Skip to content

Deployment

SecureNet IDS edited this page Aug 31, 2026 · 1 revision

🚒 Deployment

Production deployment options for SecureNet IDS.


🐳 Docker

Dockerfile (Backend)

FROM python:3.11-slim

WORKDIR /app

# Install system deps for packet capture
RUN apt-get update && apt-get install -y libpcap-dev && rm -rf /var/lib/apt/lists/*

COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt

COPY backend/ ./backend/
COPY model/ ./model/
COPY .env .env

EXPOSE 8000

CMD ["python", "backend/main.py"]

docker-compose.yml

version: "3.9"

services:
  securenet-backend:
    build: .
    ports:
      - "8000:8000"
    environment:
      - SUPABASE_URL=${SUPABASE_URL}
      - SUPABASE_KEY=${SUPABASE_KEY}
      - NETWORK_INTERFACE=eth0
    network_mode: host   # Required for packet capture
    restart: unless-stopped

  securenet-ui:
    image: node:18-alpine
    working_dir: /app
    volumes:
      - ./securenet-ui:/app
    command: sh -c "npm install && npm run build && npx serve dist -p 3000"
    ports:
      - "3000:3000"
    restart: unless-stopped
# Start everything
docker compose up -d

# View logs
docker compose logs -f securenet-backend

🌐 Nginx Reverse Proxy

server {
    listen 80;
    server_name your-domain.com;

    # Frontend
    location / {
        root /opt/securenet-ui/dist;
        try_files $uri $uri/ /index.html;
    }

    # Backend API
    location /api/ {
        proxy_pass http://localhost:8000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    }

    # WebSocket
    location /ws {
        proxy_pass http://localhost:8000;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_read_timeout 86400;
    }
}

πŸ”§ Systemd Service (Linux)

Create /etc/systemd/system/securenet.service:

[Unit]
Description=SecureNet IDS Backend
After=network.target

[Service]
Type=simple
User=root
WorkingDirectory=/opt/SecureNet_IDS
EnvironmentFile=/opt/SecureNet_IDS/.env
ExecStart=/opt/SecureNet_IDS/venv/bin/python backend/main.py
Restart=always
RestartSec=5
StandardOutput=journal
StandardError=journal

[Install]
WantedBy=multi-user.target
sudo systemctl daemon-reload
sudo systemctl enable securenet
sudo systemctl start securenet
sudo systemctl status securenet

πŸš€ Frontend Production Build

cd securenet-ui
npm run build
# Output is in: securenet-ui/dist/

Serve the dist/ folder with any static host:

  • Nginx: Point root to dist/
  • Vercel/Netlify: Deploy dist/ folder
  • GitHub Pages: Push dist/ to gh-pages branch

πŸ”’ Production Checklist

  • Set DEBUG=false in .env
  • Use strong SECRET_KEY
  • Configure HTTPS (SSL/TLS) via Nginx + Let's Encrypt
  • Set firewall rules (only expose ports 80/443)
  • Run backend as dedicated non-root user (except packet capture requires root/cap_net_raw)
  • Set up log rotation for ids.log
  • Configure Supabase for cloud backup
  • Set appropriate rate limits for public API endpoints

Clone this wiki locally