Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.webhook-ubuntu-24-04-aec17966-3f3d-43d6-a232-84bce5cc0dda/image5_logolarge.png

webhook on Ubuntu 24.04 LTS

by cloudimg

webhook on Ubuntu 24.04: run commands from HTTP hooks, secure by default with a per VM secret

webhook is a lightweight, configurable tool written in Go that lets you create HTTP endpoints (hooks) on your server which run configured commands when they are called. It is the simple way to connect an external event to an action on your machine, such as a Git push triggering a deployment, a build job triggering a packaging step, or a monitoring alert triggering a remediation script. This cloudimg image runs webhook on Ubuntu 24.04 LTS as a hardened systemd service behind an nginx reverse proxy, security patched and kept current by unattended upgrades.

Because webhook runs commands in response to HTTP requests, this image is configured to be secure by default. It ships exactly one demonstration hook whose command is a fixed, non parameterised script that receives no request supplied data, so a caller can never inject a command. That hook is gated by a trigger rule requiring a secret matched from the X-Webhook-Token header, and that secret is generated uniquely on this virtual machine's first boot and never baked into the image, so a request without it is rejected with an HTTP 403 and the command is not run. webhook itself runs as a non root restricted user, hardened with systemd sandboxing, and is bound to loopback behind nginx rather than exposed directly.

Use this image as a ready base to define your own hooks: continuous deployment and build triggers, automated redeploys on a Git push, scheduled or event driven maintenance tasks, or any glue that should run a command when an HTTP endpoint is called. The paired deployment guide walks through triggering the demo hook, then defining and securing your own.

webhook is distributed under the MIT license, free and open source with no per CPU or per deployment fee. cloudimg is not affiliated with or endorsed by the webhook project; webhook is a mark of its owner. cloudimg provides packaging, the secure by default first boot posture with a per VM trigger secret and a fixed non parameterised demo command, security patching, and 24/7 support with a guaranteed 24 hour response SLA.

At a glance

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.webhook-ubuntu-24-04-aec17966-3f3d-43d6-a232-84bce5cc0dda/image6_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.webhook-ubuntu-24-04-aec17966-3f3d-43d6-a232-84bce5cc0dda/image0_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.webhook-ubuntu-24-04-aec17966-3f3d-43d6-a232-84bce5cc0dda/image2_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.webhook-ubuntu-24-04-aec17966-3f3d-43d6-a232-84bce5cc0dda/image3_screenshot04.png
English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies