Deployment Overview of Redmine on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: A Linux-based environment with Docker support.
-
Privileges: Root or sudo access is required for directory creation and service management.
-
Ports:
-
80(HTTP) for Let's Encrypt certificate challenges and redirection. -
443(HTTPS) for secure application access.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain generated based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | redmine |
| Domain | hostkey.in |
| Full template | redmine{Server_ID_from_Invapi}.hostkey.in |
File and Directory Structure¶
The following directory structure is maintained on the host system:
-
/opt/redmine: Application deployment directory containing the Docker Compose configuration. -
/data/nginx/user_conf.d/: Location for Nginx virtual host configurations. -
/data/nginx/nginx-certbot.env: Environment file used by the Nginx container. -
nginx_secrets(Docker Volume): External volume used to store SSL certificates and sensitive data.
Application Installation Process¶
The application is deployed using Docker Compose. The installation process involves:
-
Environment Preparation: Creation of the
/opt/redminedirectory with specific permissions (0644). -
Configuration Generation: A
docker-compose.ymlfile and an Nginx configuration file are generated in/opt/redmineand/data/nginx/user_conf.d/respectively. -
Service Orchestration: The deployment is initiated using the following command within the application directory:
Access Rights and Security¶
-
File Permissions: Configuration files in
/opt/redmineare owned byroot:rootwith mode0644. -
SSL/TLS: The deployment utilizes Certbot via a proxy container to manage SSL certificates. Traffic is encrypted using the certificates located in the
nginx_secretsvolume. -
Network Isolation: Application services communicate within a Docker network, with only the Nginx container exposing ports 80 and 443 to the host.
Databases¶
The application uses an embedded MySQL database container for data persistence.
| Parameter | Value |
|---|---|
| Database Engine | mysql:8.0 |
| Database Name | redmine |
| Connection Method | Internal Docker network (service name: db) |
Docker Containers and Their Deployment¶
The deployment consists of three primary containers managed via docker-compose.yml:
MySQL Container¶
-
Image:
mysql:8.0 -
Container Name:
redmine-mysql -
Restart Policy:
always -
Environment Variables:
-
MYSQL_ROOT_PASSWORD: System root password. -
MYSQL_DATABASE:redmine
Redmine Application Container¶
-
Image:
redmine -
Container Name:
redmine -
Restart Policy:
always -
Environment Variables:
-
REDMINE_DB_MYSQL:db -
REDMINE_DB_PASSWORD: Database password. -
REDMINE_SECRET_KEY_BASE: Unique application secret key.
Nginx Proxy Container¶
-
Image:
jonasal/nginx-certbot:latest -
Container Name:
redmine-nginx -
Restart Policy:
unless-stopped -
Ports:
-
80:80 -
443:443 -
Environment Variables:
-
CERTBOT_EMAIL:[email protected] -
Volumes:
-
nginx_secrets:/etc/letsencrypt -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d
Application Update Instructions¶
To update the Redmine application, navigate to the installation directory and pull the latest images before restarting the services:
Location of configuration files and data¶
-
Docker Compose File:
/opt/redmine/docker-compose.yml -
Nginx Configuration:
/data/nginx/user_conf.d/redmine{Server_ID}.hostkey.in.conf -
SSL Certificates: Managed within the
nginx_secretsDocker volume.
Available ports for connection¶
-
HTTPS:
443(Standard access via domain) -
HTTP:
80(Used for redirection and SSL challenges)