Deployment Overview of Plane on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu (or compatible Linux distribution).
-
Privileges: Root or sudo access is required for package installation and directory management.
-
Domain: A valid domain managed via
hostkey.inis required for SSL certificate issuance. -
Ports:
-
Port
443: External HTTPS traffic. -
Port
8080: Internal application communication.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain generated based on the server's unique identifier.
| Parameter | Value |
|---|---|
| Prefix | plane |
| Domain | hostkey.in |
| Full template | plane{Server_ID_from_Invapi}.hostkey.in |
File and Directory Structure¶
The application uses the following directory structure for data persistence and configuration:
-
/opt/plane: Main application data directory. -
/root/nginx: Contains the Nginx proxy configuration files and Docker Compose setup. -
/root/plane-app/: Application environment configurations. -
/data/nginx/user_conf.d: Custom Nginx user configurations. -
/data/nginx/nginx-certbot.env: Environment variables for the SSL proxy.
Application installation process¶
The application is installed using a combination of system package management and a dedicated installation script:
-
System Preparation: The system packages are updated and upgraded via
apt. -
Directory Creation: The application data directory
/opt/planeis created with0755permissions. -
Script Acquisition: An official installation script (
setup.sh) is downloaded from the Plane GitHub repository to/root/install.sh. -
Automated Installation:
-
The installation script is executed to perform the initial setup (Action 1).
-
The application environment variables are modified to set
NGINX_PORTto8080and configureCORS_ALLOWED_ORIGINSto match the server's FQDN. -
The installation script is executed again to start the services (Action 2).
Access Rights and Security¶
-
Firewall: Only necessary ports (
443for HTTPS) should be exposed externally. -
Permissions: Data directories are set with
0755permissions to ensure proper ownership by the system user. -
CORS Policy: Cross-Origin Resource Sharing (CORS) is restricted specifically to the application's FQDN for security.
Docker Containers and Their Deployment¶
The deployment utilizes a containerized proxy service to handle SSL termination:
| Container Name | Image | Ports | Volumes | Environment Variables | Restart Policy |
|---|---|---|---|---|---|
nginx | jonasal/nginx-certbot:latest | Host Mode (443) | - nginx_secrets:/etc/letsencrypt- /data/nginx/user_conf.d:/etc/nginx/user_conf.d | [email protected] | unless-stopped |
Custom Scripts and Additional Setup¶
The deployment involves several configuration adjustments performed after the main installation:
-
Environment Configuration: The file
/root/plane-app/plane.envis modified to ensure the application correctly communicates with the Nginx proxy on port8080. -
CORS Configuration: The
CORS_ALLOWED_ORIGINSparameter in the environment configuration is dynamically set to the server's specific domain to allow secure browser-based access.
Application Update Instructions¶
To update the Plane application, you must re-run the installation script:
Follow the interactive prompts to select the appropriate action for updating the existing installation.
Location of configuration files and data¶
-
Application Data:
/opt/plane -
Environment Variables:
/root/plane-app/plane.env -
Nginx User Configs:
/data/nginx/user_conf.d
Available ports for connection¶
-
HTTPS (External):
443 -
HTTP (Internal Proxy):
8080
Starting and Stopping the application¶
The proxy service is managed via Docker Compose from the /root/nginx directory:
-
Start services:
-
Stop services: