# Production-shaped RVBox Linux-server Compose deployment This directory is intentionally separate from the development/toolchain Compose files. It starts only the Linux server and nginx TLS terminator; Windows clients connect through nginx at `/v1/agent`. Before the first start, create `server.toml` from the authoritative example and prepare writable state directories for the runtime image UID/GID `65532`: ```sh cp ../../docs/examples/server.toml server.toml install -d -m 0700 -o 65532 -g 65532 state run chmod 0640 server.toml ``` Set `RVBOX_SERVER_IMAGE` to an immutable image reference, plus absolute paths for `RVBOX_TLS_CERT` and `RVBOX_TLS_KEY`. The TLS key must be readable by Docker but should remain inaccessible to ordinary host users. Validate before start: ```sh docker compose -f compose.yaml config docker compose -f compose.yaml up -d ``` Only `state/` and `run/` are persistent/owned deployment data. Back up the whole `state/` directory while the server is stopped; `run/` contains only the ephemeral local control socket. Do not publish, proxy, or enable JSON-RPC except for intentional loopback debugging.