1
0
mirror of https://github.com/LaCasemate/fab-manager.git synced 2024-12-01 12:24:28 +01:00
fab-manager/docker/README.md

329 lines
10 KiB
Markdown
Raw Normal View History

2017-07-20 16:48:34 +02:00
# Install Fabmanager app in production with Docker
2016-03-23 18:39:41 +01:00
2017-07-20 19:54:37 +02:00
This README tries to describe all the steps to put a fabmanager app into production on a server, based on a solution using Docker and Docker-compose.
We recommend DigitalOcean, but these steps will work on any Docker-compatible cloud provider or local server.
2017-07-20 16:48:34 +02:00
In order to make it work, please use the same directories structure as described in this guide in your fabmanager app folder.
2017-07-20 19:54:37 +02:00
You will need to be root through the rest of the setup.
2016-03-23 18:39:41 +01:00
2017-07-20 17:14:02 +02:00
##### Table of contents
2017-07-20 17:18:19 +02:00
1. [Preliminary steps](#preliminary-steps)<br/>
2017-07-20 19:54:37 +02:00
1.1. setup the server<br/>
1.2. buy a domain name and link it with the droplet<br/>
1.3. connect to the droplet via SSH<br/>
1.4. prepare server<br/>
1.5. setup folders and env file<br/>
1.6. setup nginx file<br/>
1.7. SSL certificate with LetsEncrypt<br/>
1.8. requirements
2. [Install Fabmanager](#install-fabmanager)<br/>
2017-07-21 09:27:29 +02:00
2.1. Add docker-compose.yml file<br/>
2.2. pull images<br/>
2.3. setup database<br/>
2.4. build assets<br/>
2.5. prepare Elasticsearch (search engine)<br/>
2017-07-20 19:54:37 +02:00
2.6. start all services
2017-07-20 17:43:59 +02:00
3. [Generate SSL certificate by Letsencrypt](#generate-ssl-certificate-by-letsencrypt)
2017-07-20 17:14:02 +02:00
4. [Docker utils](#docker-utils)
2017-07-20 19:54:37 +02:00
5. [Update Fabmanager](#update-fabmanager)<br/>
2017-07-20 17:42:55 +02:00
5.1. Steps<br/>
5.2. Good to know
2017-07-20 17:14:02 +02:00
2017-07-20 17:37:03 +02:00
## Preliminary steps
2017-07-20 16:48:34 +02:00
2017-07-20 17:37:03 +02:00
### setup the server
2016-04-11 20:24:09 +02:00
2017-07-20 19:54:37 +02:00
Go to [DigitalOcean](https://www.digitalocean.com/) and create a Droplet with One-click apps **"Docker on Ubuntu 16.04 LTS"** (Docker and Docker-compose are preinstalled).
2017-07-20 16:48:34 +02:00
You need at least 2GB of addressable memory (RAM + swap) to install and use FabManager.
2017-07-20 19:54:37 +02:00
We recommend 4 GB RAM for larger communities.
2017-07-20 16:48:34 +02:00
Choose a datacenter. Set the hostname as your domain name.
2016-04-11 20:24:09 +02:00
2017-07-20 19:54:37 +02:00
### buy a domain name and link it with the server
2016-04-11 20:24:09 +02:00
2017-07-20 17:37:03 +02:00
1. Buy a domain name on [OVH](https://www.ovh.com/fr/)
2017-07-20 16:48:34 +02:00
2. Replace the IP address of the domain with the droplet's IP (you can enable the flexible ip and use it)
3. **Do not** try to access your domain name right away, DNS are not aware of the change yet so **WAIT** and be patient.
2016-04-11 20:24:09 +02:00
2017-07-20 19:54:37 +02:00
### connect to the server via SSH
2016-04-11 20:24:09 +02:00
2017-07-20 19:54:37 +02:00
You can already connect to the server with this command: `ssh root@server-ip`. When DNS propagation will be done, you will be able to
connect to the server with `ssh root@your-domain-name`.
2016-03-23 18:39:41 +01:00
2017-07-20 19:54:37 +02:00
### prepare server
2016-04-11 20:24:09 +02:00
2017-07-20 19:54:37 +02:00
We recommend you to :
- ugprade your system
- add at least 2GB of swap
- verify that you are using a connection via an SSH key. If so, you can set the root passord (for the debug console) and disable password connection.
To do this, you can use the following script :
2016-04-11 20:24:09 +02:00
2016-03-23 18:39:41 +01:00
```bash
2017-07-20 19:54:37 +02:00
cd /root
git clone https://github.com/sleede/lazyscripts.git
cd lazyscripts/
chmod a+x prepare-vps.sh
./prepare-vps
2016-03-23 18:39:41 +01:00
```
2017-07-20 17:37:03 +02:00
### setup folders and env file
2016-03-23 18:39:41 +01:00
2017-07-20 17:37:03 +02:00
Create the config folder:
2016-04-11 20:24:09 +02:00
```bash
2017-07-20 19:54:37 +02:00
mkdir -p /apps/fabmanager/config
2016-04-11 20:24:09 +02:00
```
2017-07-20 19:54:37 +02:00
Make a copy of the **docker/env.example** file and use it as a starting point.
Set all the environment variables needed by your application. Please refer to the [FabManager README](https://github.com/LaCasemate/fab-manager/blob/master/README.md) for explanations about those variables.
Then, copy the previously customized `env.example` file as `/apps/fabmanager/config/env`
### setup nginx file
2016-04-11 20:24:09 +02:00
2017-07-20 17:37:03 +02:00
Create the nginx folder:
2016-04-11 20:24:09 +02:00
```bash
2017-07-20 19:54:37 +02:00
mkdir -p /apps/fabmanager/config/nginx
2016-04-11 20:24:09 +02:00
```
2016-03-23 18:39:41 +01:00
2017-07-20 19:54:37 +02:00
Customize the docker/nginx_with_ssl.conf.example file
* Replace **MAIN_DOMAIN** (example: fab-manager.com).
* Replace **URL_WITH_PROTOCOL_HTTPS** (example: https://www.fab-manager.com).
* Replace **ANOTHER_URL_1**, **ANOTHER_URL_2** (example: .fab-manager.fr)
**Use nginx.conf.example if you don't want SSL for your app.**
2017-07-20 17:37:03 +02:00
Then,
2017-07-20 19:54:37 +02:00
Copy the previously customized `nginx_with_ssl.conf.example` as `/apps/fabmanager/config/nginx/fabmanager.conf`
2017-07-20 17:37:03 +02:00
**OR**
2017-07-20 19:54:37 +02:00
Copy the previously customized `nginx.conf.example` as `/apps/fabmanager/config/nginx/fabmanager.conf` if you do not want to use ssl (not recommended !).
2017-07-20 17:37:03 +02:00
### SSL certificate with LetsEncrypt
2017-07-20 17:14:02 +02:00
2017-07-20 17:37:03 +02:00
**FOLLOW THOSE INSTRUCTIONS ONLY IF YOU WANT TO USE SSL**.
2017-07-20 16:48:34 +02:00
Let's Encrypt is a new Certificate Authority that is free, automated, and open.
Lets Encrypt certificates expire after 90 days, so automation of renewing your certificates is important.
2017-07-20 16:48:34 +02:00
Here is the setup for a systemd timer and service to renew the certificates and reboot the app Docker container:
```bash
2017-07-20 19:54:37 +02:00
mkdir -p /apps/fabmanager/config/nginx/ssl
```
2017-07-20 19:54:37 +02:00
Run `openssl dhparam -out dhparam.pem 4096` in the folder /apps/fabmanager/config/nginx/ssl (generate dhparam.pem file)
```bash
2017-07-20 19:54:37 +02:00
mkdir -p /apps/fabmanager/letsencrypt/config/
```
2017-07-20 19:54:37 +02:00
Copy the previously customized `webroot.ini.example` as `/appsfabmanager/letsencrypt/config/webroot.ini`
```bash
2017-07-20 19:54:37 +02:00
mkdir -p /apps/fabmanager/letsencrypt/etc/webrootauth
```
Run `docker pull quay.io/letsencrypt/letsencrypt:latest`
2017-07-20 16:48:34 +02:00
Create file (with sudo) /etc/systemd/system/letsencrypt.service and paste the following configuration into it:
```bash
[Unit]
Description=letsencrypt cert update oneshot
Requires=docker.service
[Service]
Type=oneshot
2017-07-20 19:54:37 +02:00
ExecStart=/usr/bin/docker run --rm --name letsencrypt -v "/apps/fabmanager/log:/var/log/letsencrypt" -v "/apps/fabmanager/letsencrypt/etc:/etc/letsencrypt" -v "/apps/fabmanager/letsencrypt/config:/letsencrypt-config" quay.io/letsencrypt/letsencrypt:latest -c "/letsencrypt-config/webroot.ini" certonly
2016-11-30 21:48:46 +01:00
ExecStartPost=-/usr/bin/docker restart fabmanager_nginx_1
```
2017-07-20 16:48:34 +02:00
Create file (with sudo) /etc/systemd/system/letsencrypt.timer and paste the following configuration into it:
```bash
[Unit]
Description=letsencrypt oneshot timer
Requires=docker.service
[Timer]
OnCalendar=*-*-1 06:00:00
Persistent=true
Unit=letsencrypt.service
2016-11-30 21:48:46 +01:00
[Install]
WantedBy=timers.target
```
2017-07-20 16:48:34 +02:00
That's all for the moment. Keep on with the installation, we'll complete that part after deployment in the [Generate SSL certificate by Letsencrypt](#generate-ssl-cert-letsencrypt).
2016-03-23 18:39:41 +01:00
2017-07-20 19:54:37 +02:00
### Requirements
Verify that Docker and Docker-composer are installed :
(This is normally the case if you used a pre-configured image.)
2016-03-23 18:39:41 +01:00
```bash
2017-07-20 19:54:37 +02:00
docker info
docker-compose -v
```
Otherwise, you can install docker to ubuntu with the following instructions :
https://docs.docker.com/engine/installation/linux/ubuntu/#install-using-the-repository
To install docker-compose :
```bash
curl -L https://github.com/docker/compose/releases/download/1.13.0/docker-compose-`uname -s`-`uname -m` > ./docker-compose
2017-07-20 16:48:34 +02:00
sudo mkdir -p /opt/bin
sudo mv docker-compose /opt/bin/
sudo chmod +x /opt/bin/docker-compose
2016-03-23 18:39:41 +01:00
```
2017-07-20 19:54:37 +02:00
## Install Fabmanager
### Add docker-compose.yml file
Copy docker-compose.yml to your app folder `/apps/fabmanager`.
The docker-compose commands must be launched from the folder `/apps/fabmanager`.
2016-03-23 18:39:41 +01:00
2017-07-20 17:37:03 +02:00
### pull images
2016-03-23 18:39:41 +01:00
```bash
2017-07-20 16:48:34 +02:00
docker-compose pull
2016-03-23 18:39:41 +01:00
```
2017-07-20 17:37:03 +02:00
### setup database
2016-03-23 18:39:41 +01:00
```bash
2017-07-20 16:48:34 +02:00
docker-compose run --rm fabmanager bundle exec rake db:create # create the database
docker-compose run --rm fabmanager bundle exec rake db:migrate # run all the migrations
docker-compose run --rm -e ADMIN_EMAIL=xxx ADMIN_PASSWORD=xxx fabmanager bundle exec rake db:seed # seed the database
2016-03-23 18:39:41 +01:00
```
2017-07-20 17:37:03 +02:00
### build assets
2016-03-23 18:39:41 +01:00
2017-07-20 16:48:34 +02:00
`docker-compose run --rm fabmanager bundle exec rake assets:precompile`
2016-03-23 18:39:41 +01:00
2017-07-20 17:37:03 +02:00
### prepare Elasticsearch (search engine)
2016-03-23 18:39:41 +01:00
2017-07-20 16:48:34 +02:00
`docker-compose run --rm fabmanager bundle exec rake fablab:es_build_stats`
2016-03-23 18:39:41 +01:00
2017-07-20 17:37:03 +02:00
#### start all services
2016-03-23 18:39:41 +01:00
2017-07-20 16:48:34 +02:00
`docker-compose up -d`
2016-09-06 12:19:47 +02:00
2017-07-20 16:48:34 +02:00
### Generate SSL certificate by Letsencrypt
2016-03-23 18:39:41 +01:00
2017-07-20 19:54:37 +02:00
**Important: app must be run on http before starting letsencrypt**
Start letsencrypt service :
```bash
sudo systemctl start letsencrypt.service
```
2017-07-20 16:48:34 +02:00
If the certificate was successfully generated then update the nginx configuration file and activate the ssl port and certificate
2017-07-20 19:54:37 +02:00
editing the file `/apps/fabmanager/config/nginx/fabmanager.conf`.
2017-07-20 16:48:34 +02:00
Remove your app container and run your app to apply the changes running the following commands:
```bash
docker-compose down
docker-compose up -d
```
Finally, if everything is ok, start letsencrypt timer to update the certificate every 1st of the month :
```bash
2016-11-30 21:48:46 +01:00
sudo systemctl enable letsencrypt.timer
sudo systemctl start letsencrypt.timer
2016-11-30 21:48:46 +01:00
(check) sudo systemctl list-timers
```
2017-07-20 19:54:37 +02:00
## Docker utils with docker-compose
2016-03-23 18:39:41 +01:00
2017-07-20 16:48:34 +02:00
### Restart app
2016-04-11 20:24:09 +02:00
2017-07-20 19:54:37 +02:00
`docker-compose restart fabmanager`
2016-04-11 20:24:09 +02:00
2017-07-20 16:48:34 +02:00
### Remove app
2016-04-11 20:24:09 +02:00
2017-07-20 19:54:37 +02:00
`docker-compose down fabmanager`
### Restart all containers
`docker-compose restart`
### Remove all containers
`docker-compose down`
### Start all containers
`docker-compose up -d`
2016-04-11 20:24:09 +02:00
2017-07-20 16:48:34 +02:00
### Open a bash in the app context
2016-04-11 20:24:09 +02:00
2017-07-20 19:54:37 +02:00
`docker-compose run --rm fabmanager bash`
2016-04-11 20:24:09 +02:00
2017-07-20 16:48:34 +02:00
### Show services status
2016-06-14 14:33:57 +02:00
2017-07-20 16:48:34 +02:00
`docker-compose ps`
2016-06-14 14:33:57 +02:00
2017-07-20 19:54:37 +02:00
### Restart nginx container
`docker-compose restart nginx`
### Example of command passing env variables
2017-07-20 19:54:37 +02:00
docker-compose run --rm -e ADMIN_EMAIL=xxx ADMIN_PASSWORD=xxx fabmanager bundle exec rake db:seed
2016-06-14 14:33:57 +02:00
2017-07-20 19:54:37 +02:00
## update Fabmanager
2017-07-20 17:14:02 +02:00
*This procedure updates fabmanager to the most recent version by default.*
2017-07-20 17:14:02 +02:00
2017-07-20 17:37:03 +02:00
### Steps
2017-07-20 17:14:02 +02:00
2017-07-20 16:48:34 +02:00
When a new version is available, this is how to update fabmanager app in a production environment, using docker-compose :
2016-06-14 14:33:57 +02:00
2017-07-20 17:37:03 +02:00
1. go to your app folder
2016-06-14 14:33:57 +02:00
2017-07-20 19:54:37 +02:00
`cd /apps/fabmanager`
2016-06-14 14:33:57 +02:00
2017-07-20 17:37:03 +02:00
2. pull last docker images
2016-06-14 14:33:57 +02:00
`docker-compose pull`
2017-07-20 17:37:03 +02:00
3. stop the app
2016-06-14 14:33:57 +02:00
`docker-compose stop fabmanager`
2016-06-14 14:33:57 +02:00
2017-07-20 17:37:03 +02:00
4. remove old assets
2016-06-14 14:33:57 +02:00
2017-07-20 19:54:37 +02:00
`rm -Rf public/assets/`
2016-06-14 14:33:57 +02:00
2017-07-20 17:37:03 +02:00
5. compile new assets
2016-06-14 14:33:57 +02:00
`docker-compose run --rm fabmanager bundle exec rake assets:precompile`
2016-06-14 14:33:57 +02:00
2017-07-20 17:37:03 +02:00
6. run specific commands
2016-06-14 14:33:57 +02:00
**Do not forget** to check if there are commands to run for your upgrade. Those commands
are always specified in the [CHANGELOG](https://github.com/LaCasemate/fab-manager/blob/master/CHANGELOG.md) and prefixed by **[TODO DEPLOY]**.
They are also present in the [releases page](https://github.com/LaCasemate/fab-manager/releases).
Those commands execute specific tasks and have to be run by hand.
2016-06-14 14:33:57 +02:00
2017-07-20 17:37:03 +02:00
7. restart all containers
2016-06-14 14:33:57 +02:00
```bash
docker-compose down
docker-compose up -d
```
2016-06-14 14:33:57 +02:00
2017-07-20 16:48:34 +02:00
You can check that all containers are running with `docker ps`.
2016-06-14 14:33:57 +02:00
2017-07-20 17:37:03 +02:00
### Good to know
2016-06-14 14:33:57 +02:00
2017-07-20 16:48:34 +02:00
#### Is it possible to update several versions at the same time ?
2016-06-14 14:33:57 +02:00
2017-07-20 16:48:34 +02:00
Yes, indeed. It's the default behaviour as `docker-compose pull` command will fetch the latest versions of the docker images.
Be sure to run all the specific commands listed in the [CHANGELOG](https://github.com/LaCasemate/fab-manager/blob/master/CHANGELOG.md) between your actual
and the new version in sequential order. (Example: to update from 2.4.0 to 2.4.3, you will run the specific commands for the 2.4.1, then for the 2.4.2 and then for the 2.4.3).