Deployment & Operations

Krewire applications compile into single static binaries with embedded assets, making production operations simpler, faster, and more reliable than traditional multi-language web runtimes.


1. Multi-Stage Dockerfile

Because Krewire monoliths and services have zero runtime CGo or Node.js dependencies, production container images can be based on lightweight Alpine or scratch images:

# Stage 1: Build binary
FROM golang:1.27-alpine AS builder

WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download

COPY . .
RUN CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -ldflags="-w -s" -o /app/server ./cmd/server/main.go

# Stage 2: Minimal runtime image
FROM alpine:3.20

RUN apk --no-cache add ca-certificates tzdata
WORKDIR /app

COPY --from=builder /app/server /app/server

EXPOSE 8080
USER nobody:nobody

ENTRYPOINT ["/app/server"]

The resulting container image is typically under 25MB with zero operating system vulnerabilities.


2. Nginx Reverse Proxy Configuration

When hosting multiple applications behind Nginx on a Linux VPS:

server {
    listen 80;
    server_name example.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl http2;
    server_name example.com;

    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;

    location / {
        proxy_pass http://127.0.0.1:8080;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

3. Systemd Service Unit

To run a Krewire binary directly as a managed system daemon:

# /etc/systemd/system/krewire-app.service
[Unit]
Description=Krewire Production Web Application
After=network.target

[Service]
Type=simple
User=www-data
Group=www-data
WorkingDirectory=/var/www/app
ExecStart=/var/www/app/bin/server
Restart=always
RestartSec=5
Environment=KIW_ENV=production
Environment=KIW_PORT=8080

# Hardening
ProtectSystem=full
NoNewPrivileges=true

[Install]
WantedBy=multi-user.target

Enable and start the service:

sudo systemctl daemon-reload
sudo systemctl enable --now krewire-app