5 ms·
Digital Ocean: Ubuntu, Nginx, Unicorn, Rails
- meritt 12y agoGreat writeup. One suggestion on the nginx front I might suggest is you add an entry to drop requests for unknown hosts. e.g. http://104.131.41.220 http://104.131.41.220 https://github.com/h5bp/server-configs-nginx/blob/master/sites-available/no-default https://github.com/h5bp/server-configs-nginx/blob/master/sit... That github repo is a goldmine for understanding nginx configs too.
- jonmccartie 12y agoGood call. Thanks, man.
- latch 12y agoother things to consider: # if you compiled --with-http_spdy_module listen 443 ssl spdy; # amusing how many of these you'll get location ~*\.php { add_header "Not Found" 404; } # pretty sure you need to do this to have keepalive working # between nginx and the upstream proxy_set_header Connection ""; proxy_http_version 1.1; # buffer writes to disk (for a busy site, you can use much larger values than 1K) access_log /var/log/nginx/access.log buffer=1K; # cache the ssl connction parameters ssl_session_cache shared:SSL:20m; ssl_session_timeout 10m;
- jonmccartie 12y agoThe .php block gave me a good laugh. Great idea. Just rejecting /wp-admin.php should reduce load significantly. :)
- thejerz 12y agoI wouldn't recommend running Nginx, Unicorn, Rails, Redis, and PostgreSQL all on one instance. Better to offload the databases onto their own VPS's.
- jonmccartie 12y agoAgreed. This is just a temporary solution for a small-ish app. Looking forward to solving those problems...
- threeseed 12y agoEven better idea is not to host the databases at all. Only those who have never experienced a corrupted backup or failed slaves think a database is something that is relatively trivial to manage. You're much better off looking at platforms like RDS, MongoHQ, Cloudant etc.
- sespindola 12y agoIn my experience, hosted database providers are almost always either cost or latency prohibitive. Nowadays, in PostgreSQL is quite simple to replicate a db via log shipping[1]. You can even stream the WAL to an S3 bucket. [1]: http://www.postgresql.org/docs/9.3/static/warm-standby.html http://www.postgresql.org/docs/9.3/static/warm-standby.html
- threeseed 12y agoI currently use MongoHQ and get response times in the tens of milliseconds for $18/month. Hardly cost or latency prohibitive. I've seen similar times for less money with Cloudant. Making sure that master/slave scenario works when you need it to requires extensive testing and care. You also failed to address backups. I've yet to meet anyone who runs their own database who actually tests their backup.
- davidlumley 12y agoI used to prefer the flexibility and efficiency of having my VPS setup, and it's certainly cheaper. Over the past 2 years though, I've saved so much time and sanity using Heroku. I certainly can understand saving thousands of dollars and improving performance by moving from Heroku to a VPS or bare metal solution, but $90 is not uncomfortable enough for me to warrant the change. Interesting article!
- jonmccartie 12y agoThanks, David. We use Heroku a TON at work and I absolutely love them. For my small-ish app, I just couldn't afford the extra cash to pay Heroku to manage my app. Thanks for reading!
- davidlumley 12y agoAh, that makes a lot more sense! I quickly skimmed through SproutMark and it seemed great so assumed it was a full time job.
- jonmccartie 12y agoThat's the best compliment I've gotten all day. Thanks! :)
- brettskiii 12y agoHeroku apps aren't performant in many areas of the world e.g Australia like where I am, Amazon EC2 has an Australian region which is amazing
- davidlumley 12y agoI'm also Australian, but we have a fairly international customer base so the ~150ms difference for requests that hit the application hasn't been that big for us in the scheme of things.
- 12y ago
- akbar501 12y agoAlso worth noting that you should run a firewall as part of the basic configuration. AWS includes this via the Security Groups, but with DO you'll need to use iptables or ifw.
- jonmccartie 12y agoGood point. I didn't mention it in this post, but DO has a great article on getting started with firewalls: https://www.digitalocean.com/community/tutorials/how-to-set-up-a-firewall-using-iptables-on-ubuntu-14-04 https://www.digitalocean.com/community/tutorials/how-to-set-...
- donw 12y agoOr `ufw` if you're on Ubuntu -- very easy to set up, much easier than crafting rules by hand. I'm also a fan of running `sshd` on an off-numbered port to add another layer of protection against zero-day attacks. Most worms spread by compromising a service on a host, and then hitting everything around that host, but (to my knowledge) most of these depend on targeted services living on their default ports. It won't buy you anything against a direct attack, but security is all about layers of defense, not just having a hard outer shell.
- MaxGabriel 12y agoI think this is a typo; "deafult" instead of "default" nano /etc/nginx/sites-enabled/deafult
- jonmccartie 12y agoAck! Good catch! Fixed!
- xtrumanx 12y agoQuick question; I don't know much about setting up a Linux server but I found it interesting the post had nothing related to security besides setting up a ssh key and separate user for deployment. What security-related tasks do you do when setting up a new server? Besides the above, the only things that come to mind for me are: 1. Change ssh port from default. 2. Block unwanted traffic via iptables. 3. Protect ssh with fail2ban.
- latch 12y ago#2 and #3 in your list are rather sweeping (fail2ban does more than protect ssh). I'm no expert either, the only thing I'd add is to disable password-based logins and root-login [1] [1] http://www.unixlore.net/articles/five-minutes-to-more-secure-ssh.html http://www.unixlore.net/articles/five-minutes-to-more-secure...
- yeukhon 12y agoI personally have a mixed feeling about disabling password-based login. What if you've lot your key and you need to access the server for reasons such as getting the data out, how do you do it without root and without login password? Is there a way to go around this issue? Let me know if there is because right now, I have login password that I don't re-use. Well, I guess for real deployment, serving real users, you'd have shading and a good central logging system so losing an instance is not a big deal, but for me I run a personal server and this is so far the way I protect myself (have login and ssh) in the case of lossing my key :( Anyhow, DO droplets allow people to "reset" root password and it is important to protect your DO account.
- dmourati 12y agoI find the references to the nano text editor endearing.
- jonmccartie 12y agoLOL! It was intentional. :)
- locusm 12y agoWhat about backup, check out Duplicity for backing up to S3. Rackspace has quite a nice built in tool for backups too if you ever leave your current setup. Duplicity http://duplicity.nongnu.org/ http://duplicity.nongnu.org/
- michaelbuckbee 12y agoWhile I appreciate the time and effort put into both this hosting move (and the subsequent writeup), I really can't help but feel the time and effort would have been better spent on gaining more traffic and users than on the move. OP is saving $90/mo, less than the cost of adding just one new monthly subscriber at his 'Premium' plan.
- jonmccartie 12y agoIt didn't take long ... and I wanted to take a break from staring at my non-performant Facebook ads and making cold calls.
- frik 12y agoI heard Ansible over SSH is good to automate the installation. Has some experience with it? I am interested in a good tutorial similar to OP's article.
- elithrar 12y agoHave you looked at these? https://www.digitalocean.com/community/tutorials/how-to-create-ansible-playbooks-to-automate-system-configuration-on-ubuntu https://www.digitalocean.com/community/tutorials/how-to-crea... + https://www.digitalocean.com/community/tutorials/how-to-install-and-configure-ansible-on-an-ubuntu-12-04-vps https://www.digitalocean.com/community/tutorials/how-to-inst...
- castell 12y agoThanks for sharing! Great that DigitalOcean has many useful tutorials. The tutorial doesn't touch the "replace" command (http://docs.ansible.com/replace_module.html http://docs.ansible.com/replace_module.html), that seem to be useful to modifying existing config files.
- buttermint 12y agoWould love to see a part two of this, for when you app gets popular... covering three simple (but perplexing for beginners) things: 1) dedicated database server 2) two application servers 3) git push to multiple application servers
- jonmccartie 12y agoGreat idea, thanks!
- tovmeod 12y ago> sudo apt-get install nginx no, the ubuntu repository is outdated, you should add the nginx team ppa: sudo add-apt-repository ppa:nginx/stable now you can 'sudo apt-get install nginx'
- xxdesmus 12y agoAnother potential repo: https://launchpad.net/~chris-lea/+archive/ubuntu/nginx-devel https://launchpad.net/~chris-lea/+archive/ubuntu/nginx-devel