Corrected the path for the certificate renewal script in the documentation to use /cert/etc/xray/cert/renew.sh instead of ~/cert/etc/xray/cert/renew.sh.
4.5 KiB
4.5 KiB
Automated Web Deployment Script
A comprehensive automation script for deploying professional portfolio websites with SSL certificates and optimized web server configuration.
🚀 Features
- Automated Web Server Setup: Configures Nginx with optimized settings
- SSL Certificate Management: Automatic SSL certificate provisioning and renewal using acme.sh
- Professional Portfolio Template: Includes a beautiful, responsive portfolio website
- System Optimization: Configures BBR congestion control and other performance optimizations
- Certificate Auto-Renewal: Sets up automated certificate renewal via cron jobs
- Security Headers: Implements HSTS and other security best practices
📋 Prerequisites
- Ubuntu/Debian-based Linux server
- Root or sudo access
- Domain name pointing to your server's IP address
- Open ports 80 and 443
🛠️ Usage
-
Log in as a non-root user and update your system:
sudo apt update && sudo apt upgrade -y -
Run the setup script with required parameters:
curl -L https://github.com/xixu-me/automated-web-deployment/raw/main/setup.sh | bash -s <username> <domain> <unique-id> -
If you encounter the following error:
bash: curl: command not foundPlease install
curlandbashfirst:sudo apt install curl bash -y
Parameters
<username>: Your system username<domain>: Your domain name (e.g., example.com)<unique-id>: A unique identifier (UUID format recommended)
Example
./setup.sh john example.com 12345678-1234-1234-1234-123456789abc
🎨 Portfolio Features
The included portfolio template features:
- Responsive Design: Works on all devices and screen sizes
- Modern UI: Clean, professional design with CSS Grid and Flexbox
- Contact Form: Ready-to-use contact form structure
- Project Showcase: Grid layout for displaying projects
- Skills Section: Tag-based skills display
- SEO Optimized: Proper HTML structure and meta tags
Customization
To customize the portfolio:
- Edit
/var/www/html/index.htmlafter installation - Modify the personal information, projects, and skills
- Update the color scheme by changing CSS custom properties
🔧 What the Script Does
- Package Installation: Installs required packages (cron, nginx)
- Web Server Configuration: Sets up Nginx with optimized configuration
- SSL Certificate Setup: Provisions SSL certificates using Let's Encrypt
- Portfolio Deployment: Creates and deploys a professional portfolio website
- Auto-Renewal Setup: Configures automatic certificate renewal
- System Optimization: Applies performance optimizations
- Security Configuration: Implements security headers and HTTPS redirect
📁 File Structure
/var/www/html/ # Web root directory
├── index.html # Portfolio website
/etc/xray/cert/ # SSL certificates directory
├── x.crt # SSL certificate
├── x.key # Private key
└── renew.sh # Certificate renewal script
🔒 Security Features
- HTTPS Redirect: Automatic HTTP to HTTPS redirection
- HSTS Headers: Strict Transport Security implementation
- SSL Configuration: Modern TLS protocols and cipher suites
- Secure File Permissions: Proper file ownership and permissions
🔄 Maintenance
Certificate Renewal
Certificates are automatically renewed monthly via cron job. To manually renew:
bash /cert/etc/xray/cert/renew.sh
Nginx Configuration
Main configuration file: /etc/nginx/nginx.conf
To reload Nginx after changes:
sudo systemctl reload nginx
🐛 Troubleshooting
Common Issues
- Domain not pointing to server: Ensure DNS A record points to your server's IP
- Firewall blocking ports: Make sure ports 80 and 443 are open
- Permission errors: Ensure script is run with appropriate privileges
Log Files
- Nginx access logs:
/var/log/nginx/access.log - Nginx error logs:
/var/log/nginx/error.log - System logs:
journalctl -u nginx
📝 License
This project is licensed under the GNU General Public License v3.0 - see the LICENSE file for details.
⚠️ Important Notes
- This script will reboot the server at the end of installation
- Backup any existing Nginx configuration before running
- The script is designed for fresh server installations
- Domain validation is required for SSL certificate issuance