Skip to content

Deployment Overview of Dify on Server

Prerequisites and Basic Requirements

To ensure a successful deployment, the following requirements must be met:

  • Operating System: Ubuntu (latest stable version recommended).

  • Privileges: Root or sudo access is required for package installation and Docker management.

  • Domain Name: A valid domain name pointing to the server's IP address is required for SSL certificate issuance via Certbot.

  • Ports: The following ports must be open in the firewall:

  • 80/TCP: For HTTP traffic and Let's Encrypt validation.

  • 443/TCP: For secure HTTPS traffic.

FQDN of the final panel on the hostkey.in domain

The application is accessible via a specific subdomain template based on the server ID.

Parameter Value
Prefix dify
Domain hostkey.in
Full template dify{Server_ID}.hostkey.in

File and Directory Structure

The deployment utilizes the following directory structure for configuration and data persistence:

  • /opt/dify: Main application directory containing source files and Docker configurations.

  • /root/nginx: Contains the Nginx reverse proxy configuration and compose.yml.

  • /data/nginx/user_conf.d: Stores custom Nginx virtual host configurations.

  • /data/nginx/nginx-certbot.env: Environment variables for the SSL proxy container.

Application installation process

The application is installed using a combination of system package management and Docker Compose:

  1. System Preparation: The system updates its package index and installs essential dependencies including ca-certificates, curl, gnupg, and git.

  2. Docker Installation: The official Docker repository is added to the system, and the following packages are installed via apt:

  3. docker-ce

  4. docker-ce-cli

  5. containerd.io

  6. docker-buildx-plugin

  7. docker-compose-plugin

  8. Source Code Retrieval: The Dify repository (version 1.12.1) is cloned from GitHub into /opt/dify.

  9. Environment Configuration: An environment file (.env) is generated from the provided example. To prevent port conflicts with the external proxy, the internal Nginx ports are bound to 127.0.0.1 and SSL is disabled within the application container as TLS termination is handled by a dedicated proxy.

  10. Container Deployment: The application services are started using Docker Compose in detached mode from the /opt/dify/docker directory.

Access Rights and Security

  • Firewall: Only ports 80 and 443 are exposed to the public internet via the Nginx proxy.

  • Internal Networking: The application's internal web services are bound to localhost (127.0.0.1) to ensure they are not directly accessible from the outside, preventing unauthorized access bypassing the SSL proxy.

Docker Containers and Their Deployment

The deployment consists of two primary container groups:

Application Containers (Dify)

These containers run the core application logic as defined in /opt/dify/docker/compose.yml.

Service Image Ports (Internal) Restart Policy
Dify Services langgenius/dify (various) Managed via .env Default

Proxy Container (Nginx-Certbot)

A dedicated container manages SSL certificates and handles incoming web traffic.

  • Image: jonasal/nginx-certbot:latest

  • Network Mode: host

  • Volumes:

  • nginx_secrets:/etc/letsencrypt

  • /data/nginx/user_conf.d:/etc/nginx/user_conf.d

  • Environment Variables:

  • [email protected]

Custom Scripts and Additional Setup

The deployment includes an automated SSL provisioning process:

  1. Nginx Configuration Generation: A custom Nginx configuration is created in /data/nginx/user_conf.d/ to handle the redirection from HTTP to HTTPS and proxy requests to the application on port 3000.

  2. SSL Certificate Acquisition: The system executes a command within the nginx-certbot container to obtain a Let's Encrypt certificate using the --webroot method.

  3. Proxy Reloading: Once certificates are obtained, the Nginx proxy container is restarted to apply the new SSL settings.

Application Update Instructions

To update the Dify application, perform the following steps:

  1. Navigate to the application directory:

    cd /opt/dify/docker
    

  2. Pull the latest images and restart the services:

    docker compose pull && docker compose up -d
    

Location of configuration files and data

  • Application Config: /opt/dify/docker/.env

  • Nginx Proxy Configs: /data/nginx/user_conf.d/

  • SSL Certificates: Managed within the nginx_secrets Docker volume.

Available ports for connection

Service Port Protocol Access
Web Interface 443 HTTPS Public
HTTP Redirect 80 HTTP Public
Internal API/Web 3000 HTTP Localhost Only

Starting and Stopping the application

The application is managed via Docker Compose.

  • Start Application:

    cd /opt/dify/docker && docker compose up -d
    

  • Stop Application:

    cd /opt/dify/docker && docker compose down
    

question_mark
Is there anything I can help you with?
question_mark
AI Assistant ×