Deployment Overview of Temporal on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following system requirements must be met:
-
Operating System: Debian or Ubuntu.
-
Privileges: Root or sudo access is required for package installation and Docker management.
-
Network/Ports:
-
443(HTTPS) for external traffic. -
8080(Internal application port). -
Various internal ports for microservices (7233, 9200, 5432, etc.).
FQDN of the final panel on the hostkey.in domain¶
The application is accessed via a specific subdomain template based on the server ID:
| Parameter | Value |
|---|---|
| Prefix | temporal |
| Domain | hostkey.in |
| Full template | temporal{Server_ID}.hostkey.in |
File and Directory Structure¶
The deployment utilizes several specific directories for configuration and data persistence:
-
/root/docker-compose: Contains the core Temporal Docker Compose files. -
/root/nginx: Stores Nginx configurations and SSL management files. -
/data/nginx/user_conf.d: Contains custom Nginx virtual host configurations. -
/data/grafana: Directory for Grafana configuration files (grafana.ini).
Application Installation Process¶
The installation is performed through a series of automated steps that prepare the environment and deploy the containerized stack:
-
System Preparation: The system packages are updated and upgraded via
apt. -
Container Engine Setup: Docker and Docker Compose are installed on the host.
-
Repository Acquisition: The official Temporal Docker Compose repository is cloned to
/root/docker-compose. -
Environment Configuration:
-
A shell alias for
tctlis created in.bashrcto allow direct interaction with the admin tools container:alias tctl="docker exec temporal-admin-tools tctl". -
The Loki Docker driver is installed to enable centralized logging via Grafana.
-
Proxy and SSL Setup:
-
An Nginx instance is configured using a specialized Docker image (
jonasal/nginx-certbot) to handle SSL certificates via Let's Encrypt. -
Custom Nginx configuration files are generated to route traffic to the application, Grafana, and Prometheus.
-
Service Deployment: The main Temporal stack is launched using
docker composefrom the/root/docker-composedirectory.
Access Rights and Security¶
-
Firewall: Only necessary ports (primarily 443) should be exposed to the public internet.
-
SSL/TLS: All external traffic is secured via SSL certificates managed by Certbot within a Docker container.
-
Logging Driver: The
lokidriver is used for all application containers to ensure logs are forwarded to the Loki service.
Databases¶
The deployment includes several database and storage components:
| Component | Type/Image | Purpose |
|---|---|---|
| PostgreSQL | postgres | Primary relational database for Temporal metadata and history. |
| Elasticsearch | elasticsearch | Used for visibility and advanced search capabilities within Temporal. |
| Loki | grafana/loki | Centralized log aggregation. |
Docker Containers and Their Deployment¶
The deployment consists of multiple containers running on a dedicated bridge network named temporal-network.
Core Application Containers¶
| Container Name | Image | Ports (Published) | Purpose |
|---|---|---|---|
temporal-history | temporalio/auto-setup:${TEMPORAL_VERSION} | 7234, 8000 | Manages event history. |
temporal-matching | temporalio/server:${TEMPORAL_VERSION} | 7235, 8001 | Handles task matching. |
temporal-frontend | temporalio/server:${TEMPORAL_VERSION} | 7237, 8002 | Primary gRPC frontend. |
temporal-frontend2 | temporalio/server:${TEMPORAL_VERSION} | 7236, 8004 | Secondary frontend for high availability. |
temporal-worker | temporalio/server:${TEMPORAL_VERSION} | 7232, 8003 | Processes tasks and workflows. |
temporal-ui | temporalio/ui:${TEMPORAL_UI_VERSION} | 8080 | Web interface for Temporal. |
temporal-admin-tools | temporalio/admin-tools:${TEMPORAL_ADMINTOOLS_VERSION} | N/A | CLI tools (tctl). |
Infrastructure and Observability Containers¶
| Container Name | Image | Ports (Published) | Purpose |
|---|---|---|---|
loki | grafana/loki:latest | 3100 | Log aggregation. |
elasticsearch | elasticsearch:${ELASTICSEARCH_VERSION} | 9200 | Search and visibility engine. |
postgresql | postgres:${POSTGRESQL_VERSION} | ${POSTGRES_DEFAULT_PORT} | Relational data storage. |
prometheus | prom/prometheus:v2.37.0 | 9090 | Metrics collection. |
grafana | grafana/grafana:7.5.16 | 8085 | Data visualization dashboard. |
jaeger-all-in-one | jaegertracing/all-in-one:1.37 | 16686, 14268, 14250 | Distributed tracing. |
otel-collector | otel/opentelemetry-collector:0.47.0 | 1888, 13133, 4317, 55670 | OpenTelemetry data processing. |
temporal-nginx | nginx:1.22.1 | 7233 | Internal gRPC/HTTP proxy. |
Proxy Container¶
| Container Name | Image | Ports (Published) | Purpose |
|---|---|---|---|
nginx | jonasal/nginx-certbot:latest | Host Network | SSL termination and reverse proxy. |
Custom Scripts and Additional Setup¶
The deployment performs several non-standard configuration actions:
-
Log Routing: All application containers are configured with a custom logging driver to push logs directly to the
lokiservice viahost.docker.internal. -
Dynamic Configuration: Temporal services use dynamic configuration files located in
./dynamicconfigwithin the project directory. -
Nginx Upstreams: Custom Nginx upstream blocks are created for
grafanaandprometheusto allow them to be served under specific URL paths (e.g.,/grafana/and/prometheus/).
Application Update Instructions¶
To update the main Temporal application, perform the following steps:
-
Navigate to the deployment directory:
-
Pull the latest images defined in your configuration:
-
Restart the services to apply changes:
Location of Configuration Files and Data¶
| Type | Path / Source |
|---|---|
| Main Compose File | /root/docker-compose/docker-compose-multirole_edited.yaml |
| Nginx Configs | /data/nginx/user_conf.d/ |
| Grafana Config | /data/grafana/grafana.ini |
| PostgreSQL Data | Docker Volume (managed by Docker) |
| Temporal Dynamic Config | /root/docker-compose/dynamicconfig/ |
Available Ports for Connection¶
-
Web UI:
8080(via Nginx proxy on port 443). -
gRPC API:
7233(via Nginx proxy on port 443). -
Grafana Dashboard: Accessible via
/grafana/path on the main domain. -
Prometheus Metrics: Accessible via
/prometheus/path on the main domain.