Deployment Overview of TeamSpeak on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu (recommended).
-
Privileges: Root or sudo access is required for installing dependencies and managing Docker containers.
-
Network/Ports: The following ports must be open on the host firewall:
-
9987/udp: TeamSpeak Voice Service. -
10011,10022: Server Query (TCP). -
30033: File Transfer (FTP). -
41144: Application specific traffic. -
80/443: Web management interface access via Nginx proxy.
FQDN of the final panel on the hostkey.in domain¶
The web management interface is accessible via a specific subdomain. If no custom domain is provided, the following template is used:
| Parameter | Value |
|---|---|
| Prefix | teamspeak |
| Domain | hostkey.in |
| Full template | teamspeak{Server_ID}.hostkey.in |
File and Directory Structure¶
The application uses the following directory structure for data persistence and configuration:
-
/opt/teamspeak: Main TeamSpeak server data files. -
/opt/tsi-web: Data for the TS3-Manager web interface. -
/root/nginx: Configuration files for the Nginx reverse proxy. -
/data/nginx/user_conf.d: Custom Nginx configuration templates.
Application installation process¶
The application is deployed using a combination of system package management and Docker containers:
-
System Preparation: The server environment is prepared by installing Docker and necessary dependencies. A dedicated Docker bridge network named
bridgeis created to facilitate communication between services. -
Security Setup: A unique 32-byte hex string is generated via
opensslto serve as aJWT_SECRETfor secure authentication in the web manager. -
Data Directory Creation: The system creates required directories at
/opt/teamspeakand/opt/tsi-webwith appropriate permissions (0755). -
Container Deployment: Docker containers are pulled and started to run the TeamSpeak server, the Web Manager, and the Nginx reverse proxy.
-
SSL Provisioning: An Nginx container is deployed using a
compose.ymlfile located in/root/nginx. Certbot is used within this container to obtain SSL certificates via Let's Encrypt for the final domain.
Access Rights and Security¶
-
Firewall: Only necessary ports (Voice, Query, FTP, and Web) should be exposed.
-
Reverse Proxy: The web interface is protected by an Nginx reverse proxy that enforces HTTPS redirection from port 80 to 443.
-
Internal Networking: Containers communicate over a dedicated Docker bridge network.
Databases¶
The application does not utilize an external database server; instead, it relies on local file storage within the containers for data persistence.
Docker Containers and Their Deployment¶
The deployment consists of three primary containers:
TeamSpeak Server¶
-
Image:
teamspeak:latest -
Ports:
-
9987/udp->9987/udp -
10011->10011 -
10022->10022 -
30033->30033 -
41144->41144 -
Volumes:
/opt/teamspeak:/data -
Environment Variables:
-
TS3SERVER_LICENSE: "accept" -
Restart Policy:
unless-stopped
TS3-Manager (Web Interface)¶
-
Image:
joni1802/ts3-manager:v2.2.3 -
Ports:
8080:8080 -
Volumes:
/opt/tsi-web:/app/data -
Environment Variables:
-
PORT: "8080" -
JWT_SECRET: [Generated Secret] -
Restart Policy:
unless-stopped
Nginx Certbot Proxy¶
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Volumes:
-
nginx_secrets:/etc/letsencrypt -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d -
Environment Variables:
-
CERTBOT_EMAIL: [email protected] -
Restart Policy:
unless-stopped
Application Update Instructions¶
To update the main application components, perform the following steps:
-
TeamSpeak Server & TS3-Manager: Pull the latest images and restart the containers:
-
Nginx Proxy: To refresh SSL certificates or configurations, restart the Nginx container:
Location of configuration files and data¶
| Component | Data/Config Path |
|---|---|
| TeamSpeak Server Data | /opt/teamspeak |
| TS3-Manager Data | /opt/tsi-web |
| Nginx User Configs | /data/nginx/user_conf.d |
| SSL Certificates | Managed via Docker volume nginx_secrets |
Available ports for connection¶
-
Voice Connection:
9987(UDP) -
Web Management:
443(HTTPS) -
Server Query:
10011,10022(TCP) -
File Transfer:
30033(TCP)
Starting and Stopping the application¶
The services are managed via Docker. Use the following commands:
-
Stop all containers:
-
Start all containers: