ECS deployment guide
This guide is for the service administrator. It starts PostgreSQL, the API, Caddy, and the static website on one Linux ECS.
Pre-flight checks
- A Linux ECS (this project is sized for 2 GiB RAM) with Docker Engine and Docker Compose v2.
- An A record for your domain pointing at the ECS public IP.
- Security-group access to 80/443 only; restrict SSH and any control panel to trusted sources; never expose 5432.
- Nothing else, including a hosting panel, is using ports 80 or 443.
- Read access from the ECS to this private GitHub repository (for example, a deploy key). Complete GitHub authorization before cloning.
First deployment
On the ECS, run:
git clone https://github.com/chenyanze66/memory-sync-infra.git
cd memory-sync-infra/server
cp .env.example .env
chmod 600 .env
Edit .env. Replace every replace-with-... value. The admin database password, application database password, JWT secret, and invite code must all be different. Do not send .env through chat, commit it to Git, or store it in a synced folder.
Validate, build, and start the stack:
docker compose config
docker compose up -d --build
docker compose ps
curl -fsS "https://your-domain/readyz"
postgres, api, and caddy should all be running/healthy, and the final command should return HTTP 200. Caddy automatically requests HTTPS certificates after DNS has propagated and ports 80/443 are reachable.
Onboard users
Privately send each user the HTTPS URL and invite code, then point them to the user guide. If the invite code leaks, change it in .env, restart the API, and issue a new code for future registrations.
Update from GitHub
From the repository root on the ECS:
git fetch origin
git status
git pull --ff-only origin main
cd server
docker compose up -d --build
docker compose ps
curl -fsS "https://your-domain/readyz"
Back up before an update. If git status reports local changes, resolve them first; do not force an overwrite. See the operations guide for checks and backups.
Never do this
- Do not publish PostgreSQL port 5432.
- Do not reverse-proxy the Dashboard to the Internet; it is localhost-only.
- Do not put employer-confidential P2 material or P3 credentials in a synced folder.
- Do not commit
.env, backups, client configuration, tokens, private keys, or invite codes.