Deployment Overview of VictoriaMetrics on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: A Linux-based system with Docker installed.
-
Privileges: Root or sudo access is required for directory creation and service management.
-
Docker Service: The
dockerservice must be installed, started, and enabled to run on boot. -
Ports: The following ports must be available and not blocked by a firewall:
-
80/tcp: For HTTP traffic (Certbot validation). -
443/tcp: For HTTPS traffic. -
8427/tcp: Internal authentication service. -
8428/tcp: VictoriaMetrics internal API.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | victoriametrics |
| Domain | hostkey.in |
| Full template | victoriametrics{Server_ID}.hostkey.in |
File and Directory Structure¶
The application data and configurations are organized in the following directory structure:
-
/root/victoria-metrics-data/: Main application directory containing configuration files and Docker Compose settings. -
/root/victoria-metrics-data/authconfig.yml: Authentication configuration file. -
/root/victoria-metrics-data/compose.yml: Docker Compose orchestration file. -
/data/nginx/user_conf.d/: Nginx user configuration directory for proxying traffic.
Application installation process¶
The application is deployed using a combination of manual setup and Docker Compose:
-
Environment Setup: The system creates the necessary data directories in
/root/victoria-metrics-data. -
Configuration Generation: Configuration files for authentication (
authconfig.yml) and orchestration (compose.yml) are generated in the application directory. -
Volume Creation: A dedicated Docker volume named
victoriametricsis created to ensure data persistence. -
Container Deployment: The deployment uses
docker composewithin the/root/victoria-metrics-datadirectory to launch all required services.
Access Rights and Security¶
-
Firewall: Only ports 80, 443, 8427, and 8428 are utilized.
-
SSL/TLS: SSL certificates are managed via Certbot and integrated through an Nginx proxy container.
-
Authentication: Access to the VictoriaMetrics API is controlled via
vmauth, which uses a configuration file located at/root/victoria-metrics-data/authconfig.yml.
Databases¶
VictoriaMetrics utilizes Docker volumes for persistent storage of time-series data:
-
Storage Location: Data is stored in the
victoriametricsDocker volume and mapped to/victoria-metricsinside the container. -
Connection Method: The service is accessed internally via port
8428.
Docker Containers and Their Deployment¶
The deployment consists of three primary containers managed via Docker Compose:
| Container Name | Image | Ports | Volumes | Environment Variables | Restart Policy |
|---|---|---|---|---|---|
nginx | jonasal/nginx-certbot:latest | 80:80, 443:443 | nginx_secrets:/etc/letsencrypt, /data/nginx/user_conf.d:/etc/nginx/user_conf.d | [email protected] | unless-stopped |
victoriametrics | victoriametrics/victoria-metrics:latest | 8428:8428 | /root/victoria-metrics-data:/victoria-metrics-data, victoriametrics:/victoria-metrics | N/A | unless-stopped |
vmauth | victoriametrics/vmauth | 8427:8427 | /root/victoria-metrics-data:/root/victoria-metrics-data | N/A | unless-stopped |
Custom Scripts and Additional Setup¶
The deployment performs the following specialized configuration steps:
-
Nginx Proxy Configuration: The system modifies the Nginx proxy configuration to route incoming traffic from the external domain through
vmauth(port 8427) instead of directly to VictoriaMetrics. -
Authentication Setup: A custom
authconfig.ymlis generated to define user access permissions and URL prefixes for the authentication layer.
Application Update Instructions¶
To update the application, navigate to the deployment directory and perform a pull of the latest images:
Location of configuration files and data¶
| Component | Path |
|---|---|
| Docker Compose File | /root/victoria-metrics-data/compose.yml |
| Auth Configuration | /root/victoria-metrics-data/authconfig.yml |
| Persistent Data Volume | victoriametrics (Docker Managed) |
Available ports for connection¶
-
External HTTPS:
443 -
Internal VictoriaMetrics API:
8428 -
vmauth Authentication Port:
8427