[OCI,Linux]๋„์ปค + mysql + express / Docker + mysql + express(1)

๐Ÿ‘‰OCIํ™˜๊ฒฝ์„ค์ • / OCI environment settings

๐Ÿ‘‰npm init ํ–ˆ์„๋•Œ ๋‹ค์Œ๊ณผ ๊ฐ™์ด npm์ด ์—†๋‹ค๋ฉด npm์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.
If npm is not present when you run npm init, install npm.

ubuntu@app-20251223-1824:~/dockerApp/routes$ npm init
Command 'npm' not found, but can be installed with:
sudo apt install npm
sudo apt install npm

๐Ÿ‘‰nodejs ์ตœ์‹ ๋ฒ„์ „ ์„ค์น˜ / Install the latest version of nodejs

# NVM ์„ค์น˜ ์Šคํฌ๋ฆฝํŠธ ์‹คํ–‰ (๊ณต์‹ GitHub์—์„œ ๊ฐ€์ ธ์˜ด)
# Run the NVM installation script (from the official GitHub)
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.1/install.sh | bash

# ์‰˜ ์žฌ์‹œ์ž‘ํ•˜๊ฑฐ๋‚˜ ์„ค์ • ์ ์šฉ
# Restart shell or apply settings
source ~/.bashrc  # ๋˜๋Š” ~/.zshrc nแบฟu Zsh ์‚ฌ์šฉ ์ค‘
# (ํ„ฐ๋ฏธ๋„ ์žฌ์‹œ์ž‘ํ•ด๋„ ๋จ)

# ์„ค์น˜ ํ™•์ธ / Check installation
nvm --version

# ์ตœ์‹  Current ๋ฒ„์ „ ์„ค์น˜ / Install the latest Current version
nvm install node  # ํ˜„์žฌ v25.2.1 ์„ค์น˜๋จ

# ๋˜๋Š” ์ตœ์‹  LTS ๋ฒ„์ „ ์„ค์น˜ 
# or install the latest LTS version
nvm install --lts

# ์‚ฌ์šฉ ์ค‘์ธ ๋ฒ„์ „ ํ™•์ธ
# Check the version you are using
node -v
npm -v

๐Ÿ‘‰mysql ์„ค์น˜ ํ•˜๊ธฐ / Install mysql

sudo apt update
sudo apt install mysql-server

โœ”๏ธ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ช…๋ น์–ด๋กœ mysql์‹คํ–‰ ์ƒํƒœ๋ฅผ ํ™•์ธ ํ•ฉ๋‹ˆ๋‹ค.
Check the mysql execution status with the following command.

service mysql status
#๋˜๋Š” / or
sudo systemctl status mysql

โœ”๏ธ๊ทธ๋Ÿฌ๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์ด active ๋ฉ”์„ธ์ง€๊ฐ€ ๋ณด์ด๋ฉด ์ •์ƒ ์„ค์น˜๋œ ๊ฒƒ์ž…๋‹ˆ๋‹ค.
If you see an active message like this, it means it was installed successfully.

โ— mysql.service - MySQL Community Server
     Loaded: loaded (/usr/lib/systemd/system/mysql.service; enabled; preset: enabled)
     Active: active (running) since Wed 2025-12-24 07:05:58 UTC; 1min 42s ago
    Process: 27273 ExecStartPre=/usr/share/mysql/mysql-systemd-start pre (code=exited, status=0/SUCCESS)
   Main PID: 27287 (mysqld)
     Status: "Server is operational"
      Tasks: 37 (limit: 14233)
     Memory: 365.5M (peak: 379.8M)
        CPU: 806ms
     CGroup: /system.slice/mysql.service
             โ””โ”€27287 /usr/sbin/mysqld

Dec 24 07:05:57 app-20251223-1824 systemd[1]: Starting mysql.service - MySQL Community Server...
Dec 24 07:05:58 app-20251223-1824 systemd[1]: Started mysql.service - MySQL Community Server.

โœ”๏ธmysql secure installation์„ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.
Run mysql secure installation.

โœ”๏ธ์•„๋ž˜ ์„ค์ •์„ ์ฐธ์กฐํ•˜์„ธ์š” / See settings below

ubuntu@app-20251223-1824:~/dockerApp/routes$ sudo mysql_secure_installation

Securing the MySQL server deployment.

Connecting to MySQL using a blank password.

VALIDATE PASSWORD COMPONENT can be used to test passwords
and improve security. It checks the strength of password
and allows the users to set only those passwords which are
secure enough. Would you like to setup VALIDATE PASSWORD component?

Press y|Y for Yes, any other key for No: y

There are three levels of password validation policy:

LOW    Length >= 8
MEDIUM Length >= 8, numeric, mixed case, and special characters
STRONG Length >= 8, numeric, mixed case, special characters and dictionary                  file

Please enter 0 = LOW, 1 = MEDIUM and 2 = STRONG: 0

Skipping password set for root as authentication with auth_socket is used by default.
If you would like to use password authentication instead, this can be done with the "ALTER_USER" command.
See https://dev.mysql.com/doc/refman/8.0/en/alter-user.html#alter-user-password-management for more information.

By default, a MySQL installation has an anonymous user,
allowing anyone to log into MySQL without having to have
a user account created for them. This is intended only for
testing, and to make the installation go a bit smoother.
You should remove them before moving into a production
environment.

Remove anonymous users? (Press y|Y for Yes, any other key for No) : y
Success.


Normally, root should only be allowed to connect from
'localhost'. This ensures that someone cannot guess at
the root password from the network.

Disallow root login remotely? (Press y|Y for Yes, any other key for No) : y
Success.

By default, MySQL comes with a database named 'test' that
anyone can access. This is also intended only for testing,
and should be removed before moving into a production
environment.


Remove test database and access to it? (Press y|Y for Yes, any other key for No) : y
 - Dropping test database...
Success.

 - Removing privileges on test database...
Success.

Reloading the privilege tables will ensure that all changes
made so far will take effect immediately.

Reload privilege tables now? (Press y|Y for Yes, any other key for No) : y
Success.

All done!

โœ”๏ธOCI๋ฐฉํ™”๋ฒฝ ์˜คํ”ˆ / OCI Firewall Open

— ์ผ๋‹จ ์ „์ฒด ์˜คํ”ˆ ์„ค์ •ํ•จ / First, set the entire open

โœ”๏ธiptables๋ฐฉํ™”๋ฒฝ ์˜คํ”ˆ / Open iptables firewall

โญ์ฃผ์˜:22๋ฒˆํฌํŠธ๋Š” ์ ˆ๋Œ€ ๋ง‰์ง€๋งˆ์„ธ์š” ๋‹ค์‹œ ๋กœ๊ทธ์ธ ๋ชปํ•ฉ๋‹ˆ๋‹ค.(vm์‚ญ์ œํ•ด์•ผ ํ•จ)
Caution: Never block port 22. You will not be able to log in again (you will need to delete the VM).

— iptables persistant์„ค์น˜(์…‹ํŒ… ์˜๊ตฌ์ €์žฅ)
Install iptables persistent (permanently save settings)

sudo apt update
sudo apt install iptables-persistent

โœ”๏ธ ๋ฐฉํ™”๋ฒฝ ์˜คํ”ˆ

# 3000๋ฒˆ ์˜คํ”ˆ / 3000 open
sudo iptables -I INPUT 1 -p tcp --dport 3000 -j ACCEPT

# ํ™•์ธ (1๋ฒˆ์— ์žˆ์–ด์•ผ ํ•จ) / Check (should be at 1)
sudo iptables -L INPUT --line-numbers -v -n

# ์˜๊ตฌ ์ €์žฅ / Save permanently
sudo netfilter-persistent save

โญ๋ฐฉํ™”๋ฒฝ ๊ทœ์น™ ์‚ญ์ œํ•˜๋ ค๋ฉด(2๋ฒˆ์„ ์‚ญ์ œํ•˜๋Š” ๊ฒฝ์šฐ)
To delete a firewall rule (if deleting step 2)

— ์‹คํ–‰ ํ›„ ์›๋ž˜ 2๋ฒˆ์ด์—ˆ๋˜ ๊ทœ์น™์ด ์‚ฌ๋ผ์ง€๊ณ , ์•„๋ž˜ ๊ทœ์น™๋“ค์ด ํ•˜๋‚˜์”ฉ ์œ„๋กœ ์˜ฌ๋ผ์˜ต๋‹ˆ๋‹ค (3๋ฒˆ โ†’ 2๋ฒˆ, 4๋ฒˆ โ†’ 3๋ฒˆ โ€ฆ)
After execution, the original rule number 2 disappears, and the rules below move up one by one (number 3 โ†’ number 2, number 4 โ†’ number 3โ€ฆ)

sudo iptables -D INPUT 2

โœ”๏ธ๋ฐฉํ™”๋ฒฝ ์„ค์ •(ํ•„์ˆ˜์ ์œผ๋กœ ์˜คํ”ˆํ•ด์•ผ ํ•˜๋Š” ํฌํŠธ)
Firewall settings (ports that must be opened)

# 8000๋ฒˆ ํฌํŠธ ํ—ˆ์šฉ (๋งจ ์œ„์— ์‚ฝ์ž…)
sudo iptables -I INPUT 1 -p tcp --dport 8000 -j ACCEPT

# 443๋ฒˆ ํฌํŠธ ํ—ˆ์šฉ (HTTPS, ๋งจ ์œ„์— ์‚ฝ์ž… โ†’ ์ด์ œ 1๋ฒˆ์ด ๋จ)
sudo iptables -I INPUT 1 -p tcp --dport 443 -j ACCEPT

# 80๋ฒˆ ํฌํŠธ ํ—ˆ์šฉ (HTTP, ๋งจ ์œ„์— ์‚ฝ์ž… โ†’ ์ด์ œ 1๋ฒˆ์ด ๋จ)
sudo iptables -I INPUT 1 -p tcp --dport 80 -j ACCEPT

#3306๋ฒˆ ํฌํŠธํ—ˆ์šฉ (MYSQLํฌํŠธ)
sudo iptables -I INPUT 1 -p tcp --dport 3306 -j ACCEPT

# ์˜๊ตฌ์ €์žฅ
sudo netfilter-persistent save

โœ”๏ธ์ตœ์ข… iptables๋ฐฉํ™”๋ฒฝ ์…‹ํŒ… ํ™•์ธ
Check the final iptables firewall settings

ubuntu@app-20251223-1824:~/dockerApp$ sudo iptables -L INPUT --line-numbers -v -n
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
num   pkts bytes target     prot opt in     out     source               destination
1        9   942 ACCEPT     6    --  *      *       0.0.0.0/0            0.0.0.0/0            tcp dpt:3306
2    24531 1855K ACCEPT     6    --  *      *       0.0.0.0/0            0.0.0.0/0            tcp dpt:22
3        8   384 ACCEPT     6    --  *      *       0.0.0.0/0            0.0.0.0/0            tcp dpt:443
4       53  2720 ACCEPT     6    --  *      *       0.0.0.0/0            0.0.0.0/0            tcp dpt:8000
5       20  1338 ACCEPT     6    --  *      *       0.0.0.0/0            0.0.0.0/0            tcp dpt:3000
6    34403  403M ACCEPT     0    --  *      *       0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
7     1235 83838 ACCEPT     1    --  *      *       0.0.0.0/0            0.0.0.0/0
8      256 25388 ACCEPT     0    --  lo     *       0.0.0.0/0            0.0.0.0/0
9        7   332 ACCEPT     6    --  *      *       0.0.0.0/0            0.0.0.0/0            state NEW tcp dpt:22
10    1187 53712 REJECT     0    --  *      *       0.0.0.0/0            0.0.0.0/0            reject-with icmp-host-prohibited
11       0     0 ufw-before-logging-input  0    --  *      *       0.0.0.0/0            0.0.0.0/0
12       0     0 ufw-before-input  0    --  *      *       0.0.0.0/0            0.0.0.0/0
13       0     0 ufw-after-input  0    --  *      *       0.0.0.0/0            0.0.0.0/0
14       0     0 ufw-after-logging-input  0    --  *      *       0.0.0.0/0            0.0.0.0/0
15       0     0 ufw-reject-input  0    --  *      *       0.0.0.0/0            0.0.0.0/0
16       0     0 ufw-track-input  0    --  *      *       0.0.0.0/0            0.0.0.0/0
17       0     0 ACCEPT     0    --  *      *       0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED

โœ”๏ธmysql๊ณ„์ • ์ถ”๊ฐ€ / Add a mysql account

— root๋กœ ์ ‘์† / Connect as root

sudo mysql -u root -p

— ์‚ฌ์šฉ์ž ๊ณ„์ • ์ถ”๊ฐ€ / Add user account

CREATE DATABASE myapp CHARACTER SET utf8mb4 COLLATE utf8mb4_general_ci;
CREATE USER 'myapp'@'%' IDENTIFIED BY 'Myapp@1234';
GRANT ALL PRIVILEGES ON myapp.* TO 'myapp'@'%';
FLUSH PRIVILEGES;
EXIT;

— mysql์ ‘์† ํ—ˆ์šฉ / Allow mysql access

-127.0.0.1 : MySQL์ด ๋กœ์ปฌ ๋ฃจํ”„๋ฐฑ(์ž๊ธฐ ์ž์‹ )์—์„œ๋งŒ ์—ฐ๊ฒฐ์„ ๋ฐ›์•„๋“ค์ž„
127.0.0.1: MySQL accepts connections only on the local loopback (itself)

-0.0.0.0 : ๋ชจ๋“  ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค์—์„œ ์—ฐ๊ฒฐ์„ ๋ฐ›์•„๋“ค์ž„
0.0.0.0: Accept connections on all network interfaces

sudo nano /etc/mysql/mysql.conf.d/mysqld.cnf

์ด ์ค„์„ / Change this line

bind-address = 127.0.0.1

์ด๋ ‡๊ฒŒ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค. / to this

bind-address = 0.0.0.0

— mysql ์žฌ์‹œ์ž‘ / restart mysql

sudo systemctl restart mysql

๐Ÿ‘‰์—ฌ๊ธฐ๊นŒ์ง€ ์™„๋ฃŒํ•˜๋ฉด ํ™˜๊ฒฝ์„ค์ •์ด ์™„๋ฃŒ๋ฉ๋‹ˆ๋‹ค.
Once you’ve completed this, your setup is complete.

Leave a Reply