Skip to content

Deployment Overview of JupyterLab on Server

Prerequisites and Basic Requirements

The application requires a server running Ubuntu to ensure compatibility with the installation process. The following system requirements and configurations must be met:

  • Operating System: Ubuntu

  • Privileges: Root or sudo access is required for package installation and service management.

  • Ports:

  • External Access: 443 (HTTPS)

  • Internal Service Port: 8888

FQDN of the final panel on the hostkey.in domain

The application is accessible via a specific subdomain template based on the server ID.

Parameter Value
Prefix lab
Domain hostkey.in
Full template lab{Server_ID}.hostkey.in

File and Directory Structure

The deployment utilizes several specific directories for data persistence, configuration, and system services:

  • /opt/data: Primary application data directory.

  • /opt/data/jupyter: Python virtual environment and Jupyter installation files.

  • /root/nginx: Configuration directory for the Nginx reverse proxy.

  • /data/nginx/user_conf.d: Custom Nginx configuration files.

  • /data/nginx/nginx-certbot.env: Environment variables for the Nginx container.

Application Installation Process

The installation follows a multi-step process involving system package management and Python environment setup:

  1. System Dependencies: The system installs python3, python3-pip, jupyter, and python3-virtualenv via the apt package manager.

  2. User Configuration: A dedicated system user named jupyter (UID 2841) is created to manage application processes securely.

  3. Virtual Environment Setup:

  4. A virtual environment is initialized in /opt/data/jupyter.

  5. The following Python packages are installed within the virtual environment: jupyterlab, jupyter-core, voila, and jupyter-server.

  6. Configuration Generation:

  7. Jupyter Lab configuration files are generated for the user.

  8. A specific security configuration is applied to allow cross-origin requests (c.ServerApp.allow_origin = '*').

  9. Service Registration: A systemd service file jupyterlab.service is created to manage the application as a background service.

Access Rights and Security

Security is managed through user isolation and SSL encryption:

  • User Isolation: The application runs under the jupyter user for data operations, while the proxy handles external traffic.

  • SSL/TLS: An Nginx container with Certbot integration is used to provide secure HTTPS access via Let's Encrypt certificates.

  • Firewall: Access is restricted to the standard HTTPS port (443).

Docker Containers and Their Deployment

The deployment utilizes a Docker container to manage reverse proxying and SSL certificate renewal:

Container Name Image Ports Volumes Restart Policy
nginx jonasal/nginx-certbot:latest Host Network Mode - nginx_secrets:/etc/letsencrypt
- /data/nginx/user_conf.d:/etc/nginx/user_conf.d
- /home:/home
unless-stopped

Custom Scripts and Additional Setup

The installation performs several automated setup actions:

  • Password Generation: An automated process generates a secure login password for the Jupyter interface during deployment.

  • Environment Configuration: The Nginx container is configured using an external environment file located at /data/nginx/nginx-certbot.env.

  • Service Initialization: The jupyterlab service is enabled to start automatically upon system boot.

Application Update Instructions

To update the main JupyterLab application, follow these steps:

  1. Ensure the virtual environment remains intact.

  2. Since the application is managed as a systemd service with a Python virtual environment, updates are typically performed by updating the packages within the virtual environment:

    /opt/data/jupyter/bin/pip install --upgrade jupyterlab jupyter-server
    

  3. Restart the service to apply changes:

    systemctl restart jupyterlab
    

Location of Configuration Files and Data

Component Path
Jupyter Lab Config /root/.jupyter/jupyter_lab_config.py
Application Data /opt/data
Virtual Environment /opt/data/jupyter
Nginx Compose File /root/nginx/compose.yml

Available Ports for Connection

  • HTTPS: 443 (via Nginx proxy)

  • Internal Jupyter Port: 8888 (accessible locally via the service)

Starting and Stopping the Application

The application is managed using systemctl.

To start the application:

systemctl start jupyterlab

To stop the application:

systemctl stop jupyterlab

To check the status of the application:

systemctl status jupyterlab

Proxy Servers

The deployment uses an nginx-certbot container acting as a reverse proxy. It handles SSL termination using Let's Encrypt certificates stored in the nginx_secrets volume and routes traffic to the JupyterLab service running on the host.

question_mark
Is there anything I can help you with?
question_mark
AI Assistant ×