Architecture

Platform architecture

Servers

ssdserver206.51.227.27 · Ubuntu 26.04 · 8 cores / 30 GB RAM / 473 GB disk — ALL production + monitoring stack (Prometheus/Grafana/Loki) + Gitea runner
dev server13.140.162.231 · Ubuntu 24.04 · ALL staging + Gitea (git.ivydigitals.com) + mailcow (email for ivydigitals.com) + CloudPanel

URL map

Productionwww / lumen / one / launchpad / infinity / ppm / pulsehr / einv (+admin, developers, status, support) / ivyos .ivydigitals.com → ssdserver
Stagingstaging.<app>.ivydigitals.com (and staging-admin.einv etc.) → dev server
Platformreleases.ivydigitals.com (Release Center) · docs.ivydigitals.com (this site) · git.ivydigitals.com (Gitea) → ssdserver / ssdserver / dev

DNS & TLS

  • DNS zone ivydigitals.com on Cloudflare. Some records are proxied (orange cloud), some DNS-only — proxied settings were preserved during all migrations.
  • Every host has its own Let's Encrypt certificate, issued via DNS-01 (Cloudflare API token at /root/.secrets/cloudflare.ini on each server) — auto-renews.
  • On the dev server, the nginx :443 master is NOT systemd-managed — reload with kill -HUP to the master pid (pgrep -f 'nginx: master process nginx$'), not systemctl reload nginx.

Code movement

  • Source of truth: Gitea (private repos). Dev server working directories are git clones; pushes flow Gitea → Release Center → production.
  • Secrets (.env, keys) and runtime state (databases, uploads) never enter git — they live server-side only.

IVY Digital · docs.ivydigitals.com · generated 2026-10-01 · Release Center · Gitea