Updated the README to focus on an automated script for deploying professional portfolio websites with SSL, optimized Nginx configuration, and enhanced security features. Added detailed usage instructions, feature list, customization steps, troubleshooting, and important disclaimers for users.
5.9 KiB
Automated Web Deployment Script
A comprehensive automation script for deploying professional portfolio websites with SSL certificates and optimized web server configuration.
🚀 Features
- Automated Web Server Setup: Configures Nginx with optimized settings
- SSL Certificate Management: Automatic SSL certificate provisioning and renewal using acme.sh
- Professional Portfolio Template: Includes a beautiful, responsive portfolio website
- System Optimization: Configures BBR congestion control and other performance optimizations
- Certificate Auto-Renewal: Sets up automated certificate renewal via cron jobs
- Security Headers: Implements HSTS and other security best practices
📋 Prerequisites
- Ubuntu/Debian-based Linux server
- Root or sudo access
- Domain name pointing to your server's IP address
- Open ports 80 and 443
🛠️ Usage
-
Log in as a non-root user and update your system:
sudo apt update && sudo apt upgrade -y -
Run the setup script with required parameters:
curl -L https://github.com/xixu-me/automated-web-deployment/raw/main/setup.sh | bash -s <username> <domain> <unique-id> -
If you encounter the following error:
bash: curl: command not foundPlease install
curlandbashfirst:sudo apt install curl bash -y
Parameters
<username>: Your system username<domain>: Your domain name (e.g., example.com)<unique-id>: A unique identifier (UUID format recommended)
Example
./setup.sh john example.com 12345678-1234-1234-1234-123456789abc
🎨 Portfolio Features
The included portfolio template features:
- Responsive Design: Works on all devices and screen sizes
- Modern UI: Clean, professional design with CSS Grid and Flexbox
- Contact Form: Ready-to-use contact form structure
- Project Showcase: Grid layout for displaying projects
- Skills Section: Tag-based skills display
- SEO Optimized: Proper HTML structure and meta tags
Customization
To customize the portfolio:
- Edit
/var/www/html/index.htmlafter installation - Modify the personal information, projects, and skills
- Update the color scheme by changing CSS custom properties
🔧 What the Script Does
- Package Installation: Installs required packages (cron, nginx)
- Web Server Configuration: Sets up Nginx with optimized configuration
- SSL Certificate Setup: Provisions SSL certificates using Let's Encrypt
- Portfolio Deployment: Creates and deploys a professional portfolio website
- Auto-Renewal Setup: Configures automatic certificate renewal
- System Optimization: Applies performance optimizations
- Security Configuration: Implements security headers and HTTPS redirect
📁 File Structure
/var/www/html/ # Web root directory
├── index.html # Portfolio website
~/cert/ # SSL certificates directory
├── x.crt # SSL certificate
├── x.key # Private key
└── cert-renew.sh # Certificate renewal script
🔒 Security Features
- HTTPS Redirect: Automatic HTTP to HTTPS redirection
- HSTS Headers: Strict Transport Security implementation
- SSL Configuration: Modern TLS protocols and cipher suites
- Secure File Permissions: Proper file ownership and permissions
🔄 Maintenance
Certificate Renewal
Certificates are automatically renewed monthly via cron job. To manually renew:
bash ~/cert/cert-renew.sh
Nginx Configuration
Main configuration file: /etc/nginx/nginx.conf
To reload Nginx after changes:
sudo systemctl reload nginx
🐛 Troubleshooting
Common Issues
- Domain not pointing to server: Ensure DNS A record points to your server's IP
- Firewall blocking ports: Make sure ports 80 and 443 are open
- Permission errors: Ensure script is run with appropriate privileges
Log Files
- Nginx access logs:
/var/log/nginx/access.log - Nginx error logs:
/var/log/nginx/error.log - System logs:
journalctl -u nginx
📝 License
This project is licensed under the GNU General Public License v3.0 - see the LICENSE file for details.
⚠️ Important Notes
- This script will reboot the server at the end of installation
- Backup any existing Nginx configuration before running
- The script is designed for fresh server installations
- Domain validation is required for SSL certificate issuance
⚠️ Disclaimer
USE AT YOUR OWN RISK: This script is provided "as is" without warranty of any kind, express or implied. The authors and contributors are not responsible for any damage, data loss, security vulnerabilities, or system issues that may result from using this script.
Important Considerations:
- This script makes significant changes to your server configuration
- It modifies system files and installs packages that may affect existing services
- Always test on a development environment before deploying to production
- Ensure you have proper backups before running the script
- Review the script code before execution to understand what changes will be made
- The script requires root privileges and will make system-wide changes
- SSL certificate provisioning depends on external services (Let's Encrypt/acme.sh)
- Network connectivity and DNS configuration are required for proper operation
Security Notice: While this script implements security best practices, no automated deployment can account for all possible security scenarios. It is your responsibility to:
- Keep your system updated with security patches
- Monitor your server for unusual activity
- Implement additional security measures as needed for your environment
- Regularly review and update configurations
By using this script, you acknowledge that you understand these risks and accept full responsibility for any consequences.