Maintenance contacts
Yueteng yh958@cornell.edu
Root domain
Root domain is: diaper.cf
Registered as a free domain (renewable every 12 months) at https://www.freenom.com/
User account login info (email, password) are the same as gmail/github/etc
Current registration expires on 2021-12-05 (December 5th) (Must renew at the above website before expiration)
Domains to use
| Environment | Backend | Domain | Note |
|---|---|---|---|
| Production | On-line | on-prod.diaper.cf | This points to AWS under Cornell contract |
| Test | On-line | on-test.diaper.cf | (Not set up yet) This points to public AWS (under Tan's account) |
| Production | Off-line | off-prod.diaper.cf | (Not set up yet) This points to AWS under Cornell contract |
| Test | Off-line | off-test.diaper.cf | (Not set up yet) This points to public AWS (under Tan's account) |
For API callers (i.e. frontend web/app)
Choose the domain accordingly, prepend it with http or https, and append it with port number and path.
e.g. https://on-prod.diaper.cf:5001/api/version
SSL Certificate for https
The free SSL cert from Let's Encrypt is used for this purpose.
Let's Encrypt: https://letsencrypt.org/
Tutorial for creating SSL cert
[Tutorial: Configure SSL/TLS on Amazon Linux 2 - Amazon Elastic Compute Cloud]
(https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/SSL-on-amazon-linux-2.html#letsencrypt)
On section "Certificate automation: Let’s Encrypt with Certbot on Amazon Linux 2", Use this to instal `certauto`, but not to create
Stop after done `sudo yum install -y certbot python2-certbot-apache`
[Generate Wildcard SSL certificate using Let’s Encrypt/Certbot | by Saurabh Palande | Medium]
(https://medium.com/@saurabh6790/generate-wildcard-ssl-certificate-using-lets-encrypt-certbot-273e432794d7)
Start at Step 3. Replace `./certbot-auto` with `sudo certbot`
Use this to run command to create
Note: There can be multiple domains in command, e.g. `-d yueteng.me -d *.yueteng.me`
Note: (The order is important) First deploy DNS TXT record under the prompted domain, pause for 5 minutes for it to activate, use the website below to verify it’s been activated (mind the value must be correct) then hit continue (otherwise will fail)
Note: If you include multiple domains, you will be required to enter multiple DNS TXT records
[DNS Lookup Text Record - MxToolbox](https://mxtoolbox.com/TXTLookup.aspx)
Command line to use
sudo certbot certonly --manual --preferred-challenges=dns --email diapertestemail@gmail.com --server https://acme-v02.api.letsencrypt.org/directory --agree-tos -d diaper.cf -d *.diaper.cf
Cert information
Upon success, you'll see some information similar to below
Press Enter to Continue Waiting for verification... Cleaning up challenges Subscribe to the EFF mailing list (email: diapertestemail@gmail.com). IMPORTANT NOTES: - Congratulations! Your certificate and chain have been saved at: /etc/letsencrypt/live/diaper.cf/fullchain.pem Your key file has been saved at: /etc/letsencrypt/live/diaper.cf/privkey.pem Your cert will expire on 2021-03-05. To obtain a new or tweaked version of this certificate in the future, simply run certbot again. To non-interactively renew *all* of your certificates, run "certbot renew"
Copy cert files to somewhere docker can access and give permission
Create a cert folder under project path, and copy both .pem files into the folder. Then change the permissions by:
sudo chown ec2-user:ec2user ./certs/*
This will allow flask and docker to access the cert files.
Specify which yml file to use when launching docker on production (and test) environment
A separate docker-compose config file named docker-compose-prod.yml is created.
Since only production (and test) environment will use this cert. When launching docker, must specify this yml file.
Command Line
docker-compose -f docker-compose-prod.yml up -d