Files
picpeak/DEPLOYMENT.md
T
paul 1773ed5f95
Mirror to GitHub / mirror (push) Successful in 26s
Test and Lint / backend-test (push) Successful in 1m11s
continuous-integration/drone/push Build is passing
Test and Lint / frontend-test (push) Successful in 2m28s
Version and Release / version-bump (push) Successful in 32s
Version and Release / trigger-drone (push) Has been skipped
Initial commit - Project start (July 17, 2025)
Original: feat: enhance security logging and ensure rate limit blocks are properly tracked

- Add comprehensive logging for rate limit blocks with full request details
  - IP address (with proper proxy detection), user agent, headers, timestamps
  - Rate limit info (current count, limit, remaining, reset time)
  - Separate tracking for auth vs general endpoints

- Enhance authentication failure logging
  - JWT validation failures with detailed error info
  - Admin auth attempts without token
  - Failed token validation with user context
  - All events include IP, path, method, user agent

- Improve Winston logger configuration for production
  - Add automatic log rotation (10MB errors, 50MB combined)
  - Create separate security.log for auth/rate limit events
  - Ensure logs directory exists automatically
  - Add structured JSON format for log aggregation
  - Support container logging with LOG_TO_CONSOLE env var

- Create comprehensive documentation
  - Security logging guide with examples
  - Monitoring recommendations
  - Configuration reference

- Add test script to verify logging functionality

All rate limit settings remain configurable via admin panel:
- Window duration, max requests, auth limits
- Skip authenticated requests option
- Public endpoints only option

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-24 16:57:07 +02:00

4.6 KiB

🚀 PicPeak Deployment Guide

This guide will help you deploy PicPeak in production. The entire process takes about 10-15 minutes.

📋 Prerequisites

  • A server with Docker and Docker Compose installed
  • A domain name (for SSL certificates)
  • SMTP credentials for sending emails
  • Basic command line knowledge

1. Clone and Configure

# Clone the repository
git clone https://github.com/the-luap/picpeak.git
cd picpeak

# Copy environment template
cp .env.production.example .env

# Generate a secure JWT secret
echo "JWT_SECRET=$(openssl rand -base64 32)" >> .env

# Edit configuration
nano .env

2. Required Environment Variables

Edit your .env file with these essential settings:

# Application URLs
FRONTEND_URL=https://your-domain.com
BACKEND_URL=https://your-domain.com

# Email Configuration (Required for notifications)
SMTP_HOST=smtp.gmail.com
SMTP_PORT=587
SMTP_USER=your-email@gmail.com
SMTP_PASS=your-app-password
SMTP_FROM=your-email@gmail.com

# Admin Configuration
ADMIN_EMAIL=admin@your-domain.com
ADMIN_PASSWORD=your-secure-password

# Database (PostgreSQL for production)
DATABASE_CLIENT=pg
DB_HOST=postgres
DB_NAME=picpeak
DB_USER=picpeak
DB_PASSWORD=secure-db-password

3. Deploy with Docker Compose

# Start all services
docker-compose -f docker-compose.prod.yml up -d

# Check logs
docker-compose logs -f

# Access your site at https://your-domain.com

🔧 Configuration Options

Storage Settings

# Storage paths (default: ./storage)
STORAGE_PATH=./storage
ARCHIVE_PATH=./storage/archives

# Gallery expiration (days)
DEFAULT_EXPIRATION_DAYS=30
WARNING_DAYS_BEFORE_EXPIRY=7

Security Settings

# Session timeout (minutes)
SESSION_TIMEOUT=60

# Rate limiting
RATE_LIMIT_WINDOW_MS=900000  # 15 minutes
RATE_LIMIT_MAX_REQUESTS=100

Analytics (Optional)

# Umami Analytics
VITE_UMAMI_URL=https://analytics.your-domain.com
VITE_UMAMI_WEBSITE_ID=your-website-id

🔒 SSL/TLS Setup

The production Docker Compose includes automatic SSL via Let's Encrypt:

  1. Ensure your domain points to your server
  2. Update nginx configuration:
    nano nginx/nginx.conf
    # Replace your-domain.com with your actual domain
    
  3. Start services - Certbot will automatically obtain certificates

📁 Directory Structure

After deployment, your directory structure will be:

picpeak/
├── backend/          # API server
├── frontend/         # React app
├── storage/          # Photo storage
│   ├── events/       # Active galleries
│   │   ├── active/   # Current photos
│   │   └── archived/ # Expired galleries
│   ├── thumbnails/   # Generated thumbnails
│   └── uploads/      # User uploads
├── data/            # Database files
└── logs/            # Application logs

🔄 Maintenance

Backup

# Backup database and photos
./scripts/backup.sh

# Backups are stored in ./backups/

Update

# Pull latest changes
git pull

# Rebuild and restart
docker-compose -f docker-compose.prod.yml up -d --build

Logs

# View all logs
docker-compose logs

# View specific service
docker-compose logs backend
docker-compose logs frontend

🚨 Troubleshooting

Common Issues

Photos not appearing:

  • Check storage permissions: chmod -R 755 storage/
  • Verify file watcher is running: docker-compose logs backend | grep watcher

Email not sending:

  • Test SMTP settings: Admin Panel → Settings → Email → Send Test
  • Check email queue: Admin Panel → System → Email Queue

Can't access admin panel:

  • Default login: Use email/password from .env
  • Reset password: docker exec picpeak-backend npm run reset-admin

Health Check

# Check service status
docker-compose ps

# Test backend API
curl https://your-domain.com/api/health

# Check disk space
df -h storage/

🐳 Alternative Deployment Methods

Using Docker Swarm

For high availability deployments, see Docker Swarm Setup.

Manual Installation

If you prefer not to use Docker:

  1. Install Node.js 18+
  2. Install PostgreSQL
  3. Clone repository
  4. Install dependencies: npm install in both /backend and /frontend
  5. Build frontend: cd frontend && npm run build
  6. Start services with PM2

📞 Support


Need help? Open an issue on GitHub and we'll assist you!