Deployment Overview of Owncast on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu
-
Privileges: Root or sudo access is required for package installation and service management.
-
Dependencies:
unzipandffmpegmust be installed on the host system. -
Ports:
-
Internal Port:
8080(Application) -
External Port:
443(HTTPS via Proxy)
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain pattern based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | owncast |
| Domain | hostkey.in |
| Full template | owncast{Server_ID_from_Invapi}.hostkey.in |
File and Directory Structure¶
The deployment utilizes the following directory structure for configuration and data persistence:
-
/root/nginx: Contains the Nginx Docker Compose configuration. -
/data/nginx/user_conf.d/: Stores Nginx virtual host configuration files. -
/data/nginx/nginx-certbot.env: Environment file for SSL certificate management. -
/root/owncast: The application working directory containing the binary and local data.
Application Installation Process¶
The installation of Owncast is performed through a combination of package management and an automated installation script:
-
System Preparation: The system package cache is updated, and
unzipandffmpegare installed viaapt. -
Application Installation: An official installation script is executed using the following command:
-
Service Configuration: A systemd service unit named
owncast.serviceis created to manage the application process. -
Service Activation: The service is enabled to start automatically on boot and is started immediately using
systemctl.
Access Rights and Security¶
-
Firewall: Ensure that port
443(HTTPS) is open to allow external traffic. -
User Permissions: The Owncast service runs under the
rootuser within its working directory/root/owncast. -
SSL/TLS: SSL certificates are managed via a dedicated Docker container and stored in an external volume named
nginx_secrets.
Docker Containers and Their Deployment¶
The deployment utilizes a reverse proxy container to handle SSL termination and traffic routing.
Nginx Proxy Container¶
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Restart Policy:
unless-stopped -
Environment Variables:
-
CERTBOT_EMAIL:[email protected] -
Volumes:
-
nginx_secrets:/etc/letsencrypt(SSL Certificates) -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d(Configuration files)
Custom Scripts and Additional Setup¶
The deployment includes several configuration steps to integrate the application with the Nginx proxy:
-
Nginx Configuration Injection: The installation process automatically modifies the Nginx configuration file located in
/data/nginx/user_conf.d/to include aproxy_passdirective pointing tohttp://127.0.0.1:8080. This routes incoming HTTPS traffic from the proxy to the Owncast application running on the host. -
Service Management: A custom systemd unit is configured at
/etc/systemd/system/owncast.servicewith the following parameters: -
WorkingDirectory:/root/owncast -
ExecStart:/root/owncast/owncast
Application Update Instructions¶
To update the Owncast application, you must re-run the installation script to fetch the latest version and replace the existing binary:
After updating the binary, restart the service to apply changes:
Location of Configuration Files and Data¶
-
Application Binary:
/root/owncast/owncast -
Nginx User Configs:
/data/nginx/user_conf.d/ -
SSL Certificates: Managed via the
nginx_secretsDocker volume.
Available Ports for Connection¶
-
HTTPS (External):
443 -
HTTP (Internal/Localhost):
8080
Starting and Stopping the Application¶
The application is managed as a systemd service. Use the following commands to control the service:
-
Start Owncast:
systemctl start owncast -
Stop Owncast:
systemctl stop owncast -
Restart Owncast:
systemctl restart owncast -
Check Status:
systemctl status owncast