S
Supanote
Sign in Sign up
Infrastructure Snippets

DevOps & Infrastructure Templates

Production-tested configurations for Nginx reverse proxies, Docker Compose stacks, Systemd services, Caddyfiles, and Prometheus alerts.

nginx Verified Starter

Nginx Reverse Proxy with SSL & Security Headers

Production-ready reverse proxy with TLS 1.3, Brotli, and strict security headers.

# Production Nginx Reverse Proxy Configuration
server {
    listen 443 ssl http2;
    listen [::]:443 ssl http2;
    server_name api.example.com;

    # SSL Certificates & Modern Ciphers
    ssl_certificate...
yaml Verified Starter

Docker Compose Production Web Stack

Full-stack production docker-compose with web app, Postgres, and Redis.

version: '3.8'

services:
  web:
    build: .
    restart: always
    environment:
      NODE_ENV: production
      DATABASE_URL: ${DATABASE_URL}
      REDIS_URL: ${REDIS_URL}
    ports:
      - "3000:3000"
    depends_on:
      - db
      - redis
  ...
nginx Verified Starter

Nginx WebSocket Reverse Proxy Configuration

Production reverse proxy configuration with WebSocket upgrade headers, HTTP/1.1 keepalive, and timeout tuning.

# Nginx Reverse Proxy with Full WebSocket Support
map $http_upgrade $connection_upgrade {
    default upgrade;
    ''      close;
}

upstream websocket_backend {
    server 127.0.0.1:4000;
    keepalive 64;
}

server {
    listen 443 ssl http2;
   ...
nginx Verified Starter

Nginx SPA Single-Page App Fallback & Caching Routing

Optimized configuration for React, Vue, Vite, and Next export SPAs with aggressive asset caching and index.html fallback.

# Nginx Single Page Application (SPA) Routing & Caching
server {
    listen 80;
    listen [::]:80;
    server_name app.example.com;
    root /var/www/app/dist;
    index index.html;

    # Gzip & Brotli Compression
    gzip on;
    gzip_types...
yaml Verified Starter

Docker Compose Next.js Stack with Caddy Auto-SSL

Containerized Next.js production deployment with Caddy reverse proxy providing automatic Let's Encrypt certificates.

version: '3.8'

services:
  caddy:
    image: caddy:2-alpine
    restart: unless-stopped
    ports:
      - "80:80"
      - "443:443"
    volumes:
      - ./Caddyfile:/etc/caddy/Caddyfile:ro
      - caddy_data:/data
      - caddy_config:/config
   ...
ini Verified Starter

Systemd Production Service Unit for Node.js Application

Hardened systemd unit file with automatic restart on failure, resource limits, unprivileged user execution, and environment variable loading.

[Unit]
Description=Node.js Production Application Service
After=network.target postgresql.service
Wants=postgresql.service

[Service]
Type=simple
User=deploy
Group=deploy
WorkingDirectory=/var/www/app
ExecStart=/usr/bin/node...
dockerfile Verified Starter

Multi-Stage Production Node.js Dockerfile with Distroless

Secure, minimal Node.js Dockerfile using multi-stage build, npm cache mounting, non-root user, and Google distroless runtime.

# Stage 1: Dependency resolution and compilation
FROM node:20-alpine AS deps
WORKDIR /app
COPY package*.json ./
RUN --mount=type=cache,target=/root/.npm \
    npm ci --omit=dev --ignore-scripts

# Stage 2: Application builder (if TypeScript/bundler...
caddyfile Verified Starter

Production Caddyfile Reverse Proxy with Automatic HTTPS

Minimal, hardened Caddyfile configuration featuring automatic Let's Encrypt certificates, HSTS, Brotli, and reverse proxy.

# Global Caddy Configuration
{
  email ops@example.com
  admin off
}

# Production Domain Reverse Proxy
example.com {
  # Automatic TLS and HTTP to HTTPS redirection is built-in

  # Security & Protection Headers
  header {
   ...
yaml Verified Starter

Prometheus Alertmanager Production Alert Rules Template

Essential Prometheus alerting rules for host CPU usage (>85%), high RAM exhaustion, disk space threshold (<10%), and service down.

groups:
  - name: host_infrastructure_alerts
    rules:
      - alert: HostHighCpuUsage
        expr: 100 - (avg by (instance) (rate(node_cpu_seconds_total{mode="idle"}[5m])) * 100) > 85
        for: 5m
        labels:
          severity: warning
   ...
caddyfile Verified Starter

Caddyfile Multi-Domain Production TLS Reverse Proxy

Zero-configuration automatic Let's Encrypt TLS, Brotli/Zstandard compression, and security headers with Caddy.

# Production Caddy Multi-Domain Proxy
{
    email admin@example.com
    admin off
}

app.example.com {
    encode zstd gzip

    header {
        Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
        X-Content-Type-Options...
toml Verified Starter

Vector.dev Log Shipping Pipeline Configuration (vector.toml)

High-throughput log aggregator routing Docker & Syslog streams into Grafana Loki, Datadog, or S3.

# vector.toml - High-Performance Log Shipping Pipeline

[sources.docker_logs]
type = "docker_logs"
include_units = ["app-*", "nginx-*"]

[transforms.parse_json]
type = "remap"
inputs = ["docker_logs"]
source = '''
  . = parse_json(.message) ?? .
 ...
yaml Verified Starter

Tailscale Subnet Router & Exit Node Docker Compose

Lightweight Docker container exposing internal VPC subnets and homelabs securely via Tailscale overlay network.

version: '3.8'

services:
  tailscale:
    image: tailscale/tailscale:latest
    container_name: tailscale-subnet-router
    hostname: vpc-subnet-router
    restart: unless-stopped
    cap_add:
      - NET_ADMIN
      - NET_RAW
    network_mode:...
Notification