iT邦幫忙

2026 iThome 鐵人賽

DAY 24
0
Build on Google AI

給藥袋裝一張嘴:30 天用 Android 與 Google VLM 實作高齡語音用藥助手系列 第 24 篇

Day 24|公網營運安全第一線!雲端自動化部署腳本與 Let's Encrypt SSL/TLS 憑證實作

  • 分享至 

  • xImage
  •  

✏️【本日實作紀錄:雲端 VPS 自動化部署與 Certbot SSL 數位憑證】

在 Day 23 完成 Gunicorn WSGI 伺服器與 Nginx 反向代理架構 後,PrescriptionVLM 系統已具備處理併發與靜態快取的能力。

然而,LINE Messaging API 的 Webhook 規範要求伺服器必須使用 HTTPS 加密傳輸協定。如果系統要從本地端的 ngrok 測試通道轉移至正式的雲端 VPS 伺服器,我們必須配置網域名稱、防火牆規則,並透過 Let's Encrypt 申請 SSL/TLS 數位憑證。

今天我們將為 PrescriptionVLM 系統實作 雲端自動化部署腳本與 Certbot SSL/TLS 自動續約機制。完成項目包含:

  • 一鍵自動化部署腳本 — 自動安裝 Docker、Docker Compose、複製專案代碼並啟動三層容器服務。
  • Certbot + Let's Encrypt HTTPS 憑證自動化申請 — 建立 Nginx 憑證驗證與 SSL/TLS 加密連線。
  • SSL 憑證自動續約 Cron Job — 設定定時任務防止 SSL 憑證過期。

一、HTTPS 加密與雲端部署架構

在正式公網環境中,安全傳輸與部署自動化是維持系統可用性的重要部分:

  • LINE Webhook 安全規範:LINE 伺服器會驗證 Webhook URL 的 SSL/TLS 憑證有效性,未經過 Let's Encrypt 等機構簽署的 HTTP 網址將無法接收訊息。
  • 自動化部署:透過 Shell 腳本自動化部署步驟,避免手動安裝環境造成的設定差異。
  • 憑證自動化維護:Let's Encrypt 憑證有效期為 90 天,結合 Certbot 與 Cron 定時任務可達成自動續約。

二、更新 Nginx 支持 HTTPS 與 Certbot 驗證(nginx/nginx.conf)

修改 nginx/nginx.conf,加入 Let's Encrypt 驗證路徑 (.well-known/acme-challenge/) 與 443 Port 的 SSL 代理規則:

server {
    listen 80;
    server_name your-domain.com; # 請替換為你的實際網域名稱

    # 用於 Let's Encrypt 憑證簽發驗證
    location /.well-known/acme-challenge/ {
        root /var/www/certbot;
    }

    # 強制將 HTTP 流量重導向至 HTTPS
    location / {
        return 301 https://$host$request_uri;
    }
}

server {
    listen 443 ssl;
    server_name your-domain.com; # 請替換為你的實際網域名稱

    # SSL 憑證檔案路徑
    ssl_certificate /etc/letsencrypt/live/your-domain.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/your-domain.com/privkey.pem;

    # SSL 安全強化設定
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;

    client_max_body_size 16M;

    # 靜態檔案快取
    location /static/ {
        alias /app/static/;
        expires 7d;
    }

    # 反向代理轉發給 Gunicorn Flask 服務
    location / {
        proxy_pass http://web:5000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header X-Request-ID $http_x_request_id;

        proxy_connect_timeout 120s;
        proxy_read_timeout 120s;
        proxy_send_timeout 120s;
    }
}

三、更新 docker-compose.yml 導入 Certbot 服務

請更新專案根目錄的 docker-compose.yml,掛載憑證目錄並加入 Certbot 容器:

version: '3.8'

services:
  redis:
    image: redis:7.2-alpine
    container_name: prescription_redis
    ports:
      - "6379:6379"
    restart: always

  web:
    build:
      context: .
      dockerfile: Dockerfile
    container_name: prescription_service
    env_file:
      - .env
    environment:
      - REDIS_HOST=redis
      - REDIS_PORT=6379
    depends_on:
      - redis
    restart: always

  nginx:
    image: nginx:1.25-alpine
    container_name: prescription_nginx
    ports:
      - "80:80"
      - "443:443"
    volumes:
      - ./nginx/nginx.conf:/etc/nginx/conf.d/default.conf:ro
      - ./certbot/conf:/etc/letsencrypt:ro
      - ./certbot/www:/var/www/certbot:ro
    depends_on:
      - web
    restart: always

  certbot:
    image: certbot/certbot:v2.8.0
    container_name: prescription_certbot
    volumes:
      - ./certbot/conf:/etc/letsencrypt
      - ./certbot/www:/var/www/certbot

四、撰寫雲端一鍵部署腳本(deploy.sh)

在專案根目錄建立自動化部署腳本 deploy.sh:

#!/bin/bash
set -e

DOMAIN="your-domain.com" # 請修改為你的網域名稱
EMAIL="your-email@example.com" # 請修改為你的 Email

echo "開始執行 PrescriptionVLM 雲端自動化部署..."

# 1. 安裝系統基礎套件與 Docker (若未安裝)
if ! command -v docker &> /dev/null; then
    echo "正在安裝 Docker 與 Docker Compose..."
    curl -fsSL https://get.docker.com -o get-docker.sh
    sh get-docker.sh
    rm get-docker.sh
fi

# 2. 建立 Certbot 必要目錄
mkdir -p ./certbot/conf ./certbot/www

# 3. 啟動服務進行初次 SSL 憑證簽發
echo "正在向 Let's Encrypt 申請 SSL 憑證..."
docker-compose run --rm certbot certonly --webroot \
    --webroot-path=/var/www/certbot \
    --email $EMAIL \
    --agree-tos \
    --no-eff-email \
    -d $DOMAIN

# 4. 啟動 Production 完整容器組
echo "啟動 Docker 生產環境服務..."
docker-compose up --build -d

# 5. 設定 Cron 自動續約任務 (每月 1 號執行)
(crontab -l 2>/dev/null; echo "0 0 1 * * cd $(pwd) && docker-compose run --rm certbot renew && docker-compose exec nginx nginx -s reload") | crontab -

echo "部署完成!您的 PrescriptionVLM 已成功運行於 https://$DOMAIN"

確保腳本具備可執行權限:

chmod +x deploy.sh

五、測試與成果驗證

1. 執行部署腳本

在公網 VPS 上執行:

./deploy.sh

2. 驗證 HTTPS 與 LINE Webhook 連線

  1. 在瀏覽器開啟 https://your-domain.com/dashboard,確認網址列出現綠色安全鎖頭圖示。
  2. 前往 LINE Developers Console,將 Webhook URL 更新為 https://your-domain.com/callback。
  3. 點擊 Verify 按鈕,確保跳出 Success 提示!

六、版本控制與提交 GitHub

測試通過後,將 Day 24 的修改提交至 GitHub:

git add nginx/nginx.conf docker-compose.yml deploy.sh
git commit -m "保留雙引號 改填寫自己要記錄的標記 ex.鐵人賽第二十四天"
git push

七、本日小結與明日預告

今天我們完成了 PrescriptionVLM 邁向正式公網營運的關鍵步驟:透過 deploy.sh 一鍵部署腳本、Nginx 443 SSL 設定 與 Let's Encrypt 自動續約,建立起符合 LINE 官方資安規範的 HTTPS 加密連線。

明天(Day 25),我們將進入系統的品質最後檢視,實作全系統端到端測試與負載壓力測試,驗證系統在多使用者同時上傳藥單時的承載能力!


上一篇
Day 23|邁向正式營運!實作 Gunicorn 高效能 WSGI 伺服器與 Nginx 反向代理配置
系列文
給藥袋裝一張嘴:30 天用 Android 與 Google VLM 實作高齡語音用藥助手 共 24 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言