Deployment Overview of Curiosity on Server¶
Prerequisites and Basic Requirements¶
The application requires a server running a Debian or Ubuntu-based operating system. The following packages and dependencies are installed during the setup process:
-
wget -
curl -
libc-dev -
libsnappy1v5
The deployment environment must have Docker installed to manage the application containers and the reverse proxy.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain generated based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | curiosity |
| Domain | hostkey.in |
| Full template | curiosity{Server_ID}.hostkey.in |
File and Directory Structure¶
The deployment utilizes the following directory structure for configuration and data persistence:
-
/root/nginx: Contains the Nginx reverse proxy configuration files and Docker Compose file. -
/root/curiosity: Contains the Curiosity application configuration files and Docker Compose file. -
/data/nginx/user_conf.d: Directory used for custom Nginx configurations. -
/data/nginx/nginx-certbot.env: Environment file containing Certbot credentials.
Application installation process¶
The installation follows a multi-stage deployment process:
-
System Preparation: The system packages are updated and upgraded, and required libraries (
libc-dev,libsnappy1v5) are installed via the package manager. -
Proxy Setup: A reverse proxy environment is initialized in
/root/nginxusing Docker Compose to handle SSL termination. -
Application Deployment: The Curiosity application workspace is initialized in
/root/curiosity. The deployment uses a specific Docker image:curiosityai/curiosity:70130.
Access Rights and Security¶
-
Firewall: The application is configured to listen on the standard HTTPS port (
443) via the reverse proxy. -
Internal Networking: The main application container is bound to
127.0.0.1on port8080, ensuring it is not directly accessible from the external network, only through the local proxy. -
SSL/TLS: SSL certificates are managed via Certbot and provided to the Nginx service through a shared Docker volume (
nginx_secrets).
Docker Containers and Their Deployment¶
The deployment consists of two primary containers:
Nginx Reverse Proxy¶
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Volumes:
-
nginx_secrets:/etc/letsencrypt -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d -
Environment Variables:
-
CERTBOT_EMAIL: Set via the configuration file for automated SSL management.
Curiosity Application¶
-
Image:
curiosityai/curiosity:70130 -
Container Name:
curiosity -
Ports:
127.0.0.1:8080 -> 8080 -
Restart Policy:
unless-stopped -
Volumes:
-
curiosity-data:/data -
Environment Variables:
-
MSK_GRAPH_STORAGE:/data/curiosity -
MSK_PUBLIC_ADDRESS: The full FQDN of the service. -
MSK_ADMIN_USER:admin -
MSK_ADMIN_EMAIL: Configured administrator email. -
MSK_ADMIN_PASSWORD: Administrator password.
Application Update Instructions¶
To update the Curiosity application, navigate to the application directory and perform a pull of the latest image followed by a restart of the services:
Location of configuration files and data¶
-
Application Data: Managed via Docker volume
curiosity-data. -
Nginx Configuration: Located in
/root/nginx/compose.ymland custom configs in/data/nginx/user_conf.d. -
SSL Certificates: Stored in the
nginx_secretsDocker volume.
Available ports for connection¶
| Port | Protocol | Description |
|---|---|---|
| 443 | TCP | Secure HTTPS access to the application via Nginx |
| 8080 | TCP | Internal application port (accessible only locally) |