Files
rvbox/deploy/production/README.md
T

2.3 KiB

Production-shaped RVBox Linux-server Compose deployment

This directory is intentionally separate from the development/toolchain Compose files. It starts only the Linux server and nginx TLS terminator; Windows clients connect through nginx at /v1/agent.

Before the first start, create server.toml from the Compose-specific example:

cp server.toml.example server.toml
chmod 0644 server.toml

Set RVBOX_SERVER_IMAGE to an immutable image reference, plus absolute paths for RVBOX_TLS_CERT and RVBOX_TLS_KEY. The TLS key must be readable by Docker but should remain inaccessible to ordinary host users. server.toml can be kept outside this directory by setting RVBOX_SERVER_CONFIG to its absolute path; this is useful for a controlled smoke run without changing deployment files. Validate before start:

docker compose -f compose.yaml config
docker compose -f compose.yaml up -d

The stack's init container creates the two named volumes with the runtime ownership required by the non-root server. server-data is the sole persistent data volume and must be backed up as a whole while the server is stopped; server-run contains only the ephemeral local control socket. Do not publish, proxy, or enable JSON-RPC except for intentional loopback debugging.

server.toml contains configuration rather than credentials and must be world-readable on the host (0644): a bind mount preserves host file ownership, while the server intentionally runs as the fixed unprivileged container UID 65532. Keep TLS private keys outside server.toml and restrict the key file separately.

The provided Compose-specific example binds the private agent and observability listeners to 0.0.0.0 inside the Compose network. This is required for nginx to proxy them. It does not publish those ports to the host.

Set RVBOX_HTTPS_BIND when a deployment must bind a particular host interface; it defaults to 0.0.0.0. The repeatable test-only smoke lane binds only loopback, uses material beneath .test-runs, and can be run after building a local runtime image:

docker build -f deploy/Dockerfile.runtime -t rvbox-server:test .
scripts/test-production-compose run --run-id production-smoke
scripts/test-production-compose clean --run-id production-smoke --purge --yes