Deployment Overview of Outline on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu (recommended).
-
Privileges: Root or sudo access is required for package installation and script execution.
-
Packages:
curlmust be installed via the system package manager. -
Network Requirements:
-
Outbound access to
raw.githubusercontent.comto download the installation script. -
Access to Docker registries to pull necessary images.
FQDN of the final panel on the hostkey.in domain¶
The application is configured with a specific domain template for SSL and proxying purposes:
| Parameter | Value |
|---|---|
| Prefix | OutlineVPN |
| Domain | hostkey.in |
| Full template | OutlineVPN{Server_ID}.hostkey.in |
Application installation process¶
The installation of Outline VPN is performed using a combination of an official installation script and Docker for the proxy layer:
-
System Preparation: The system package cache is updated, and
curlis installed. -
Script Acquisition: The official Outline Server installation script is downloaded from GitHub to
/root/install_outline.sh. -
Core Installation: The installer script
/root/install_outline.shis executed. This process sets up the VPN environment and generates necessary API credentials. -
Credential Storage: Upon successful execution of the installer, the resulting API key and connection details are saved to
/root/outline_api_key.txt. -
Proxy Configuration: A Docker-based Nginx container is deployed to handle SSL termination and proxy traffic to the application via port
8080.
Access Rights and Security¶
-
Firewall: Ensure that ports required by Outline VPN (as specified during the script execution) are open. The Nginx proxy handles incoming HTTPS traffic on standard web ports.
-
File Permissions:
-
The installation script is granted execution permissions (
0755). -
The API key file
/root/outline_api_key.txtis restricted to the root user with0600permissions for security.
Docker Containers and Their Deployment¶
The deployment utilizes a Docker container to manage Nginx and SSL certificates via Certbot:
| Container Name | Image | Ports / Network | Volumes | Restart Policy |
|---|---|---|---|---|
nginx | jonasal/nginx-certbot:latest | host network mode | - nginx_secrets:/etc/letsencrypt- /data/nginx/user_conf.d:/etc/nginx/user_conf.d | unless-stopped |
Note: The Nginx container uses the host's network stack and relies on an external volume named nginx_secrets. It is configured to proxy traffic to http://127.0.0.1:8080.
Custom Scripts and Additional Setup¶
The following scripts are used during or after the installation process:
-
Installation Script:
/root/install_outline.sh- Used to initialize the Outline VPN server components. -
API Key Generation: The output of the installation script is captured and stored in
/root/outline_api_key.txtfor administrative access. -
Nginx Configuration Management: A configuration file is generated at
/root/nginx/compose.ymlto manage the proxy service.
Application Update Instructions¶
To update the application, follow these steps:
-
Core Application: Since the core VPN components are managed by the Outline installation script, you should re-run the installer or follow the specific instructions provided in the
outline_api_key.txtfile if a version upgrade is required. -
Proxy Layer: To update the Nginx proxy container, navigate to
/root/nginxand execute:
Location of configuration files and data¶
-
Outline API Credentials:
/root/outline_api_key.txt -
Nginx Compose File:
/root/nginx/compose.yml -
Nginx User Configurations:
/data/nginx/user_conf.d/ -
SSL Certificates: Managed via the
nginx_secretsDocker volume.
Available ports for connection¶
-
HTTPS (Proxy): Standard port 443 (via Nginx).
-
Internal Application Port:
8080(used for internal proxying from Nginx to the application).