Deployment Overview of OpenSearch on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu
-
Privileges: Root or sudo access is required for installing Docker and managing system services.
-
Network/Ports:
-
9200: OpenSearch API (Internal) -
9600: OpenSearch Performance Analyzer (Internal) -
5601: OpenSearch Dashboards (Internal) -
443: HTTPS Access (External via Nginx Proxy)
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template based on your server ID:
| Parameter | Value |
|---|---|
| Prefix | opensearch |
| Domain | hostkey.in |
| Full template | opensearch{Server_ID}.hostkey.in |
File and Directory Structure¶
The deployment utilizes the following directory structure for configuration and data persistence:
-
/home/{{user}}/opensearch-project/: Main application directory containing Docker Compose files and persistent data. -
/home/{{user}}/opensearch-project/opensearch-data/: Persistent storage for OpenSearch indices and data. -
/root/nginx/: Directory containing the Nginx reverse proxy configuration. -
/data/nginx/user_conf.d/: Configuration directory for SSL certificates and site-specific Nginx settings.
Application installation process¶
The application is deployed using a combination of system package management and Docker Compose:
-
System Dependencies: The
dockerengine anddocker-composeare installed via theaptpackage manager. -
Project Setup: A dedicated project directory is created in the user's home folder to isolate OpenSearch files.
-
Container Orchestration: The application services are deployed using a
docker-compose.ymlfile located in/home/{{user}}/opensearch-project/. -
Reverse Proxy Configuration: An Nginx container is configured with SSL certificates via Certbot and acts as a reverse proxy for the OpenSearch Dashboards service.
Access Rights and Security¶
-
Firewall: Only essential ports are exposed to the host. The application relies on an Nginx proxy to handle secure HTTPS traffic on port
443. -
User Permissions: Project files are owned by the deployment user with specific permissions (
0666for the compose file) to ensure proper execution.
Databases¶
OpenSearch functions as a distributed search and analytics engine. The data is stored locally within the containerized environment:
-
Storage Location:
./opensearch-data(relative to the project directory). -
Engine: OpenSearch 2.17.0.
Docker Containers and Their Deployment¶
The deployment consists of three primary containers:
OpenSearch Node¶
-
Image:
opensearchproject/opensearch:2.17.0 -
Container Name:
opensearch-node1 -
Ports:
-
9200:9200 -
9600:9600 -
Environment Variables:
-
discovery.type=single-node -
bootstrap.memory_lock=true -
OPENSEARCH_JAVA_OPTS=-Xms512m -Xmx512m -
OPENSEARCH_INITIAL_ADMIN_PASSWORD={password} -
Volumes:
./opensearch-data:/usr/share/opensearch/data -
Restart Policy: Default (Docker Compose)
OpenSearch Dashboards¶
-
Image:
opensearchproject/opensearch-dashboards:2.17.0 -
Container Name:
opensearch-dashboards -
Ports:
5601:5601 -
Environment Variables:
-
OPENSEARCH_HOSTS=["https://opensearch-node1:9200"] -
Networks:
opensearch-net
Nginx Proxy¶
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Volumes:
-
nginx_secrets:/etc/letsencrypt -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d -
Environment Variables:
Application Update Instructions¶
To update the OpenSearch application, navigate to the project directory and pull the latest images: