DevOps & Infrastructure Templates
Production-tested configurations for Nginx reverse proxies, Docker Compose stacks, Systemd services, Caddyfiles, and Prometheus alerts.
Nginx Reverse Proxy with SSL & Security Headers
Production-ready reverse proxy with TLS 1.3, Brotli, and strict security headers.
# Production Nginx Reverse Proxy Configuration
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name api.example.com;
# SSL Certificates & Modern Ciphers
ssl_certificate...
Docker Compose Production Web Stack
Full-stack production docker-compose with web app, Postgres, and Redis.
version: '3.8'
services:
web:
build: .
restart: always
environment:
NODE_ENV: production
DATABASE_URL: ${DATABASE_URL}
REDIS_URL: ${REDIS_URL}
ports:
- "3000:3000"
depends_on:
- db
- redis
...
Nginx WebSocket Reverse Proxy Configuration
Production reverse proxy configuration with WebSocket upgrade headers, HTTP/1.1 keepalive, and timeout tuning.
# Nginx Reverse Proxy with Full WebSocket Support
map $http_upgrade $connection_upgrade {
default upgrade;
'' close;
}
upstream websocket_backend {
server 127.0.0.1:4000;
keepalive 64;
}
server {
listen 443 ssl http2;
...
Nginx SPA Single-Page App Fallback & Caching Routing
Optimized configuration for React, Vue, Vite, and Next export SPAs with aggressive asset caching and index.html fallback.
# Nginx Single Page Application (SPA) Routing & Caching
server {
listen 80;
listen [::]:80;
server_name app.example.com;
root /var/www/app/dist;
index index.html;
# Gzip & Brotli Compression
gzip on;
gzip_types...
Docker Compose Next.js Stack with Caddy Auto-SSL
Containerized Next.js production deployment with Caddy reverse proxy providing automatic Let's Encrypt certificates.
version: '3.8'
services:
caddy:
image: caddy:2-alpine
restart: unless-stopped
ports:
- "80:80"
- "443:443"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile:ro
- caddy_data:/data
- caddy_config:/config
...
Systemd Production Service Unit for Node.js Application
Hardened systemd unit file with automatic restart on failure, resource limits, unprivileged user execution, and environment variable loading.
[Unit]
Description=Node.js Production Application Service
After=network.target postgresql.service
Wants=postgresql.service
[Service]
Type=simple
User=deploy
Group=deploy
WorkingDirectory=/var/www/app
ExecStart=/usr/bin/node...
Multi-Stage Production Node.js Dockerfile with Distroless
Secure, minimal Node.js Dockerfile using multi-stage build, npm cache mounting, non-root user, and Google distroless runtime.
# Stage 1: Dependency resolution and compilation
FROM node:20-alpine AS deps
WORKDIR /app
COPY package*.json ./
RUN --mount=type=cache,target=/root/.npm \
npm ci --omit=dev --ignore-scripts
# Stage 2: Application builder (if TypeScript/bundler...
Production Caddyfile Reverse Proxy with Automatic HTTPS
Minimal, hardened Caddyfile configuration featuring automatic Let's Encrypt certificates, HSTS, Brotli, and reverse proxy.
# Global Caddy Configuration
{
email ops@example.com
admin off
}
# Production Domain Reverse Proxy
example.com {
# Automatic TLS and HTTP to HTTPS redirection is built-in
# Security & Protection Headers
header {
...
Prometheus Alertmanager Production Alert Rules Template
Essential Prometheus alerting rules for host CPU usage (>85%), high RAM exhaustion, disk space threshold (<10%), and service down.
groups:
- name: host_infrastructure_alerts
rules:
- alert: HostHighCpuUsage
expr: 100 - (avg by (instance) (rate(node_cpu_seconds_total{mode="idle"}[5m])) * 100) > 85
for: 5m
labels:
severity: warning
...
Caddyfile Multi-Domain Production TLS Reverse Proxy
Zero-configuration automatic Let's Encrypt TLS, Brotli/Zstandard compression, and security headers with Caddy.
# Production Caddy Multi-Domain Proxy
{
email admin@example.com
admin off
}
app.example.com {
encode zstd gzip
header {
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
X-Content-Type-Options...
Vector.dev Log Shipping Pipeline Configuration (vector.toml)
High-throughput log aggregator routing Docker & Syslog streams into Grafana Loki, Datadog, or S3.
# vector.toml - High-Performance Log Shipping Pipeline
[sources.docker_logs]
type = "docker_logs"
include_units = ["app-*", "nginx-*"]
[transforms.parse_json]
type = "remap"
inputs = ["docker_logs"]
source = '''
. = parse_json(.message) ?? .
...
Tailscale Subnet Router & Exit Node Docker Compose
Lightweight Docker container exposing internal VPC subnets and homelabs securely via Tailscale overlay network.
version: '3.8'
services:
tailscale:
image: tailscale/tailscale:latest
container_name: tailscale-subnet-router
hostname: vpc-subnet-router
restart: unless-stopped
cap_add:
- NET_ADMIN
- NET_RAW
network_mode:...