Appearance
Server-Setup
MATEV 2026 läuft auf einem Linux-Server (Ubuntu 24.04 LTS oder Debian 12) mit zwei klar getrennten Setup-Schienen:
| Klassisch (Bare Metal) | FrankenPHP + Caddy (Docker Compose, via Portainer) | |
|---|---|---|
| Einsatzgebiet | Lokal/Dev, Notfall-Setup ohne Docker | Standard für Staging und Production |
| Webserver | Nginx + PHP-FPM (manuell konfiguriert) | Caddy (Reverse Proxy) + FrankenPHP (PHP-Workloads) |
| SSL | Certbot / Let's Encrypt | Caddy Auto-SSL (built-in) |
| PHP-Runtime | php-fpm | FrankenPHP + Laravel Octane (Worker-Mode) |
| Service-Orchestrierung | systemd | Docker Compose, Stack-Verzeichnisse in home/bengel/stacks/ |
| Container-UI | — | Portainer (Cockpit only — Stacks bleiben Git-based) |
| Zertifikate | manuell via Certbot | automatisch durch Caddy |
| Empfohlen für | Lernen / Bare-Metal-Setup ohne Docker | alles produktive Hosting |
Standard-Setup (Production)
→ FrankenPHP + Caddy via Docker Compose — komplettes Setup für proxy/, mgmt/, git/, apps/ Stacks. Ist die Variante, die in home/bengel/stacks/ lebt.
→ Stacks-Referenz — pro Stack: was läuft, welche Volumes, welche Env-Vars, wie Backup.
→ Backup-Strategie — Restic + DB-Dumps, Disaster-Recovery-Pfad.
Alternative
→ Klassisch (Bare Metal) — Nginx + PHP-FPM + systemd, ohne Docker. Nur sinnvoll, wenn auf der Maschine kein Docker laufen darf (rare).
Architektur-Bild
┌──────────────────────┐
│ Internet (HTTPS/443)│
└──────────┬───────────┘
│
┌──────────▼───────────┐
│ Caddy (proxy/) │ Auto-SSL, HTTP/3
│ alle *.matev.eu │
└──────────┬───────────┘
┌───────────────────────┼───────────────────────┐
│ │ │
┌────────▼────────┐ ┌─────────▼────────┐ ┌─────────▼────────┐
│ apps/ │ │ git/ │ │ mgmt/ │
│ ─────────── │ │ ─────────── │ │ ─────────── │
│ admin (Filament│ │ forgejo +db │ │ matomo +db │
│ cms (Kirby) │ │ woodpecker +ag. │ │ portainer │
│ staging (Nuxt) │ │ │ │ (off-domain, │
│ b2b (Livewire) │ │ │ │ Server-IP) │
│ storybook │ │ │ │ │
│ docs (Vite) │ │ │ │ │
│ design (Penpot)│ │ │ │ │
│ project (Taiga)│ │ │ │ │
└─────────────────┘ └──────────────────┘ └──────────────────┘
└─────────── docker network: gateway ──────────────┘Alle Stacks hängen am externen Docker-Netz gateway — so findet Caddy jeden Service über seinen Container-Namen ohne Port-Mapping.
Server-Layout (Pfade)
/home/bengel/stacks/ ← Compose + .env + persistente Daten-Volumes
└── proxy/ mgmt/ git/ apps/
/var/www/ ← Source-Code pro Service (Webroot)
└── admin/ cms/ b2b/ staging/ docs/ storybook/ …
Eigentum: bengel:www-data 2775 (setgid + group-writable)Build-Context der apps/docker-compose.yml zeigt auf /var/www/<service>/ — die Dockerfiles leben im Webroot, nicht im Stack-Verzeichnis. Vorlagen liegen in home/bengel/stacks/apps/dockerfiles-reference/.
Voraussetzungen (alle Varianten)
- Ubuntu 24.04 LTS oder Debian 12
- Root-Zugang oder sudo-Berechtigungen
- Domain
matev.eumit DNS-Wildcard (*.matev.eu→ Server-IP) - Subdomains:
admin,cms,staging,b2b,git,ci,analytics,design,docs,project,storybook - Open Ports:
80,443,443/udp(für HTTP/3), optional222(Forgejo-SSH) - Portainer-Port:
9443nur in der Firewall für Admin-IPs / VPN freigeben
DNS-Beispiel
matev.eu A <server-ip>
*.matev.eu A <server-ip>
admin.matev.eu CNAME matev.eu
cms.matev.eu CNAME matev.eu
staging.matev.eu CNAME matev.eu
b2b.matev.eu CNAME matev.eu
git.matev.eu CNAME matev.eu
ci.matev.eu CNAME matev.eu
analytics.matev.eu CNAME matev.eu
design.matev.eu CNAME matev.eu
docs.matev.eu CNAME matev.eu
project.matev.eu CNAME matev.eu
storybook.matev.eu CNAME matev.euWenn Wildcard-DNS gesetzt ist, sind die einzelnen CNAMEs optional — Caddy holt SSL-Zertifikate ohnehin pro Hostname.