663 lines
14 KiB
Plaintext
663 lines
14 KiB
Plaintext
---
|
|
title: Azure Deployment
|
|
description: Deploy Chatwoot on Microsoft Azure with various deployment options
|
|
sidebarTitle: Azure
|
|
---
|
|
|
|
# Azure Deployment Guide
|
|
|
|
Deploy Chatwoot on Microsoft Azure using various deployment options including Virtual Machines, Container Instances, or App Service for a scalable, production-ready setup.
|
|
|
|
## Deployment Options
|
|
|
|
<CardGroup cols={3}>
|
|
<Card title="Virtual Machines" icon="server" href="#virtual-machines">
|
|
Full control with custom VM deployment
|
|
</Card>
|
|
<Card title="Container Instances" icon="docker" href="#container-instances">
|
|
Serverless container deployment
|
|
</Card>
|
|
<Card title="App Service" icon="cloud" href="#app-service">
|
|
Platform-as-a-Service deployment
|
|
</Card>
|
|
</CardGroup>
|
|
|
|
## Virtual Machines Deployment
|
|
|
|
### Architecture Overview
|
|
|
|
```
|
|
Azure Load Balancer
|
|
|
|
|
Virtual Machines (Availability Set)
|
|
|
|
|
Azure Database for PostgreSQL + Azure Cache for Redis
|
|
```
|
|
|
|
### Prerequisites
|
|
|
|
- Azure subscription with appropriate permissions
|
|
- Azure CLI installed and configured
|
|
- Domain name for your Chatwoot installation
|
|
|
|
### Step 1: Resource Group and Network
|
|
|
|
#### Create Resource Group
|
|
|
|
```bash
|
|
# Create resource group
|
|
az group create \
|
|
--name chatwoot-rg \
|
|
--location eastus
|
|
```
|
|
|
|
#### Create Virtual Network
|
|
|
|
```bash
|
|
# Create virtual network
|
|
az network vnet create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-vnet \
|
|
--address-prefix 10.0.0.0/16 \
|
|
--subnet-name chatwoot-subnet \
|
|
--subnet-prefix 10.0.1.0/24
|
|
```
|
|
|
|
#### Create Network Security Group
|
|
|
|
```bash
|
|
# Create NSG
|
|
az network nsg create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-nsg
|
|
|
|
# Add rules
|
|
az network nsg rule create \
|
|
--resource-group chatwoot-rg \
|
|
--nsg-name chatwoot-nsg \
|
|
--name AllowHTTP \
|
|
--protocol tcp \
|
|
--priority 1000 \
|
|
--destination-port-range 80
|
|
|
|
az network nsg rule create \
|
|
--resource-group chatwoot-rg \
|
|
--nsg-name chatwoot-nsg \
|
|
--name AllowHTTPS \
|
|
--protocol tcp \
|
|
--priority 1001 \
|
|
--destination-port-range 443
|
|
|
|
az network nsg rule create \
|
|
--resource-group chatwoot-rg \
|
|
--nsg-name chatwoot-nsg \
|
|
--name AllowSSH \
|
|
--protocol tcp \
|
|
--priority 1002 \
|
|
--destination-port-range 22 \
|
|
--source-address-prefix "YOUR_IP_ADDRESS"
|
|
```
|
|
|
|
### Step 2: Database Setup
|
|
|
|
#### Create PostgreSQL Server
|
|
|
|
```bash
|
|
# Create PostgreSQL server
|
|
az postgres server create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-postgres \
|
|
--location eastus \
|
|
--admin-user chatwoot \
|
|
--admin-password "YourSecurePassword123!" \
|
|
--sku-name GP_Gen5_2 \
|
|
--version 13
|
|
|
|
# Create database
|
|
az postgres db create \
|
|
--resource-group chatwoot-rg \
|
|
--server-name chatwoot-postgres \
|
|
--name chatwoot_production
|
|
|
|
# Configure firewall
|
|
az postgres server firewall-rule create \
|
|
--resource-group chatwoot-rg \
|
|
--server chatwoot-postgres \
|
|
--name AllowAzureServices \
|
|
--start-ip-address 0.0.0.0 \
|
|
--end-ip-address 0.0.0.0
|
|
```
|
|
|
|
#### Create Redis Cache
|
|
|
|
```bash
|
|
# Create Redis cache
|
|
az redis create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-redis \
|
|
--location eastus \
|
|
--sku Basic \
|
|
--vm-size c0
|
|
```
|
|
|
|
### Step 3: Storage Account
|
|
|
|
```bash
|
|
# Create storage account
|
|
az storage account create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwootstorage \
|
|
--location eastus \
|
|
--sku Standard_LRS
|
|
|
|
# Create container for file uploads
|
|
az storage container create \
|
|
--account-name chatwootstorage \
|
|
--name uploads \
|
|
--public-access blob
|
|
```
|
|
|
|
### Step 4: Virtual Machine
|
|
|
|
#### Create Availability Set
|
|
|
|
```bash
|
|
# Create availability set
|
|
az vm availability-set create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-avset \
|
|
--platform-fault-domain-count 2 \
|
|
--platform-update-domain-count 2
|
|
```
|
|
|
|
#### Create Virtual Machine
|
|
|
|
```bash
|
|
# Create VM
|
|
az vm create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-vm \
|
|
--image UbuntuLTS \
|
|
--size Standard_D2s_v3 \
|
|
--availability-set chatwoot-avset \
|
|
--vnet-name chatwoot-vnet \
|
|
--subnet chatwoot-subnet \
|
|
--nsg chatwoot-nsg \
|
|
--admin-username azureuser \
|
|
--generate-ssh-keys \
|
|
--custom-data cloud-init.txt
|
|
```
|
|
|
|
#### Cloud-Init Configuration
|
|
|
|
Create `cloud-init.txt`:
|
|
|
|
```yaml
|
|
#cloud-config
|
|
package_upgrade: true
|
|
packages:
|
|
- curl
|
|
- wget
|
|
- git
|
|
|
|
runcmd:
|
|
- wget https://get.chatwoot.app/linux/install.sh
|
|
- chmod +x install.sh
|
|
- ./install.sh --install
|
|
```
|
|
|
|
### Step 5: Load Balancer
|
|
|
|
```bash
|
|
# Create public IP
|
|
az network public-ip create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-lb-ip \
|
|
--sku Standard
|
|
|
|
# Create load balancer
|
|
az network lb create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-lb \
|
|
--public-ip-address chatwoot-lb-ip \
|
|
--frontend-ip-name chatwoot-frontend \
|
|
--backend-pool-name chatwoot-backend
|
|
|
|
# Create health probe
|
|
az network lb probe create \
|
|
--resource-group chatwoot-rg \
|
|
--lb-name chatwoot-lb \
|
|
--name chatwoot-health \
|
|
--protocol http \
|
|
--port 3000 \
|
|
--path /api
|
|
|
|
# Create load balancing rule
|
|
az network lb rule create \
|
|
--resource-group chatwoot-rg \
|
|
--lb-name chatwoot-lb \
|
|
--name chatwoot-rule \
|
|
--protocol tcp \
|
|
--frontend-port 80 \
|
|
--backend-port 3000 \
|
|
--frontend-ip-name chatwoot-frontend \
|
|
--backend-pool-name chatwoot-backend \
|
|
--probe-name chatwoot-health
|
|
```
|
|
|
|
### Step 6: Configuration
|
|
|
|
SSH to the VM and configure Chatwoot:
|
|
|
|
```bash
|
|
# SSH to VM
|
|
ssh azureuser@<VM_PUBLIC_IP>
|
|
|
|
# Switch to chatwoot user
|
|
sudo -i -u chatwoot
|
|
cd chatwoot
|
|
|
|
# Edit environment variables
|
|
nano .env
|
|
```
|
|
|
|
Update `.env` with Azure services:
|
|
|
|
```bash
|
|
# Database
|
|
DATABASE_URL="postgresql://chatwoot:YourSecurePassword123!@chatwoot-postgres.postgres.database.azure.com:5432/chatwoot_production"
|
|
|
|
# Redis
|
|
REDIS_URL="redis://:PRIMARY_ACCESS_KEY@chatwoot-redis.redis.cache.windows.net:6380/0?ssl=true"
|
|
|
|
# Storage (Azure Blob)
|
|
ACTIVE_STORAGE_SERVICE="azure"
|
|
AZURE_STORAGE_ACCOUNT_NAME="chatwootstorage"
|
|
AZURE_STORAGE_ACCESS_KEY="your-access-key"
|
|
AZURE_STORAGE_CONTAINER="uploads"
|
|
|
|
# Frontend URL
|
|
FRONTEND_URL="https://chatwoot.yourdomain.com"
|
|
FORCE_SSL=true
|
|
```
|
|
|
|
## Container Instances Deployment
|
|
|
|
### Docker Compose for Azure
|
|
|
|
Create `docker-compose.azure.yml`:
|
|
|
|
```yaml
|
|
version: '3.8'
|
|
|
|
services:
|
|
chatwoot-web:
|
|
image: chatwoot/chatwoot:latest
|
|
environment:
|
|
- RAILS_ENV=production
|
|
- DATABASE_URL=postgresql://chatwoot:password@postgres:5432/chatwoot_production
|
|
- REDIS_URL=redis://redis:6379/0
|
|
- FRONTEND_URL=https://chatwoot.yourdomain.com
|
|
- FORCE_SSL=true
|
|
ports:
|
|
- "3000:3000"
|
|
depends_on:
|
|
- postgres
|
|
- redis
|
|
|
|
chatwoot-worker:
|
|
image: chatwoot/chatwoot:latest
|
|
environment:
|
|
- RAILS_ENV=production
|
|
- DATABASE_URL=postgresql://chatwoot:password@postgres:5432/chatwoot_production
|
|
- REDIS_URL=redis://redis:6379/0
|
|
command: bundle exec sidekiq -C config/sidekiq.yml
|
|
depends_on:
|
|
- postgres
|
|
- redis
|
|
|
|
postgres:
|
|
image: postgres:13
|
|
environment:
|
|
- POSTGRES_DB=chatwoot_production
|
|
- POSTGRES_USER=chatwoot
|
|
- POSTGRES_PASSWORD=password
|
|
volumes:
|
|
- postgres_data:/var/lib/postgresql/data
|
|
|
|
redis:
|
|
image: redis:7-alpine
|
|
volumes:
|
|
- redis_data:/data
|
|
|
|
volumes:
|
|
postgres_data:
|
|
redis_data:
|
|
```
|
|
|
|
### Deploy with Azure Container Instances
|
|
|
|
```bash
|
|
# Create container group
|
|
az container create \
|
|
--resource-group chatwoot-rg \
|
|
--file docker-compose.azure.yml \
|
|
--dns-name-label chatwoot-app \
|
|
--ports 3000
|
|
```
|
|
|
|
## App Service Deployment
|
|
|
|
### Create App Service Plan
|
|
|
|
```bash
|
|
# Create App Service plan
|
|
az appservice plan create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-plan \
|
|
--sku P1V2 \
|
|
--is-linux
|
|
|
|
# Create web app
|
|
az webapp create \
|
|
--resource-group chatwoot-rg \
|
|
--plan chatwoot-plan \
|
|
--name chatwoot-app \
|
|
--deployment-container-image-name chatwoot/chatwoot:latest
|
|
```
|
|
|
|
### Configure App Settings
|
|
|
|
```bash
|
|
# Set environment variables
|
|
az webapp config appsettings set \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-app \
|
|
--settings \
|
|
RAILS_ENV=production \
|
|
DATABASE_URL="postgresql://chatwoot:password@chatwoot-postgres.postgres.database.azure.com:5432/chatwoot_production" \
|
|
REDIS_URL="redis://:key@chatwoot-redis.redis.cache.windows.net:6380/0?ssl=true" \
|
|
FRONTEND_URL="https://chatwoot-app.azurewebsites.net" \
|
|
FORCE_SSL=true
|
|
```
|
|
|
|
## Monitoring and Logging
|
|
|
|
### Application Insights
|
|
|
|
```bash
|
|
# Create Application Insights
|
|
az monitor app-insights component create \
|
|
--resource-group chatwoot-rg \
|
|
--app chatwoot-insights \
|
|
--location eastus \
|
|
--kind web
|
|
|
|
# Get instrumentation key
|
|
az monitor app-insights component show \
|
|
--resource-group chatwoot-rg \
|
|
--app chatwoot-insights \
|
|
--query instrumentationKey
|
|
```
|
|
|
|
### Log Analytics Workspace
|
|
|
|
```bash
|
|
# Create Log Analytics workspace
|
|
az monitor log-analytics workspace create \
|
|
--resource-group chatwoot-rg \
|
|
--workspace-name chatwoot-logs \
|
|
--location eastus
|
|
```
|
|
|
|
## Security Configuration
|
|
|
|
### Key Vault for Secrets
|
|
|
|
```bash
|
|
# Create Key Vault
|
|
az keyvault create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-vault \
|
|
--location eastus
|
|
|
|
# Store secrets
|
|
az keyvault secret set \
|
|
--vault-name chatwoot-vault \
|
|
--name database-password \
|
|
--value "YourSecurePassword123!"
|
|
|
|
az keyvault secret set \
|
|
--vault-name chatwoot-vault \
|
|
--name redis-key \
|
|
--value "your-redis-access-key"
|
|
```
|
|
|
|
### Managed Identity
|
|
|
|
```bash
|
|
# Enable managed identity for VM
|
|
az vm identity assign \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-vm
|
|
|
|
# Grant access to Key Vault
|
|
az keyvault set-policy \
|
|
--name chatwoot-vault \
|
|
--object-id <MANAGED_IDENTITY_PRINCIPAL_ID> \
|
|
--secret-permissions get list
|
|
```
|
|
|
|
## Backup and Disaster Recovery
|
|
|
|
### Database Backup
|
|
|
|
```bash
|
|
# Enable automated backup for PostgreSQL
|
|
az postgres server configuration set \
|
|
--resource-group chatwoot-rg \
|
|
--server-name chatwoot-postgres \
|
|
--name backup_retention_days \
|
|
--value 7
|
|
|
|
# Create manual backup
|
|
az postgres server backup create \
|
|
--resource-group chatwoot-rg \
|
|
--server-name chatwoot-postgres \
|
|
--backup-name manual-backup-$(date +%Y%m%d)
|
|
```
|
|
|
|
### VM Backup
|
|
|
|
```bash
|
|
# Create Recovery Services vault
|
|
az backup vault create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-vault \
|
|
--location eastus
|
|
|
|
# Enable backup for VM
|
|
az backup protection enable-for-vm \
|
|
--resource-group chatwoot-rg \
|
|
--vault-name chatwoot-vault \
|
|
--vm chatwoot-vm \
|
|
--policy-name DefaultPolicy
|
|
```
|
|
|
|
## Scaling and Performance
|
|
|
|
### VM Scale Sets
|
|
|
|
```bash
|
|
# Create VM scale set
|
|
az vmss create \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-vmss \
|
|
--image UbuntuLTS \
|
|
--vm-sku Standard_D2s_v3 \
|
|
--instance-count 2 \
|
|
--vnet-name chatwoot-vnet \
|
|
--subnet chatwoot-subnet \
|
|
--lb chatwoot-lb \
|
|
--backend-pool-name chatwoot-backend \
|
|
--custom-data cloud-init.txt
|
|
|
|
# Configure autoscaling
|
|
az monitor autoscale create \
|
|
--resource-group chatwoot-rg \
|
|
--resource chatwoot-vmss \
|
|
--resource-type Microsoft.Compute/virtualMachineScaleSets \
|
|
--name chatwoot-autoscale \
|
|
--min-count 2 \
|
|
--max-count 5 \
|
|
--count 2
|
|
|
|
# Add scale-out rule
|
|
az monitor autoscale rule create \
|
|
--resource-group chatwoot-rg \
|
|
--autoscale-name chatwoot-autoscale \
|
|
--condition "Percentage CPU > 70 avg 5m" \
|
|
--scale out 1
|
|
|
|
# Add scale-in rule
|
|
az monitor autoscale rule create \
|
|
--resource-group chatwoot-rg \
|
|
--autoscale-name chatwoot-autoscale \
|
|
--condition "Percentage CPU < 30 avg 5m" \
|
|
--scale in 1
|
|
```
|
|
|
|
## SSL Certificate
|
|
|
|
### App Service Certificate
|
|
|
|
```bash
|
|
# Create App Service certificate
|
|
az webapp config ssl upload \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-app \
|
|
--certificate-file certificate.pfx \
|
|
--certificate-password "certificate-password"
|
|
|
|
# Bind certificate to domain
|
|
az webapp config ssl bind \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-app \
|
|
--certificate-thumbprint <THUMBPRINT> \
|
|
--ssl-type SNI
|
|
```
|
|
|
|
### Let's Encrypt with VM
|
|
|
|
```bash
|
|
# Install Certbot on VM
|
|
sudo apt update
|
|
sudo apt install certbot python3-certbot-nginx
|
|
|
|
# Obtain certificate
|
|
sudo certbot --nginx -d chatwoot.yourdomain.com
|
|
|
|
# Auto-renewal
|
|
sudo crontab -e
|
|
# Add: 0 12 * * * /usr/bin/certbot renew --quiet
|
|
```
|
|
|
|
## Cost Optimization
|
|
|
|
### Reserved Instances
|
|
|
|
```bash
|
|
# Purchase reserved capacity for VMs
|
|
az reservations reservation-order purchase \
|
|
--reservation-order-id <ORDER_ID> \
|
|
--sku Standard_D2s_v3 \
|
|
--location eastus \
|
|
--quantity 2 \
|
|
--term P1Y
|
|
```
|
|
|
|
### Azure Advisor
|
|
|
|
```bash
|
|
# Get cost recommendations
|
|
az advisor recommendation list \
|
|
--category Cost \
|
|
--resource-group chatwoot-rg
|
|
```
|
|
|
|
## Troubleshooting
|
|
|
|
### Common Issues
|
|
|
|
<Accordion title="Database connection timeout">
|
|
Check:
|
|
- PostgreSQL firewall rules
|
|
- Network security group rules
|
|
- Connection string format
|
|
- SSL requirements for Azure Database
|
|
</Accordion>
|
|
|
|
<Accordion title="Redis connection issues">
|
|
Verify:
|
|
- Redis access keys
|
|
- SSL configuration (required for Azure Cache)
|
|
- Network connectivity
|
|
- Port 6380 (SSL) vs 6379 (non-SSL)
|
|
</Accordion>
|
|
|
|
<Accordion title="Storage upload failures">
|
|
Solutions:
|
|
- Verify storage account access keys
|
|
- Check container permissions
|
|
- Ensure CORS settings if needed
|
|
- Validate Azure Storage configuration
|
|
</Accordion>
|
|
|
|
### Diagnostic Commands
|
|
|
|
```bash
|
|
# Check VM status
|
|
az vm get-instance-view \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-vm
|
|
|
|
# View application logs
|
|
az webapp log tail \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-app
|
|
|
|
# Check database connectivity
|
|
az postgres server show \
|
|
--resource-group chatwoot-rg \
|
|
--name chatwoot-postgres
|
|
```
|
|
|
|
## Best Practices
|
|
|
|
### Security
|
|
- Use Azure Key Vault for secrets management
|
|
- Enable managed identities for Azure resources
|
|
- Implement network security groups with least privilege
|
|
- Enable Azure Security Center recommendations
|
|
|
|
### Performance
|
|
- Use Azure CDN for static assets
|
|
- Implement Redis caching strategies
|
|
- Monitor with Application Insights
|
|
- Use proximity placement groups for low latency
|
|
|
|
### Cost Management
|
|
- Use Azure Cost Management for monitoring
|
|
- Implement auto-shutdown for development VMs
|
|
- Consider spot instances for non-critical workloads
|
|
- Use reserved instances for predictable workloads
|
|
|
|
### Backup and Recovery
|
|
- Enable automated backups for all data services
|
|
- Test backup restoration procedures regularly
|
|
- Implement geo-redundant storage for critical data
|
|
- Document disaster recovery procedures
|
|
|
|
---
|
|
|
|
This Azure deployment guide provides multiple options for hosting Chatwoot on Microsoft Azure. Choose the deployment method that best fits your requirements, budget, and operational preferences. |