VM Provisioning Workflow on MTN Cloud

This guide walks you through the complete process of provisioning virtual machines on MTN Cloud, from initial setup to deployment and configuration.

📋 Before You Start (Prerequisites)

  1. Have an MTN Cloud login with permissions to view Infrastructure and Provisioning.
  2. Tip:If you don't see your imported SSH keys, networks, or security groups when provisioning, contact support or refresh the portal.
  3. Plan your deployments

🔄 The Right Sequence

  • Generate SSH Keys (recommended): For enhanced security, configure SSH key-based login instead of a username and password.
  • Create a User (Linux/Windows): Add the required user under User Settings. Add the SSH-key to this login details as well.
  • Define Security Groups: Create a new security group specifying the ports needed for ingress and egress traffic. This new security group can be appended to the VM (in addition to the default) after the VM has been created. The default security group provides basic functionalities such as console access and instance health checks. It is highly recommended that you use this during the VM creation process.
  • Provision the Virtual Machine: Deploy the VM, attach it to the appropriate network (either ubuntu_net), assign a floating IP, and apply the default security group(s). At this point, your VM will be ready for use. After provisioning, defined or additional security group can be added to the VM.

👤 Part 1 — Create Linux/Windows User

Purpose: Allow logins to VM provisioned via the console and resource ownership within MTN Cloud

  1. Login to User Account
  2. Navigate to User Settings (can be found at the top right corner of your screen when the dropdown beside name is clicked)
  3. User Settings
  4. Locate Linux Settings
  5. Assign:
    • Username
    • Password
    • Confirm Password
    • Select an ssh-key entry if you have one (optional)
  6. Do the same for your Windows Settings. Scroll to the bottom and Save
  7. Windows Settings

🔒 Part 2 — Define Security Groups

Purpose: Controls network access to (ingress) and from (egress) your VM.

  1. Navigate to: Infrastructure > Network > Security Groups
  2. Security Groups NavigationSecurity Groups List
  3. Click +Add
  4. Add Security Group
  5. Assign:
    • Name
    • Description
    • Scoped Cloud = MTNNG_CLOUD_AZ_1
    • Security Group Configuration
  6. Click the Security Group recently created
  7. Navigate to Rules
  8. Security Group Rules
  9. Click on +Add Rules
  10. Add Security Group Rule
  11. Assign:
    • Name
    • Direction = (Ingress or Egress)
    • Rule Type = Custom Rule
    • Protocol = (TCP, UDP OR ICMP)
    • Port Range (available depending on protocol selected)
    • Source Type
    • Source
    • Destination Type
    • Destination Port Range
    • Security Group Rule Configuration
  12. Scroll Down to Save Changes
  13. Navigate to Location
  14. Click on +Add Location
  15. Select the required Cloud where the workload to be protected is provisioned
  16. Click on Save Changes

💡 Use Case: Restricting SSH Access to Only My Laptop

Scenario: You want only your laptop (with IP 200.200.113.15) to be able to SSH into your VM. All other devices should be blocked.

Steps:

  1. Navigate to: Infrastructure > Network > Security Groups
  2. Click + Add
    • Name: Laptop-SSH-Only
    • Description: Allow SSH (Secure Remote Connection) only from my laptop
    • Scoped Cloud: MTNNG_CLOUD-AZ1 (Important to choose the AZ) and not ALL
    • Select the Laptop-SSH-Only group.
  3. Go to the Rules tab → click + Add Rules.
    • Name: Allow-SSH-From-Laptop
    • Direction: Ingress
    • Rule Type: Custom Rule
    • Protocol: TCP
    • Port Range: 22
    • Source Type: Network
    • Source: 200.200.113.15/32 (your laptop's public IP)
    • Destination Type: Instance
    • Destination Port Range: 22
  4. Save Changes.
  5. Attach the Laptop-SSH-Only group to your VM in addition to the default SG.

Result: Only your laptop can successfully SSH into the VM on port 22. All other SSH attempts will be denied.

🔑 Part 3 — Create or Import SSH Keys

Purpose: Enables secure, password-less access to provisioned VMs.

⚙️ For Generating:

  1. Navigate to: Infrastructure > Trust > Key Pairs
  2. Key Pairs Navigation
  3. Click: +Add
  4. Select Generate Key Pair. Note: This is needed if you wish to use the ssh console into your cloud instances. You may also import both Public and Private keys to your local machine if you wish to ssh with the same keys.
  5. Assign Name
  6. Generate Key Pair
  7. Save Changes.
  8. Immediately after creation, the Public and Private keys are shown on the screen. Handle the information with care.
  9. On recently generated key pair, select info icon
  10. Copy Key Pair if needed for external storage or use
  11. Navigate to User Settings
  12. Locate Linux Settings
  13. On SSH Tab, select your generated ssh key pair
  14. Scroll down to Save Changes
  15. SSH Key Selection

📥 For Importing:

  1. Generate SSH Key Pair on your local machine:
    ssh-keygen -m pem -t rsa
  2. Add SSH Key to Morpheus:
    • Navigate to: Infrastructure > Trust > Key Pairs
    • Click: +Add
    • Add Key Pair
    • Select Existing Key Pair
    • Import Existing Key Pair
    • Assign Name
    • Browse for or paste your Private Key
    • Browse for or Paste your Public key (with .pub file extension)
  3. Navigate to User Settings
  4. Locate Linux Settings
  5. On SSH Tab, select your imported ssh key pair
  6. Scroll down to Save Changes

🚀 Part 4 — Provision the Virtual Machine

Once your SSH key, security group, and network are ready, you can provision your VM in MTN Cloud Console by following these steps:

  1. Navigate to: Provisioning → Instances
  2. Provisioning Instances
  3. Click +Add
  4. Add Instance
  5. Select the Instance Type, which determines the operating system to be installed (e.g., MTN_DEBIAN_11, MTN_CENTOS_STREAM_9).
  6. Instance Type Selection
  7. Select the Group and Cloud where the VM will be deployed (e.g., MTNNG_Cloud_AZ_1).
  8. Group and Cloud Selection
  9. Select the Group assigned to your account. This defines the location and resource scope for the VM.
  10. Input the VM Name or leave the automatic generated name by MTN Cloud based on naming conventions.
  11. Choose the appropriate Environment for the VM (e.g., Development, Staging, Production).
  12. A Label can be added if required.
  13. Select Next
  14. The Layout is automatically determined by the selected Instance Type and reflects the operating system configuration.
  15. Select a Planthat defines the VM's CPU, memory, and storage resources.
  16. Choose any of the Networks provided either Ubuntu_net or DELL.
  17. Assign Floating IPs (01 for Ubuntu_net or 02 for DELL)
  18. In the Availability Zonesection, select one of the three available Fault Domains to define the VM's physical placement and redundancy.
  19. First Assign the default Security Group available to manage necessary firewall rules and traffic access, after provisioning, your own created Security Groups can be attached.
  20. Open the User Config tab, check the Create Your User box
  21. Under Advanced Options, Modify any required Ports and Protocols for the VM (e.g., SSH, HTTP, custom application ports). Remember Load balancing requires at least a port to be available, which will then be configured on the available port protocol.
  22. Advanced Options
  23. Allowing Agent install ensures Enabling alerts and logging for VM health and performance. And other ancillary tasks
  24. Specify the hostname or leave to be autogenerated one
  25. (Optional) Attach any Automation Workflows/Tasks for post/pre-provisioning tasks such as software installation, configuration, or monitoring setup.
  26. (Optional) Deployments to keep track of versions
  27. (Optional) Load Balancer: To Create as Load balancer Virtual Service to load balance service from the server. Note the ports available for this service will match the services already opened in the earlier portion of this page
  28. (Optional) Scale: Provide Scale Type and Threshold setting for scaling
  29. (Optional) Backups and Lifecycle
  30. Carefully review all configuration details to ensure accuracy and alignment with your deployment requirements.
  31. Click Complete to launch the VM. MTN Cloud will begin provisioning and display the instance status once deployment is underway.
  32. Navigate to: Provisioning → Instances and click on the VM being deployed (notice the green Rocket image) and watch the deployment process.
  33. VM Deployment ProcessVM Deployment Status
  34. Once deployment completes, Click on Network and toggle the button from Interfaces to Security Groups.
  35. Network Security Groups
  36. Click on Edit Security Groups to add the security group you created to the Default that is currently applied.
  37. To proceed, type the name into the Search Security Group box, click to select from the list that pops up.
  38. Edit Security Groups
  39. Click Save
  40. Click on the Summary tab to view your deployed VM. Take note of the details.
  41. VM Summary
  42. Accessing the VM should be via the Console or SSH (based on the use case above)
  43. VM Console Access

📝 Final Notes for Customers

  • Naming conventions: Use consistent names for keys, networks, and instances.
  • Documentation: Keep a record of IPs, credentials, and assigned resources.
  • SSH Keys: Used exclusively for Linux VMs, providing secure, password-less authentication.
  • Monitoring: Allowing Agent install ensures Enabling alerts and logging for VM health and performance.
  • Security Groups: Regularly review and update rules to follow the principle of least privilege.
  • You may reuse the SSH-Key, Security Groups and Username/Password for subsequent VM installation - based on your security consideration.