Deployment Overview of Dify on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu (latest stable version recommended).
-
Privileges: Root or sudo access is required for package installation and Docker management.
-
Domain Name: A valid domain name pointing to the server's IP address is required for SSL certificate issuance via Certbot.
-
Ports: The following ports must be open in the firewall:
-
80/TCP: For HTTP traffic and Let's Encrypt validation. -
443/TCP: For secure HTTPS traffic.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | dify |
| Domain | hostkey.in |
| Full template | dify{Server_ID}.hostkey.in |
File and Directory Structure¶
The deployment utilizes the following directory structure for configuration and data persistence:
-
/opt/dify: Main application directory containing source files and Docker configurations. -
/root/nginx: Contains the Nginx reverse proxy configuration andcompose.yml. -
/data/nginx/user_conf.d: Stores custom Nginx virtual host configurations. -
/data/nginx/nginx-certbot.env: Environment variables for the SSL proxy container.
Application installation process¶
The application is installed using a combination of system package management and Docker Compose:
-
System Preparation: The system updates its package index and installs essential dependencies including
ca-certificates,curl,gnupg, andgit. -
Docker Installation: The official Docker repository is added to the system, and the following packages are installed via
apt: -
docker-ce -
docker-ce-cli -
containerd.io -
docker-buildx-plugin -
docker-compose-plugin -
Source Code Retrieval: The Dify repository (version
1.12.1) is cloned from GitHub into/opt/dify. -
Environment Configuration: An environment file (
.env) is generated from the provided example. To prevent port conflicts with the external proxy, the internal Nginx ports are bound to127.0.0.1and SSL is disabled within the application container as TLS termination is handled by a dedicated proxy. -
Container Deployment: The application services are started using Docker Compose in detached mode from the
/opt/dify/dockerdirectory.
Access Rights and Security¶
-
Firewall: Only ports
80and443are exposed to the public internet via the Nginx proxy. -
Internal Networking: The application's internal web services are bound to
localhost(127.0.0.1) to ensure they are not directly accessible from the outside, preventing unauthorized access bypassing the SSL proxy.
Docker Containers and Their Deployment¶
The deployment consists of two primary container groups:
Application Containers (Dify)¶
These containers run the core application logic as defined in /opt/dify/docker/compose.yml.
| Service | Image | Ports (Internal) | Restart Policy |
|---|---|---|---|
| Dify Services | langgenius/dify (various) | Managed via .env | Default |
Proxy Container (Nginx-Certbot)¶
A dedicated container manages SSL certificates and handles incoming web traffic.
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Volumes:
-
nginx_secrets:/etc/letsencrypt -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d -
Environment Variables:
Custom Scripts and Additional Setup¶
The deployment includes an automated SSL provisioning process:
-
Nginx Configuration Generation: A custom Nginx configuration is created in
/data/nginx/user_conf.d/to handle the redirection from HTTP to HTTPS and proxy requests to the application on port3000. -
SSL Certificate Acquisition: The system executes a command within the
nginx-certbotcontainer to obtain a Let's Encrypt certificate using the--webrootmethod. -
Proxy Reloading: Once certificates are obtained, the Nginx proxy container is restarted to apply the new SSL settings.
Application Update Instructions¶
To update the Dify application, perform the following steps:
-
Navigate to the application directory:
-
Pull the latest images and restart the services:
Location of configuration files and data¶
-
Application Config:
/opt/dify/docker/.env -
Nginx Proxy Configs:
/data/nginx/user_conf.d/ -
SSL Certificates: Managed within the
nginx_secretsDocker volume.
Available ports for connection¶
| Service | Port | Protocol | Access |
|---|---|---|---|
| Web Interface | 443 | HTTPS | Public |
| HTTP Redirect | 80 | HTTP | Public |
| Internal API/Web | 3000 | HTTP | Localhost Only |
Starting and Stopping the application¶
The application is managed via Docker Compose.
-
Start Application:
-
Stop Application: