This document defines the software breakout strategy used in the server provisioning system.
Instead of installing all software on every server, packages are divided into:
- Base software (common to all servers)
- Role-specific software (installed based on server purpose)
This approach ensures:
- minimal attack surface
- better performance
- clearer infrastructure design
- easier maintenance and scalability
Installed on all servers.
BASE_SOFTWARE=(
"ufw"
"git"
"wireguard"
"fail2ban"
"openssh-server"
"ca-certificates"
"curl"
"tree"
)
Provides:
- secure remote access
- firewall protection
- VPN connectivity
- system utilities
Each server type has its own software profile.
PRODUCTION_WEB_SERVER_SOFTWARE=(
"nginx"
"postgresql"
)
- host production web applications
- handle HTTP/HTTPS traffic
- connect to database
- NGINX reverse proxy
- systemd service for application
- secure service startup
STORAGE_SERVER_SOFTWARE=(
"postgresql"
)
- dedicated database server
- data storage and management
- restrict database access (VPN only)
- enable backups and data persistence
DEVELOPMENT_WEB_SERVER_SOFTWARE=(
"nginx"
"postgresql"
)
- test web applications in development
- simulate production environment
- NGINX setup for testing
- systemd service for dev apps
- debugging-friendly environment
DEVELOPMENT_SERVER_SOFTWARE=(
"postgresql"
"cargo"
"python3"
)
- application development environment
- backend and tooling support
- Python environment setup
- Rust (Cargo) toolchain setup
- developer utilities
install_package_list "${BASE_SOFTWARE[@]}"
User selects:
- Production Web Server
- Storage Server
- Development Web Server
- Development Server
install_package_list "${ROLE_SOFTWARE[@]}"
Examples:
- systemd service files
- NGINX configuration
- database initialization