# Recipes Tab

Use the **Recipes** tab to run guided setup, hardening, verification, TLS, and maintenance actions on one server. Recipes are designed for repeatable server tasks where the platform can do the routine work and then show whether the result is active, inactive, running, or needs review.

Recipes apply to the selected member only. Pool-wide features such as Protection, Managed DNS, and Storage Pools are managed from their own pool tabs.

### What recipes are

Recipes are guided actions for common server tasks:

<div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover" id="bkmrk-enable-or-disable-ss"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content"><div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content">- Enable or disable SSH access.
- Harden cPanel, OpenLiteSpeed, or database firewall rules.
- Verify cPanel services.
- Check WHM linking.
- Back up cPanel configuration.
- Run AutoSSL after failover.
- Issue Let's Encrypt certificates where supported.
- Update the balctl agent.
- Show Galera state when detected.

</div></div></div></div></div></div>The Recipes tab shows only recipes that make sense for the selected server. A cPanel server will show cPanel recipes. A database server will show database recipes. An OpenLiteSpeed server will show OpenLiteSpeed recipes.

### Free and Pro

<div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover" id="bkmrk-feature-community-pr-7"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content"><div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content"><div><div><table><thead><tr><th>Feature</th><th>Community</th><th>Pro</th></tr></thead><tbody><tr><td>View available recipe cards</td><td>Included</td><td>Included</td></tr><tr><td>View Active, Inactive, Running, and Needs review state</td><td>Included</td><td>Included</td></tr><tr><td>View read-only detected recipes such as Galera state</td><td>Included</td><td>Included</td></tr><tr><td>Run agent update when available</td><td>Included where allowed</td><td>Included</td></tr><tr><td>Run service verification recipes</td><td>Upgrade may be required</td><td>Included</td></tr><tr><td>Run hardening recipes</td><td>Upgrade required</td><td>Included</td></tr><tr><td>Run TLS and certificate recipes</td><td>Upgrade required</td><td>Included</td></tr><tr><td>Run cPanel, OpenLiteSpeed, database, SSH, and backup actions</td><td>Upgrade required</td><td>Included</td></tr><tr><td>Disable supported recipe changes</td><td>Upgrade required</td><td>Included</td></tr></tbody></table>

</div></div></div></div></div></div></div></div>Community is useful for visibility. Pro turns Recipes into a guided operations toolkit for production hosts.

### Recipe card states

<div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover" id="bkmrk-state-meaning-inacti"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content"><div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content"><div><div><table><thead><tr><th>State</th><th>Meaning</th></tr></thead><tbody><tr><td>**Inactive**</td><td>The recipe is available but not currently active on this member.</td></tr><tr><td>**Running**</td><td>A recipe job has been queued or is still being applied.</td></tr><tr><td>**Active**</td><td>The member reports the expected result.</td></tr><tr><td>**Needs review**</td><td>The recipe was seen before or may need attention, but the latest member report does not show it as fully active.</td></tr></tbody></table>

</div></div></div></div></div></div></div></div>If a card says the agent must be updated first, run **Update balctl agent**, wait for the member to check in again, then return to the recipe.

### Running a recipe

<div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover" id="bkmrk-open-the-pool.-selec-2"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content"><div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content">1. Open the pool.
2. Select the member.
3. Open **Recipes**.
4. Choose the recipe card.
5. Select **Enable**, **Run again**, **Verify link**, or **Update agent**, depending on the card.
6. Watch the card state.
7. Check **Cron &amp; Jobs** if you want more job detail.

</div></div></div></div></div></div>Some recipes can be disabled again from the card menu. Disable actions can affect access or service behavior, so read the confirmation before continuing.

## Common recipes

<div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover" id="bkmrk-recipe-use-it-when-e"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content"><div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content"><div><div><table><thead><tr><th>Recipe</th><th>Use it when</th></tr></thead><tbody><tr><td>**Enable SSH access**</td><td>SSH is disabled and you want the host SSH service available again.</td></tr><tr><td>**Harden cPanel ports**</td><td>You want cPanel/WHM service ports allowed and reviewed.</td></tr><tr><td>**Verify cPanel services**</td><td>You want a read-only cPanel health refresh without restarting services.</td></tr><tr><td>**WHM link check**</td><td>You want to confirm the server matches the linked WHM host and DNS setup.</td></tr><tr><td>**Backup cPanel configuration**</td><td>You want a WHM/cPanel configuration recovery point before changes.</td></tr><tr><td>**AutoSSL after failover**</td><td>DNS has moved to this cPanel host and you want AutoSSL checked.</td></tr><tr><td>**Harden database**</td><td>You want MySQL/MariaDB access rules reviewed.</td></tr><tr><td>**Harden OpenLiteSpeed**</td><td>You want HTTP, HTTPS, and WebAdmin access rules reviewed.</td></tr><tr><td>**Let's Encrypt (this server)**</td><td>You want host TLS for a domain under a linked DNS provider.</td></tr><tr><td>**Let's Encrypt (failover / HAProxy)**</td><td>You want TLS for a failover hostname on a HAProxy member.</td></tr><tr><td>**Update balctl agent**</td><td>A newer agent is available or a feature requires a newer agent.</td></tr><tr><td>**Galera cluster**</td><td>Galera has been detected and you want to see cluster-related status.</td></tr></tbody></table>

</div></div></div></div></div></div></div></div>Install recipes for cPanel, OpenLiteSpeed, and MariaDB/MySQL may be launched from the relevant product area instead of appearing as general recipe cards. After installation is detected, the matching member tab becomes available or active.

### TLS recipes

TLS recipes need a compatible DNS setup because certificate validation may require DNS changes.

Before running TLS recipes:

<div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover" id="bkmrk-make-sure-the-domain"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content"><div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content">- Make sure the domain is controlled by a saved DNS provider.
- Confirm the member is healthy and checking in.
- Update the agent if the recipe asks for a newer version.
- Know where the certificate will be used after it is issued.

</div></div></div></div></div></div>Use the Control panel or service-specific tab after the certificate is issued if the web server still needs configuration.

### Hardening recipes

Hardening recipes usually adjust or verify firewall/service access for the selected stack.

Before running a hardening recipe:

<div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover" id="bkmrk-check-the-security-t"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content"><div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content">- Check the **Security** tab so you understand current firewall state.
- Make sure SSH remains allowed from a trusted source.
- Confirm the service ports you expect customers to use.
- Create a backup where available before major changes.

</div></div></div></div></div></div>Hardening helps with standard access rules, but it does not replace a full security review.

### WHM and cPanel recipes

cPanel recipes appear when cPanel is detected.

Use them to:

<div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover" id="bkmrk-check-the-whm-link.-"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content"><div class="ui-scroll-area" data-direction="horizontal" data-scroll-padding="4" data-visibility="hover"><div class="ui-scroll-area__viewport"><div class="ui-scroll-area__content">- Check the WHM link.
- Verify cPanel services.
- Harden cPanel ports.
- Back up cPanel configuration.
- Trigger AutoSSL after failover.

</div></div></div></div></div></div>Account management still belongs in the **cPanel** tab. Scheduled standby replication still belongs in the pool **Protection** tab.