All user input is validated before processing. 13 validation types are available:
| Type | Validation | Example |
|---|---|---|
domain |
RFC 1035, labels 1-63 chars, TLD 2+ letters | example.com |
database |
Max 64 chars, [a-zA-Z0-9_-] |
shop-production |
username |
Max 32 chars, [a-zA-Z0-9_-] |
shop-user |
linux_username |
POSIX-compliant, lowercase, max 32, no leading digit | shopdev |
ssh_public_key |
No newlines, 40-8192 chars, ssh-rsa/ed25519/ecdsa/sk-* | ssh-ed25519 AAAA... |
path |
Path traversal protection via realpath + whitelist check |
/var/www/shop |
email |
Basic RFC 5322 | admin@example.com |
password |
Length check (configurable, min 8) | |
php_version |
Whitelist: 7.4, 8.0-8.4 | 8.3 |
cron_schedule |
5-field cron regex, max 500 chars | 0 3 * * * |
port |
1-65535, numeric | 443 |
protocol |
tcp or udp | tcp |
ip_address |
IPv4 with octet validation (0-255) | 192.168.1.1 |
url |
http/https with valid host | https://example.com |
mysql_escape() + backtick quotingrealpath + whitelist (ST_ALLOWED_DOCROOT_PATHS)safe_write_file() (mktemp + mv, TOCTOU-safe, symlink check).my.cnf permissionsopenssl rand -base64 (~6 bits/char entropy)uninstall only ever deletes paths that are recognizable as a Server Tools installation, and only removes shortcuts if they still point at its own binary; install aborts with a clear error instead of failing partway through when started from an already-installed copy[2026-02-18 14:32:15] [INFO] user=root action=create_database db=shop_production user=shop_user
[2026-02-18 14:33:01] [INFO] user=root action=create_vhost domain=shop.example.com php=8.3
[2026-02-19 10:15:42] [INFO] user=root action=create_user username=shopdev domain=shop.example.com
[2026-02-18 14:35:22] [WARNING] user=root action=delete_database db=old_staging backup=true
All destructive operations (delete, modify) automatically create a backup when
ST_AUTO_BACKUP=true(default). If the backup fails, you are asked whether to proceed.