在 Day 23 完成 Gunicorn WSGI 伺服器與 Nginx 反向代理架構 後,PrescriptionVLM 系統已具備處理併發與靜態快取的能力。
然而,LINE Messaging API 的 Webhook 規範要求伺服器必須使用 HTTPS 加密傳輸協定。如果系統要從本地端的 ngrok 測試通道轉移至正式的雲端 VPS 伺服器,我們必須配置網域名稱、防火牆規則,並透過 Let's Encrypt 申請 SSL/TLS 數位憑證。
今天我們將為 PrescriptionVLM 系統實作 雲端自動化部署腳本與 Certbot SSL/TLS 自動續約機制。完成項目包含:
在正式公網環境中,安全傳輸與部署自動化是維持系統可用性的重要部分:
nginx/nginx.conf)修改 nginx/nginx.conf,加入 Let's Encrypt 驗證路徑 (.well-known/acme-challenge/) 與 443 Port 的 SSL 代理規則:
server {
listen 80;
server_name your-domain.com; # 請替換為你的實際網域名稱
# 用於 Let's Encrypt 憑證簽發驗證
location /.well-known/acme-challenge/ {
root /var/www/certbot;
}
# 強制將 HTTP 流量重導向至 HTTPS
location / {
return 301 https://$host$request_uri;
}
}
server {
listen 443 ssl;
server_name your-domain.com; # 請替換為你的實際網域名稱
# SSL 憑證檔案路徑
ssl_certificate /etc/letsencrypt/live/your-domain.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/your-domain.com/privkey.pem;
# SSL 安全強化設定
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
client_max_body_size 16M;
# 靜態檔案快取
location /static/ {
alias /app/static/;
expires 7d;
}
# 反向代理轉發給 Gunicorn Flask 服務
location / {
proxy_pass http://web:5000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Request-ID $http_x_request_id;
proxy_connect_timeout 120s;
proxy_read_timeout 120s;
proxy_send_timeout 120s;
}
}
docker-compose.yml 導入 Certbot 服務請更新專案根目錄的 docker-compose.yml,掛載憑證目錄並加入 Certbot 容器:
version: '3.8'
services:
redis:
image: redis:7.2-alpine
container_name: prescription_redis
ports:
- "6379:6379"
restart: always
web:
build:
context: .
dockerfile: Dockerfile
container_name: prescription_service
env_file:
- .env
environment:
- REDIS_HOST=redis
- REDIS_PORT=6379
depends_on:
- redis
restart: always
nginx:
image: nginx:1.25-alpine
container_name: prescription_nginx
ports:
- "80:80"
- "443:443"
volumes:
- ./nginx/nginx.conf:/etc/nginx/conf.d/default.conf:ro
- ./certbot/conf:/etc/letsencrypt:ro
- ./certbot/www:/var/www/certbot:ro
depends_on:
- web
restart: always
certbot:
image: certbot/certbot:v2.8.0
container_name: prescription_certbot
volumes:
- ./certbot/conf:/etc/letsencrypt
- ./certbot/www:/var/www/certbot
deploy.sh)在專案根目錄建立自動化部署腳本 deploy.sh:
#!/bin/bash
set -e
DOMAIN="your-domain.com" # 請修改為你的網域名稱
EMAIL="your-email@example.com" # 請修改為你的 Email
echo "開始執行 PrescriptionVLM 雲端自動化部署..."
# 1. 安裝系統基礎套件與 Docker (若未安裝)
if ! command -v docker &> /dev/null; then
echo "正在安裝 Docker 與 Docker Compose..."
curl -fsSL https://get.docker.com -o get-docker.sh
sh get-docker.sh
rm get-docker.sh
fi
# 2. 建立 Certbot 必要目錄
mkdir -p ./certbot/conf ./certbot/www
# 3. 啟動服務進行初次 SSL 憑證簽發
echo "正在向 Let's Encrypt 申請 SSL 憑證..."
docker-compose run --rm certbot certonly --webroot \
--webroot-path=/var/www/certbot \
--email $EMAIL \
--agree-tos \
--no-eff-email \
-d $DOMAIN
# 4. 啟動 Production 完整容器組
echo "啟動 Docker 生產環境服務..."
docker-compose up --build -d
# 5. 設定 Cron 自動續約任務 (每月 1 號執行)
(crontab -l 2>/dev/null; echo "0 0 1 * * cd $(pwd) && docker-compose run --rm certbot renew && docker-compose exec nginx nginx -s reload") | crontab -
echo "部署完成!您的 PrescriptionVLM 已成功運行於 https://$DOMAIN"
確保腳本具備可執行權限:
chmod +x deploy.sh
1. 執行部署腳本
在公網 VPS 上執行:
./deploy.sh
2. 驗證 HTTPS 與 LINE Webhook 連線
https://your-domain.com/dashboard,確認網址列出現綠色安全鎖頭圖示。https://your-domain.com/callback。測試通過後,將 Day 24 的修改提交至 GitHub:
git add nginx/nginx.conf docker-compose.yml deploy.sh
git commit -m "保留雙引號 改填寫自己要記錄的標記 ex.鐵人賽第二十四天"
git push
今天我們完成了 PrescriptionVLM 邁向正式公網營運的關鍵步驟:透過 deploy.sh 一鍵部署腳本、Nginx 443 SSL 設定 與 Let's Encrypt 自動續約,建立起符合 LINE 官方資安規範的 HTTPS 加密連線。
明天(Day 25),我們將進入系統的品質最後檢視,實作全系統端到端測試與負載壓力測試,驗證系統在多使用者同時上傳藥單時的承載能力!