Skip to content

Sword Backend Deployment Guide with HTTPS

This guide explains how to deploy the Sword Backend application with HTTPS on a Linux server.

Prerequisites

  • A Linux server (Ubuntu/Debian recommended)
  • A domain name pointing to your server
  • Root or sudo access to the server

Deployment Steps

1. Clone the Repository

First, clone the repository to your local machine or directly to the server.

git clone <repository-url> sword-backend
cd sword-backend

2. Update Deployment Script Variables

Edit the scripts/shell/deploy_https.sh script and update the following variables:

  • DOMAIN: Your actual domain name (e.g., api.yourdomain.com)
  • EMAIL: Your email address for Let's Encrypt notifications
# Open the file
nano scripts/shell/deploy_https.sh

# Update these lines
DOMAIN="your-domain.com"  # Replace with your actual domain
EMAIL="your-email@example.com"  # Replace with your email for Let's Encrypt

3. Make the Script Executable

chmod +x scripts/shell/deploy_https.sh

4. Run the Deployment Script

./scripts/shell/deploy_https.sh

The script will: - Install all necessary dependencies - Set up a Python virtual environment - Configure Nginx as a reverse proxy - Obtain SSL certificates from Let's Encrypt - Set up your application as a systemd service - Start all services

5. Verify the Deployment

After the script completes, verify that your application is running:

# Check the status of the application service
sudo systemctl status sword-backend

# Check Nginx status
sudo systemctl status nginx

# Test the API
curl -k https://your-domain.com/docs

Environment Variables

Make sure your .env file contains all necessary environment variables:

DATABASE_URL=postgresql://username:password@localhost:5432/sword_db
SECRET_KEY=your-secret-key
ALGORITHM=HS256
ACCESS_TOKEN_EXPIRE_MINUTES=30
MAIL_USERNAME=your-email@example.com
MAIL_PASSWORD=your-password
MAIL_FROM=your-email@example.com
MAIL_PORT=587
MAIL_SERVER=smtp.gmail.com

Troubleshooting

Check Logs

If you encounter issues, check the logs:

# Application logs
sudo journalctl -u sword-backend

# Nginx logs
sudo tail -f /var/log/nginx/error.log
sudo tail -f /var/log/nginx/access.log

SSL Certificate Issues

If you have issues with SSL certificates:

# Check certificate status
sudo certbot certificates

# Renew certificates manually
sudo certbot renew --dry-run

Firewall Configuration

Make sure your firewall allows HTTP (80) and HTTPS (443) traffic:

sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

Maintenance

Updating the Application

To update the application:

  1. Pull the latest changes from the repository
  2. Copy the updated files to the deployment directory
  3. Restart the service
cd /path/to/local/repository
git pull
rsync -av --exclude 'venv' --exclude '__pycache__' --exclude '.git' ./ /home/projects/sword-backend/
sudo systemctl restart sword-backend

SSL Certificate Renewal

Let's Encrypt certificates are valid for 90 days. Certbot automatically sets up a renewal cron job, but you can manually renew with:

sudo certbot renew

Database Backups

It's recommended to set up regular database backups:

# Example PostgreSQL backup command
pg_dump -U postgres sword_db > /path/to/backup/sword_db_$(date +%Y%m%d).sql