-
Notifications
You must be signed in to change notification settings - Fork 2
Deployment
SecureNet IDS edited this page Aug 31, 2026
·
1 revision
Production deployment options for SecureNet IDS.
FROM python:3.11-slim
WORKDIR /app
# Install system deps for packet capture
RUN apt-get update && apt-get install -y libpcap-dev && rm -rf /var/lib/apt/lists/*
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY backend/ ./backend/
COPY model/ ./model/
COPY .env .env
EXPOSE 8000
CMD ["python", "backend/main.py"]version: "3.9"
services:
securenet-backend:
build: .
ports:
- "8000:8000"
environment:
- SUPABASE_URL=${SUPABASE_URL}
- SUPABASE_KEY=${SUPABASE_KEY}
- NETWORK_INTERFACE=eth0
network_mode: host # Required for packet capture
restart: unless-stopped
securenet-ui:
image: node:18-alpine
working_dir: /app
volumes:
- ./securenet-ui:/app
command: sh -c "npm install && npm run build && npx serve dist -p 3000"
ports:
- "3000:3000"
restart: unless-stopped# Start everything
docker compose up -d
# View logs
docker compose logs -f securenet-backendserver {
listen 80;
server_name your-domain.com;
# Frontend
location / {
root /opt/securenet-ui/dist;
try_files $uri $uri/ /index.html;
}
# Backend API
location /api/ {
proxy_pass http://localhost:8000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
# WebSocket
location /ws {
proxy_pass http://localhost:8000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_read_timeout 86400;
}
}Create /etc/systemd/system/securenet.service:
[Unit]
Description=SecureNet IDS Backend
After=network.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/SecureNet_IDS
EnvironmentFile=/opt/SecureNet_IDS/.env
ExecStart=/opt/SecureNet_IDS/venv/bin/python backend/main.py
Restart=always
RestartSec=5
StandardOutput=journal
StandardError=journal
[Install]
WantedBy=multi-user.targetsudo systemctl daemon-reload
sudo systemctl enable securenet
sudo systemctl start securenet
sudo systemctl status securenetcd securenet-ui
npm run build
# Output is in: securenet-ui/dist/Serve the dist/ folder with any static host:
-
Nginx: Point root to
dist/ -
Vercel/Netlify: Deploy
dist/folder -
GitHub Pages: Push
dist/to gh-pages branch
- Set
DEBUG=falsein.env - Use strong
SECRET_KEY - Configure HTTPS (SSL/TLS) via Nginx + Let's Encrypt
- Set firewall rules (only expose ports 80/443)
- Run backend as dedicated non-root user (except packet capture requires root/cap_net_raw)
- Set up log rotation for
ids.log - Configure Supabase for cloud backup
- Set appropriate rate limits for public API endpoints