Skip to content

Instantly share code, notes, and snippets.

Last active October 4, 2024 22:49
Show Gist options
  • Save bradtraversy/cd90d1ed3c462fe3bddd11bf8953a896 to your computer and use it in GitHub Desktop.
Save bradtraversy/cd90d1ed3c462fe3bddd11bf8953a896 to your computer and use it in GitHub Desktop.
Node app deploy with nginx & SSL

Node.js Deployment

Steps to deploy a Node.js app to DigitalOcean using PM2, NGINX as a reverse proxy and an SSL from LetsEncrypt

1. Sign up for Digital Ocean

If you use the referal link below, you get $10 free (1 or 2 months)

2. Create a droplet and log in via ssh

I will be using the root user, but would suggest creating a new user

3. Install Node/NPM

curl -sL | sudo -E bash -

sudo apt install nodejs

node --version

4. Clone your project from Github

There are a few ways to get your files on to the server, I would suggest using Git

git clone yourproject.git

5. Install dependencies and test app

cd yourproject
npm install
npm start (or whatever your start command)
# stop app

6. Setup PM2 process manager to keep your app running

sudo npm i pm2 -g
pm2 start app (or whatever your file name)

# Other pm2 commands
pm2 show app
pm2 status
pm2 restart app
pm2 stop app
pm2 logs (Show log stream)
pm2 flush (Clear logs)

# To make sure app starts when reboot
pm2 startup ubuntu

You should now be able to access your app using your IP and port. Now we want to setup a firewall blocking that port and setup NGINX as a reverse proxy so we can access it directly using port 80 (http)

7. Setup ufw firewall

sudo ufw enable
sudo ufw status
sudo ufw allow ssh (Port 22)
sudo ufw allow http (Port 80)
sudo ufw allow https (Port 443)

8. Install NGINX and configure

sudo apt install nginx

sudo nano /etc/nginx/sites-available/default

Add the following to the location part of the server block


    location / {
        proxy_pass http://localhost:5000; #whatever port your app runs on
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_cache_bypass $http_upgrade;
# Check NGINX config
sudo nginx -t

# Restart NGINX
sudo service nginx restart

You should now be able to visit your IP with no port (port 80) and see your app. Now let's add a domain

9. Add domain in Digital Ocean

In Digital Ocean, go to networking and add a domain

Add an A record for @ and for www to your droplet

Register and/or setup domain from registrar

I prefer Namecheap for domains. Please use this affiliate link if you are going to use them

Choose "Custom nameservers" and add these 3


It may take a bit to propogate

  1. Add SSL with LetsEncrypt
sudo add-apt-repository ppa:certbot/certbot
sudo apt-get update
sudo apt-get install python-certbot-nginx
sudo certbot --nginx -d -d

# Only valid for 90 days, test the renewal process with
certbot renew --dry-run

Now visit and you should see your Node app

Copy link

ranjandsingh commented May 18, 2022

I can't seem to run POST requests with this configuration. When I post i get this message, all the post data is undefined


Thanks in advance

Some Times It does due to using HTTP instead of HTTPS please use HTTPS if you installed SSL already hope it helps.

Copy link

Best one !

Copy link

Getting this after configuring all configuration on EC2-instance
"ErrorResponse is not defined"

Copy link

Great tutorial, but my node website is not loading the css and javascript files, any idea how to fix it?

Copy link

how can I redirect from to

Copy link


Copy link

For people who don't want to bother their minds with this, I created an automatic installer!

Copy link

This is a life-saver. Great work Brad. Thanks also to all the inline comments.

Copy link

serfoll commented Sep 2, 2022

This was great, works well with google cloud too

Copy link

vinsonw commented Oct 17, 2022

Successfully deployed on vultr. Left out the security and ssl part due to time limit.
Great course, learned a lot, thanks!

Copy link

hall500 commented Oct 30, 2022, www is a subdomain already. so you can only use

Copy link

Thanks! This was extremely helpful. For anyone having trouble with POST requests, the problem is NGINX redirects requests to https with status code 301, which sometimes changes the method of the request to GET. The solution is to redirect requests with status code 308, which doesn't change the method of the request

Copy link

is it possible to do the ssl without a domain and use the IP address instead?

Copy link

msrumon commented Dec 14, 2022

is it possible to do the ssl without a domain and use the IP address instead?

No. SSL is issued to domain names, not IP addresses.

Copy link

Is this works with Let's Encrypt and auto renew of SSL from Let's Encrypt after 90 days?

Copy link

SV-sites commented Mar 2, 2023

Update 2023 install Certbot
sudo pip3 install certbot-nginx

Thanks a lot!

"Do not use no-name name servers, because you will suck with NGINX!" => I learned this after 2.5 day struggling :)

Copy link

Answer32 commented Apr 3, 2023

What if I deploy the app on a local server and acces it through HTTP only on my local network? Will the browser complain about an insecure connection?

Copy link

msrumon commented Apr 3, 2023

What if I deploy the app on a local server and acces it through HTTP only on my local network? Will the browser complain about an insecure connection?

If the browser sees "localhost" in the address bar, it'll most probably not complain.

Copy link

Answer32 commented Apr 3, 2023

What if I deploy the app on a local server and acces it through HTTP only on my local network? Will the browser complain about an insecure connection?

If the browser sees "localhost" in the address bar, it'll most probably not complain.

What if I access it from another computer that is on the same network?

Copy link

msrumon commented Apr 3, 2023

What if I deploy the app on a local server and acces it through HTTP only on my local network? Will the browser complain about an insecure connection?

If the browser sees "localhost" in the address bar, it'll most probably not complain.

What if I access it from another computer that is on the same network?

Same. 'Cause the other device and the device the server is running on are technically under the same network.

Copy link

ahmedRSA commented Apr 4, 2023

for ssl just move your name servers to cloudflare

Copy link

for SSL , i have use instruction from , as given in th doc is depricated

Copy link

ENO-QC commented Jun 18, 2023

sudo apt-get install certbot python3-certbot-nginx worked for me

Copy link

I've configured it as shown and it's working perfectly fine.

But only one problem I'm facing very badly.

I'm continuously getting one error in the console.
WebSocketClient.js:16 WebSocket connection to 'wss://' failed:

Copy link

sudo pip3 install certbot-nginx

Thank you for this!!!

Copy link

Are you sure "localhost" will work in Nginx config? I recall you have to use instead, because nginx expects to see an IP, not "localhost".

Copy link

Thanks bro! It worked!

Copy link, www is a subdomain already. so you can only use

Can You please help on how to setup subdomain for my api instead of main domain

Copy link

Looks like step 10 is deprecated. The link below helped me to get https working.

Copy link


Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment