Skip to content

Deployment Overview of LAMP on Server

This document provides a technical overview of the LAMP (Linux, Apache, MariaDB, PHP) stack deployment. The installation configures a web server environment with an integrated Nginx-based SSL proxy for automated certificate management via Certbot.

Prerequisites and Basic Requirements

The following requirements must be met for a successful deployment:

  • Operating System: Ubuntu or Debian based distributions.

  • Privileges: Root or sudo access is required to install packages and manage services.

  • Ports:

  • 443/TCP: External HTTPS traffic (managed by the Nginx container).

  • 80/TCP: External HTTP traffic (managed by the Nginx container for Let's Encrypt challenges).

  • 8080/TCP (or configured internal_port): Internal Apache service.

FQDN of the final panel on the hostkey.in domain

The application uses a specific domain template to assign a Fully Qualified Domain Name (FQDN) to the server.

Parameter Value
Prefix lamp
Domain hostkey.in
Full template lamp{Server_ID}.hostkey.in

File and Directory Structure

The deployment utilizes several specific locations for configuration and data persistence:

  • /root/nginx/: Contains the Docker Compose configuration for the SSL proxy.

  • /data/nginx/user_conf.d/: Stores Nginx virtual host configurations and custom headers.

  • /data/nginx/nginx-certbot.env: Environment file for the Nginx container.

  • /etc/apache2/: Standard Apache configuration directory, modified to listen on an internal port.

  • /var/www/html/: Default web root for Apache.

Application installation process

The installation follows a multi-step process involving package management and service reconfiguration:

  1. System Preparation: The system updates the package cache and ensures all existing apt locks are released.

  2. Web Server Installation: Apache is installed via the system package manager.

  3. Database Installation: MariaDB server and client are installed from official repositories (including specific mirrors for certain regions).

  4. PHP Installation:

  5. On Ubuntu: PHP 8.2 is installed via the ppa:ondrej/php repository, including modules for MySQL, Curl, and CGI.

  6. On Debian: The standard PHP package is installed from default repositories.

  7. Apache Reconfiguration: Apache is reconfigured to listen on an internal port (defaulting to 8080) instead of the standard port 80/443 to allow the Nginx proxy to handle external traffic. Headers for X-Forwarded-Proto are configured to ensure correct protocol detection behind the proxy.

  8. SSL Proxy Setup: A Docker container is deployed to manage SSL certificates and act as a reverse proxy.

Access Rights and Security

  • Firewall: The system relies on an external or local firewall to allow traffic on port 443 (HTTPS) and 80 (HTTP for Certbot).

  • Apache Security: Apache is bound to an internal loopback/internal interface to prevent direct exposure of the unencrypted service.

  • Nginx Proxy: The Nginx container handles SSL termination, ensuring that only encrypted traffic reaches the application via port 443.

Databases

The deployment includes a MariaDB server instance.

  • Connection Method: Localhost connection for applications hosted on the same machine.

  • Storage Location: Standard MariaDB data directories (e.g., /var/lib/mysql).

  • Settings: Configured via standard system package defaults.

Docker Containers and Their Deployment

The deployment utilizes a single primary container to manage SSL certificates and reverse proxying:

Container Name Image Ports Volumes Environment Variables Restart Policy
nginx jonasal/nginx-certbot:latest Host Network - nginx_secrets:/etc/letsencrypt
- /data/nginx/user_conf.d:/etc/nginx/user_conf.d
CERTBOT_EMAIL (from config) unless-stopped

Note: The container operates in network_mode: host to facilitate seamless communication with the local Apache service and for efficient certificate management.

Custom Scripts and Additional Setup

The following setup actions are performed during deployment:

  • Apache Header Configuration: A custom configuration file (remoteip-forwarded.conf) is created to ensure Apache correctly identifies the client's original protocol (HTTPS) when proxied.

  • Nginx Proxy Headers: The installation automatically injects proxy_set_header Host $host; and proxy_set_header X-Forwarded-Proto $scheme; into the Nginx configuration files to ensure proper routing and URL generation for the application.

  • Test File Creation: A info.php file is generated in /var/www/html/ to verify that PHP is functioning correctly.

Application Update Instructions

To update the core components of the stack:

  • Web Server (Apache) & PHP: Use the system package manager:

    sudo apt update && sudo apt upgrade
    

  • Database (MariaDB): Use the system package manager:

    sudo apt update && sudo apt upgrade mariadb-server
    

  • SSL Proxy (Nginx Container): To pull the latest version of the proxy container and apply changes, navigate to /root/nginx and run:

    docker compose pull && docker compose up -d
    

Location of configuration files and data

  • Apache Configs: /etc/apache2/

  • Nginx User Configs: /data/nginx/user_conf.d/

  • Docker Compose File: /root/nginx/compose.yml

  • Web Content: /var/www/html/

Available ports for connection

  • HTTPS (External): 443

  • HTTP (External - Certbot only): 80

  • Apache (Internal): 8080 (default)

Starting and Stopping the application

  • Apache:

  • Start: systemctl start apache2

  • Stop: systemctl stop apache2

  • Nginx Proxy Container:

  • Start/Restart: docker compose up -d (within /root/nginx)

  • Stop: docker compose down (within /root/nginx)

question_mark
Is there anything I can help you with?
question_mark
AI Assistant ×