Recipes Tab

Use the Recipes tab to run guided setup, hardening, verification, TLS, and maintenance actions on one server. Recipes are designed for repeatable server tasks where the platform can do the routine work and then show whether the result is active, inactive, running, or needs review.

Recipes apply to the selected member only. Pool-wide features such as Protection, Managed DNS, and Storage Pools are managed from their own pool tabs.

What recipes are

Recipes are guided actions for common server tasks:

  • Enable or disable SSH access.
  • Harden cPanel, OpenLiteSpeed, or database firewall rules.
  • Verify cPanel services.
  • Check WHM linking.
  • Back up cPanel configuration.
  • Run AutoSSL after failover.
  • Issue Let's Encrypt certificates where supported.
  • Update the balctl agent.
  • Show Galera state when detected.

The Recipes tab shows only recipes that make sense for the selected server. A cPanel server will show cPanel recipes. A database server will show database recipes. An OpenLiteSpeed server will show OpenLiteSpeed recipes.

Free and Pro

Feature Community Pro
View available recipe cards Included Included
View Active, Inactive, Running, and Needs review state Included Included
View read-only detected recipes such as Galera state Included Included
Run agent update when available Included where allowed Included
Run service verification recipes Upgrade may be required Included
Run hardening recipes Upgrade required Included
Run TLS and certificate recipes Upgrade required Included
Run cPanel, OpenLiteSpeed, database, SSH, and backup actions Upgrade required Included
Disable supported recipe changes Upgrade required Included

Community is useful for visibility. Pro turns Recipes into a guided operations toolkit for production hosts.

Recipe card states

State Meaning
Inactive The recipe is available but not currently active on this member.
Running A recipe job has been queued or is still being applied.
Active The member reports the expected result.
Needs review The recipe was seen before or may need attention, but the latest member report does not show it as fully active.

If a card says the agent must be updated first, run Update balctl agent, wait for the member to check in again, then return to the recipe.

Running a recipe

  1. Open the pool.
  2. Select the member.
  3. Open Recipes.
  4. Choose the recipe card.
  5. Select Enable, Run again, Verify link, or Update agent, depending on the card.
  6. Watch the card state.
  7. Check Cron & Jobs if you want more job detail.

Some recipes can be disabled again from the card menu. Disable actions can affect access or service behavior, so read the confirmation before continuing.

Common recipes

Recipe Use it when
Enable SSH access SSH is disabled and you want the host SSH service available again.
Harden cPanel ports You want cPanel/WHM service ports allowed and reviewed.
Verify cPanel services You want a read-only cPanel health refresh without restarting services.
WHM link check You want to confirm the server matches the linked WHM host and DNS setup.
Backup cPanel configuration You want a WHM/cPanel configuration recovery point before changes.
AutoSSL after failover DNS has moved to this cPanel host and you want AutoSSL checked.
Harden database You want MySQL/MariaDB access rules reviewed.
Harden OpenLiteSpeed You want HTTP, HTTPS, and WebAdmin access rules reviewed.
Let's Encrypt (this server) You want host TLS for a domain under a linked DNS provider.
Let's Encrypt (failover / HAProxy) You want TLS for a failover hostname on a HAProxy member.
Update balctl agent A newer agent is available or a feature requires a newer agent.
Galera cluster Galera has been detected and you want to see cluster-related status.

Install recipes for cPanel, OpenLiteSpeed, and MariaDB/MySQL may be launched from the relevant product area instead of appearing as general recipe cards. After installation is detected, the matching member tab becomes available or active.

TLS recipes

TLS recipes need a compatible DNS setup because certificate validation may require DNS changes.

Before running TLS recipes:

  • Make sure the domain is controlled by a saved DNS provider.
  • Confirm the member is healthy and checking in.
  • Update the agent if the recipe asks for a newer version.
  • Know where the certificate will be used after it is issued.

Use the Control panel or service-specific tab after the certificate is issued if the web server still needs configuration.

Hardening recipes

Hardening recipes usually adjust or verify firewall/service access for the selected stack.

Before running a hardening recipe:

  • Check the Security tab so you understand current firewall state.
  • Make sure SSH remains allowed from a trusted source.
  • Confirm the service ports you expect customers to use.
  • Create a backup where available before major changes.

Hardening helps with standard access rules, but it does not replace a full security review.

WHM and cPanel recipes

cPanel recipes appear when cPanel is detected.

Use them to:

  • Check the WHM link.
  • Verify cPanel services.
  • Harden cPanel ports.
  • Back up cPanel configuration.
  • Trigger AutoSSL after failover.

Account management still belongs in the cPanel tab. Scheduled standby replication still belongs in the pool Protection tab.


Revision #1
Created 2026-07-08 19:31:28 UTC by ServersCTL
Updated 2026-07-08 19:32:17 UTC by ServersCTL