Skip to content

Server-Setup ​

MATEV 2026 läuft auf einem Linux-Server (Ubuntu 24.04 LTS oder Debian 12) mit zwei klar getrennten Setup-Schienen:

Klassisch (Bare Metal)FrankenPHP + Caddy (Docker Compose, via Portainer)
EinsatzgebietLokal/Dev, Notfall-Setup ohne DockerStandard für Staging und Production
WebserverNginx + PHP-FPM (manuell konfiguriert)Caddy (Reverse Proxy) + FrankenPHP (PHP-Workloads)
SSLCertbot / Let's EncryptCaddy Auto-SSL (built-in)
PHP-Runtimephp-fpmFrankenPHP + Laravel Octane (Worker-Mode)
Service-OrchestrierungsystemdDocker Compose, Stack-Verzeichnisse in home/bengel/stacks/
Container-UI—Portainer (Cockpit only — Stacks bleiben Git-based)
Zertifikatemanuell via Certbotautomatisch durch Caddy
Empfohlen fürLernen / Bare-Metal-Setup ohne Dockeralles produktive Hosting

Standard-Setup (Production) ​

→ FrankenPHP + Caddy via Docker Compose — komplettes Setup für proxy/, mgmt/, git/, apps/ Stacks. Ist die Variante, die in home/bengel/stacks/ lebt.

→ Stacks-Referenz — pro Stack: was läuft, welche Volumes, welche Env-Vars, wie Backup.

→ Backup-Strategie — Restic + DB-Dumps, Disaster-Recovery-Pfad.

Alternative ​

→ Klassisch (Bare Metal) — Nginx + PHP-FPM + systemd, ohne Docker. Nur sinnvoll, wenn auf der Maschine kein Docker laufen darf (rare).

Architektur-Bild ​

                         ┌──────────────────────┐
                         │  Internet (HTTPS/443)│
                         └──────────┬───────────┘
                                    │
                         ┌──────────▼───────────┐
                         │  Caddy (proxy/)      │  Auto-SSL, HTTP/3
                         │  alle *.matev.eu     │
                         └──────────┬───────────┘
            ┌───────────────────────┼───────────────────────┐
            │                       │                       │
   ┌────────▼────────┐    ┌─────────▼────────┐    ┌─────────▼────────┐
   │   apps/         │    │   git/           │    │   mgmt/          │
   │  ───────────    │    │  ───────────     │    │  ───────────     │
   │  admin (Filament│    │  forgejo +db     │    │  matomo +db      │
   │  cms (Kirby)    │    │  woodpecker +ag. │    │  portainer       │
   │  staging (Nuxt) │    │                  │    │   (off-domain,   │
   │  b2b (Livewire) │    │                  │    │    Server-IP)    │
   │  storybook      │    │                  │    │                  │
   │  docs (Vite)    │    │                  │    │                  │
   │  design (Penpot)│    │                  │    │                  │
   │  project (Taiga)│    │                  │    │                  │
   └─────────────────┘    └──────────────────┘    └──────────────────┘
            └─────────── docker network: gateway ──────────────┘

Alle Stacks hängen am externen Docker-Netz gateway — so findet Caddy jeden Service über seinen Container-Namen ohne Port-Mapping.

Server-Layout (Pfade) ​

/home/bengel/stacks/    ← Compose + .env + persistente Daten-Volumes
└── proxy/  mgmt/  git/  apps/

/var/www/               ← Source-Code pro Service (Webroot)
└── admin/  cms/  b2b/  staging/  docs/  storybook/  …
    Eigentum: bengel:www-data 2775 (setgid + group-writable)

Build-Context der apps/docker-compose.yml zeigt auf /var/www/<service>/ — die Dockerfiles leben im Webroot, nicht im Stack-Verzeichnis. Vorlagen liegen in home/bengel/stacks/apps/dockerfiles-reference/.

Voraussetzungen (alle Varianten) ​

  • Ubuntu 24.04 LTS oder Debian 12
  • Root-Zugang oder sudo-Berechtigungen
  • Domain matev.eu mit DNS-Wildcard (*.matev.eu → Server-IP)
  • Subdomains: admin, cms, staging, b2b, git, ci, analytics, design, docs, project, storybook
  • Open Ports: 80, 443, 443/udp (für HTTP/3), optional 222 (Forgejo-SSH)
  • Portainer-Port: 9443 nur in der Firewall für Admin-IPs / VPN freigeben

DNS-Beispiel ​

matev.eu              A     <server-ip>
*.matev.eu            A     <server-ip>
admin.matev.eu        CNAME matev.eu
cms.matev.eu          CNAME matev.eu
staging.matev.eu      CNAME matev.eu
b2b.matev.eu          CNAME matev.eu
git.matev.eu          CNAME matev.eu
ci.matev.eu           CNAME matev.eu
analytics.matev.eu    CNAME matev.eu
design.matev.eu       CNAME matev.eu
docs.matev.eu         CNAME matev.eu
project.matev.eu      CNAME matev.eu
storybook.matev.eu    CNAME matev.eu

Wenn Wildcard-DNS gesetzt ist, sind die einzelnen CNAMEs optional — Caddy holt SSL-Zertifikate ohnehin pro Hostname.