๐OCIํ๊ฒฝ์ค์ / OCI environment settings
๐npm init ํ์๋ ๋ค์๊ณผ ๊ฐ์ด npm์ด ์๋ค๋ฉด npm์ค์นํฉ๋๋ค.
If npm is not present when you run npm init, install npm.
ubuntu@app-20251223-1824:~/dockerApp/routes$ npm init
Command 'npm' not found, but can be installed with:
sudo apt install npm
sudo apt install npm
๐nodejs ์ต์ ๋ฒ์ ์ค์น / Install the latest version of nodejs
# NVM ์ค์น ์คํฌ๋ฆฝํธ ์คํ (๊ณต์ GitHub์์ ๊ฐ์ ธ์ด)
# Run the NVM installation script (from the official GitHub)
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.1/install.sh | bash
# ์ ์ฌ์์ํ๊ฑฐ๋ ์ค์ ์ ์ฉ
# Restart shell or apply settings
source ~/.bashrc # ๋๋ ~/.zshrc nแบฟu Zsh ์ฌ์ฉ ์ค
# (ํฐ๋ฏธ๋ ์ฌ์์ํด๋ ๋จ)
# ์ค์น ํ์ธ / Check installation
nvm --version
# ์ต์ Current ๋ฒ์ ์ค์น / Install the latest Current version
nvm install node # ํ์ฌ v25.2.1 ์ค์น๋จ
# ๋๋ ์ต์ LTS ๋ฒ์ ์ค์น
# or install the latest LTS version
nvm install --lts
# ์ฌ์ฉ ์ค์ธ ๋ฒ์ ํ์ธ
# Check the version you are using
node -v
npm -v
๐mysql ์ค์น ํ๊ธฐ / Install mysql
sudo apt update
sudo apt install mysql-server
โ๏ธ๋ค์๊ณผ ๊ฐ์ ๋ช
๋ น์ด๋ก mysql์คํ ์ํ๋ฅผ ํ์ธ ํฉ๋๋ค.
Check the mysql execution status with the following command.
service mysql status
#๋๋ / or
sudo systemctl status mysql
โ๏ธ๊ทธ๋ฌ๋ฉด ๋ค์๊ณผ ๊ฐ์ด active ๋ฉ์ธ์ง๊ฐ ๋ณด์ด๋ฉด ์ ์ ์ค์น๋ ๊ฒ์
๋๋ค.
If you see an active message like this, it means it was installed successfully.
โ mysql.service - MySQL Community Server
Loaded: loaded (/usr/lib/systemd/system/mysql.service; enabled; preset: enabled)
Active: active (running) since Wed 2025-12-24 07:05:58 UTC; 1min 42s ago
Process: 27273 ExecStartPre=/usr/share/mysql/mysql-systemd-start pre (code=exited, status=0/SUCCESS)
Main PID: 27287 (mysqld)
Status: "Server is operational"
Tasks: 37 (limit: 14233)
Memory: 365.5M (peak: 379.8M)
CPU: 806ms
CGroup: /system.slice/mysql.service
โโ27287 /usr/sbin/mysqld
Dec 24 07:05:57 app-20251223-1824 systemd[1]: Starting mysql.service - MySQL Community Server...
Dec 24 07:05:58 app-20251223-1824 systemd[1]: Started mysql.service - MySQL Community Server.
โ๏ธmysql secure installation์ ์คํํฉ๋๋ค.
Run mysql secure installation.
โ๏ธ์๋ ์ค์ ์ ์ฐธ์กฐํ์ธ์ / See settings below
ubuntu@app-20251223-1824:~/dockerApp/routes$ sudo mysql_secure_installation
Securing the MySQL server deployment.
Connecting to MySQL using a blank password.
VALIDATE PASSWORD COMPONENT can be used to test passwords
and improve security. It checks the strength of password
and allows the users to set only those passwords which are
secure enough. Would you like to setup VALIDATE PASSWORD component?
Press y|Y for Yes, any other key for No: y
There are three levels of password validation policy:
LOW Length >= 8
MEDIUM Length >= 8, numeric, mixed case, and special characters
STRONG Length >= 8, numeric, mixed case, special characters and dictionary file
Please enter 0 = LOW, 1 = MEDIUM and 2 = STRONG: 0
Skipping password set for root as authentication with auth_socket is used by default.
If you would like to use password authentication instead, this can be done with the "ALTER_USER" command.
See https://dev.mysql.com/doc/refman/8.0/en/alter-user.html#alter-user-password-management for more information.
By default, a MySQL installation has an anonymous user,
allowing anyone to log into MySQL without having to have
a user account created for them. This is intended only for
testing, and to make the installation go a bit smoother.
You should remove them before moving into a production
environment.
Remove anonymous users? (Press y|Y for Yes, any other key for No) : y
Success.
Normally, root should only be allowed to connect from
'localhost'. This ensures that someone cannot guess at
the root password from the network.
Disallow root login remotely? (Press y|Y for Yes, any other key for No) : y
Success.
By default, MySQL comes with a database named 'test' that
anyone can access. This is also intended only for testing,
and should be removed before moving into a production
environment.
Remove test database and access to it? (Press y|Y for Yes, any other key for No) : y
- Dropping test database...
Success.
- Removing privileges on test database...
Success.
Reloading the privilege tables will ensure that all changes
made so far will take effect immediately.
Reload privilege tables now? (Press y|Y for Yes, any other key for No) : y
Success.
All done!
โ๏ธOCI๋ฐฉํ๋ฒฝ ์คํ / OCI Firewall Open
— ์ผ๋จ ์ ์ฒด ์คํ ์ค์ ํจ / First, set the entire open
โ๏ธiptables๋ฐฉํ๋ฒฝ ์คํ / Open iptables firewall
โญ์ฃผ์:22๋ฒํฌํธ๋ ์ ๋ ๋ง์ง๋ง์ธ์ ๋ค์ ๋ก๊ทธ์ธ ๋ชปํฉ๋๋ค.(vm์ญ์ ํด์ผ ํจ)
Caution: Never block port 22. You will not be able to log in again (you will need to delete the VM).
— iptables persistant์ค์น(์
ํ
์๊ตฌ์ ์ฅ)
Install iptables persistent (permanently save settings)
sudo apt update
sudo apt install iptables-persistent
โ๏ธ ๋ฐฉํ๋ฒฝ ์คํ
# 3000๋ฒ ์คํ / 3000 open
sudo iptables -I INPUT 1 -p tcp --dport 3000 -j ACCEPT
# ํ์ธ (1๋ฒ์ ์์ด์ผ ํจ) / Check (should be at 1)
sudo iptables -L INPUT --line-numbers -v -n
# ์๊ตฌ ์ ์ฅ / Save permanently
sudo netfilter-persistent save
โญ๋ฐฉํ๋ฒฝ ๊ท์น ์ญ์ ํ๋ ค๋ฉด(2๋ฒ์ ์ญ์ ํ๋ ๊ฒฝ์ฐ)
To delete a firewall rule (if deleting step 2)
— ์คํ ํ ์๋ 2๋ฒ์ด์๋ ๊ท์น์ด ์ฌ๋ผ์ง๊ณ , ์๋ ๊ท์น๋ค์ด ํ๋์ฉ ์๋ก ์ฌ๋ผ์ต๋๋ค (3๋ฒ โ 2๋ฒ, 4๋ฒ โ 3๋ฒ โฆ)
After execution, the original rule number 2 disappears, and the rules below move up one by one (number 3 โ number 2, number 4 โ number 3โฆ)
sudo iptables -D INPUT 2
โ๏ธ๋ฐฉํ๋ฒฝ ์ค์ (ํ์์ ์ผ๋ก ์คํํด์ผ ํ๋ ํฌํธ)
Firewall settings (ports that must be opened)
# 8000๋ฒ ํฌํธ ํ์ฉ (๋งจ ์์ ์ฝ์
)
sudo iptables -I INPUT 1 -p tcp --dport 8000 -j ACCEPT
# 443๋ฒ ํฌํธ ํ์ฉ (HTTPS, ๋งจ ์์ ์ฝ์
โ ์ด์ 1๋ฒ์ด ๋จ)
sudo iptables -I INPUT 1 -p tcp --dport 443 -j ACCEPT
# 80๋ฒ ํฌํธ ํ์ฉ (HTTP, ๋งจ ์์ ์ฝ์
โ ์ด์ 1๋ฒ์ด ๋จ)
sudo iptables -I INPUT 1 -p tcp --dport 80 -j ACCEPT
#3306๋ฒ ํฌํธํ์ฉ (MYSQLํฌํธ)
sudo iptables -I INPUT 1 -p tcp --dport 3306 -j ACCEPT
# ์๊ตฌ์ ์ฅ
sudo netfilter-persistent save
โ๏ธ์ต์ข
iptables๋ฐฉํ๋ฒฝ ์
ํ
ํ์ธ
Check the final iptables firewall settings
ubuntu@app-20251223-1824:~/dockerApp$ sudo iptables -L INPUT --line-numbers -v -n
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
num pkts bytes target prot opt in out source destination
1 9 942 ACCEPT 6 -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3306
2 24531 1855K ACCEPT 6 -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
3 8 384 ACCEPT 6 -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
4 53 2720 ACCEPT 6 -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8000
5 20 1338 ACCEPT 6 -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3000
6 34403 403M ACCEPT 0 -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
7 1235 83838 ACCEPT 1 -- * * 0.0.0.0/0 0.0.0.0/0
8 256 25388 ACCEPT 0 -- lo * 0.0.0.0/0 0.0.0.0/0
9 7 332 ACCEPT 6 -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:22
10 1187 53712 REJECT 0 -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
11 0 0 ufw-before-logging-input 0 -- * * 0.0.0.0/0 0.0.0.0/0
12 0 0 ufw-before-input 0 -- * * 0.0.0.0/0 0.0.0.0/0
13 0 0 ufw-after-input 0 -- * * 0.0.0.0/0 0.0.0.0/0
14 0 0 ufw-after-logging-input 0 -- * * 0.0.0.0/0 0.0.0.0/0
15 0 0 ufw-reject-input 0 -- * * 0.0.0.0/0 0.0.0.0/0
16 0 0 ufw-track-input 0 -- * * 0.0.0.0/0 0.0.0.0/0
17 0 0 ACCEPT 0 -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
โ๏ธmysql๊ณ์ ์ถ๊ฐ / Add a mysql account
— root๋ก ์ ์ / Connect as root
sudo mysql -u root -p
— ์ฌ์ฉ์ ๊ณ์ ์ถ๊ฐ / Add user account
CREATE DATABASE myapp CHARACTER SET utf8mb4 COLLATE utf8mb4_general_ci;
CREATE USER 'myapp'@'%' IDENTIFIED BY 'Myapp@1234';
GRANT ALL PRIVILEGES ON myapp.* TO 'myapp'@'%';
FLUSH PRIVILEGES;
EXIT;
— mysql์ ์ ํ์ฉ / Allow mysql access
-127.0.0.1 : MySQL์ด ๋ก์ปฌ ๋ฃจํ๋ฐฑ(์๊ธฐ ์์ )์์๋ง ์ฐ๊ฒฐ์ ๋ฐ์๋ค์
127.0.0.1: MySQL accepts connections only on the local loopback (itself)
-0.0.0.0 : ๋ชจ๋ ๋คํธ์ํฌ ์ธํฐํ์ด์ค์์ ์ฐ๊ฒฐ์ ๋ฐ์๋ค์
0.0.0.0: Accept connections on all network interfaces
sudo nano /etc/mysql/mysql.conf.d/mysqld.cnf
์ด ์ค์ / Change this line
bind-address = 127.0.0.1
์ด๋ ๊ฒ ๋ฐ๊ฟ๋๋ค. / to this
bind-address = 0.0.0.0
— mysql ์ฌ์์ / restart mysql
sudo systemctl restart mysql
๐์ฌ๊ธฐ๊น์ง ์๋ฃํ๋ฉด ํ๊ฒฝ์ค์ ์ด ์๋ฃ๋ฉ๋๋ค.
Once you’ve completed this, your setup is complete.