Deployment Overview of LinuxPatch Appliance on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: A compatible Linux distribution with support for Docker.
-
Privileges: Root or sudo access is required to manage system services and directories.
-
Docker: The Docker engine must be installed and the service must be enabled and running.
-
Ports:
-
80(HTTP) - Required for web traffic and SSL certificate challenges. -
443(HTTPS) - Required for secure web traffic.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template within the hostkey.in zone.
| Parameter | Value |
|---|---|
| Prefix | linuxpatch |
| Domain | hostkey.in |
| Full template | linuxpatch{Server_ID}.hostkey.in |
File and Directory Structure¶
The application uses the following directory structure for configuration, data persistence, and logs:
-
/root/linuxpatch/: The main installation directory containing the deployment files and Docker Compose configuration. -
/root/linuxpatch/data/: Application data directory, including: -
data/.env: Configuration file containing environment variables and credentials. -
data/certs/: SSL/TLS certificates. -
data/logs/: Application log files. -
/data/nginx/user_conf.d/: Directory for Nginx proxy configurations.
Application Installation Process¶
The installation is performed using a combination of repository cloning and an automated configuration script:
-
Repository Setup: The application source code is cloned from
https://github.com/linuxpatch/self-hosted.gitinto the/root/linuxpatchdirectory. -
Configuration Generation: An installation script named
configure.shis executed. This script performs several critical actions: -
Creates necessary subdirectories (
data/certs,data/logs). -
Generates a unique
.envfile containing random credentials for the database, Redis, SMTP, and administrative access. -
Configures environment variables such as
DB_NAME,SESSION_SECRET, andADMIN_PASSWORD. -
Dynamically updates the
docker-compose.ymlfile with the newly generated credentials and domain information. -
Container Orchestration: The application is launched using Docker Compose to manage all required services.
Access Rights and Security¶
-
Firewall: Ensure that ports
80and443are open to allow incoming web traffic. -
Permissions:
-
Directories in
/root/linuxpatchare owned byroot. -
The application data directory is managed within the container environment for security.
-
Credentials: Administrative credentials (Username and Password) are generated during installation and displayed in the terminal upon completion.
Databases¶
The application utilizes two types of databases to manage state and persistence:
| Database Type | Service Name | Storage Location | Purpose |
|---|---|---|---|
| MySQL (Percona Server 8.0) | linuxpatch-db | linuxpatch-mysql-data volume | Primary application data |
| Redis 6 | linuxpatch-redis | linuxpatch-redis-data volume | Session and cache management |
Docker Containers and Their Deployment¶
The deployment consists of four main containers running on a bridge network named linuxpatch-app-network:
Nginx Proxy (SSL)¶
-
Image:
jonasal/nginx-certbot:latest -
Ports:
80:80,443:443 -
Volumes:
-
nginx_secrets:/etc/letsencrypt -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d -
Restart Policy:
unless-stopped
LinuxPatch Application¶
-
Image:
linuxpatch/appliance:latest -
Command:
./web -
Environment Variables: Includes database credentials, Redis settings, SMTP configuration, and TLS paths.
-
Volumes:
./data:/app/data -
Restart Policy:
unless-stopped
Database (Percona Server)¶
-
Image:
percona/percona-server:8.0 -
Environment Variables:
MYSQL_ROOT_PASSWORD,MYSQL_DATABASE,MYSQL_USER,MYSQL_PASSWORD. -
Volumes:
linuxpatch-mysql-data:/var/lib/mysql -
Restart Policy:
unless-stopped
Redis¶
-
Image:
redis:6 -
Command:
redis-server -
Volumes:
linuxpatch-redis-data:/data -
Restart Policy:
unless-stopped
Custom Scripts and Additional Setup¶
The deployment utilizes a custom installation script located at /root/linuxpatch/configure.sh.
Purpose of configure.sh:
-
Credential Generation: Uses
/dev/urandomto create high-entropy strings for the database, SMTP, and administrative accounts. -
Environment Management: Automatically creates the
.envfile used by the application container to maintain state between restarts. -
Dynamic Configuration: Modifies the
docker-compose.ymlfile on the fly to inject the correct hostnames, ports, and secrets into the service definitions.
Application Update Instructions¶
To update the main LinuxPatch application, execute the following commands in the installation directory:
This will pull the latest image for the application container and restart it with any updated configurations.
Location of Configuration Files and Data¶
| File/Directory | Path |
|---|---|
Main Config (.env) | /root/linuxpatch/data/.env |
| Application Logs | /root/linuxpatch/data/logs/ |
| SSL Certificates | /root/linuxpatch/data/certs/ |
| Docker Compose File | /root/linuxpatch/docker-compose.yml |
Available Ports for Connection¶
-
HTTPS:
443(Primary access via the configured FQDN) -
HTTP:
80(Used for redirection and SSL challenges)