You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
sims-hq/deploy/PATHS-AND-NAMES.md

4.2 KiB

SiMS HQ — Deployment Paths & Names (reference)

The single source of truth for where things live and what they're called in production. If a name here disagrees with a command you're about to run, this file wins. Server is the existing company Amazon Linux 2 EC2 box; HQ runs as its own Docker container beside the other apps. (D20 target, revised: .in not .com, Docker not RDS — see notes at bottom.)

Identity

Thing Value
Public URL https://hq.simssoftware.in
EC2 public IP (Elastic) 13.232.53.115
DNS record A · hq13.232.53.115, in the simssoftware.in zone (same place as gitea.simssoftware.in)
SSH user ec2-user
Box hostname ip-172-31-14-238

Git

Thing Value
Repo (Gitea) https://gitea.simssoftware.in/SIMS/sims-hq.git (moved from gitadmin/; old URL redirects)
Branch main

Folders on the box

Path What it is
/usr/share/nginx/sims-hq App folder — the whole project (owned by ec2-user). Docker builds from here.
/usr/share/nginx/sims-hq/apps/hq/.env Environment file — DB URL + secrets (chmod 600).
/usr/share/nginx/sims-hq/deploy/sims.hq.conf nginx vhost source (copied into nginx below).
/etc/nginx/conf.d/sims.hq.conf Live nginx vhost (must end in .conf; sudo to edit).
/etc/ssl/sims/sims.crt · /etc/ssl/sims/sims.key Wildcard TLS cert for *.simssoftware.in (shared).

Rule: anything under /etc/ (nginx, ssl) is root-owned — create/edit it in the PuTTY terminal with sudo, never via WinSCP. WinSCP can only write /usr/share/nginx/sims-hq (after chown ec2-user) and your home folder.

Docker

Thing Value
HQ container name sims-hq
HQ image sims-hq (built from Dockerfile)
Compose file /usr/share/nginx/sims-hq/docker-compose.yml
HQ port (host→container) 127.0.0.1:51825182 (localhost only; nginx proxies to it)
Postgres container accurate-postgres (image postgres) — shared with other apps
Postgres port (host) 0.0.0.0:5432
How HQ reaches Postgres host.docker.internal:5432 (via the host gateway)

Database (inside accurate-postgres)

Thing Value
Superuser (admin) postgres (connect via sudo docker exec -it accurate-postgres psql -U postgres)
HQ database hq (owned by postgres)
HQ login postgres — the shared superuser. Every app on this box uses it; there are no per-app roles (checked 2026-07-18). A dedicated hq role is a future hardening.
Connection string postgres://postgres:<postgres-password>@host.docker.internal:5432/hq

App environment (apps/hq/.env)

Key Value
HQ_PORT 5182
HQ_OWNER_EMAIL simssoftware13@gmail.com (first-boot owner login)
DATABASE_URL postgres://postgres:<postgres-password>@host.docker.internal:5432/hq
SIMS_PIN_PEPPER generated on box — set once, never change
HQ_SECRET_KEY generated on box (needed before Gmail)

Owner login

Thing Value
Email simssoftware13@gmail.com
First password printed once in sudo docker logs sims-hq on first boot — change immediately

Everyday commands (run from /usr/share/nginx/sims-hq)

Do this Command
Build + start sudo docker compose up -d --build
View logs sudo docker logs sims-hq (-f to follow)
Restart sudo docker compose restart hq
Stop sudo docker compose down
Health check curl -s localhost:5182/api/health{"ok":true}
nginx test + reload sudo nginx -t && sudo systemctl reload nginx

Notes / decisions

  • Domain is .in (not .com): the wildcard cert is *.simssoftware.in and every other app is on .in; hq.simssoftware.com was a stray easyDNS URL-forward.
  • Docker, not RDS: the box is Amazon Linux 2 (glibc 2.26) which can't run Node 20 natively, and Postgres already runs in the accurate-postgres container — so HQ is containerized and reuses that DB with its own isolated hq database + role.
  • Node runs only inside the container (node:20); the host's Node 16 and the other apps are untouched.