Deployment Overview of JupyterLab on Server¶
Prerequisites and Basic Requirements¶
The application requires a server running Ubuntu to ensure compatibility with the installation process. The following system requirements and configurations must be met:
-
Operating System: Ubuntu
-
Privileges: Root or sudo access is required for package installation and service management.
-
Ports:
-
External Access:
443(HTTPS) -
Internal Service Port:
8888
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | lab |
| Domain | hostkey.in |
| Full template | lab{Server_ID}.hostkey.in |
File and Directory Structure¶
The deployment utilizes several specific directories for data persistence, configuration, and system services:
-
/opt/data: Primary application data directory. -
/opt/data/jupyter: Python virtual environment and Jupyter installation files. -
/root/nginx: Configuration directory for the Nginx reverse proxy. -
/data/nginx/user_conf.d: Custom Nginx configuration files. -
/data/nginx/nginx-certbot.env: Environment variables for the Nginx container.
Application Installation Process¶
The installation follows a multi-step process involving system package management and Python environment setup:
-
System Dependencies: The system installs
python3,python3-pip,jupyter, andpython3-virtualenvvia theaptpackage manager. -
User Configuration: A dedicated system user named
jupyter(UID2841) is created to manage application processes securely. -
Virtual Environment Setup:
-
A virtual environment is initialized in
/opt/data/jupyter. -
The following Python packages are installed within the virtual environment:
jupyterlab,jupyter-core,voila, andjupyter-server. -
Configuration Generation:
-
Jupyter Lab configuration files are generated for the user.
-
A specific security configuration is applied to allow cross-origin requests (
c.ServerApp.allow_origin = '*'). -
Service Registration: A systemd service file
jupyterlab.serviceis created to manage the application as a background service.
Access Rights and Security¶
Security is managed through user isolation and SSL encryption:
-
User Isolation: The application runs under the
jupyteruser for data operations, while the proxy handles external traffic. -
SSL/TLS: An Nginx container with Certbot integration is used to provide secure HTTPS access via Let's Encrypt certificates.
-
Firewall: Access is restricted to the standard HTTPS port (
443).
Docker Containers and Their Deployment¶
The deployment utilizes a Docker container to manage reverse proxying and SSL certificate renewal:
| Container Name | Image | Ports | Volumes | Restart Policy |
|---|---|---|---|---|
nginx | jonasal/nginx-certbot:latest | Host Network Mode | - nginx_secrets:/etc/letsencrypt- /data/nginx/user_conf.d:/etc/nginx/user_conf.d- /home:/home | unless-stopped |
Custom Scripts and Additional Setup¶
The installation performs several automated setup actions:
-
Password Generation: An automated process generates a secure login password for the Jupyter interface during deployment.
-
Environment Configuration: The Nginx container is configured using an external environment file located at
/data/nginx/nginx-certbot.env. -
Service Initialization: The
jupyterlabservice is enabled to start automatically upon system boot.
Application Update Instructions¶
To update the main JupyterLab application, follow these steps:
-
Ensure the virtual environment remains intact.
-
Since the application is managed as a systemd service with a Python virtual environment, updates are typically performed by updating the packages within the virtual environment:
-
Restart the service to apply changes:
Location of Configuration Files and Data¶
| Component | Path |
|---|---|
| Jupyter Lab Config | /root/.jupyter/jupyter_lab_config.py |
| Application Data | /opt/data |
| Virtual Environment | /opt/data/jupyter |
| Nginx Compose File | /root/nginx/compose.yml |
Available Ports for Connection¶
-
HTTPS:
443(via Nginx proxy) -
Internal Jupyter Port:
8888(accessible locally via the service)
Starting and Stopping the Application¶
The application is managed using systemctl.
To start the application:
To stop the application:
To check the status of the application:
Proxy Servers¶
The deployment uses an nginx-certbot container acting as a reverse proxy. It handles SSL termination using Let's Encrypt certificates stored in the nginx_secrets volume and routes traffic to the JupyterLab service running on the host.