GuidesProduction setup
The flags of ferryd
Five flags in the unit give ferryd its data folder, its domain, its public ports and HTTPS.
ExecStart=/usr/local/bin/ferryd run \
--data-dir /var/lib/ferry \
--base-domain apps.example.com \
--proxy-addr 0.0.0.0:80 \
--https-addr 0.0.0.0:443 \
--acme-email you@example.comWhat each flag does
| Flag | Effect |
|---|---|
--data-dir /var/lib/ferry | The data directory: the database, logs, uploads, git caches and certificates. Ferry creates it with mode 0700. |
--base-domain apps.example.com | The base domain: your apps answer at <name>.apps.example.com. It is the first domain of the server. You connect other domains while the server runs. |
--proxy-addr 0.0.0.0:80 | Public HTTP. Let’s Encrypt does its test on port 80. For a host that has a certificate, the proxy redirects HTTP requests to HTTPS. |
--https-addr 0.0.0.0:443 and --acme-email | Together, they turn on automatic HTTPS. Both are necessary. |
What needs no flag
The API and the dashboard stay on 127.0.0.1:7878. This is the default of --api-addr.
Each container gets 512 MiB of memory and 1 CPU by default. You need no flag at the start. Size the limits when you know what the server runs.
Server options lists each option.
Let's Encrypt has a rate limit for production certificates. If you expect to restart often, first try the certificate setup with --acme-staging. When you remove the flag, Ferry replaces the certificates of the staging certificate authority automatically.