# Deploy a companion app beside WordPress

Assess server capacity, domain separation, app setup, and backup ownership. Both addresses resolve securely and a failure in one has a documented owner.

Canonical: https://xcloud.host/use-cases/playbooks/deploy-a-companion-app-beside-wordpress/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Assess server capacity, domain separation, app setup, and backup ownership.
For: business-owner, operator

## Requirements and responsibilities

- Have named ownership of the domain, selected xCloud team and site, and WordPress administrator access. For this scenario, agree who supplies the data and signs off: A WordPress site needs a separate internal tool while keeping public content independent. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- Use a compatible Nginx or OpenLiteSpeed stack for native WordPress. Verify current server resources, plan eligibility and each selected plugin or service license and requirements before installing; a Docker server does not host a new native WordPress site. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)
- Prepare a safe test identity and a completed, accessible backup before consequential changes. The important failure to plan around is: A one-click catalog listing does not guarantee installation through MCP. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/)
- Before any database copy or restore starts, the authorized operator restricts the target and quarantines outbound mail, payment, fulfillment and other provider effects. Restored settings may overwrite plugin suppression; reapply sandbox credentials and verify isolation before testing. Sources: [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/)

## Illustrative situation

Illustrative scenario, not a customer case study: A WordPress site needs a separate internal tool while keeping public content independent. Both addresses resolve securely and a failure in one has a documented owner.

## Choose the approach

- Choose separate domains, accounts and backups for the companion app. Verify the selected provider or plugin documentation and license against this requirement; xCloud hosting does not supply its business configuration. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- Keep application setup, domain/DNS ownership, mail delivery and external integrations with their named administrators. Use a plain documented path when a proposed integration cannot be demonstrated end to end. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

## Dashboard and application procedure

### 1. Specify the companion app boundary

**Where:** WordPress or selected plugin/app administrator

**Permissions:** Named WordPress or app administrator; business owner signs results.

**Inputs:** Owner, hostname, approved requirements, sample record and decision date. Specify the companion app boundary.

**Action:** Write its job, data exchanged with WordPress, authentication owner and failure behavior. Decide whether a simple link meets the need before promising integration.

**Expected result:** Both workloads have separate responsibilities.

**Verify:** The owner traces a sample record and names who may correct it.

**If it fails:** If no documented connection exists, keep systems independent.

Capability: Configure WordPress content, users and selected plugins
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

### 2. Check catalog and stack fit

**Where:** xCloud selected team/site resource view and owner planning sheet

**Permissions:** Named xCloud team/site administrator; verify the exact target.

**Inputs:** Target team/site, server or plugin version, license and documented prerequisites. Check catalog and stack fit.

**Action:** Inspect the current one-click catalog and upstream app requirements. Confirm Docker server, persistent storage, hostname and resource fit in the selected team.

**Expected result:** Deployment eligibility is established.

**Verify:** Record exact catalog entry, server stack, required inputs and dashboard path.

**If it fails:** If MCP lacks an install operation for the template, use dashboard deployment.

Capability: Confirm requirements and inspect resources
Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

### 3. Deploy through supported path

**Where:** xCloud Add site → current One-Click Apps catalog

**Permissions:** Named xCloud team/site dashboard administrator; verify the selected app and stack in the current catalog.

**Inputs:** Approved change scope, backup state, selected version and maintenance window. Deploy through supported path.

**Action:** In xCloud Add site → One-Click Apps, deploy the approved app with its own address and administrator. Complete first-run configuration inside the app.

**Expected result:** The companion opens securely with an authorized administrator.

**Verify:** Inspect site status, sign in and save a small persistent sample.

**If it fails:** If setup fails, review template logs and app docs before repeating installation.

Capability: Deploy selected catalog application in xCloud dashboard
Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

### 4. Test the link or integration

**Where:** WordPress public pages and relevant external provider

**Permissions:** Named WordPress or app administrator; business owner signs results.

**Inputs:** Test accounts, sample content or transaction, expected result and provider access. Test the link or integration.

**Action:** Add a WordPress link to the app and test destination, authentication and outage behavior from another browser session. If a separate integration is documented and selected, run its own sample-record test.

**Expected result:** Users reach the intended app without admin exposure.

**Verify:** For a plain link check destination and login only; compare records at both endpoints solely when a documented integration was installed.

**If it fails:** If synchronization is incomplete, publish only the supported link and document reconciliation.

Capability: Review a WordPress business journey
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

### 5. Plan independent recovery

**Where:** xCloud Docker Site Backup dashboard

**Permissions:** Named xCloud team/site administrator; verify the exact target.

**Inputs:** Observed results, unresolved failures, backup point and owner contacts. Plan independent recovery.

**Action:** Confirm separate WordPress and Docker backups, update owners and outage route. Docker capture may briefly stop the app; choose a window.

**Expected result:** Each system has a recoverable point.

**Verify:** Inspect two completed backup records and a safe recovery test for one record.

**If it fails:** If backup scope or restore access is unknown, defer a critical dependency on the integration.

Capability: Create and inspect Docker backups
Sources: [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Maintenance

- Assign a cadence for selected WordPress core, theme and plugin updates, review version-based findings and retest the path in this guide. In particular, repeat: Both addresses resolve securely and a failure in one has a documented owner. A chat prompt is not a scheduled task. Sources: [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/)
- Record actual backup completion, storage access and responsible staff. Recheck connected application and provider behavior after changes rather than relying on a site health status alone. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Recovery decisions

- Restore WordPress and the companion Docker application from their own verified points. Compare any exchanged records with data written since capture and decide whether to replay them before reconnecting the systems. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/)

## AI handoff

Connect xCloud MCP through the current documented profile and grant only the scopes needed for the selected team. Discover tool schemas first. Read resources to plan; require approval for any supported write. Use returned dashboard URLs for manual work. The packaged REST wrapper accepts GET requests only.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Configure WordPress content, users and selected plugins** (app; manual): Requires a named WordPress administrator or suitable editor. Plugin behavior, commercial license, payment, email and external integration are verified in the chosen vendor documentation and application; xCloud hosting or MCP reads do not configure them. Checkpoint: Open the actual WordPress or selected plugin interface, record the version and role, and have the business owner accept a real user journey. Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)
- **Deploy selected catalog application in xCloud dashboard** (dashboard; manual): Verify current catalog entry, compatible stack, domain and app prerequisites. An MCP resource read cannot establish installation support for a particular app or perform application setup. Checkpoint: Confirm the exact dashboard app, team, server, hostname and completed first-run setup before relying on it. Sources: [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Review a WordPress business journey** (app; manual): Application data and observed transactions cannot be inferred from xCloud resource reads. Use authorized test accounts and the application or provider evidence. Checkpoint: Record the test identity, timestamp, expected outcome, observed result and owner decision. Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- **Create and inspect Docker backups** (mcp; write): Backup capture briefly stops the app. Use supported local, S3-compatible or SFTP storage; the packaged REST wrapper is GET-only. Checkpoint: Confirm site, storage, retention and the interruption window before creating a backup or changing settings. Check terminal completion. Operation identifiers to discover: sites.docker.backup, sites.docker.backups, sites.docker.backupSettings.update. Scopes: read:sites, write:sites. Sources: [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/)

### Copyable agent brief

```text
Help with deploy a companion app beside wordpress for the exact xCloud team and site I name. First inspect only resources the connection permits and confirm returned identity, stack and relevant versions. Prepare the following authored workflow: Specify the companion app boundary; Check catalog and stack fit; Deploy through supported path; Test the link or integration; Plan independent recovery. Ask the named dashboard, domain, WordPress and application owners to perform operations outside connected capabilities. WordPress staging push/pull, native backup schedules, restore and cache settings remain manual dashboard tasks; the packaged REST wrapper is GET-only. Use the guide’s checks to report observed application evidence, unresolved questions and recovery implications; do not claim completion from a hosting resource read. Acceptance: Users reach the intended app without admin exposure.
```

### Manual checkpoints

- The named WordPress, app, dashboard or provider administrator performs the guide’s actual configuration step: In xCloud Add site → One-Click Apps, deploy the approved app with its own address and administrator. Complete first-run configuration inside the app.
- The business owner compares the controlled sample with this observable result: Users reach the intended app without admin exposure.
- Staging push/pull, native backup schedules, restores and cache-setting edits require the authorized xCloud dashboard operator; the packaged REST wrapper is GET-only.

## Feature coverage

- **business-acceptance** (covered): Both addresses resolve securely and a failure in one has a documented owner. Steps: phase-4
- **recovery** (covered): A one-click catalog listing does not guarantee installation through MCP. Steps: phase-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/) — reviewed 2026-09-30
- [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/) — reviewed 2026-09-30
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/) — reviewed 2026-09-30
- [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/) — reviewed 2026-09-30
- [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/) — reviewed 2026-09-30
- [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/) — reviewed 2026-09-30
- [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md) — reviewed 2026-09-30; v4.4.2

## Continue

[Explore the next WordPress workflow](https://xcloud.host/use-cases/for/wordpress-for-barbershops/)

- [Add an app subdomain beside a WordPress site](https://xcloud.host/use-cases/workflows/add-an-app-subdomain-beside-a-wordpress-site/)
- [Deploy a private analytics service beside WordPress](https://xcloud.host/use-cases/workflows/deploy-a-private-analytics-service-beside-wordpress/)
- [Deploy a knowledge base beside WordPress](https://xcloud.host/use-cases/workflows/deploy-a-knowledge-base-beside-wordpress/)
