> **Orange Host** only offers shared hosting, so it uses `DEPLOY-CPANEL.md`. This guide is for a VPS (any provider) with Docker.

# Deploying ANish 24 on a VPS (Docker, HTTPS, backups)

Puts MariaDB, the API, the alert worker and the web app on one small Linux server. Caddy fetches and renews the HTTPS certificate. HTTPS is required for phones to install the app.

## 1. Server
- Linux VPS, KVM virtualization, Ubuntu 24.04, 2 vCPU, 2-4 GB RAM, 40 GB disk, a dedicated IPv4, root SSH, ports 80/443 open. Roughly $5-7/month at common providers; check each provider's current price and renewal price.
- Pick a region near your users (for Pakistan: Singapore, India, Dubai, Bahrain, or a local VPS host) and ping it from a real school connection first.

## 2. Domain
Add an **A record** `school` pointing at the server's IPv4 (so `school.aromanish.com`). Do not host this on the same server as another website using ports 80/443.

## 3. Prepare the server
```bash
ssh root@SERVER_IP
adduser deploy && usermod -aG sudo deploy          # then log in as deploy
sudo apt update && sudo apt -y upgrade
sudo ufw allow OpenSSH && sudo ufw allow 80 && sudo ufw allow 443 && sudo ufw --force enable
curl -fsSL https://get.docker.com | sudo sh && sudo usermod -aG docker deploy   # log out and back in
```
Use SSH keys and turn off SSH password login.

## 4. Upload and configure
```bash
unzip anish24-api.zip && cd anish24-api
sh deploy/check-server.sh school.aromanish.com     # fix any WARNING first
cp .env.production.example .env
nano .env      # set DOMAIN and passwords/secrets from: openssl rand -hex 24
```

## 5. Start
```bash
docker compose up -d --build
docker compose ps                  # four services running
```
The first start creates the database and tables from `schema.sql`. Open `https://school.aromanish.com/health`.

## 6. Create your school and admin
```bash
docker compose run --rm app node scripts/create-school.js "Your School Name" 03XXXXXXXXX
```
Open the printed link, sign in, choose a new password.

## 7. Backups (day one)
```bash
chmod +x deploy/backup.sh
crontab -e     # add:   30 2 * * * /home/deploy/anish24-api/deploy/backup.sh >> /home/deploy/backup.log 2>&1
```
Copy `backups/` off the server regularly. Test a restore into a spare database before relying on it.

## 8. Alerts and payments
Set `ALERTS_PROVIDER=live` and the WhatsApp/SMS values in `.env`, then `docker compose up -d`. Fill the `GATEWAY_SECRET_*` values only after replacing the webhook signature check in `src/fees.js` with the exact JazzCash/Easypaisa specification.

## 9. Updating
```bash
docker compose up -d --build
docker compose run --rm app npm run migrate      # applies any new migration files
```

## 10. Monitoring and safety
Add `/health` to a free uptime monitor, enable `unattended-upgrades`, keep the database port closed (it is not published), rotate `JWT_SECRET` if exposed, and limit admin accounts: student records are children's personal data.
