Deployment Overview of Nginx on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Debian or Ubuntu.
-
Privileges: Root or sudo access is required for directory creation and Docker management.
-
Docker: Docker and Docker Compose must be installed on the host system.
-
Ports: The following ports must be open in the firewall to allow traffic:
-
80/TCP(HTTP) -
443/TCP(HTTPS)
FQDN of the final panel on the hostkey.in domain¶
The application uses a dynamic Fully Qualified Domain Name (FQDN) based on the server ID. The template for the domain is as follows:
| Parameter | Value |
|---|---|
| Prefix | nginx |
| Domain | hostkey.in |
| Full template | nginx{Server_ID}.hostkey.in |
File and Directory Structure¶
The application configuration and data are stored in the following locations:
-
/data/: Base directory for application data. -
/data/nginx/: Main application directory containing Docker Compose files and environment settings. -
/data/nginx/user_conf.d/: Contains custom Nginx configuration files. -
/etc/hosts: Modified to include the local loopback entry for the FQDN.
Application installation process¶
The installation is performed via a deployment script that executes the following steps:
-
Environment Preparation: Creates necessary directories (
/data,/data/nginx, and/data/nginx/user_conf.d) with specific permissions (0640). -
Host Configuration: Updates the
/etc/hostsfile to map the local FQDN to127.0.0.1. -
Configuration Generation:
-
Generates a
docker-compose.ymlfile in/data/nginx/. -
Generates a specific Nginx configuration file in
/data/nginx/user_conf.d/based on the server's FQDN. -
Environment Setup: Creates an environment file
nginx-certbot.envlocated in/data/nginx/. -
Volume Creation: Initializes a Docker volume named
nginx_secretsto manage SSL certificates securely. -
Service Deployment: Executes
docker compose up -dfrom the/data/nginx/directory to start the containers.
Access Rights and Security¶
-
Directory Permissions: Data directories are owned by
root:rootwith mode0640. -
SSL/TLS: The setup is configured to use Let's Encrypt certificates via Certbot for secure HTTPS communication.
-
Docker Volumes: Sensitive certificate data is stored in a dedicated Docker volume named
nginx_secrets.
Docker Containers and Their Deployment¶
The deployment utilizes the following container:
| Service | Image | Ports | Volumes | Environment Variables | Restart Policy |
|---|---|---|---|---|---|
| nginx | jonasal/nginx-certbot:latest | 80:80, 443:443 | - nginx_secrets:/etc/letsencrypt- ./user_conf.d:/etc/nginx/user_conf.d | [email protected] (via .env file) | unless-stopped |
Application Update Instructions¶
To update the Nginx application, navigate to the installation directory and run the following command: