Deployment Overview of Web-LGSM on Server¶
This document provides the technical deployment specifications for the Web-LGSM application and its associated management components. The installation includes the Linux Game Server Manager (LGSM) core, a web-based management interface (Web-LGSM), and an Nginx reverse proxy with automated SSL via Certbot.
Prerequisites and Basic Requirements¶
The following requirements must be met for a successful deployment:
-
Operating System: Debian or Ubuntu.
-
Privileges: Sudo access is required for initial dependency installation and service configuration.
-
Dependencies: The system requires several packages, including
sudo,git,python3,python3-venv,python3-pip,jq,unzip, and various 32-bit libraries (lib32gcc-s1,lib32stdc++6). -
Network: Access to the internet is required to fetch installation scripts, clone repositories, and obtain SSL certificates.
FQDN of the final panel on the hostkey.in domain¶
The web interface is accessible via a specific subdomain template based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | web-lgsm |
| Domain | hostkey.in |
| Full template | web-lgsm{Server_ID_from_Invapi}.hostkey.in |
File and Directory Structure¶
The application utilizes the following directory structure for configuration, data, and service management:
-
/home/mcbserver/: Home directory for the dedicated application user. -
/home/mcbserver/web-lgsm/: Repository and installation directory for the Web-LGSM interface. -
/root/nginx/: Configuration directory for the Nginx reverse proxy. -
/data/nginx/user_conf.d/: Custom Nginx configuration files. -
/etc/systemd/system/web-lgsm.service: Systemd unit file for the Web-LGSM backend.
Application installation process¶
The deployment follows a multi-stage installation process:
-
System Preparation: A dedicated user
mcbserveris created with passwordless sudo privileges to execute necessary administrative commands without manual intervention. -
Dependency Installation: The system package manager (
apt) installs all required runtime dependencies and libraries. -
LGSM Core Installation:
-
The official LinuxGSM installation script is downloaded from
https://linuxgsm.sh. -
The script is executed as the
mcbserveruser to initialize the game server environment. -
Web-LGSM Interface Installation:
-
The Web-LGSM repository is cloned from GitHub into the user's home directory.
-
An installation script (
install.sh) is executed within the repository folder to configure the web interface. -
Service Configuration: A systemd service unit is created to manage the Web-LGSM backend as a background process.
Access Rights and Security¶
-
User Isolation: The application runs under a dedicated non-root user (
mcbserver). -
Sudo Restrictions: Passwordless sudo is configured specifically for the
mcbserveruser to allow automated service management while maintaining security boundaries. -
File Permissions: Strict permissions are applied to sensitive directories, including
/etc/sudoers.dand the application's home directory.
Docker Containers and Their Deployment¶
The deployment utilizes a Docker container to handle Nginx and SSL certificate management via Certbot.
Nginx Proxy Container¶
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Restart Policy:
unless-stopped -
Environment Variables:
-
CERTBOT_EMAIL:[email protected] -
Volumes:
-
nginx_secrets:/etc/letsencrypt(External volume for SSL certificates) -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d(Custom Nginx configurations) -
/home:/home(Access to application files)
Custom Scripts and Additional Setup¶
The following actions are performed during the deployment process:
-
Environment Cleanup: The
/tmp/.directory is cleared and recreated with specific permissions (0777) to ensure a clean environment for installation processes. -
Backend Service Management: A custom Python script
web-lgsm.pyis used as the backend entry point, managed via systemd with support for--stopflags for graceful shutdowns.
Application Update Instructions¶
To update the Web-LGSM application:
-
Web Interface: Navigate to the installation directory and pull the latest changes from the repository (if manual updates are required) or re-run the
install.shscript within theweb-lgsmdirectory. -
Docker Proxy: To update the Nginx/Certbot container, execute:
Location of configuration files and data¶
-
Web-LGSM Backend Configs: Located in
/home/mcbserver/web-lgsm/. -
Nginx Configurations: Custom site configurations are stored in
/data/nginx/user_conf.d/. -
SSL Certificates: Managed within the
nginx_secretsDocker volume.
Available ports for connection¶
| Service | Port | Protocol | Access Type |
|---|---|---|---|
| Web-LGSM Backend (Local) | 12357 | TCP | Internal Only |
| Nginx Proxy (Web Interface) | 443 | HTTPS | External |
Starting and Stopping the application¶
The Web-LGSM backend is managed via systemd:
-
Start the service:
-
Stop the service:
-
Check status:
Proxy Servers¶
The application uses an Nginx container (via nginx-certbot) acting as a reverse proxy. It handles SSL termination for the domain and routes traffic from external port 443 to the internal Web-LGSM backend listening on port 12357.