Skip to content

Deployment Overview of Temporal on Server

Prerequisites and Basic Requirements

To ensure a successful deployment, the following system requirements must be met:

  • Operating System: Debian or Ubuntu.

  • Privileges: Root or sudo access is required for package installation and Docker management.

  • Network/Ports:

  • 443 (HTTPS) for external traffic.

  • 8080 (Internal application port).

  • Various internal ports for microservices (7233, 9200, 5432, etc.).

FQDN of the final panel on the hostkey.in domain

The application is accessed via a specific subdomain template based on the server ID:

Parameter Value
Prefix temporal
Domain hostkey.in
Full template temporal{Server_ID}.hostkey.in

File and Directory Structure

The deployment utilizes several specific directories for configuration and data persistence:

  • /root/docker-compose: Contains the core Temporal Docker Compose files.

  • /root/nginx: Stores Nginx configurations and SSL management files.

  • /data/nginx/user_conf.d: Contains custom Nginx virtual host configurations.

  • /data/grafana: Directory for Grafana configuration files (grafana.ini).

Application Installation Process

The installation is performed through a series of automated steps that prepare the environment and deploy the containerized stack:

  1. System Preparation: The system packages are updated and upgraded via apt.

  2. Container Engine Setup: Docker and Docker Compose are installed on the host.

  3. Repository Acquisition: The official Temporal Docker Compose repository is cloned to /root/docker-compose.

  4. Environment Configuration:

  5. A shell alias for tctl is created in .bashrc to allow direct interaction with the admin tools container: alias tctl="docker exec temporal-admin-tools tctl".

  6. The Loki Docker driver is installed to enable centralized logging via Grafana.

  7. Proxy and SSL Setup:

  8. An Nginx instance is configured using a specialized Docker image (jonasal/nginx-certbot) to handle SSL certificates via Let's Encrypt.

  9. Custom Nginx configuration files are generated to route traffic to the application, Grafana, and Prometheus.

  10. Service Deployment: The main Temporal stack is launched using docker compose from the /root/docker-compose directory.

Access Rights and Security

  • Firewall: Only necessary ports (primarily 443) should be exposed to the public internet.

  • SSL/TLS: All external traffic is secured via SSL certificates managed by Certbot within a Docker container.

  • Logging Driver: The loki driver is used for all application containers to ensure logs are forwarded to the Loki service.

Databases

The deployment includes several database and storage components:

Component Type/Image Purpose
PostgreSQL postgres Primary relational database for Temporal metadata and history.
Elasticsearch elasticsearch Used for visibility and advanced search capabilities within Temporal.
Loki grafana/loki Centralized log aggregation.

Docker Containers and Their Deployment

The deployment consists of multiple containers running on a dedicated bridge network named temporal-network.

Core Application Containers

Container Name Image Ports (Published) Purpose
temporal-history temporalio/auto-setup:${TEMPORAL_VERSION} 7234, 8000 Manages event history.
temporal-matching temporalio/server:${TEMPORAL_VERSION} 7235, 8001 Handles task matching.
temporal-frontend temporalio/server:${TEMPORAL_VERSION} 7237, 8002 Primary gRPC frontend.
temporal-frontend2 temporalio/server:${TEMPORAL_VERSION} 7236, 8004 Secondary frontend for high availability.
temporal-worker temporalio/server:${TEMPORAL_VERSION} 7232, 8003 Processes tasks and workflows.
temporal-ui temporalio/ui:${TEMPORAL_UI_VERSION} 8080 Web interface for Temporal.
temporal-admin-tools temporalio/admin-tools:${TEMPORAL_ADMINTOOLS_VERSION} N/A CLI tools (tctl).

Infrastructure and Observability Containers

Container Name Image Ports (Published) Purpose
loki grafana/loki:latest 3100 Log aggregation.
elasticsearch elasticsearch:${ELASTICSEARCH_VERSION} 9200 Search and visibility engine.
postgresql postgres:${POSTGRESQL_VERSION} ${POSTGRES_DEFAULT_PORT} Relational data storage.
prometheus prom/prometheus:v2.37.0 9090 Metrics collection.
grafana grafana/grafana:7.5.16 8085 Data visualization dashboard.
jaeger-all-in-one jaegertracing/all-in-one:1.37 16686, 14268, 14250 Distributed tracing.
otel-collector otel/opentelemetry-collector:0.47.0 1888, 13133, 4317, 55670 OpenTelemetry data processing.
temporal-nginx nginx:1.22.1 7233 Internal gRPC/HTTP proxy.

Proxy Container

Container Name Image Ports (Published) Purpose
nginx jonasal/nginx-certbot:latest Host Network SSL termination and reverse proxy.

Custom Scripts and Additional Setup

The deployment performs several non-standard configuration actions:

  • Log Routing: All application containers are configured with a custom logging driver to push logs directly to the loki service via host.docker.internal.

  • Dynamic Configuration: Temporal services use dynamic configuration files located in ./dynamicconfig within the project directory.

  • Nginx Upstreams: Custom Nginx upstream blocks are created for grafana and prometheus to allow them to be served under specific URL paths (e.g., /grafana/ and /prometheus/).

Application Update Instructions

To update the main Temporal application, perform the following steps:

  1. Navigate to the deployment directory:

    cd /root/docker-compose
    

  2. Pull the latest images defined in your configuration:

    docker compose pull
    

  3. Restart the services to apply changes:

    docker compose up -d
    

Location of Configuration Files and Data

Type Path / Source
Main Compose File /root/docker-compose/docker-compose-multirole_edited.yaml
Nginx Configs /data/nginx/user_conf.d/
Grafana Config /data/grafana/grafana.ini
PostgreSQL Data Docker Volume (managed by Docker)
Temporal Dynamic Config /root/docker-compose/dynamicconfig/

Available Ports for Connection

  • Web UI: 8080 (via Nginx proxy on port 443).

  • gRPC API: 7233 (via Nginx proxy on port 443).

  • Grafana Dashboard: Accessible via /grafana/ path on the main domain.

  • Prometheus Metrics: Accessible via /prometheus/ path on the main domain.

question_mark
Is there anything I can help you with?
question_mark
AI Assistant ×