1773ed5f95
Mirror to GitHub / mirror (push) Successful in 26s
Test and Lint / backend-test (push) Successful in 1m11s
continuous-integration/drone/push Build is passing
Test and Lint / frontend-test (push) Successful in 2m28s
Version and Release / version-bump (push) Successful in 32s
Version and Release / trigger-drone (push) Has been skipped
Original: feat: enhance security logging and ensure rate limit blocks are properly tracked - Add comprehensive logging for rate limit blocks with full request details - IP address (with proper proxy detection), user agent, headers, timestamps - Rate limit info (current count, limit, remaining, reset time) - Separate tracking for auth vs general endpoints - Enhance authentication failure logging - JWT validation failures with detailed error info - Admin auth attempts without token - Failed token validation with user context - All events include IP, path, method, user agent - Improve Winston logger configuration for production - Add automatic log rotation (10MB errors, 50MB combined) - Create separate security.log for auth/rate limit events - Ensure logs directory exists automatically - Add structured JSON format for log aggregation - Support container logging with LOG_TO_CONSOLE env var - Create comprehensive documentation - Security logging guide with examples - Monitoring recommendations - Configuration reference - Add test script to verify logging functionality All rate limit settings remain configurable via admin panel: - Window duration, max requests, auth limits - Skip authenticated requests option - Public endpoints only option 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
220 lines
4.6 KiB
Markdown
220 lines
4.6 KiB
Markdown
# 🚀 PicPeak Deployment Guide
|
|
|
|
This guide will help you deploy PicPeak in production. The entire process takes about 10-15 minutes.
|
|
|
|
## 📋 Prerequisites
|
|
|
|
- A server with Docker and Docker Compose installed
|
|
- A domain name (for SSL certificates)
|
|
- SMTP credentials for sending emails
|
|
- Basic command line knowledge
|
|
|
|
## 🏃 Quick Deploy (Recommended)
|
|
|
|
### 1. Clone and Configure
|
|
|
|
```bash
|
|
# Clone the repository
|
|
git clone https://github.com/the-luap/picpeak.git
|
|
cd picpeak
|
|
|
|
# Copy environment template
|
|
cp .env.production.example .env
|
|
|
|
# Generate a secure JWT secret
|
|
echo "JWT_SECRET=$(openssl rand -base64 32)" >> .env
|
|
|
|
# Edit configuration
|
|
nano .env
|
|
```
|
|
|
|
### 2. Required Environment Variables
|
|
|
|
Edit your `.env` file with these essential settings:
|
|
|
|
```env
|
|
# Application URLs
|
|
FRONTEND_URL=https://your-domain.com
|
|
BACKEND_URL=https://your-domain.com
|
|
|
|
# Email Configuration (Required for notifications)
|
|
SMTP_HOST=smtp.gmail.com
|
|
SMTP_PORT=587
|
|
SMTP_USER=your-email@gmail.com
|
|
SMTP_PASS=your-app-password
|
|
SMTP_FROM=your-email@gmail.com
|
|
|
|
# Admin Configuration
|
|
ADMIN_EMAIL=admin@your-domain.com
|
|
ADMIN_PASSWORD=your-secure-password
|
|
|
|
# Database (PostgreSQL for production)
|
|
DATABASE_CLIENT=pg
|
|
DB_HOST=postgres
|
|
DB_NAME=picpeak
|
|
DB_USER=picpeak
|
|
DB_PASSWORD=secure-db-password
|
|
```
|
|
|
|
### 3. Deploy with Docker Compose
|
|
|
|
```bash
|
|
# Start all services
|
|
docker-compose -f docker-compose.prod.yml up -d
|
|
|
|
# Check logs
|
|
docker-compose logs -f
|
|
|
|
# Access your site at https://your-domain.com
|
|
```
|
|
|
|
## 🔧 Configuration Options
|
|
|
|
### Storage Settings
|
|
|
|
```env
|
|
# Storage paths (default: ./storage)
|
|
STORAGE_PATH=./storage
|
|
ARCHIVE_PATH=./storage/archives
|
|
|
|
# Gallery expiration (days)
|
|
DEFAULT_EXPIRATION_DAYS=30
|
|
WARNING_DAYS_BEFORE_EXPIRY=7
|
|
```
|
|
|
|
### Security Settings
|
|
|
|
```env
|
|
# Session timeout (minutes)
|
|
SESSION_TIMEOUT=60
|
|
|
|
# Rate limiting
|
|
RATE_LIMIT_WINDOW_MS=900000 # 15 minutes
|
|
RATE_LIMIT_MAX_REQUESTS=100
|
|
```
|
|
|
|
### Analytics (Optional)
|
|
|
|
```env
|
|
# Umami Analytics
|
|
VITE_UMAMI_URL=https://analytics.your-domain.com
|
|
VITE_UMAMI_WEBSITE_ID=your-website-id
|
|
```
|
|
|
|
## 🔒 SSL/TLS Setup
|
|
|
|
The production Docker Compose includes automatic SSL via Let's Encrypt:
|
|
|
|
1. **Ensure your domain points to your server**
|
|
2. **Update nginx configuration**:
|
|
```bash
|
|
nano nginx/nginx.conf
|
|
# Replace your-domain.com with your actual domain
|
|
```
|
|
3. **Start services** - Certbot will automatically obtain certificates
|
|
|
|
## 📁 Directory Structure
|
|
|
|
After deployment, your directory structure will be:
|
|
|
|
```
|
|
picpeak/
|
|
├── backend/ # API server
|
|
├── frontend/ # React app
|
|
├── storage/ # Photo storage
|
|
│ ├── events/ # Active galleries
|
|
│ │ ├── active/ # Current photos
|
|
│ │ └── archived/ # Expired galleries
|
|
│ ├── thumbnails/ # Generated thumbnails
|
|
│ └── uploads/ # User uploads
|
|
├── data/ # Database files
|
|
└── logs/ # Application logs
|
|
```
|
|
|
|
## 🔄 Maintenance
|
|
|
|
### Backup
|
|
|
|
```bash
|
|
# Backup database and photos
|
|
./scripts/backup.sh
|
|
|
|
# Backups are stored in ./backups/
|
|
```
|
|
|
|
### Update
|
|
|
|
```bash
|
|
# Pull latest changes
|
|
git pull
|
|
|
|
# Rebuild and restart
|
|
docker-compose -f docker-compose.prod.yml up -d --build
|
|
```
|
|
|
|
### Logs
|
|
|
|
```bash
|
|
# View all logs
|
|
docker-compose logs
|
|
|
|
# View specific service
|
|
docker-compose logs backend
|
|
docker-compose logs frontend
|
|
```
|
|
|
|
## 🚨 Troubleshooting
|
|
|
|
### Common Issues
|
|
|
|
**Photos not appearing:**
|
|
- Check storage permissions: `chmod -R 755 storage/`
|
|
- Verify file watcher is running: `docker-compose logs backend | grep watcher`
|
|
|
|
**Email not sending:**
|
|
- Test SMTP settings: Admin Panel → Settings → Email → Send Test
|
|
- Check email queue: Admin Panel → System → Email Queue
|
|
|
|
**Can't access admin panel:**
|
|
- Default login: Use email/password from `.env`
|
|
- Reset password: `docker exec picpeak-backend npm run reset-admin`
|
|
|
|
### Health Check
|
|
|
|
```bash
|
|
# Check service status
|
|
docker-compose ps
|
|
|
|
# Test backend API
|
|
curl https://your-domain.com/api/health
|
|
|
|
# Check disk space
|
|
df -h storage/
|
|
```
|
|
|
|
## 🐳 Alternative Deployment Methods
|
|
|
|
### Using Docker Swarm
|
|
|
|
For high availability deployments, see [Docker Swarm Setup](deploy/README.md).
|
|
|
|
### Manual Installation
|
|
|
|
If you prefer not to use Docker:
|
|
|
|
1. Install Node.js 18+
|
|
2. Install PostgreSQL
|
|
3. Clone repository
|
|
4. Install dependencies: `npm install` in both `/backend` and `/frontend`
|
|
5. Build frontend: `cd frontend && npm run build`
|
|
6. Start services with PM2
|
|
|
|
## 📞 Support
|
|
|
|
- 📘 [Documentation](https://github.com/the-luap/picpeak)
|
|
- 🐛 [Report Issues](https://github.com/the-luap/picpeak/issues)
|
|
- 💬 [Discussions](https://github.com/the-luap/picpeak/discussions)
|
|
|
|
---
|
|
|
|
**Need help?** Open an issue on GitHub and we'll assist you! |