Onboarding checklist

Bring your first server into HostSSH step by step — account, agent, storage, first capture, first app, and schedules.

Onboarding checklist

This is the ordered path from zero to a protected, serving server. Each step links to the full guide. Budget about 30 minutes; most of it is waiting on installs.

New to the vocabulary (Node, App, Slot, Fleet)? Skim Concepts first — every step below uses those words exactly.

Step 1 — Create your account and save your license key

  1. Sign up at hostssh.com.
  2. Copy your license key (HSSH-XXXX-XXXX-XXXX) from the dashboard into a password manager. You will paste it once per server.
  3. Confirm you can see the Fleet view (empty for now).

What you get at this point: a control-plane account, a trial license, and an empty fleet. Nothing runs on your hardware yet. See Licensing.

Step 2 — Add your first server

Pick one path; both end in the same fleet.

  • You have no server yet: dashboard → Fleet → Provision, choose provider, region, size → Provision. HostSSH creates the VPS and enrolls its agent.
  • You already have a box: dashboard → Fleet → Add node and follow the signed installer (or request assisted onboarding while the public mirror gate is closed). Full flags in Install.
  • Home/office box with no public IP: same join, then add the tunnel-first path so apps on it are reachable.

Verify from the box:

hostssh status              # health, license, last backup
hostssh doctor              # non-destructive preflight; fix anything red

The server should now appear in the fleet dashboard as online.

Step 3 — Connect your storage (one connection, five minutes)

Backups need a home — your bucket, your keys. Add one storage backend:

hostssh connections add        # interactive: R2, S3, MinIO, B2, Wasabi, SFTP, local
hostssh connections test <id>  # live probe: writes, reads, deletes a test object

R2 is the default (zero-egress restores). Details, least-privilege scoping, and key custody in Connections (BYOK).

Step 4 — Run your first capture

hostssh capture
hostssh status    # confirm: last image, size, integrity

Then open the dashboard Recovery console and confirm the image is listed. If it is there, your server is portable from this moment on.

Step 5 — Ship one app (prove the box serves)

Deploy anything small — a static page is ideal for the first run:

hostssh deploy --name hello --source ./hello --builder hostpack \
  --domain hello.example.com --port 3000 --readiness-path /healthz

Point the domain's A record at the node, wait for the certificate (~10–30 s), and open it in a browser. Full playbook in Deploying apps; certificate detail in Domains & TLS.

Prefer proving it with code? A minimal health check from any machine:

// check-hello.js — run with: node check-hello.js
const res = await fetch("https://hello.example.com/healthz");
if (!res.ok) throw new Error(`unhealthy: ${res.status}`);
console.log("serving:", await res.text());

Step 6 — Put protection on autopilot

  1. Nightly capture: dashboard → Backups → Schedule (time + target + cadence).
  2. Monthly restore-drill: dashboard → Recovery → Restore-drills → Monthly. This restores your image to a throwaway box and proves it boots — the difference between "backed up" and "recoverable". See Backups & recovery.
  3. Failure alerts: add a notification connection (Slack, email, webhook) so a missed backup pages you instead of surprising you.

Step 7 — Invite your team (optional)

Add seats in License management, and give operators the least privilege they need (read-only operators can view the fleet but cannot run changes). Admin surfaces are under docs/user/admin/.

Done — what next?