Deployment Overview of NATS on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu
-
Privileges: Root or sudo access is required for service management and directory creation.
-
Docker: Docker engine must be installed to run the application containers.
-
Ports: The following ports must be open on the host firewall:
-
4222: NATS Client communication. -
8222: NATS HTTP monitoring/management interface. -
443: HTTPS (via Nginx proxy).
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template:
| Parameter | Value |
|---|---|
| Prefix | nats |
| Domain | hostkey.in |
| Full template | nats{Server_ID}.hostkey.in |
File and Directory Structure¶
The application uses the following directory structure for configuration and data persistence:
-
/opt/nats: Base directory for NATS. -
/opt/nats/conf: Contains the server configuration file (nats-server.conf). -
/opt/nats/data: Persistent storage directory for NATS data. -
/root/nginx: Directory containing the Nginx reverse proxy configuration. -
/data/nginx/user_conf.d: Directory for custom Nginx virtual host configurations.
Application Installation Process¶
The installation process involves setting up the environment, configuring the service, and deploying containers:
-
System Preparation: The system is updated, and Docker is installed to support containerized deployment.
-
Directory Creation: Required directories for configuration and data (
/opt/nats/confand/opt/nats/data) are created with0755permissions. -
Configuration Generation: A NATS server configuration file is generated at
/opt/nats/conf/nats-server.conf. This file includes settings for client listeners, HTTP monitoring, and authentication (Token or User/Password mode). If JetStream is enabled, persistence settings are also configured. -
Service Configuration: A systemd unit file is created at
/etc/systemd/system/nats.serviceto manage the NATS Docker container as a background service. -
Container Deployment: The NATS image is pulled from Docker Hub, and the container is started via the systemd service.
-
Proxy Setup: An Nginx reverse proxy is deployed using Docker Compose to handle SSL termination and route traffic from port 443 to the internal monitoring port.
Access Rights and Security¶
-
Firewall: Only necessary ports (
4222,8222,443) should be exposed. -
Authentication: NATS supports multiple authentication modes:
-
Token Mode: Uses a pre-defined security token for authorization.
-
User/Password Mode: Requires a specific username and password for access.
-
Service Isolation: The NATS container runs with read-only access to its configuration file to prevent unauthorized runtime changes.
Docker Containers and Their Deployment¶
The deployment utilizes the following containers:
NATS Server¶
-
Image Name:
nats:latest -
Ports:
-
4222(Client) -
8222(HTTP Monitoring) -
Volumes:
-
/opt/nats/conf/nats-server.confmapped to/etc/nats/nats-server.conf:ro -
/opt/nats/datamapped to/data -
Restart Policy: Always
Nginx Proxy (via Docker Compose)¶
-
Image Name:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Volumes:
-
nginx_secrets:/etc/letsencrypt -
/data/nginx/user_conf.dmapped to/etc/nginx/user_conf.d -
Environment Variables:
Application Update Instructions¶
To update the NATS application, follow these steps:
-
Pull the latest image:
-
Restart the service to apply changes:
Location of Configuration Files and Data¶
-
NATS Server Config:
/opt/nats/conf/nats-server.conf -
NATS Persistent Data:
/opt/nats/data -
Nginx User Configs:
/data/nginx/user_conf.d/ -
Nginx Compose File:
/root/nginx/compose.yml
Available Ports for Connection¶
| Port | Protocol | Purpose |
|---|---|---|
4222 | TCP | NATS Client Communication |
8222 | HTTP | NATS Monitoring / Management API |
443 | HTTPS | Secure Web Access (via Proxy) |
Starting and Stopping the Application¶
The application is managed via systemctl:
-
Start NATS:
sudo systemctl start nats -
Stop NATS:
sudo systemctl stop nats -
Restart NATS:
sudo systemctl restart nats -
Check Status:
sudo systemctl status nats