Deployment Overview of OpenCart on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the server must meet the following requirements:
-
Operating System: Compatible with Debian/Ubuntu or RedHat-based distributions (CentOS, Rocky Linux, AlmaLinux).
-
Privileges: Root or sudo access is required for package installation and service management.
-
Ports:
-
80(HTTP): Used by the proxy for SSL certificate challenges. -
443(HTTPS): The primary external port for secure web traffic. -
8080: Internal port used by the web server to communicate with the proxy.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template.
| Parameter | Value |
|---|---|
| Prefix | opencart |
| Domain | hostkey.in |
| Full template | opencart{Server_ID_from_Invapi}.hostkey.in/opencart |
File and Directory Structure¶
The deployment utilizes the following directory structure for configuration and application data:
-
/root/opencart/: Source files for the OpenCart installation. -
/var/www/html/opencart/: The web root containing the application files. -
/root/nginx/: Contains the Docker Compose configuration for the Nginx proxy. -
/data/nginx/user_conf.d/: Stores custom Nginx configuration files for specific domains. -
/etc/apache2/or/etc/httpd/: Web server configuration directories (distribution dependent).
Application Installation Process¶
The installation process varies depending on the operating system:
Debian and Ubuntu Systems¶
-
System Preparation: The system is updated, and necessary repositories (such as PHP PPA) are added. IPv6 is disabled via
sysctlto prevent connectivity issues. -
Dependency Installation: Packages including
apache2,mysql-server,php8,git, and various PHP extensions (php-gd,php-curl, etc.) are installed. -
Application Deployment:
-
The OpenCart source code (version 3.0.x.x) is cloned from GitHub to
/root/opencart/. -
Files are moved to the web root at
/var/www/html/opencart/. -
Configuration files (
config-dist.php) are renamed toconfig.phpin both the root and admin directories. -
Database Setup: A MySQL database named
opencartis created, along with a dedicated user for the application.
RedHat-based Systems (CentOS, Rocky, AlmaLinux)¶
-
System Preparation: EPEL and Remi repositories are enabled to provide modern PHP versions.
-
Dependency Installation: Packages including
httpd,mysql-server, and required PHP modules are installed via the package manager. -
Application Deployment:
-
The OpenCart source code is cloned from GitHub.
-
Files are moved to
/var/www/html/opencart/. -
Configuration files (
config-dist.php) are renamed toconfig.phpin both the root and admin directories. -
Database Setup: A MySQL database named
opencartis created, along with a dedicated user for the application.
Access Rights and Security¶
-
Firewall: On RedHat systems,
firewalldis configured to allow traffic on ports80/tcpand443/tcp. -
Web Server Permissions: The web root
/var/www/html/opencartand its contents are owned by thewww-data(Debian) orapache(RedHat) user/group to ensure proper execution. -
Internal Binding: To allow a Docker container to handle SSL, the local web server (Apache/httpd) is reconfigured to listen on an internal port (
8080) instead of the standard port80.
Databases¶
The application uses a MySQL/MariaDB database for data storage.
-
Database Name:
opencart -
Connection Method: Local socket connection.
-
User Management: A dedicated user is created with full privileges restricted to the
opencartdatabase.
Docker Containers and Their Deployment¶
The deployment utilizes a Docker container to manage SSL certificates via Nginx and Certbot.
Nginx-Certbot Container¶
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Environment Variables:
-
CERTBOT_EMAIL: Set via configuration (default:[email protected]). -
Volumes:
-
nginx_secrets:/etc/letsencrypt: For storing SSL certificates. -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d: For custom Nginx site configurations. -
Restart Policy:
unless-stopped
Custom Scripts and Additional Setup¶
The deployment includes several configuration adjustments to ensure the application functions correctly behind a reverse proxy:
-
Proxy Header Configuration: The web server is configured to honor
X-Forwarded-Protoheaders. This ensures that OpenCart recognizes incoming requests as HTTPS, even though the local connection between Nginx and Apache is HTTP. -
Nginx Proxy Headers: Custom configuration files are generated in
/data/nginx/user_conf.d/to include: -
proxy_set_header Host $host; -
proxy_set_header X-Forwarded-Proto $scheme;
Application Update Instructions¶
To update the main OpenCart application, follow these steps:
-
Manual Update: Since the application is installed via source files from GitHub, you must pull the latest changes into the
/root/opencart/directory and copy them to/var/www/html/opencart/. -
Configuration Preservation: Ensure that your
config.phpandadmin/config.phpfiles are backed up before overwriting application files.
Location of Configuration Files and Data¶
-
Application Configs:
/var/www/html/opencart/config.phpand/var/www/html/opencart/admin/config.php. -
Nginx Proxy Configs:
/data/nginx/user_conf.d/. -
Docker Compose File:
/root/nginx/compose.yml.
Available Ports for Connection¶
| Port | Service | Access Type |
|---|---|---|
80 | HTTP (Proxy) | External (SSL Challenge only) |
443 | HTTPS (Nginx Proxy) | External (Main Application Access) |
8080 | Apache/httpd | Internal Only |
Starting and Stopping the Application¶
-
Web Server (Debian):
-
systemctl restart apache2 -
Web Server (RedHat):
-
systemctl restart httpd -
Database:
-
systemctl restart mysqld -
Nginx Proxy Container:
-
Navigate to
/root/nginxand rundocker compose up -dordocker compose down.
Proxy Servers¶
The application is deployed behind an Nginx proxy container (jonasal/nginx-certbot) which handles SSL termination using Let's Encrypt. The proxy forwards requests to the local web server (Apache or httpd) running on port 8080.