Setting up RhodeCode on Ubuntu 12.04

2012-10-29
#rhodecode #mercurial #ubuntu #howto #server

This howto is based on a great guide, with modifications. All settings are made for the server domain hg.kenarius.org. You can replace it with your own easily.

§ Preparation

§ Ubuntu

Update Ubuntu with the commands:

1sudo apt-get update
2sudo apt-get upgrade

Install pip and virtualenv with the commands:

1sudo apt-get install python-pip
2sudo pip install virtualenv

§ Nginx

Install nginx:

1sudo apt-get install nginx

Create SSL certificates:

1sudo openssl req -new -x509 -days 9999 -nodes -out host.pem -keyout host.key

Create /etc/nginx/ssl.conf file:

1# Sert generation:
2# openssl req -new -x509 -days 9999 -nodes -out cert.pem -keyout     cert.key
3
4ssl         on;
5ssl_protocols       SSLv3 TLSv1;
6ssl_certificate     /etc/nginx/ssl/host.pem;
7ssl_certificate_key /etc/nginx/ssl/host.key;

§ Installing RhodeCode

Install Python sources:

1sudo apt-get install python-dev

Create the base directory and temporarily give yourself ownership:

1sudo mkdir /srv/hg.kenarius.org
2sudo su
3cd /srv/hg.kenarius.org

Create the data directory, virtual environment, and install RhodeCode:

1virtualenv --no-site-packages /srv/hg.kenarius.org/venv
2source /srv/hg.kenarius.org/venv/bin/activate
3(venv) pip install pastescript
4(venv) easy_install rhodecode

Create directories and the production configuration:

1mkdir /home/repository
2mkdir /srv/hg.kenarius.org/data
3cd /srv/hg.kenarius.org/data
4(venv) paster make-config RhodeCode production.ini

Generate the RhodeCode database and create the initial admin account:

1(venv) paster setup-rhodecode production.ini

§ Starting RhodeCode on boot

Create start.sh in /srv/hg.kenarius.org:

 1#!/bin/bash
 2# run this as the rhodecode user!
 3
 4WDIR=/srv/hg.kenarius.org
 5VIRTUALENV_DIR=/srv/hg.kenarius.org/venv
 6
 7source $VIRTUALENV_DIR/bin/activate
 8
 9cd $WDIR
10paster serve $WDIR/data/production.ini 1> debug.log 2> error.log

Create rhodecode in /etc/init.d:

 1#!/bin/sh -e
 2########################################
 3#### THIS IS A DEBIAN INIT.D SCRIPT ####
 4########################################
 5
 6### BEGIN INIT INFO
 7# Provides:          rhodecode
 8# Required-Start:    $all
 9# Required-Stop:     $all
10# Default-Start:     2 3 4 5
11# Default-Stop:      0 1 6
12# Short-Description: starts instance of rhodecode
13# Description:       starts instance of rhodecode using start-stop-    daemon
14### EN    D INIT INFO
15
16APP_NAME="rhodecode"
17APP_HOMEDIR="hg.kenarius.org"
18APP_PATH="/srv/$APP_HOMEDIR"
19
20CONF_NAME="data/production.ini"
21
22PID_PATH="$APP_PATH/$APP_NAME.pid"
23LOG_PATH="$APP_PATH/$APP_NAME.log"
24
25PYTHON_PATH="/srv/$APP_HOMEDIR/venv"
26
27RUN_AS="www-data"
28
29DAEMON="$PYTHON_PATH/bin/paster"
30
31DAEMON_OPTS="serve --daemon \
32  --user=$RUN_AS \
33  --group=$RUN_AS \
34  --pid-file=$PID_PATH \
35  --log-file=$LOG_PATH  $APP_PATH/$CONF_NAME"
36
37
38start() {
39  echo "Starting $APP_NAME"
40  PYTHON_EGG_CACHE="/tmp" start-stop-daemon -d $APP_PATH \
41      --start --quiet \
42      --pidfile $PID_PATH \
43      --user $RUN_AS \
44      --exec $DAEMON -- $DAEMON_OPTS
45}
46
47stop() {
48  echo "Stopping $APP_NAME"
49  start-stop-daemon -d $APP_PATH \
50      --stop --quiet \
51      --pidfile $PID_PATH || echo "$APP_NAME - Not running!"
52
53  if [ -f $PID_PATH ]; then
54    rm $PID_PATH
55  fi
56}
57
58case "$1" in
59  start)
60    start
61    ;;
62  stop)
63    stop
64    ;;
65  restart)
66    echo "Restarting $APP_NAME"
67    ### stop ###
68    stop
69    wait
70    ### start ###
71    start
72    ;;
73  *)
74    echo "Usage: $0 {start|stop|restart}"
75    exit 1
76esac

Allow executing the script:

1cd /etc/init.d
2chmod +x rhodecode
3sudo ./rhodecode-init.d.sh start

Install the script:

1sudo update-rc.d rhodecode defaults 90

Test the script once more:

1sudo service rhodecode start
2sudo service rhodecode stop

§ Adding Nginx as a front-end for SSL

Create /etc/nginx/proxy.conf file:

 1proxy_redirect              off;
 2proxy_set_header            Host $host;
 3proxy_set_header            X-Url-Scheme $scheme;
 4proxy_set_header            X-Host $http_host;
 5proxy_set_header            X-Real-IP $remote_addr;
 6proxy_set_header            X-Forwarded-For $proxy_add_x_forwarded_for;
 7proxy_set_header            Proxy-host $proxy_host;
 8client_max_body_size        400m;
 9client_body_buffer_size     128k;
10proxy_buffering             off;
11proxy_connect_timeout       7200;
12proxy_send_timeout          7200;
13proxy_read_timeout          7200;
14proxy_buffers               8 32k;

Create the /etc/nginx/sites-enabled/hg.kenarius.org file (assuming you already have SSL settings for nginx):

 1server {
 2    listen          80;
 3    server_name     hg.kenarius.org;
 4    rewrite        ^ https://$server_name$request_uri? permanent;
 5}
 6
 7server {
 8    listen          443;
 9    server_name     hg.kenarius.org;
10    access_log      /var/log/nginx/rhodecode.access.log;
11    error_log       /var/log/nginx/rhodecode.error.log;
12    include         /etc/nginx/proxy.conf;
13
14    include      /etc/nginx/ssl.conf;
15
16    location / {
17         try_files $uri @rhode;
18    }
19
20    location @rhode {
21         proxy_pass      http://127.0.0.1:5000;
22    }
23}

Reload nginx settings:

1nginx -s reload