Skip to content

Deployment Overview of NATS on Server

Prerequisites and Basic Requirements

To ensure a successful deployment, the following requirements must be met:

  • Operating System: Ubuntu

  • Privileges: Root or sudo access is required for service management and directory creation.

  • Docker: Docker engine must be installed to run the application containers.

  • Ports: The following ports must be open on the host firewall:

  • 4222: NATS Client communication.

  • 8222: NATS HTTP monitoring/management interface.

  • 443: HTTPS (via Nginx proxy).

FQDN of the final panel on the hostkey.in domain

The application is accessible via a specific subdomain template:

Parameter Value
Prefix nats
Domain hostkey.in
Full template nats{Server_ID}.hostkey.in

File and Directory Structure

The application uses the following directory structure for configuration and data persistence:

  • /opt/nats: Base directory for NATS.

  • /opt/nats/conf: Contains the server configuration file (nats-server.conf).

  • /opt/nats/data: Persistent storage directory for NATS data.

  • /root/nginx: Directory containing the Nginx reverse proxy configuration.

  • /data/nginx/user_conf.d: Directory for custom Nginx virtual host configurations.

Application Installation Process

The installation process involves setting up the environment, configuring the service, and deploying containers:

  1. System Preparation: The system is updated, and Docker is installed to support containerized deployment.

  2. Directory Creation: Required directories for configuration and data (/opt/nats/conf and /opt/nats/data) are created with 0755 permissions.

  3. Configuration Generation: A NATS server configuration file is generated at /opt/nats/conf/nats-server.conf. This file includes settings for client listeners, HTTP monitoring, and authentication (Token or User/Password mode). If JetStream is enabled, persistence settings are also configured.

  4. Service Configuration: A systemd unit file is created at /etc/systemd/system/nats.service to manage the NATS Docker container as a background service.

  5. Container Deployment: The NATS image is pulled from Docker Hub, and the container is started via the systemd service.

  6. Proxy Setup: An Nginx reverse proxy is deployed using Docker Compose to handle SSL termination and route traffic from port 443 to the internal monitoring port.

Access Rights and Security

  • Firewall: Only necessary ports (4222, 8222, 443) should be exposed.

  • Authentication: NATS supports multiple authentication modes:

  • Token Mode: Uses a pre-defined security token for authorization.

  • User/Password Mode: Requires a specific username and password for access.

  • Service Isolation: The NATS container runs with read-only access to its configuration file to prevent unauthorized runtime changes.

Docker Containers and Their Deployment

The deployment utilizes the following containers:

NATS Server

  • Image Name: nats:latest

  • Ports:

  • 4222 (Client)

  • 8222 (HTTP Monitoring)

  • Volumes:

  • /opt/nats/conf/nats-server.conf mapped to /etc/nats/nats-server.conf:ro

  • /opt/nats/data mapped to /data

  • Restart Policy: Always

Nginx Proxy (via Docker Compose)

  • Image Name: jonasal/nginx-certbot:latest

  • Network Mode: host

  • Volumes:

  • nginx_secrets:/etc/letsencrypt

  • /data/nginx/user_conf.d mapped to /etc/nginx/user_conf.d

  • Environment Variables:

  • [email protected]

Application Update Instructions

To update the NATS application, follow these steps:

  1. Pull the latest image:

    docker pull nats:latest
    

  2. Restart the service to apply changes:

    systemctl restart nats
    

Location of Configuration Files and Data

  • NATS Server Config: /opt/nats/conf/nats-server.conf

  • NATS Persistent Data: /opt/nats/data

  • Nginx User Configs: /data/nginx/user_conf.d/

  • Nginx Compose File: /root/nginx/compose.yml

Available Ports for Connection

Port Protocol Purpose
4222 TCP NATS Client Communication
8222 HTTP NATS Monitoring / Management API
443 HTTPS Secure Web Access (via Proxy)

Starting and Stopping the Application

The application is managed via systemctl:

  • Start NATS: sudo systemctl start nats

  • Stop NATS: sudo systemctl stop nats

  • Restart NATS: sudo systemctl restart nats

  • Check Status: sudo systemctl status nats

question_mark
Is there anything I can help you with?
question_mark
AI Assistant ×