feat(deploy): add secure production deployment configuration (Nginx, Docker Compose)

This commit is contained in:
Rafif-Riqullah-Siregar committed 2026-07-07 23:56:53 +07:00
1 parent d559f00b8a
commit c99ff191c1
3 files changed
+114

No files matched your search

+27
View File
@@ -0,0 +1,27 @@
#!/bin/bash
# -------------------------------------------------------------
# BackOne Deep Package Inspection - Secure Deployment Script
# -------------------------------------------------------------
echo "🚀 Starting deployment to demoplace..."
# Pull latest changes from master
git pull origin master
# Ensure .env.production exists
if [ ! -f .env.production ]; then
echo "⚠️ .env.production is missing! Please create it based on .env.production.example"
exit 1
fi
# Build and deploy the production docker compose configuration
echo "🐳 Building and starting Docker containers in detached mode..."
docker-compose -f docker-compose.prod.yml build
docker-compose -f docker-compose.prod.yml up -d --remove-orphans
echo "🧹 Cleaning up unused Docker images..."
docker image prune -f
echo "✅ Deployment successful!"
echo "Your BackOne Dashboard is now securely running behind NGINX."
echo "Only NGINX is exposed to the public. Internal API and MongoDB ports are completely isolated."
+56
View File
@@ -0,0 +1,56 @@
version: '3.8'
services:
mongodb:
image: mongo:6.0
container_name: backone_mongodb_prod
restart: always
# No ports exposed to the host! Completely internal.
volumes:
- mongodb_data_prod:/data/db
environment:
- MONGO_INITDB_DATABASE=backone_dpi
backend:
build:
context: ./backend
container_name: backone_backend_prod
restart: always
# No ports exposed to the host! Completely internal.
environment:
- MONGODB_URI=mongodb://mongodb:27017/backone_dpi
- BACKEND_PORT=3001
env_file:
- .env.production
depends_on:
- mongodb
frontend:
build:
context: .
# Optional: you can define a multi-stage production build in a separate Dockerfile if desired,
# but using the standard one works if it builds Next.js standalone.
container_name: backone_frontend_prod
restart: always
# No ports exposed to the host! Completely internal.
environment:
- NEXT_PUBLIC_API_URL=http://backend:3001
env_file:
- .env.production
depends_on:
- backend
nginx:
image: nginx:alpine
container_name: backone_nginx_prod
restart: always
ports:
- "80:80"
# If using SSL, add "443:443" later
volumes:
- ./nginx/conf.d:/etc/nginx/conf.d
depends_on:
- frontend
volumes:
mongodb_data_prod:
+31
View File
@@ -0,0 +1,31 @@
server {
listen 80;
server_name _; # Accept any domain name (or we can specify the demoplace domain later)
server_tokens off; # Hide NGINX version
# Security Headers
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Content-Security-Policy "default-src 'self' http: https: data: blob: 'unsafe-inline' 'unsafe-eval';" always;
# Rate Limiting zone configuration should be in nginx.conf (http block), but we can configure basic protection
# We will pass everything to the frontend container
location / {
proxy_pass http://frontend:3000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection 'upgrade';
proxy_set_header Host $host;
proxy_cache_bypass $http_upgrade;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# Hide internal technologies from being sent back to the client
proxy_hide_header X-Powered-By;
}
}