feat(deploy): add secure production deployment configuration (Nginx, Docker Compose)
This commit is contained in:
1 parent
d559f00b8a
commit
c99ff191c1
3 files changed
+114
No files matched your search
@@ -0,0 +1,27 @@
|
||||
#!/bin/bash
|
||||
# -------------------------------------------------------------
|
||||
# BackOne Deep Package Inspection - Secure Deployment Script
|
||||
# -------------------------------------------------------------
|
||||
|
||||
echo "🚀 Starting deployment to demoplace..."
|
||||
|
||||
# Pull latest changes from master
|
||||
git pull origin master
|
||||
|
||||
# Ensure .env.production exists
|
||||
if [ ! -f .env.production ]; then
|
||||
echo "⚠️ .env.production is missing! Please create it based on .env.production.example"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Build and deploy the production docker compose configuration
|
||||
echo "🐳 Building and starting Docker containers in detached mode..."
|
||||
docker-compose -f docker-compose.prod.yml build
|
||||
docker-compose -f docker-compose.prod.yml up -d --remove-orphans
|
||||
|
||||
echo "🧹 Cleaning up unused Docker images..."
|
||||
docker image prune -f
|
||||
|
||||
echo "✅ Deployment successful!"
|
||||
echo "Your BackOne Dashboard is now securely running behind NGINX."
|
||||
echo "Only NGINX is exposed to the public. Internal API and MongoDB ports are completely isolated."
|
||||
@@ -0,0 +1,56 @@
|
||||
version: '3.8'
|
||||
|
||||
services:
|
||||
mongodb:
|
||||
image: mongo:6.0
|
||||
container_name: backone_mongodb_prod
|
||||
restart: always
|
||||
# No ports exposed to the host! Completely internal.
|
||||
volumes:
|
||||
- mongodb_data_prod:/data/db
|
||||
environment:
|
||||
- MONGO_INITDB_DATABASE=backone_dpi
|
||||
|
||||
backend:
|
||||
build:
|
||||
context: ./backend
|
||||
container_name: backone_backend_prod
|
||||
restart: always
|
||||
# No ports exposed to the host! Completely internal.
|
||||
environment:
|
||||
- MONGODB_URI=mongodb://mongodb:27017/backone_dpi
|
||||
- BACKEND_PORT=3001
|
||||
env_file:
|
||||
- .env.production
|
||||
depends_on:
|
||||
- mongodb
|
||||
|
||||
frontend:
|
||||
build:
|
||||
context: .
|
||||
# Optional: you can define a multi-stage production build in a separate Dockerfile if desired,
|
||||
# but using the standard one works if it builds Next.js standalone.
|
||||
container_name: backone_frontend_prod
|
||||
restart: always
|
||||
# No ports exposed to the host! Completely internal.
|
||||
environment:
|
||||
- NEXT_PUBLIC_API_URL=http://backend:3001
|
||||
env_file:
|
||||
- .env.production
|
||||
depends_on:
|
||||
- backend
|
||||
|
||||
nginx:
|
||||
image: nginx:alpine
|
||||
container_name: backone_nginx_prod
|
||||
restart: always
|
||||
ports:
|
||||
- "80:80"
|
||||
# If using SSL, add "443:443" later
|
||||
volumes:
|
||||
- ./nginx/conf.d:/etc/nginx/conf.d
|
||||
depends_on:
|
||||
- frontend
|
||||
|
||||
volumes:
|
||||
mongodb_data_prod:
|
||||
@@ -0,0 +1,31 @@
|
||||
server {
|
||||
listen 80;
|
||||
server_name _; # Accept any domain name (or we can specify the demoplace domain later)
|
||||
|
||||
server_tokens off; # Hide NGINX version
|
||||
|
||||
# Security Headers
|
||||
add_header X-Frame-Options "SAMEORIGIN" always;
|
||||
add_header X-XSS-Protection "1; mode=block" always;
|
||||
add_header X-Content-Type-Options "nosniff" always;
|
||||
add_header Referrer-Policy "no-referrer-when-downgrade" always;
|
||||
add_header Content-Security-Policy "default-src 'self' http: https: data: blob: 'unsafe-inline' 'unsafe-eval';" always;
|
||||
|
||||
# Rate Limiting zone configuration should be in nginx.conf (http block), but we can configure basic protection
|
||||
# We will pass everything to the frontend container
|
||||
|
||||
location / {
|
||||
proxy_pass http://frontend:3000;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection 'upgrade';
|
||||
proxy_set_header Host $host;
|
||||
proxy_cache_bypass $http_upgrade;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
|
||||
# Hide internal technologies from being sent back to the client
|
||||
proxy_hide_header X-Powered-By;
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user