { directory: 'cpanel' } }],
},
{
label: 'Domains',
items: [{ autogenerate: { directory: 'domains' } }],
},
{
label: 'Email',
items: [{ autogenerate: { directory: 'email' } }],
},
{
label: 'Support',
items: [{ autogenerate: { directory: 'support' } }],
},
// Future products only appear once they have content. // Future products only appear once they have content.
], ],
pagefind: true, pagefind: true,
+59
View File
@@ -0,0 +1,59 @@
# Deploy artefacts
Config that lives on other servers but belongs under version control here,
because it exists to serve this KB.
## `whmcs-kb-redirects.conf`
301 redirects that send the retired WHMCS knowledgebase
(`secure.anhonesthost.com/knowledgebase/*`) to its replacement pages on
kb.anhonesthost.com. Installed 2026-08-01.
**Where it lives in production:** `/home/whmcs/public_html/.htaccess` on
`secure.anhonesthost.com`, prepended **before** the
`### BEGIN - WHMCS managed rules ###` marker. It has to come first — WHMCS's
own block ends with a catch-all that routes everything to `index.php`, so
rules placed after it never run.
The canonical copy on that server is `/root/kb-redirects.conf`, and the
pre-migration `.htaccess` is backed up at
`/root/htaccess-backup-20260801.bak`.
### Reinstalling
WHMCS rewrites `.htaccess` during some updates, which will silently drop
these rules. To restore:
```bash
cd /home/whmcs/public_html
cp -a .htaccess /root/htaccess-backup-$(date +%Y%m%d).bak # keep whatever WHMCS wrote
cat /root/kb-redirects.conf /root/htaccess-backup-$(date +%Y%m%d).bak > /tmp/htaccess.new
install -o whmcs -g whmcs -m 644 /tmp/htaccess.new .htaccess
apachectl -t
```
Then spot-check a redirect:
```bash
curl -sI https://secure.anhonesthost.com/knowledgebase/13/x.html | grep -i location
# expect: https://kb.anhonesthost.com/support/remote-support/
```
### Two things that will bite you when editing it
**Article and category IDs collide.** Both use the shape
`/knowledgebase/<id>/<slug>`, and the same number means different things —
article 5 is "What are my Name Servers?", category 5 is "WordPress Specific".
The *only* discriminator is the trailing `.html` on articles. That's why every
article rule appears before every category rule and terminates with `[L]`: by
the time the broad category patterns run, anything ending `.html` is already
gone. Reordering the file breaks this silently, and the wrong page still
returns 200.
**The slug is ignored.** WHMCS reads only the id, so any slug with the right
id resolves. The rules match `[^/]*` for the slug for the same reason.
Legacy pre-SEO URLs (`knowledgebase.php?action=displayarticle&id=N` and
`?action=displaycat&catid=N`) are mapped explicitly. `(^|&)id=` cannot match
`catid=` — the preceding character is `t`, not `&` or start-of-string — so the
two sets can't cross-fire.
+107
View File
@@ -0,0 +1,107 @@
### BEGIN - KB migration redirects to kb.anhonesthost.com ###
# Added 2026-08-01. The WHMCS knowledgebase is retired; these 301s send its
# URLs to the equivalent page on the dedicated KB.
#
# ORDER MATTERS. Article and category URLs share the shape
# /knowledgebase/<id>/<slug>
# and their IDs COLLIDE (article 5 is "What are my Name Servers?", category 5
# is "WordPress Specific"). The only discriminator is the trailing ".html" on
# articles. Article rules therefore come first and terminate with [L]; the
# category rules below can then match broadly because anything ending .html
# has already been redirected and will never reach them.
#
# The slug is ignored by WHMCS (only the id is read), so it is ignored here
# too — any slug with the right id resolves to the right destination.
#
# The trailing "?" on each target discards the inbound query string.
<IfModule mod_rewrite.c>
RewriteEngine on
RewriteBase /
# --- Articles (.html) -------------------------------------------------
RewriteRule ^knowledgebase/2/[^/]*\.html$ https://kb.anhonesthost.com/email/set-up-your-email-client/? [R=301,L]
RewriteRule ^knowledgebase/3/[^/]*\.html$ https://kb.anhonesthost.com/email/set-up-your-email-client/? [R=301,L]
RewriteRule ^knowledgebase/4/[^/]*\.html$ https://kb.anhonesthost.com/email/spam-filtering-changes/? [R=301,L]
RewriteRule ^knowledgebase/5/[^/]*\.html$ https://kb.anhonesthost.com/cpanel/nameservers/? [R=301,L]
RewriteRule ^knowledgebase/6/[^/]*\.html$ https://kb.anhonesthost.com/cpanel/fix-a-403-error/? [R=301,L]
RewriteRule ^knowledgebase/7/[^/]*\.html$ https://kb.anhonesthost.com/cpanel/wordpress-email-from-your-domain/? [R=301,L]
RewriteRule ^knowledgebase/8/[^/]*\.html$ https://kb.anhonesthost.com/cpanel/free-ssl-certificate/? [R=301,L]
RewriteRule ^knowledgebase/9/[^/]*\.html$ https://kb.anhonesthost.com/email/set-up-your-email-client/? [R=301,L]
RewriteRule ^knowledgebase/10/[^/]*\.html$ https://kb.anhonesthost.com/domains/transferring-a-domain-to-us/? [R=301,L]
RewriteRule ^knowledgebase/11/[^/]*\.html$ https://kb.anhonesthost.com/domains/transferring-a-domain-to-us/? [R=301,L]
RewriteRule ^knowledgebase/12/[^/]*\.html$ https://kb.anhonesthost.com/domains/flush-your-dns-cache/? [R=301,L]
RewriteRule ^knowledgebase/13/[^/]*\.html$ https://kb.anhonesthost.com/support/remote-support/? [R=301,L]
RewriteRule ^knowledgebase/14/[^/]*\.html$ https://kb.anhonesthost.com/whp/getting-started/welcome/? [R=301,L]
# --- Categories (no .html) --------------------------------------------
RewriteRule ^knowledgebase/2/[^/]*/?$ https://kb.anhonesthost.com/email/set-up-your-email-client/? [R=301,L]
RewriteRule ^knowledgebase/3/[^/]*/?$ https://kb.anhonesthost.com/email/spam-filtering-changes/? [R=301,L]
RewriteRule ^knowledgebase/4/[^/]*/?$ https://kb.anhonesthost.com/cpanel/nameservers/? [R=301,L]
RewriteRule ^knowledgebase/5/[^/]*/?$ https://kb.anhonesthost.com/cpanel/wordpress-email-from-your-domain/? [R=301,L]
RewriteRule ^knowledgebase/6/[^/]*/?$ https://kb.anhonesthost.com/domains/transferring-a-domain-to-us/? [R=301,L]
RewriteRule ^knowledgebase/7/[^/]*/?$ https://kb.anhonesthost.com/cpanel/fix-a-403-error/? [R=301,L]
RewriteRule ^knowledgebase/8/[^/]*/?$ https://kb.anhonesthost.com/support/remote-support/? [R=301,L]
RewriteRule ^knowledgebase/9/[^/]*/?$ https://kb.anhonesthost.com/whp/getting-started/welcome/? [R=301,L]
# --- Legacy query-string URLs -----------------------------------------
# Pre-SEO-URL links still in old tickets and emails:
# knowledgebase.php?action=displayarticle&id=<id>
# knowledgebase.php?action=displaycat&catid=<id>
# WHMCS used to 301 these to the friendly URL itself, but our rules above
# now intercept first — so map them explicitly or they all land on the KB
# home page and lose their destination.
#
# "(^|&)id=" cannot match "catid=" (the preceding char is "t", not & or
# start-of-string), so the two sets can't cross-fire.
RewriteCond %{QUERY_STRING} (^|&)id=2(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/email/set-up-your-email-client/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=3(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/email/set-up-your-email-client/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=4(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/email/spam-filtering-changes/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=5(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/cpanel/nameservers/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=6(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/cpanel/fix-a-403-error/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=7(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/cpanel/wordpress-email-from-your-domain/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=8(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/cpanel/free-ssl-certificate/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=9(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/email/set-up-your-email-client/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=10(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/domains/transferring-a-domain-to-us/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=11(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/domains/transferring-a-domain-to-us/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=12(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/domains/flush-your-dns-cache/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=13(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/support/remote-support/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)id=14(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/whp/getting-started/welcome/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)catid=2(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/email/set-up-your-email-client/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)catid=3(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/email/spam-filtering-changes/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)catid=4(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/cpanel/nameservers/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)catid=5(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/cpanel/wordpress-email-from-your-domain/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)catid=6(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/domains/transferring-a-domain-to-us/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)catid=7(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/cpanel/fix-a-403-error/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)catid=8(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/support/remote-support/? [R=301,L]
RewriteCond %{QUERY_STRING} (^|&)catid=9(&|$)
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/whp/getting-started/welcome/? [R=301,L]
# --- Tags, search, index, and anything else under /knowledgebase ------
# Catch-all last: any KB URL not matched above lands on the KB home page
# rather than a WHMCS 404.
RewriteRule ^knowledgebase\.php$ https://kb.anhonesthost.com/? [R=301,L]
RewriteRule ^knowledgebase(/.*)?$ https://kb.anhonesthost.com/? [R=301,L]
</IfModule>
### END - KB migration redirects to kb.anhonesthost.com ###
+83
View File
@@ -0,0 +1,83 @@
# AnHonestHost Knowledge Base
> Customer documentation for WHP (AnHonestHost's containerized Web Hosting Platform), plus cPanel hosting, domains, email, and remote support.
WHP is AnHonestHost's containerized hosting platform, and most of this knowledge base documents it: getting started, how-to guides, the Site Builder, local development with the same container images used in production, reference material, and optional add-ons. Separate sections cover legacy cPanel hosting, domain management, email setup, and remote support. Pages in the WHP Admin section document server-wide super-admin controls, which most customers won't have access to.
## WHP — Getting started
- [Welcome to WHP](https://kb.anhonesthost.com/whp/getting-started/welcome/): Quick orientation for new customers — what WHP is and where to start.
- [What is containerized hosting?](https://kb.anhonesthost.com/whp/getting-started/what-is-containerized-hosting/): Plain-language explainer of containerized hosting and how it compares to shared hosting and a VPS.
## WHP — How-to guides
- [Add a domain](https://kb.anhonesthost.com/whp/how-to/add-a-domain/): Point a domain at your WHP hosting — whether you registered it with us or elsewhere.
- [Manage DNS records](https://kb.anhonesthost.com/whp/how-to/manage-dns-records/): View, add, edit, and delete DNS records for your domains using the Domains & DNS records editor in WHP.
- [Create a site](https://kb.anhonesthost.com/whp/how-to/create-a-site/): Spin up a containerized site on a domain you've added to WHP.
- [Create an email account](https://kb.anhonesthost.com/whp/how-to/create-an-email-account/): Add a mailbox on one of your domains and connect your email client.
- [Backups](https://kb.anhonesthost.com/whp/how-to/backups/): Run on-demand and scheduled backups of your sites and databases, and confirm they're succeeding.
- [Switching your site's backend](https://kb.anhonesthost.com/whp/how-to/switching-site-backend/): Change the web engine (container type) running a site — standard PHP/FPM or the premium LiteSpeed/OpenLiteSpeed tier.
- [Clear your site's cache](https://kb.anhonesthost.com/whp/how-to/clear-your-cache/): Seeing an old version of a page after making a change? Here's how to clear cached content so your updates show up.
## WHP — Site Builder
- [Site Builder overview](https://kb.anhonesthost.com/whp/site-builder/overview/): Build a website visually inside WHP — drag-and-drop blocks, ready-made templates, draft / publish workflow.
- [Getting started](https://kb.anhonesthost.com/whp/site-builder/getting-started/): Open Site Builder, pick a template or start from scratch, make your first edits, and publish.
- [Blocks & pages](https://kb.anhonesthost.com/whp/site-builder/blocks-and-pages/): The Site Builder block library, plus how to add pages and edit the shared header and footer.
- [Styling your site](https://kb.anhonesthost.com/whp/site-builder/styling/): Set colours, fonts, and link styles once with Site Design Tokens; reach for Advanced when you need finer control.
- [Publishing & code injection](https://kb.anhonesthost.com/whp/site-builder/publishing/): Drafts vs. publish, device previews, and adding analytics, custom fonts, or global CSS via the custom head code panel.
## WHP — Local development
- [Develop locally with our containers](https://kb.anhonesthost.com/whp/local-dev/overview/): Run the same Apache/PHP and Node containers locally that we use to host your site in production.
- [PHP + Apache locally](https://kb.anhonesthost.com/whp/local-dev/php-apache/): Run the cloud-apache-container image on your laptop for WordPress and other PHP apps.
- [Node + Nginx locally](https://kb.anhonesthost.com/whp/local-dev/node/): Run the cloud-node-container image on your laptop for Express, custom Node apps, and PM2-managed processes.
## WHP — Reference
- [Service hostnames](https://kb.anhonesthost.com/whp/reference/service-hostnames/): Quick reference for connecting to MySQL, PostgreSQL, and Valkey from inside your container.
## WHP — Add-ons
- [Add-ons overview](https://kb.anhonesthost.com/whp/add-ons/overview/): Optional features you can layer on your hosting plan — monitoring, archival email, resource upgrades, and more.
- [Site Monitoring](https://kb.anhonesthost.com/whp/add-ons/monitoring/): Proactive alerts for site errors, brute-force attempts, and exploit signatures.
- [Archival email](https://kb.anhonesthost.com/whp/add-ons/archival-email/): Long-term, searchable archive of your mailbox content, separate from the live mailbox.
- [Resource upgrades](https://kb.anhonesthost.com/whp/add-ons/resource-upgrades/): Add CPU, RAM, or disk to your container without migrating to a different plan.
- [Email upgrades](https://kb.anhonesthost.com/whp/add-ons/email-upgrades/): Add mailboxes or bump per-mailbox storage on your plan.
- [Optimized Webserver (OpenLiteSpeed + LSCache)](https://kb.anhonesthost.com/whp/add-ons/optimized-webserver/): Run your sites on OpenLiteSpeed with server-level full-page caching for dramatically faster page delivery — ideal for WordPress and other dynamic CMS sites.
## WHP — Admin
- [Admin overview](https://kb.anhonesthost.com/whp/admin/overview/): What WHP super admin unlocks — server-wide controls for services, mail, DNS, security, monitoring, and users.
- [Server settings & services](https://kb.anhonesthost.com/whp/admin/server-settings/): Restart services, configure mail server, manage DNS / nameservers, HAProxy + system SSL certificates, and integration API keys.
- [Coraza WAF rules](https://kb.anhonesthost.com/whp/admin/coraza-waf/): Set the global WAF mode, tune individual rules, audit blocked requests, and add per-host overrides.
- [AI Monitor, Issues & Ignore Rules](https://kb.anhonesthost.com/whp/admin/site-monitoring/): The three admin pages that drive the Site Monitoring add-on — AI Monitor dashboard, Issues, and Ignore Rules.
- [Users & delegated access](https://kb.anhonesthost.com/whp/admin/user-management/): Create WHP users, set account types, change passwords, plus delegated user access and account suspensions.
- [Backups](https://kb.anhonesthost.com/whp/admin/backups/): How WHP's automatic backups work, the default-target requirement, full-server backups vs customer data backups, and managing backup targets.
- [Data-drive encryption (LUKS)](https://kb.anhonesthost.com/whp/admin/data-drive-encryption/): Optional LUKS2 encryption of the /docker data volume on new server installs. Encrypts customer data, databases, and container state at rest; adds a manual unlock step after every reboot.
## cPanel hosting
- [What are my nameservers?](https://kb.anhonesthost.com/cpanel/nameservers/): The nameservers to set at your registrar so your domain points at your cPanel hosting with us.
- [Get your free SSL certificate](https://kb.anhonesthost.com/cpanel/free-ssl-certificate/): Every cPanel account includes free Let's Encrypt certificates through AutoSSL. Here's what has to be in place and what to do if one doesn't issue.
- [Why is my site getting a 403 error?](https://kb.anhonesthost.com/cpanel/fix-a-403-error/): A 403 Forbidden on cPanel hosting is almost always file permissions or file ownership. Here's how to check and fix both.
- [Send WordPress email from your own domain](https://kb.anhonesthost.com/cpanel/wordpress-email-from-your-domain/): Stop WordPress sending as user@server and send from an address on your domain instead, using an SMTP plugin and a real mailbox.
## Domains
- [Transferring a domain to us](https://kb.anhonesthost.com/domains/transferring-a-domain-to-us/): What happens after you start a domain transfer — the confirmation emails, how long it takes, and the nameserver check to do afterwards.
- [Flush your DNS cache](https://kb.anhonesthost.com/domains/flush-your-dns-cache/): Your site moved or its DNS changed, but your computer still loads the old version? Clear the DNS cache your device has saved locally.
## Email
- [Set up your email](https://kb.anhonesthost.com/email/set-up-your-email-client/): Connect Outlook, Apple Mail, Thunderbird, or your phone to your mailbox — with the server settings for both WHP and cPanel hosting.
- [Changes to spam filtering](https://kb.anhonesthost.com/email/spam-filtering-changes/): We're moving spam filtering from Baruwa to Proxmox Mail Gateway. What's changing, when, and what you need to do.
## Support
- [Remote support with RustDesk](https://kb.anhonesthost.com/support/remote-support/): Install and configure the RustDesk client so our support team can connect to your device and help directly.
## Optional
- [AnHonestHost KB homepage](https://kb.anhonesthost.com/): Start page for the knowledge base.
- [Sitemap](https://kb.anhonesthost.com/sitemap-index.xml): XML sitemap index for all pages on this site.
Binary file not shown.

After

Width:  |  Height:  |  Size: 307 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 288 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 332 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 358 KiB

@@ -0,0 +1,67 @@
---
title: Why is my site getting a 403 error?
description: A 403 Forbidden on cPanel hosting is almost always file permissions or file ownership. Here's how to check and fix both.
sidebar:
order: 3
---
import { Steps, Aside } from '@astrojs/starlight/components';
import Support from '~/content/partials/support-link.mdx';
A **403 Forbidden** means the web server found your file but refused to serve it. On our cPanel servers that's nearly always one of two things: permissions that are wrong, or files owned by the wrong user.
We run **suEXEC**, which makes your site's code run as *your* account rather than a shared web-server user. That's a security benefit — one account can't read another's files — but it does mean the server is strict about ownership and permissions.
## The correct values
| Item | Permissions |
| --- | --- |
| Folders | `755` |
| Files | `644` |
Anything **more permissive** (a folder at `777`, a file at `666`) is refused by suEXEC. This surprises people, because loosening permissions is the instinctive fix for a permissions error — here it makes things worse, and it's a genuine security risk.
## Fixing it in cPanel
The File Manager handles this without needing a terminal:
<Steps>
1. Sign in to cPanel and open **File Manager**.
2. Navigate to the site's folder. For your primary domain that's normally `public_html`.
3. Select the folder or file, then click **Permissions** in the toolbar.
4. Set folders to `755` and files to `644`. To apply to everything beneath a folder at once, tick the **recurse into subdirectories** option and choose whether it applies to files or folders — you'll need one pass for each, since they take different values.
</Steps>
## When ownership is the problem
Permissions are only half of it. Files also have to be owned by your account.
- **Uploaded over FTP or SFTP?** Ownership is almost certainly fine — the files were created as you.
- **Pulled the site down over SSH** with `git clone`, `wget`, `curl`, or unpacked an archive as another user? Ownership may be wrong, and no amount of `chmod` will fix that. The files need `chown` back to your account.
If you suspect ownership, [open a ticket](https://secure.anhonesthost.com/submitticket.php) — it's a one-command fix from our side and safer than guessing.
<Aside type="caution">
Be careful with recursive commands over SSH. A `chmod -R 777` or a `chown` aimed at the wrong path can break your whole account, and in the case of `777` will leave the site returning 403 anyway. If you aren't confident, ask us.
</Aside>
## If permissions and ownership are both correct
Other causes of a 403:
- **No index file.** A folder with no `index.html` or `index.php`, on a server with directory listing disabled, returns 403.
- **An `.htaccess` rule** denying access — either one you added, or one a security plugin wrote.
- **A security plugin or firewall** blocking your IP after failed logins. Try from a different network or your phone on mobile data; if that works, it's an IP block.
## Related
- [Get your free SSL certificate](/cpanel/free-ssl-certificate/)
## Still stuck?
<Support />
@@ -0,0 +1,58 @@
---
title: Get your free SSL certificate
description: Every cPanel account includes free Let's Encrypt certificates through AutoSSL. Here's what has to be in place and what to do if one doesn't issue.
sidebar:
order: 2
---
import { Steps, Aside } from '@astrojs/starlight/components';
import Support from '~/content/partials/support-link.mdx';
Your cPanel hosting includes free SSL certificates from **Let's Encrypt**, issued automatically by cPanel's AutoSSL service. There's nothing to buy and nothing to install by hand.
## What has to be true first
AutoSSL can only issue a certificate once both of these are in place:
<Steps>
1. **The domain is added to your cPanel account** — as the primary domain, an addon domain, or a subdomain.
2. **DNS points at our server.** Let's Encrypt validates a certificate by fetching a file from wherever the domain currently resolves. If it still points at your old host, validation fails and no certificate is issued.
</Steps>
Check where a domain currently resolves at [whatsmydns.net](https://www.whatsmydns.net/).
## When it issues
AutoSSL runs on a schedule — **once every 24 hours**. So after adding a domain and pointing DNS at us, a certificate normally appears within a day without you doing anything.
Renewals are automatic too. Let's Encrypt certificates are valid for 90 days and AutoSSL renews them well before expiry, so a working site stays working.
<Aside type="tip">
Need it sooner than the next daily run? Confirm DNS is pointing at us, then [open a ticket](https://secure.anhonesthost.com/submitticket.php) — we can trigger AutoSSL by hand and usually have the certificate in place shortly after.
</Aside>
## If a certificate doesn't appear
Work through these in order — the first two cover most cases:
- **DNS isn't pointing here yet.** The most common cause by far. Verify at whatsmydns.net that the domain resolves to our server's IP.
- **It hasn't been 24 hours.** Give the scheduled run a chance before assuming something is broken.
- **The domain isn't actually in your account.** Check cPanel → **Domains**. A domain you own but haven't added is invisible to AutoSSL.
- **A redirect is intercepting validation.** Forced redirects — especially domain-wide ones in `.htaccess` — can stop Let's Encrypt from reaching the validation file.
- **CAA records are blocking issuance.** If your DNS has a CAA record naming a different certificate authority, Let's Encrypt is refused. It must permit `letsencrypt.org`.
## Making your site actually use it
An issued certificate doesn't automatically mean visitors get HTTPS. Once it's in place, make sure your site loads over `https://` and redirects visitors from `http://`. In WordPress, that's usually setting both the **WordPress Address** and **Site Address** to the `https://` version under **Settings → General**.
## Related
- [What are my nameservers?](/cpanel/nameservers/)
- [Why is my site getting a 403 error?](/cpanel/fix-a-403-error/)
## Still stuck?
<Support />
+49
View File
@@ -0,0 +1,49 @@
---
title: What are my nameservers?
description: The nameservers to set at your registrar so your domain points at your cPanel hosting with us.
sidebar:
order: 1
---
import { Aside } from '@astrojs/starlight/components';
import Support from '~/content/partials/support-link.mdx';
Nameservers tell the internet which company is in charge of your domain's DNS. To use your hosting with us, set these at whichever registrar your domain is registered with.
## Shared and reseller hosting (cPanel01)
```text
ns1.cpanel01.cloud-hosting.io
ns2.cpanel01.cloud-hosting.io
```
Both shared and reseller accounts on cPanel01 use the same pair.
<Aside type="note">
**On WHP instead?** WHP servers each have their own nameservers, so there's no single pair to publish here. Yours are shown in WHP on the **Dashboard** page under **Server Information** — see [Add a domain](/whp/how-to/add-a-domain/).
</Aside>
## Setting them
Nameservers are changed at your **registrar** (whoever you bought the domain from), not in cPanel. Look for a section called *Nameservers*, *DNS*, or *Domain settings*, choose the "custom nameservers" option, and enter both values above.
If your domain is registered with us, tell us the change you need and we'll make it for you.
## How long does it take?
Nameserver changes propagate across the internet gradually — usually within a few hours, occasionally up to 48. You can watch progress at [whatsmydns.net](https://www.whatsmydns.net/).
During that window some visitors reach the new server while others still reach the old one. That's expected, and it's why we recommend leaving your old hosting active until propagation finishes.
<Aside type="caution">
Changing nameservers moves **all** of your DNS to us — website, email, and anything else. If your email is hosted somewhere other than your website, tell us before you switch so we can recreate those mail records here first. Otherwise mail delivery stops when the change takes effect.
</Aside>
## Related
- [Flush your DNS cache](/domains/flush-your-dns-cache/) — if you still see the old site after propagation.
- [Transferring a domain to us](/domains/transferring-a-domain-to-us/)
## Still stuck?
<Support />
@@ -0,0 +1,74 @@
---
title: Send WordPress email from your own domain
description: Stop WordPress sending as user@server and send from an address on your domain instead, using an SMTP plugin and a real mailbox.
sidebar:
order: 4
---
import { Steps, Aside } from '@astrojs/starlight/components';
import Support from '~/content/partials/support-link.mdx';
If your WordPress site sends mail — contact forms, order confirmations, password resets — you may notice it arrives from something like `user@host.server-host.tld` rather than your own domain.
That's deliberate. PHP's built-in mail function is configured to send as the account that owns the site, which makes it much harder for a compromised script to forge mail as someone else. The side effect is unbranded — and often poorly delivered — email.
The fix is to send through a real mailbox on your domain using SMTP.
<Aside type="tip">
This also improves **deliverability**. Mail sent through an authenticated mailbox on your domain passes SPF and DKIM checks; mail sent by PHP as `user@server` frequently doesn't, and lands in spam.
</Aside>
## Step 1 — Create a mailbox to send from
<Steps>
1. In cPanel, open **Email Accounts** under the **Email** section.
2. Create an account for the site to send as — `noreply@yourdomain.com` is the usual choice.
3. Use the **password generator** and copy the password somewhere temporarily — you'll need it in a moment, and you won't be shown it again.
4. Set a **mailbox quota**. People reply to `noreply` addresses regardless of the name, and without a quota those replies accumulate against your hosting space indefinitely.
</Steps>
## Step 2 — Install an SMTP plugin
WordPress needs a plugin to route mail through SMTP instead of PHP. Any of the well-maintained ones work:
- [WP Mail SMTP](https://wordpress.org/plugins/wp-mail-smtp/)
- [Easy WP SMTP](https://wordpress.org/plugins/easy-wp-smtp/)
- [Post SMTP](https://wordpress.org/plugins/post-smtp/)
## Step 3 — Configure it
In the plugin's settings, choose the **Other SMTP** / custom option and enter:
| Setting | Value |
| --- | --- |
| **SMTP host** | Your server's hostname (for example `cpanel01.cloud-hosting.io`) |
| **Encryption** | TLS |
| **Port** | `587` |
| **Authentication** | On |
| **Username** | The **full** email address — `noreply@yourdomain.com`, not `noreply` |
| **Password** | The password you generated |
| **From address** | The same mailbox address |
<Aside type="caution">
Use port **587 with TLS**, or **465 with SSL** if your plugin prefers implicit TLS. Don't use port **25** without encryption — it sends your mailbox password across the network in the clear, and many networks block it outright.
</Aside>
Two details that account for most failures: the username has to be the **whole** address, and the **From** address must match the mailbox you authenticated as. A mismatch gets rejected or treated as spoofing.
## Step 4 — Send a test
Every one of these plugins has a test-email feature. Use it before assuming it works, and send to an address at a different provider (Gmail, Outlook) rather than another mailbox on your own domain — that exercises the path real recipients take.
## Related
- [What are my nameservers?](/cpanel/nameservers/)
- **On WHP?** See [Create an email account](/whp/how-to/create-an-email-account/) — the mailbox part differs, the plugin setup is the same.
## Still stuck?
<Support />
@@ -0,0 +1,80 @@
---
title: Flush your DNS cache
description: Your site moved or its DNS changed, but your computer still loads the old version? Clear the DNS cache your device has saved locally.
sidebar:
order: 2
---
import { Steps, Aside } from '@astrojs/starlight/components';
import Support from '~/content/partials/support-link.mdx';
When you visit a site, your computer saves ("caches") the answer to *which server is this domain on?* so it doesn't have to ask again every time. That's normally invisible and helpful — but right after a domain moves to a new server or its DNS records change, your device can keep using the old answer and show you the old site.
Devices are supposed to re-check after a short while, but some record lifetimes stretch to hours or even days. Clearing the cache by hand skips the wait.
## First, confirm it's actually your computer
Before changing anything locally, check whether the new DNS has actually gone out to the world. Look your domain up at [whatsmydns.net](https://www.whatsmydns.net/) — it queries servers in many countries at once.
- **Most locations show the new value** — the change has propagated, and a stale local cache is the likely culprit. Continue below.
- **Most locations still show the old value** — the change hasn't propagated yet. Flushing your own cache won't help; give it time.
<Aside type="tip">
A quick sanity check: open the site in a **private / incognito window**, or on your phone using mobile data instead of Wi-Fi. If it looks correct there, the problem is local to your computer.
</Aside>
## Windows
<Steps>
1. Press the **Windows key**, type `Command Prompt`, and open it.
2. Type this and press **Enter**:
```text
ipconfig /flushdns
```
3. You should see *"Successfully flushed the DNS Resolver Cache."*
</Steps>
## macOS
<Steps>
1. Open **Terminal** (in **Applications → Utilities**, or press `Cmd` + `Space` and search for "Terminal").
2. Type this and press **Enter**:
```bash
sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder
```
3. Enter your administrator password when prompted, then press **Enter**. Nothing is printed when it works — no news is good news.
</Steps>
<Aside type="note">
Both commands matter on macOS: the first clears the lookup cache, the second restarts the service that answers DNS queries. Running only the first often appears to do nothing.
</Aside>
## Still seeing the old site?
Your computer isn't the only thing that caches DNS. Work outward:
- **Your browser** keeps its own cache. Do a hard refresh (`Ctrl` + `Shift` + `R`, or `Cmd` + `Shift` + `R` on a Mac) or try a private window.
- **Your router** caches DNS too. Restarting it clears that.
- **Your internet provider's resolvers** cache as well, and you can't clear those — they expire on their own schedule. If everything else is clean, this is usually what's left. It typically resolves within a few hours.
If it's still wrong well after the record's lifetime should have expired, it may not be a caching problem at all — get in touch and we'll look at the actual DNS records.
## Related
- [Manage DNS records](/whp/how-to/manage-dns-records/)
- [Add a domain](/whp/how-to/add-a-domain/)
- [Clear your site's cache](/whp/how-to/clear-your-cache/) — for when *content* is stale rather than DNS.
## Still stuck?
<Support />
@@ -0,0 +1,60 @@
---
title: Transferring a domain to us
description: What happens after you start a domain transfer — the confirmation emails, how long it takes, and the nameserver check to do afterwards.
sidebar:
order: 1
---
import { Steps, Aside } from '@astrojs/starlight/components';
import Support from '~/content/partials/support-link.mdx';
You've started a domain transfer to us — here's what happens next, and the one thing worth checking once it lands.
## Before the transfer will go through
Your current registrar has to let the domain go first. At the registrar you're leaving, make sure you've:
- **Unlocked the domain.** Registrars set a transfer lock by default to prevent unauthorised moves.
- **Turned off WHOIS / domain privacy.** Privacy services can hide the administrative address the confirmation email needs to reach.
- **Got the EPP code** (sometimes called the auth code or transfer key). Your registrar provides this, usually by email or in the domain's settings.
<Aside type="caution">
Domains can't be transferred within **60 days** of being registered, or within 60 days of a previous transfer. That's an ICANN rule, not a registrar policy — nobody can waive it.
</Aside>
## Confirming the transfer
<Steps>
1. **Watch for confirmation emails.** You'll get one or both of:
- a message from **your previous registrar**, confirming the domain is moving away from them;
- a message from **NameCheap**, who we use to resell domains, confirming it's moving to our account.
They go to the domain's registered contact address — which may not be the address you use with us. If nothing arrives, check that address and its spam folder.
2. **Click the confirmation link** in the email. Nothing moves until you do; an unconfirmed transfer just sits until it expires.
3. **Wait for it to complete.** Once confirmed, the transfer usually finishes in **1 to 12 hours**, depending on how quickly the losing registrar releases it. Your account page updates to reflect the domain once it's done.
</Steps>
## After it completes: check your nameservers
This is the step people miss. Some registrars — **GoDaddy** most notably — reset a domain's nameservers when they release it. If that happens, the domain transfers to us successfully but still points at the old host, so your site or email can appear to break for no obvious reason.
Once the transfer shows as complete, confirm the domain's nameservers match the ones for your hosting. If you're on WHP, your server's nameservers are listed on the **Dashboard** page under **Server Information** — see [Add a domain](/whp/how-to/add-a-domain/) for where to set them.
<Aside type="tip">
A transfer moves *registration*, not *hosting*. Your site's files and email stay wherever they already live. If you're also moving hosting to us, that's a separate step — ask us and we'll help sequence the two so nothing goes dark.
</Aside>
## Related
- [Add a domain](/whp/how-to/add-a-domain/)
- [Manage DNS records](/whp/how-to/manage-dns-records/)
- [Flush your DNS cache](/domains/flush-your-dns-cache/)
## Still stuck?
<Support />
@@ -0,0 +1,91 @@
---
title: Set up your email
description: Connect Outlook, Apple Mail, Thunderbird, or your phone to your mailbox — with the server settings for both WHP and cPanel hosting.
sidebar:
order: 1
---
import { Steps, Aside } from '@astrojs/starlight/components';
import Support from '~/content/partials/support-link.mdx';
You can read your mail in any standard email app. Most will configure themselves once you enter your address and password — and if yours doesn't, the settings are below.
<Aside type="tip">
**Just want to check your mail?** You don't need to set anything up. Webmail works in any browser with no configuration — ask us for your webmail address if you don't have it.
</Aside>
## Let your app configure itself
Try this first. It works in most modern clients, including Outlook, Apple Mail, and the mail apps on iOS and Android.
<Steps>
1. Add a new account in your email app.
2. Enter your **full email address** (`you@yourdomain.com`) and its password.
3. Choose **Next** or **Sign in** and let the app look up the settings.
</Steps>
If the app finds everything, you're done. If it asks for server details, use the table below.
## Server settings
Use your **full email address** as the username — not just the part before the `@`. That single detail accounts for most setup failures.
### WHP hosting
| Setting | Value |
| --- | --- |
| **Incoming (IMAP)** | `mail01.cloud-hosting.io`, port **993**, SSL/TLS |
| **Incoming (POP3)** | `mail01.cloud-hosting.io`, port **995**, SSL/TLS |
| **Outgoing (SMTP)** | `mail01.cloud-hosting.io`, port **587**, STARTTLS |
| **Username** | Your full email address |
| **Authentication** | Required, for outgoing as well as incoming |
<Aside type="note">
`mail01` is an example. Your server's mail hostname is shown in WHP on the **Dashboard** page under **Server Information**, and the **Email** page has a **Setup Instructions** button with the exact values for your account.
</Aside>
### cPanel hosting
| Setting | Value |
| --- | --- |
| **Incoming (IMAP)** | `cpanel01.cloud-hosting.io`, port **993**, SSL/TLS |
| **Incoming (POP3)** | `cpanel01.cloud-hosting.io`, port **995**, SSL/TLS |
| **Outgoing (SMTP)** | `cpanel01.cloud-hosting.io`, port **465**, SSL/TLS |
| **Username** | Your full email address |
| **Authentication** | Required, for outgoing as well as incoming |
Port **587 with STARTTLS** also works for outgoing if your app prefers it.
## IMAP or POP3?
Choose **IMAP** unless you have a specific reason not to.
- **IMAP** keeps mail on the server and mirrors it to every device. Read a message on your phone and it shows as read on your laptop. This is what you want when you use more than one device.
- **POP3** downloads mail to one device and, by default, removes it from the server. Mail then exists only on that machine — if it dies, so does your mail.
<Aside type="caution">
Take care switching an existing account from POP3 to IMAP. If POP3 has been deleting messages from the server as it downloaded them, those messages exist only in your local app — and they won't reappear when you switch. Back up first, or ask us to check before you change anything.
</Aside>
## Common problems
**Incoming works, outgoing fails.** Almost always because outgoing authentication is off. Many apps leave it unticked by default. Find the option — usually *My outgoing server requires authentication* — and enable it with the same username and password.
**Password rejected.** Use the full email address as the username. If it still fails, reset the mailbox password and try again — and watch for autocorrect capitalising the first letter on phones.
**Certificate warnings.** Connect using the server hostname in the table above, not your own domain. A certificate is issued for the server's name, so connecting as `mail.yourdomain.com` can trigger a mismatch warning even though everything works.
**Old mail missing after setup.** If the account was previously POP3, see the caution above before assuming anything is lost.
## Related
- [Create an email account](/whp/how-to/create-an-email-account/) — WHP
- [Send WordPress email from your own domain](/cpanel/wordpress-email-from-your-domain/)
## Still stuck?
<Support />
@@ -0,0 +1,53 @@
---
title: Changes to spam filtering
description: We're moving spam filtering from Baruwa to Proxmox Mail Gateway. What's changing, when, and what you need to do.
sidebar:
order: 2
badge: Notice
---
import { Aside } from '@astrojs/starlight/components';
import Support from '~/content/partials/support-link.mdx';
We're changing the platform that filters spam for our mail customers.
**Baruwa**, which we've used for years, reaches end of life in **November 2026** — its developers are stopping support and security updates. Rather than run mail filtering on software that no longer receives fixes, we're moving to **Proxmox Mail Gateway**.
## What this means for you
**For most customers, nothing changes and there's nothing to do.** Your address stays the same, your mailbox and its contents are untouched, and your email app keeps working without reconfiguration. Filtering continues throughout — we're changing what does it, not whether it happens.
If you're one of the customers who uses the Baruwa web interface directly — to review quarantined mail, or to manage your own allow and block lists — that's the part that changes, since Proxmox Mail Gateway has its own interface. **We'll contact you individually** to move you across and show you the equivalent screens. You don't need to do anything in the meantime.
<Aside type="tip">
Worth doing now, whoever you are: if you've built up allow or block lists in Baruwa that matter to you, take a copy. We'll migrate what we can, but having your own record makes it easy to confirm nothing was missed.
</Aside>
## Timeline
| When | What happens |
| --- | --- |
| Now | Baruwa continues to run. We begin moving customers across. |
| Before November 2026 | Affected customers are contacted individually and migrated. |
| November 2026 | Baruwa reaches end of life and is retired. |
We'll update this page as the migration progresses.
## Questions we expect
**Will I lose quarantined mail?** Anything currently held in quarantine stays available until your migration. If something in there matters, release it to your inbox rather than leaving it quarantined.
**Do I need to change my email settings?** No. Server names, ports, and passwords are unaffected — see [Set up your email](/email/set-up-your-email-client/) if you're configuring a new device.
**Is my mail less protected during the change?** No. Filtering runs continuously through the migration; there's no window where mail is unfiltered.
**I'd rather opt out of filtering entirely.** Talk to us and we'll go through the options and the trade-offs.
## Related
- [Set up your email](/email/set-up-your-email-client/)
- [Create an email account](/whp/how-to/create-an-email-account/)
## Questions about your account?
<Support />
@@ -0,0 +1,68 @@
---
title: Remote support with RustDesk
description: Install and configure the RustDesk client so our support team can connect to your device and help directly.
sidebar:
order: 1
---
import { Steps, Aside } from '@astrojs/starlight/components';
import Support from '~/content/partials/support-link.mdx';
Sometimes the fastest way to sort something out is for us to see your screen — configuring an email client, reproducing an error we can't recreate from our side, or walking through a setting together.
We use **RustDesk**, an open-source remote-desktop tool, running on our own relay server rather than a third-party service. Nothing is installed permanently and nothing runs in the background: you start it when you want help and close it when you're done.
<Aside type="caution">
We will never ask you to install remote-support software out of the blue. If someone contacts you claiming to be from AnHonestHost and asks for remote access to your computer — especially about a payment, a refund, or a "problem with your account" — stop and [open a ticket](https://secure.anhonesthost.com/submitticket.php) to check it's really us. Only ever run this at the end of a conversation *you* started with us.
</Aside>
## Install the client
Download RustDesk for your device from the official releases:
- **Windows, macOS, and Android** — [github.com/rustdesk/rustdesk/releases/latest](https://github.com/rustdesk/rustdesk/releases/latest). Pick the `.msi` for Windows, the `.dmg` for macOS, or the signed `.apk` for Android.
- **iOS / iPadOS** — [RustDesk on the App Store](https://apps.apple.com/us/app/rustdesk-remote-desktop/id1581225015).
## Point it at our server
We run our own ID and relay server, which is faster and keeps your session off shared public infrastructure. You only need to do this once.
<Steps>
1. Open **Settings**. On desktop that's the **three dots** next to your ID; on mobile it's the settings icon.
2. On desktop, choose **Network**. (On mobile, skip straight to the next step.)
3. Choose **ID/Relay server** and enter:
| Field | Value |
| --- | --- |
| **ID server** | `rustdesk.cloud-hosting.io` |
| **Relay server** | `rustdesk.cloud-hosting.io` |
| **API server** | `https://rustdesk.cloud-hosting.io` |
| **Key** | `UmpkeFe76AKt8vw8Pj0YCSbxIcYLsqqfPGYzLRl+PgA=` |
4. **Save**, then go back to the **Home** screen.
</Steps>
## Starting a session
The support operator needs two things from the Home screen:
- **Your ID** — a nine-digit number that stays the same for your device.
- **Your one-time password** — shown beneath the ID, and regenerated each time.
Give both to your support operator over the phone, or in your ticket.
<Aside type="tip">
If you send them in a ticket rather than over the phone, **leave your computer on with RustDesk running** — the one-time password only works while the client is open, and we can't connect to a sleeping machine.
</Aside>
## Ending a session
Close the RustDesk window when you're finished. With it closed, no connection is possible — the one-time password from your session is already spent, and a new one is generated next time you open it. You can uninstall the client entirely if you'd rather.
## Still stuck?
<Support />
@@ -56,6 +56,8 @@ When you connect via SFTP, your account home (`/docker/users/<your-user>/`) show
Upload your files to the right place and the site picks them up immediately. Upload your files to the right place and the site picks them up immediately.
Logging in with your account password works out of the box. If you'd rather use an SSH key instead — or need to let a teammate connect without sharing your password — see [Manage SFTP SSH keys](/whp/how-to/manage-sftp-ssh-keys/).
## Connect to databases and caches ## Connect to databases and caches
<Hostnames /> <Hostnames />
@@ -82,6 +84,7 @@ Open your domain in a browser. You should see your site, or the default "no cont
- [Add a domain](/whp/how-to/add-a-domain/) - [Add a domain](/whp/how-to/add-a-domain/)
- [Service hostnames](/whp/reference/service-hostnames/) - [Service hostnames](/whp/reference/service-hostnames/)
- [Manage SFTP SSH keys](/whp/how-to/manage-sftp-ssh-keys/)
## Still stuck? ## Still stuck?
@@ -0,0 +1,111 @@
---
title: Manage SFTP SSH keys
description: Add SSH public keys to your account so you — and anyone else on your team — can log in over SFTP without sharing a password.
sidebar:
order: 8
---
import { Steps, Aside } from '@astrojs/starlight/components';
import SignIn from '~/content/partials/signing-in.mdx';
import Support from '~/content/partials/support-link.mdx';
SFTP normally logs in with your account password. SSH keys give you (or a teammate) a second way in — no password typing, and no need to share your password with anyone. Add one key per person, and remove any key on its own without touching anyone else's.
## Before you start
- An SSH key pair. If you don't have one yet, the steps below cover generating one — it takes about a minute.
- About 5 minutes.
<Aside type="tip">
The main reason to use this: if more than one person needs SFTP access to the same hosting account, everyone can add their own key instead of all sharing one password. Removing someone's access later is just removing their key.
</Aside>
## Sign in to WHP
<SignIn />
## Steps
<Steps>
1. In the sidebar, click **Security → SFTP SSH Keys**.
![WHP SFTP SSH Keys page with no keys added yet](~/assets/screenshots/whp/whp-sftp-keys-empty.png)
2. If you don't already have an SSH key, generate one on your own machine:
```bash
ssh-keygen -t ed25519 -C "your-email-or-a-note-to-yourself"
```
Accept the default file location (`~/.ssh/id_ed25519`) and set a passphrase if you'd like one. If you already have a key, you'll find it at `~/.ssh/id_ed25519.pub` (or `~/.ssh/id_rsa.pub` for an older RSA key).
<Aside type="caution">
Only ever paste the **`.pub`** file's contents — that's the *public* key, safe to share. Never paste the file without `.pub` (or one that starts with `-----BEGIN OPENSSH PRIVATE KEY-----`) anywhere. The panel will refuse anything that looks like a private key, but it's worth knowing the difference.
</Aside>
3. Copy the full contents of the `.pub` file — one line, starting with the key type (`ssh-ed25519`, `ssh-rsa`, etc.).
4. Paste it into the **Public key** box in the **Add Key** card. The **Note** field is optional — whatever you type there is recorded in the account's audit log, but it isn't what shows in the key list below (see the tip after this list for how to label a key so you can actually tell it apart later).
![Add Key form filled in with a public key and a note](~/assets/screenshots/whp/whp-sftp-keys-add-form.png)
5. Click **Add Key**. It appears in the **Authorized Keys** table immediately and works right away — no separate activation step.
![Authorized Keys table showing one added key](~/assets/screenshots/whp/whp-sftp-keys-list.png)
</Steps>
<Aside type="tip">
The **Comment** column in the table comes from the key itself, not from the Note field — it's whatever followed the key type when the key was generated (the `-C "..."` value above, e.g. `your-email-or-a-note-to-yourself`). If several people are adding keys to the same account, agree on a naming convention for `-C` (e.g. `-C "dana-laptop"`) so everyone can tell the keys apart at a glance. A key generated without `-C` shows as **(no comment)**.
</Aside>
## Connect over SFTP with your key
Point your SFTP client at the private key file (the one *without* `.pub`):
```bash
sftp -i ~/.ssh/id_ed25519 <username>@<your-server>.cloud-hosting.io
```
Replace `<username>` with your WHP username and `<your-server>` with your server's hostname (find it on the **Dashboard** page under Server Information). Graphical clients — FileZilla, Cyberduck, WinSCP — all support key-based login too: point the client's "private key" field at `~/.ssh/id_ed25519` instead of filling in a password.
Your account password still works for SFTP exactly as before. Adding a key doesn't disable it.
## Supported key types
- **`ssh-ed25519`** — recommended. Generate with `ssh-keygen -t ed25519`.
- `ecdsa-sha2-nistp256`, `ecdsa-sha2-nistp384`, `ecdsa-sha2-nistp521`
- `ssh-rsa`
- `sk-ssh-ed25519@openssh.com`, `sk-ecdsa-sha2-nistp256@openssh.com` — for a FIDO/hardware security key (e.g. a YubiKey)
If a key is malformed, an unsupported type, or technically well-formed but not something the SFTP server can actually use, the panel rejects it with an explanation instead of adding it — so a key that's been accepted is a key that works.
## Remove a key
Find the key in the **Authorized Keys** table and click **Remove**. Confirm in the dialog — the fingerprint and comment are shown so you can be sure you're removing the right one. This takes effect immediately: anyone using that key loses SFTP access right away, but password login is unaffected.
There's no restriction on removing your last key. If you remove every key on the account, SFTP still works with your account password — keys are additive, not a replacement for it.
Common reasons to remove a key: someone leaves the team, or a laptop with a key on it is lost or retired.
<Aside type="note">
Keys can also be added or removed directly in `~/.ssh/authorized_keys` over SFTP itself, and valid changes made that way show up here too. But changes made outside this page aren't recorded in the audit log, and anything in that file the panel doesn't recognize (an unsupported key type, a malformed line, a restricted `command=`/`from=` entry) is cleaned up automatically the next time this page loads. Comments and blank lines are always left alone.
</Aside>
## If you manage this account on someone else's behalf
Root and support staff reach the same page for any customer account — either from the same **Security → SFTP SSH Keys** sidebar entry (which then shows an account selector), or via a **SFTP Keys** button on that customer's row on the **User Management** page. Everything above works the same way once an account is selected; the only difference is picking whose keys you're managing first.
## Troubleshooting
**"This key is already present."** That exact key (by fingerprint) is already on the account — check the table before adding it again.
**Key added, but SFTP still asks for a password.** Double-check you're pointing your client at the matching **private** key file (no `.pub`), and that the username in your connection matches the account the key was added to.
**A key I added over raw SFTP disappeared.** If it didn't meet this page's rules (unsupported type, malformed, or carried a restricted option), it was removed the next time the page loaded — add it here instead so it's validated and recorded properly.
## Related
- [Create a site](/whp/how-to/create-a-site/) — including where your files go over SFTP.
## Still stuck?
<Support />
@@ -1,6 +1,6 @@
--- ---
title: Switching your site's backend title: Switching your site's backend
description: Change the web engine (container type) running a site — standard PHP/FPM or the premium LiteSpeed/OpenLiteSpeed tier. description: Change the container type running a site — standard PHP/FPM, the premium LiteSpeed/OpenLiteSpeed tier, or Node.js.
sidebar: sidebar:
order: 6 order: 6
--- ---
@@ -9,7 +9,7 @@ import { Steps, Aside } from '@astrojs/starlight/components';
import SignIn from '~/content/partials/signing-in.mdx'; import SignIn from '~/content/partials/signing-in.mdx';
import Support from '~/content/partials/support-link.mdx'; import Support from '~/content/partials/support-link.mdx';
Every WHP site runs inside a container. The **container type** determines the web engine that serves your site's files and runs your PHP code. Most sites use a standard PHP or PHP-FPM container, which handles the vast majority of WordPress and PHP workloads well. If you've enabled the **Optimized Webserver** add-on, you also have access to LiteSpeed/OpenLiteSpeed (OLS) container types — a premium engine known for its built-in full-page cache (LSCache) and lower memory usage under traffic. Every WHP site runs inside a container. The **container type** determines the engine that serves your site: PHP, LiteSpeed, or Node.js. Most sites use a standard PHP or PHP-FPM container, which handles the vast majority of WordPress and PHP workloads well. If you've enabled the **Optimized Webserver** add-on, you also have access to LiteSpeed/OpenLiteSpeed (OLS) container types — a premium engine known for its built-in full-page cache (LSCache) and lower memory usage under traffic. If you're deploying your own application code instead of PHP, Node.js container types are also available — see [Node.js](#nodejs) below.
Switching backends is a one-step change in the Sites editor, but it does briefly restart your container, so plan for a few seconds of downtime. Switching backends is a one-step change in the Sites editor, but it does briefly restart your container, so plan for a few seconds of downtime.
@@ -36,6 +36,7 @@ Switching backends is a one-step change in the Sites editor, but it does briefly
4. Select the backend you want: 4. Select the backend you want:
- **PHP** or **PHP-FPM** options — standard shared webserver tier, suitable for most WordPress and PHP sites. - **PHP** or **PHP-FPM** options — standard shared webserver tier, suitable for most WordPress and PHP sites.
- **LiteSpeed PHP** options (e.g. *LiteSpeed PHP 8.x*) — premium OLS tier. These only appear if the Optimized Webserver add-on is active on your account. - **LiteSpeed PHP** options (e.g. *LiteSpeed PHP 8.x*) — premium OLS tier. These only appear if the Optimized Webserver add-on is active on your account.
- **Node18**, **Node20**, or **Node22** — for sites running your own Node.js application code instead of PHP. See [Node.js](#nodejs) below before switching to one of these.
5. Click **Save**. WHP recreates the container with the new engine. Expect a brief moment of downtime (typically a few seconds) while the container restarts. 5. Click **Save**. WHP recreates the container with the new engine. Expect a brief moment of downtime (typically a few seconds) while the container restarts.
@@ -55,6 +56,24 @@ To enable it:
2. Enable it from your [client portal](https://secure.anhonesthost.com/clientarea.php). 2. Enable it from your [client portal](https://secure.anhonesthost.com/clientarea.php).
3. Once active, the LiteSpeed PHP options will appear in the Container Type dropdown when editing any site. 3. Once active, the LiteSpeed PHP options will appear in the Container Type dropdown when editing any site.
## Node.js
Node.js container types (**Node18**, **Node20**, **Node22**) run your own application code instead of PHP — the container starts your app the same way you would locally with `npm start`. They're for React/Next.js servers, Express APIs, and other Node apps, not for WordPress or PHP sites.
<Aside type="caution">
Switching an **existing PHP or WordPress site** to a Node container type won't make your PHP files run — Node containers don't execute PHP at all. Node backends are for sites where you're deploying your own Node.js application code. If you're starting a brand-new Node app rather than switching an existing site, [Create a site](/whp/how-to/create-a-site/) and choose **Node.js app** under "What are you building?" is the more direct path.
</Aside>
A few things behave differently for Node compared to switching between PHP tiers:
- **No PHP-FPM / LiteSpeed choice.** Node containers bundle their own web server, so the shared-vs-standalone placement option that applies to PHP and LiteSpeed containers doesn't apply here — you won't see that toggle once a Node container type is selected.
- **Higher minimum memory.** Node containers need more headroom than PHP containers. Selecting a Node container type in the editor bumps **Memory per Container** up to at least 512 MB (versus 256 MB for standard PHP). If your account doesn't have that much unused memory in its resource allowance, WHP will tell you and block the change until you free up resources or [upgrade your plan](/whp/add-ons/resource-upgrades/).
- **Optional WebSocket / real-time support.** The Edit Site form has a **WebSocket / real-time support** checkbox alongside the Container Type field. Turn it on if your Node app holds connections open (Socket.IO, live chat, streaming) — it keeps connections alive for up to 6 hours instead of the standard 5-minute timeout. This is unrelated to the container type itself and works whether or not you just switched to Node.
![Edit Site modal with Container Type set to Node22, showing Memory per Container automatically raised to 512 MB](~/assets/screenshots/whp/whp-sites-edit-node.png)
Once you've switched and saved, upload your app to the `app/` folder for that domain via SFTP — see [Create a site](/whp/how-to/create-a-site/#where-your-files-go) for the file layout and how WHP starts your app.
## Before cancelling the Optimized Webserver add-on ## Before cancelling the Optimized Webserver add-on
<Aside type="caution"> <Aside type="caution">
@@ -89,6 +108,10 @@ Once all sites are on standard backends, you can cancel or disable the add-on fr
**LiteSpeed cache not serving cached pages after the switch.** This is expected — the cache starts empty after every container recreation. It warms up automatically as visitors load pages. **LiteSpeed cache not serving cached pages after the switch.** This is expected — the cache starts empty after every container recreation. It warms up automatically as visitors load pages.
**"Your account does not have enough resources left" when selecting a Node type.** Node containers need at least 512 MB of memory. Free up resources by removing or resizing another site, or [upgrade your plan](/whp/add-ons/resource-upgrades/).
**Site shows a 502 after switching to Node.** Give the container 1530 seconds to start your app. If it's still down, confirm your app listens on the port WHP passes it via environment variable — see [Create a site](/whp/how-to/create-a-site/#troubleshooting).
## Related ## Related
- [Create a site](/whp/how-to/create-a-site/) - [Create a site](/whp/how-to/create-a-site/)
+19 -4
View File
@@ -23,10 +23,25 @@ const PRODUCT_META: Record<string, { title: string; blurb: string; firstSection:
blurb: 'Tips and tricks for getting the most out of WordPress on WHP.', blurb: 'Tips and tricks for getting the most out of WordPress on WHP.',
firstSection: 'index', firstSection: 'index',
}, },
'email-clients': { email: {
title: 'Email clients', title: 'Email',
blurb: 'Configure Outlook, Apple Mail, Thunderbird, and mobile clients.', blurb: 'Set up Outlook, Apple Mail, Thunderbird, and mobile clients — plus news about our filtering.',
firstSection: 'index', firstSection: 'set-up-your-email-client',
},
domains: {
title: 'Domains',
blurb: 'Transfer a domain to us, point it at your hosting, and sort out DNS problems.',
firstSection: 'transferring-a-domain-to-us',
},
cpanel: {
title: 'cPanel hosting',
blurb: 'Nameservers, SSL certificates, permissions, and email for our cPanel shared and reseller plans.',
firstSection: 'nameservers',
},
support: {
title: 'Support',
blurb: 'Working with our support team, including remote-assistance sessions.',
firstSection: 'remote-support',
}, },
}; };
+141
View File
@@ -0,0 +1,141 @@
/**
* SFTP SSH Keys capture — the new customer-facing key management page
* (WHP release 2026.09.11), as the demo customer.
*
* Captures:
* - whp-sftp-keys-empty.png Authorized Keys list with no keys yet
* (the real empty state).
* - whp-sftp-keys-add-form.png the Add Key form filled in with a
* throwaway demo key, before submitting.
* - whp-sftp-keys-list.png Authorized Keys list after the key was
* added — fingerprint/type/comment/added
* columns populated.
*
* This is a documentation-owned demo account (demo-user), so unlike the other
* capture-*.ts scripts, this one DOES submit the Add Key / Remove actions —
* that's the only way to show the populated list state, and the account is
* reset back to empty at the end of the run (no key is left behind).
*
* Viewport-only (1440x900, deviceScaleFactor 2), redacted for our multi-server
* fleet: server hostnames/IPs become placeholders, while the brand demo
* account (demo-user) is kept visible on purpose.
*/
import { chromium, type Page } from 'playwright';
import { mkdir } from 'node:fs/promises';
import { resolve, dirname } from 'node:path';
import { fileURLToPath } from 'node:url';
import { execFileSync } from 'node:child_process';
const __dirname = dirname(fileURLToPath(import.meta.url));
const OUT_DIR = resolve(__dirname, '../../src/assets/screenshots/whp');
function need(name: string): string {
const v = process.env[name];
if (!v) throw new Error(`missing env: ${name}`);
return v;
}
const BASE = need('WHP_BASE');
const USER = need('WHP_USER');
const PASS = need('WHP_PASS');
const HIDE_CSS = `.navbar-text, .brand-full { visibility: hidden !important; }`;
async function login(page: Page) {
await page.goto(`${BASE}/login.php`, { waitUntil: 'domcontentloaded' });
await page.fill('input[name="user"]', USER);
await page.fill('input[name="password"]', PASS);
await page.click('button[type="submit"]');
await page.waitForLoadState('networkidle');
}
async function redact(page: Page) {
await page.addStyleTag({ content: HIDE_CSS });
await page.evaluate(() => {
const swaps: [RegExp, string][] = [
[/ns[12]\.whp\d+(-[a-z0-9]+)?\.cloud-hosting\.io/gi, 'ns<n>.<your-server>.cloud-hosting.io'],
[/whp\d+(-[a-z0-9]+)?\.cloud-hosting\.io/gi, '<your-server>.cloud-hosting.io'],
[/mail\d+\.cloud-hosting\.io/gi, '<mail-server>.cloud-hosting.io'],
[/WHP\d+(-[A-Z0-9]+)?\b/g, '<YOUR-SERVER>'],
[/whp\d+(-[a-z0-9]+)?\b/gi, '<your-server>'],
[/\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b/g, '<server-IP>'],
];
const walker = document.createTreeWalker(document.body, NodeFilter.SHOW_TEXT);
const nodes: Text[] = [];
let n: Node | null = walker.nextNode();
while (n) { nodes.push(n as Text); n = walker.nextNode(); }
for (const node of nodes) {
let v = node.nodeValue ?? '';
for (const [re, rep] of swaps) v = v.replace(re, rep);
if (v !== node.nodeValue) node.nodeValue = v;
}
document.querySelectorAll<HTMLInputElement | HTMLTextAreaElement>('input, textarea').forEach((el) => {
if ((el as HTMLInputElement).type === 'password' || !el.value) return;
let v = el.value;
const swaps2: [RegExp, string][] = [
[/whp\d+(-[a-z0-9]+)?\.cloud-hosting\.io/gi, '<your-server>.cloud-hosting.io'],
[/\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b/g, '<server-IP>'],
];
for (const [re, rep] of swaps2) v = v.replace(re, rep);
if (v !== el.value) el.value = v;
});
});
}
async function shot(page: Page, id: string) {
await page.waitForTimeout(400);
await redact(page);
const path = resolve(OUT_DIR, `${id}.png`);
await page.screenshot({ path, fullPage: false });
console.log(`captured ${id} -> ${path}`);
}
async function main() {
await mkdir(OUT_DIR, { recursive: true });
// Throwaway ed25519 keypair, generated fresh for this capture only. Never
// used to actually connect; discarded with the OS temp dir.
const os = await import('node:os');
const fs = await import('node:fs/promises');
const tmpDir = await fs.mkdtemp(resolve(os.tmpdir(), 'kb-sftp-demo-key-'));
const keyPath = resolve(tmpDir, 'id_ed25519');
execFileSync('ssh-keygen', ['-t', 'ed25519', '-N', '', '-C', "dana's-laptop", '-f', keyPath]);
const pubKey = (await fs.readFile(`${keyPath}.pub`, 'utf8')).trim();
const browser = await chromium.launch({ headless: true });
const ctx = await browser.newContext({
ignoreHTTPSErrors: true,
viewport: { width: 1440, height: 900 },
deviceScaleFactor: 2,
});
const page = await ctx.newPage();
try {
await login(page);
// 1. SFTP SSH Keys page — empty state
await page.goto(`${BASE}/index.php?page=sftp-keys`, { waitUntil: 'networkidle' });
await page.waitForTimeout(600);
await shot(page, 'whp-sftp-keys-empty');
// 2. Add Key form, filled in but not yet submitted
await page.fill('#sftp-key-input', pubKey);
await page.fill('#sftp-key-note', "Dana's laptop");
await shot(page, 'whp-sftp-keys-add-form');
// 3. Submit, then capture the populated list
await page.click('#sftp-keys-add-btn');
await page.waitForTimeout(1200);
await shot(page, 'whp-sftp-keys-list');
// Clean up: remove the demo key so the account is left as it was found.
page.once('dialog', (d) => d.accept());
await page.locator('button:has-text("Remove")').first().click();
await page.waitForTimeout(1000);
console.log('cleanup: demo key removed');
} finally {
await browser.close();
await fs.rm(tmpDir, { recursive: true, force: true });
}
}
main().catch((err) => { console.error(err); process.exit(1); });
+156
View File
@@ -0,0 +1,156 @@
/**
* Sites "backend" capture — the Edit Site modal's Container Type field,
* captured with a Node.js container type selected (for the "switching your
* site's backend" how-to's Node.js section).
*
* Captures, as the demo customer:
* - whp-sites-edit-node.png Edit Site modal, Container Type = Node22,
* showing the auto-adjusted Memory per
* Container / Total Resources readout.
*
* Viewport-only (1440x900), redacted for our multi-server fleet: server /
* mail / nameserver hostnames, IPs, and the navbar brand strip become
* neutral or hidden, while the brand demo domain (whp-demo.anhh.co) stays
* visible on purpose.
*
* Read-only: opens the Edit modal and changes the Container Type dropdown
* for the shot, but never clicks Save.
*/
import { chromium, type Page } from 'playwright';
import { mkdir, readFile } from 'node:fs/promises';
import { resolve, dirname } from 'node:path';
import { fileURLToPath } from 'node:url';
const __dirname = dirname(fileURLToPath(import.meta.url));
const OUT_DIR = resolve(__dirname, '../../src/assets/screenshots/whp');
async function loadEnv(): Promise<void> {
const envPath = resolve(__dirname, '.env');
const content = await readFile(envPath, 'utf-8');
for (const line of content.split('\n')) {
const trimmed = line.trim();
if (!trimmed || trimmed.startsWith('#')) continue;
const eq = trimmed.indexOf('=');
if (eq === -1) continue;
const key = trimmed.slice(0, eq).trim();
const val = trimmed.slice(eq + 1).trim();
if (!process.env[key]) process.env[key] = val;
}
}
function need(name: string): string {
const v = process.env[name];
if (!v) throw new Error(`missing env: ${name}`);
return v;
}
const HIDE_CSS = `.navbar-text, .brand-full { visibility: hidden !important; }`;
async function login(page: Page, base: string, user: string, pass: string) {
await page.goto(`${base}/login.php`, { waitUntil: 'domcontentloaded' });
await page.fill('input[name="user"]', user);
await page.fill('input[name="password"]', pass);
await page.click('button[type="submit"]');
await page.waitForLoadState('networkidle');
}
/**
* Neutralise fleet-identifying text before the screenshot. The brand demo
* domain (anhh.co) is intentionally preserved; everything that names a
* specific server, mail host, nameserver, or IP is swapped for a placeholder.
*/
async function redact(page: Page) {
await page.addStyleTag({ content: HIDE_CSS });
await page.evaluate(() => {
const swaps: [RegExp, string][] = [
[/ns[12]\.whp\d+(-[a-z0-9]+)?\.cloud-hosting\.io/gi, 'ns<n>.<your-server>.cloud-hosting.io'],
[/whp\d+(-[a-z0-9]+)?\.cloud-hosting\.io/gi, '<your-server>.cloud-hosting.io'],
[/mail\d+\.cloud-hosting\.io/gi, '<mail-server>.cloud-hosting.io'],
[/WHP\d+(-[A-Z0-9]+)?\b/g, '<YOUR-SERVER>'],
[/whp\d+(-[a-z0-9]+)?\b/gi, '<your-server>'],
// Public IPv4 (skip RFC1918 — those read fine as generic examples)
[/\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b/g, '<server-IP>'],
[/demo-user/g, 'your-username'],
];
const walker = document.createTreeWalker(document.body, NodeFilter.SHOW_TEXT);
const nodes: Text[] = [];
let n: Node | null = walker.nextNode();
while (n) { nodes.push(n as Text); n = walker.nextNode(); }
for (const node of nodes) {
let v = node.nodeValue ?? '';
for (const [re, rep] of swaps) v = v.replace(re, rep);
if (v !== node.nodeValue) node.nodeValue = v;
}
document.querySelectorAll<HTMLInputElement>('input').forEach((el) => {
if (el.type === 'password' || !el.value) return;
let v = el.value;
for (const [re, rep] of swaps) v = v.replace(re, rep);
if (v !== el.value) el.value = v;
});
});
}
async function shot(page: Page, id: string) {
await page.waitForTimeout(400);
await redact(page);
const path = resolve(OUT_DIR, `${id}.png`);
await page.screenshot({ path, fullPage: false });
console.log(`captured ${id} -> ${path}`);
}
async function main() {
await loadEnv();
const BASE = need('WHP_BASE');
const USER = need('WHP_USER');
const PASS = need('WHP_PASS');
const DOMAIN = process.env.WHP_DEMO_DOMAIN ?? 'whp-demo.anhh.co';
await mkdir(OUT_DIR, { recursive: true });
const browser = await chromium.launch({ headless: true });
const ctx = await browser.newContext({
ignoreHTTPSErrors: true,
viewport: { width: 1440, height: 900 },
deviceScaleFactor: 2,
});
const page = await ctx.newPage();
try {
await login(page, BASE, USER, PASS);
await page.goto(`${BASE}/index.php?page=sites`, { waitUntil: 'networkidle' });
// Select the demo site from the "Select a Site" widget (Choices.js).
const siteChoicesContainer = page.locator('div.choices:has(#siteDropdown)').first();
await siteChoicesContainer.click();
await page.waitForTimeout(300);
const item = page
.locator('.choices__list--dropdown .choices__item--choice', { hasText: DOMAIN.split('.')[0] })
.first();
await item.click();
// Wait for the async site-details fetch, then open Edit (Manage).
await page.locator('#siteActionsContainer').waitFor({ state: 'visible', timeout: 10000 });
await page.waitForTimeout(300);
await page.locator('#manageSiteBtn').click();
await page.waitForTimeout(800);
// Switch the Container Type to Node22 (the newest of the three Node
// options) to show the memory floor auto-adjust to 512 MB.
const editSelect = page.locator('#edit_container_type_id');
await editSelect.waitFor({ state: 'visible', timeout: 10000 });
await editSelect.scrollIntoViewIfNeeded();
const nodeOption = editSelect.locator('option', { hasText: 'Node22' });
const nodeValue = await nodeOption.getAttribute('value');
if (!nodeValue) throw new Error('Node22 option not found in edit_container_type_id');
await editSelect.selectOption(nodeValue);
await page.waitForTimeout(600);
await shot(page, 'whp-sites-edit-node');
} finally {
await browser.close();
}
}
main().catch((err) => {
console.error(err);
process.exit(1);
});