Deployment Overview of Appwrite on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu or Debian.
-
Privileges: Root or sudo access is required for package installation and Docker management.
-
Docker: The
docker-compose-pluginmust be installed. -
Domain: A valid domain pointing to the server's IP address is required for SSL certificate acquisition via Certbot.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template based on the Server ID.
| Parameter | Value |
|---|---|
| Prefix | appwrite |
| Domain | hostkey.in |
| Full template | appwrite{Server_ID}.hostkey.in |
File and Directory Structure¶
The application uses the following directory structure for configuration and data persistence:
-
/opt/appwrite/: Main application directory containing deployment files. -
/data/nginx/: Configuration and environment files for the Nginx proxy. -
/data/nginx/user_conf.d/: Custom Nginx user configurations. -
/var/run/docker.sock: Docker socket used by Traefik for service discovery.
Application Installation Process¶
The installation is performed using a combination of system package management and Docker Compose:
-
System Preparation: The
docker-compose-pluginis installed via theaptpackage manager, and the/opt/appwritedirectory is created with0755permissions. -
Configuration Deployment: A
docker-compose.ymlfile and a.envconfiguration file are deployed to/opt/appwrite. -
Proxy Setup: An Nginx container is configured in
/data/nginxusing a dedicated compose file to handle SSL certificates via Certbot. -
Service Orchestration: The main application stack is started by executing
docker compose up -d --remove-orphanswithin the/opt/appwritedirectory.
Access Rights and Security¶
-
Firewall: Ports
80(HTTP) and443(HTTPS) must be open to allow web traffic. -
File Permissions: Configuration files in
/opt/appwrite/.envare restricted with0600permissions for security. -
Docker Security: The Traefik container is configured to only expose services that have the specific label
traefik.constraint-label-stack=appwrite.
Databases¶
The application utilizes two primary database systems:
| Database | Type | Purpose |
|---|---|---|
| MongoDB | NoSQL (Replica Set) | Primary application data storage |
| Redis | In-memory Data Store | Caching and session management |
Data for these databases is persisted in Docker volumes named appwrite-mongodb and appwrite-redis.
Docker Containers and Their Deployment¶
The deployment consists of several containers managed via Docker Compose.
Proxy and Edge Services¶
-
nginx:
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Purpose: SSL certificate management and Nginx proxying.
-
traefik:
-
Image:
traefik:3.6 -
Ports:
80,443(Internal port8080for local access) -
Volumes:
/var/run/docker.sock,appwrite-config,appwrite-certificates
Core Application Services¶
-
appwrite:
-
Image:
appwrite/appwrite:1.9.0 -
Purpose: The main Appwrite application engine.
-
appwrite-console:
-
Image:
appwrite/console:7.8.26 -
Purpose: Web-based management console (accessible via
/console). -
appwrite-realtime:
-
Image:
appwrite/appwrite:1.9.0 -
Entrypoint:
realtime -
Purpose: Real-time communication via WebSockets.
Worker and Task Services¶
The following containers run the appwrite/appwrite:1.9.0 image with specific entrypoints to handle background tasks:
-
appwrite-worker-audits: Handles audit logs.
-
appwrite-worker-webhooks: Processes webhooks.
-
appwrite-worker-deletes: Manages data deletion tasks.
-
appwrite-worker-databases: Database maintenance and migrations.
-
appwrite-worker-functions: Executes serverless functions.
-
appwrite-worker-mails: Handles email delivery.
-
appwrite-task-maintenance: Performs scheduled system maintenance.
Infrastructure Services¶
-
mongodb:
-
Image:
mongo:8.2.5 -
Purpose: Primary database (configured as a replica set).
-
redis:
-
Image:
redis:7.4.7-alpine -
Purpose: High-performance caching and task queuing.
-
openruntimes-executor:
-
Image:
openruntimes/executor:0.7.22 -
Purpose: Executes serverless functions in isolated environments.
Application Update Instructions¶
To update the main application, navigate to the installation directory and run the following commands:
This will pull the latest images defined in your configuration and restart the services with the updated versions.