mirror of
https://github.com/MengMengCode/CLICD.git
synced 2026-08-06 13:54:44 +08:00
a45e063fc2
- Introduced Container Management documentation covering lifecycle operations, resource management, and console access. - Added Dashboard documentation detailing metrics and related APIs. - Created Host Report documentation summarizing host environment and resource status. - Included Image Management documentation for template handling and management actions. - Documented Networking and Routing features including NAT4 and IPv6 management. - Added Security Alerts documentation outlining alert scenarios and API usage. - Created Snapshot Management documentation for snapshot operations and scheduling. - Documented Sub-user management for granting access to specific containers. - Added Configuration guide detailing runtime settings and security recommendations. - Created Installation guide for setting up CLICD with requirements and steps. - Added Introduction and Quick Start guides for new users. - Documented Upgrade process with version checking and pre-upgrade checklist. - Created Deployment guide for service exposure and firewall recommendations. - Added FAQ section addressing common questions and concerns. - Documented Troubleshooting steps for common issues encountered.
47 lines
974 B
Markdown
47 lines
974 B
Markdown
# Deployment
|
|
|
|
CLICD can run directly on the host or behind a reverse proxy. In production, set up access control before exposing it to administrators.
|
|
|
|
## Service Exposure
|
|
|
|
The default web port is `8999`:
|
|
|
|
```text
|
|
http://YOUR_SERVER_IP:8999
|
|
```
|
|
|
|
Recommendations:
|
|
|
|
- Allow only fixed administrator IPs.
|
|
- Use a reverse proxy with HTTPS.
|
|
- Do not expose the real login URL in public docs or screenshots.
|
|
|
|
## systemd
|
|
|
|
Common commands:
|
|
|
|
```bash
|
|
systemctl status clicd
|
|
systemctl restart clicd
|
|
systemctl enable clicd
|
|
journalctl -u clicd -f
|
|
```
|
|
|
|
## Firewall
|
|
|
|
At minimum, confirm:
|
|
|
|
- The panel port is open only to trusted sources.
|
|
- NAT mapped ports are opened only as needed.
|
|
- The SSH management port does not conflict with container mappings.
|
|
- IPv6 firewall rules are planned together with IPv4 rules.
|
|
|
|
## Backups
|
|
|
|
Back up regularly:
|
|
|
|
- CLICD configuration directory.
|
|
- SQLite database.
|
|
- Container configuration.
|
|
- Snapshots or external data backups for important containers.
|