Deployment Overview of LAMP on Server¶
This document provides a technical overview of the LAMP (Linux, Apache, MariaDB, PHP) stack deployment. The installation configures a web server environment with an integrated Nginx-based SSL proxy for automated certificate management via Certbot.
Prerequisites and Basic Requirements¶
The following requirements must be met for a successful deployment:
-
Operating System: Ubuntu or Debian based distributions.
-
Privileges: Root or sudo access is required to install packages and manage services.
-
Ports:
-
443/TCP: External HTTPS traffic (managed by the Nginx container). -
80/TCP: External HTTP traffic (managed by the Nginx container for Let's Encrypt challenges). -
8080/TCP(or configuredinternal_port): Internal Apache service.
FQDN of the final panel on the hostkey.in domain¶
The application uses a specific domain template to assign a Fully Qualified Domain Name (FQDN) to the server.
| Parameter | Value |
|---|---|
| Prefix | lamp |
| Domain | hostkey.in |
| Full template | lamp{Server_ID}.hostkey.in |
File and Directory Structure¶
The deployment utilizes several specific locations for configuration and data persistence:
-
/root/nginx/: Contains the Docker Compose configuration for the SSL proxy. -
/data/nginx/user_conf.d/: Stores Nginx virtual host configurations and custom headers. -
/data/nginx/nginx-certbot.env: Environment file for the Nginx container. -
/etc/apache2/: Standard Apache configuration directory, modified to listen on an internal port. -
/var/www/html/: Default web root for Apache.
Application installation process¶
The installation follows a multi-step process involving package management and service reconfiguration:
-
System Preparation: The system updates the package cache and ensures all existing
aptlocks are released. -
Web Server Installation: Apache is installed via the system package manager.
-
Database Installation: MariaDB server and client are installed from official repositories (including specific mirrors for certain regions).
-
PHP Installation:
-
On Ubuntu: PHP 8.2 is installed via the
ppa:ondrej/phprepository, including modules for MySQL, Curl, and CGI. -
On Debian: The standard PHP package is installed from default repositories.
-
Apache Reconfiguration: Apache is reconfigured to listen on an internal port (defaulting to
8080) instead of the standard port 80/443 to allow the Nginx proxy to handle external traffic. Headers forX-Forwarded-Protoare configured to ensure correct protocol detection behind the proxy. -
SSL Proxy Setup: A Docker container is deployed to manage SSL certificates and act as a reverse proxy.
Access Rights and Security¶
-
Firewall: The system relies on an external or local firewall to allow traffic on port 443 (HTTPS) and 80 (HTTP for Certbot).
-
Apache Security: Apache is bound to an internal loopback/internal interface to prevent direct exposure of the unencrypted service.
-
Nginx Proxy: The Nginx container handles SSL termination, ensuring that only encrypted traffic reaches the application via port 443.
Databases¶
The deployment includes a MariaDB server instance.
-
Connection Method: Localhost connection for applications hosted on the same machine.
-
Storage Location: Standard MariaDB data directories (e.g.,
/var/lib/mysql). -
Settings: Configured via standard system package defaults.
Docker Containers and Their Deployment¶
The deployment utilizes a single primary container to manage SSL certificates and reverse proxying:
| Container Name | Image | Ports | Volumes | Environment Variables | Restart Policy |
|---|---|---|---|---|---|
nginx | jonasal/nginx-certbot:latest | Host Network | - nginx_secrets:/etc/letsencrypt- /data/nginx/user_conf.d:/etc/nginx/user_conf.d | CERTBOT_EMAIL (from config) | unless-stopped |
Note: The container operates in network_mode: host to facilitate seamless communication with the local Apache service and for efficient certificate management.
Custom Scripts and Additional Setup¶
The following setup actions are performed during deployment:
-
Apache Header Configuration: A custom configuration file (
remoteip-forwarded.conf) is created to ensure Apache correctly identifies the client's original protocol (HTTPS) when proxied. -
Nginx Proxy Headers: The installation automatically injects
proxy_set_header Host $host;andproxy_set_header X-Forwarded-Proto $scheme;into the Nginx configuration files to ensure proper routing and URL generation for the application. -
Test File Creation: A
info.phpfile is generated in/var/www/html/to verify that PHP is functioning correctly.
Application Update Instructions¶
To update the core components of the stack:
-
Web Server (Apache) & PHP: Use the system package manager:
-
Database (MariaDB): Use the system package manager:
-
SSL Proxy (Nginx Container): To pull the latest version of the proxy container and apply changes, navigate to
/root/nginxand run:
Location of configuration files and data¶
-
Apache Configs:
/etc/apache2/ -
Nginx User Configs:
/data/nginx/user_conf.d/ -
Docker Compose File:
/root/nginx/compose.yml -
Web Content:
/var/www/html/
Available ports for connection¶
-
HTTPS (External):
443 -
HTTP (External - Certbot only):
80 -
Apache (Internal):
8080(default)
Starting and Stopping the application¶
-
Apache:
-
Start:
systemctl start apache2 -
Stop:
systemctl stop apache2 -
Nginx Proxy Container:
-
Start/Restart:
docker compose up -d(within/root/nginx) -
Stop:
docker compose down(within/root/nginx)