Skip to content

Deployment Overview of LinuxPatch Appliance on Server

Prerequisites and Basic Requirements

To ensure a successful deployment, the following requirements must be met:

  • Operating System: A compatible Linux distribution with support for Docker.

  • Privileges: Root or sudo access is required to manage system services and directories.

  • Docker: The Docker engine must be installed and the service must be enabled and running.

  • Ports:

  • 80 (HTTP) - Required for web traffic and SSL certificate challenges.

  • 443 (HTTPS) - Required for secure web traffic.

FQDN of the final panel on the hostkey.in domain

The application is accessible via a specific subdomain template within the hostkey.in zone.

Parameter Value
Prefix linuxpatch
Domain hostkey.in
Full template linuxpatch{Server_ID}.hostkey.in

File and Directory Structure

The application uses the following directory structure for configuration, data persistence, and logs:

  • /root/linuxpatch/: The main installation directory containing the deployment files and Docker Compose configuration.

  • /root/linuxpatch/data/: Application data directory, including:

  • data/.env: Configuration file containing environment variables and credentials.

  • data/certs/: SSL/TLS certificates.

  • data/logs/: Application log files.

  • /data/nginx/user_conf.d/: Directory for Nginx proxy configurations.

Application Installation Process

The installation is performed using a combination of repository cloning and an automated configuration script:

  1. Repository Setup: The application source code is cloned from https://github.com/linuxpatch/self-hosted.git into the /root/linuxpatch directory.

  2. Configuration Generation: An installation script named configure.sh is executed. This script performs several critical actions:

  3. Creates necessary subdirectories (data/certs, data/logs).

  4. Generates a unique .env file containing random credentials for the database, Redis, SMTP, and administrative access.

  5. Configures environment variables such as DB_NAME, SESSION_SECRET, and ADMIN_PASSWORD.

  6. Dynamically updates the docker-compose.yml file with the newly generated credentials and domain information.

  7. Container Orchestration: The application is launched using Docker Compose to manage all required services.

Access Rights and Security

  • Firewall: Ensure that ports 80 and 443 are open to allow incoming web traffic.

  • Permissions:

  • Directories in /root/linuxpatch are owned by root.

  • The application data directory is managed within the container environment for security.

  • Credentials: Administrative credentials (Username and Password) are generated during installation and displayed in the terminal upon completion.

Databases

The application utilizes two types of databases to manage state and persistence:

Database Type Service Name Storage Location Purpose
MySQL (Percona Server 8.0) linuxpatch-db linuxpatch-mysql-data volume Primary application data
Redis 6 linuxpatch-redis linuxpatch-redis-data volume Session and cache management

Docker Containers and Their Deployment

The deployment consists of four main containers running on a bridge network named linuxpatch-app-network:

Nginx Proxy (SSL)

  • Image: jonasal/nginx-certbot:latest

  • Ports: 80:80, 443:443

  • Volumes:

  • nginx_secrets:/etc/letsencrypt

  • /data/nginx/user_conf.d:/etc/nginx/user_conf.d

  • Restart Policy: unless-stopped

LinuxPatch Application

  • Image: linuxpatch/appliance:latest

  • Command: ./web

  • Environment Variables: Includes database credentials, Redis settings, SMTP configuration, and TLS paths.

  • Volumes: ./data:/app/data

  • Restart Policy: unless-stopped

Database (Percona Server)

  • Image: percona/percona-server:8.0

  • Environment Variables: MYSQL_ROOT_PASSWORD, MYSQL_DATABASE, MYSQL_USER, MYSQL_PASSWORD.

  • Volumes: linuxpatch-mysql-data:/var/lib/mysql

  • Restart Policy: unless-stopped

Redis

  • Image: redis:6

  • Command: redis-server

  • Volumes: linuxpatch-redis-data:/data

  • Restart Policy: unless-stopped

Custom Scripts and Additional Setup

The deployment utilizes a custom installation script located at /root/linuxpatch/configure.sh.

Purpose of configure.sh:

  • Credential Generation: Uses /dev/urandom to create high-entropy strings for the database, SMTP, and administrative accounts.

  • Environment Management: Automatically creates the .env file used by the application container to maintain state between restarts.

  • Dynamic Configuration: Modifies the docker-compose.yml file on the fly to inject the correct hostnames, ports, and secrets into the service definitions.

Application Update Instructions

To update the main LinuxPatch application, execute the following commands in the installation directory:

docker compose pull linuxpatch-app && docker compose up -d

This will pull the latest image for the application container and restart it with any updated configurations.

Location of Configuration Files and Data

File/Directory Path
Main Config (.env) /root/linuxpatch/data/.env
Application Logs /root/linuxpatch/data/logs/
SSL Certificates /root/linuxpatch/data/certs/
Docker Compose File /root/linuxpatch/docker-compose.yml

Available Ports for Connection

  • HTTPS: 443 (Primary access via the configured FQDN)

  • HTTP: 80 (Used for redirection and SSL challenges)

question_mark
Is there anything I can help you with?
question_mark
AI Assistant ×