Architecture
Platform architecture
Servers
| ssdserver | 206.51.227.27 · Ubuntu 26.04 · 8 cores / 30 GB RAM / 473 GB disk — ALL production + monitoring stack (Prometheus/Grafana/Loki) + Gitea runner |
|---|---|
| dev server | 13.140.162.231 · Ubuntu 24.04 · ALL staging + Gitea (git.ivydigitals.com) + mailcow (email for ivydigitals.com) + CloudPanel |
URL map
| Production | www / lumen / one / launchpad / infinity / ppm / pulsehr / einv (+admin, developers, status, support) / ivyos .ivydigitals.com → ssdserver |
|---|---|
| Staging | staging.<app>.ivydigitals.com (and staging-admin.einv etc.) → dev server |
| Platform | releases.ivydigitals.com (Release Center) · docs.ivydigitals.com (this site) · git.ivydigitals.com (Gitea) → ssdserver / ssdserver / dev |
DNS & TLS
- DNS zone
ivydigitals.comon Cloudflare. Some records are proxied (orange cloud), some DNS-only — proxied settings were preserved during all migrations. - Every host has its own Let's Encrypt certificate, issued via DNS-01 (Cloudflare API token at
/root/.secrets/cloudflare.inion each server) — auto-renews. - On the dev server, the nginx
:443master is NOT systemd-managed — reload withkill -HUPto the master pid (pgrep -f 'nginx: master process nginx$'), notsystemctl reload nginx.
Code movement
- Source of truth: Gitea (private repos). Dev server working directories are git clones; pushes flow Gitea → Release Center → production.
- Secrets (.env, keys) and runtime state (databases, uploads) never enter git — they live server-side only.
IVY Digital · docs.ivydigitals.com · generated 2026-10-01 · Release Center · Gitea