{"id":38784,"date":"2026-07-08T10:30:25","date_gmt":"2026-07-08T13:30:25","guid":{"rendered":"https:\/\/www.locaweb.com.br\/ajuda\/?post_type=ht_kb&#038;p=38784"},"modified":"2026-07-08T10:30:25","modified_gmt":"2026-07-08T13:30:25","slug":"deploy-de-alta-performance-com-laravel-octane-no-locaweb-cloud","status":"publish","type":"ht_kb","link":"https:\/\/www.locaweb.com.br\/ajuda\/wiki\/deploy-de-alta-performance-com-laravel-octane-no-locaweb-cloud\/","title":{"rendered":"Deploy de Alta Performance com Laravel Octane no Locaweb Cloud"},"content":{"rendered":"    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Informa\u00e7\u00e3o!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Este guia orienta sobre a orquestra\u00e7\u00e3o de inst\u00e2ncias virtuais no Locaweb Cloud. Voc\u00ea aprender\u00e1 a configurar um Balanceador de Carga nativo e utilizar o Nginx como proxy reverso, potencializando o desempenho de projetos Laravel Octane com o servidor Swoole.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Diferente do modelo tradicional do PHP, que reinicializa o framework a cada chamada e limita a escalabilidade, o Laravel Octane mant\u00e9m a aplica\u00e7\u00e3o carregada na mem\u00f3ria RAM via Swoole ou RoadRunner. Essa mudan\u00e7a arquitetural elimina gargalos computacionais, reduz o <\/span><i><span style=\"font-weight: 400;\">overhead<\/span><\/i><span style=\"font-weight: 400;\"> de resposta e amplia significativamente a capacidade de processamento de tr\u00e1fego do sistema.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2><b>1. Pr\u00e9-requisitos<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Para garantir a efici\u00eancia t\u00e9cnica e colocar seu projeto no ar rapidamente, valide os seguintes requisitos antes de iniciar as configura\u00e7\u00f5es:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conta ativa no <\/span><a href=\"https:\/\/painel-cloud.locaweb.com.br\"><span style=\"font-weight: 400;\">painel<\/span><\/a><span style=\"font-weight: 400;\"> do Locaweb Cloud (Apache CloudStack).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Duas M\u00e1quinas Virtuais (VMs) em execu\u00e7\u00e3o com Ubuntu 22.04 LTS na mesma rede VPC.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Uma terceira VM (ou Tier dedicada) isolada para o banco de dados.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Chave privada SSH (<\/span><span style=\"font-weight: 400;\">.key<\/span><span style=\"font-weight: 400;\"> ou <\/span><span style=\"font-weight: 400;\">.pem<\/span><span style=\"font-weight: 400;\">) configurada localmente com permiss\u00e3o restrita (<\/span><span style=\"font-weight: 400;\">chmod 400<\/span><span style=\"font-weight: 400;\">).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Um <\/span><b>dom\u00ednio<\/b><span style=\"font-weight: 400;\"> de site registrado e pronto para ser apontado para o IP p\u00fablico do projeto.<\/span><\/li>\n<\/ul>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Certifique-se de que o arquivo <\/span><span style=\"font-weight: 400;\">composer.json<\/span><span style=\"font-weight: 400;\"> da sua aplica\u00e7\u00e3o Laravel j\u00e1 declare o pacote <\/span><span style=\"font-weight: 400;\">laravel\/octane<\/span><span style=\"font-weight: 400;\"> antes de iniciar a esteira de build.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<p><span style=\"font-weight: 400;\">Est\u00e1 com d\u00favidas sobre como come\u00e7ar no Locaweb Cloud? Acesse nosso <\/span><a href=\"https:\/\/www.locaweb.com.br\/ajuda\/wiki\/por-onde-comecar-no-locaweb-cloud\/\"><span style=\"font-weight: 400;\">tutorial de apoio<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<h2><b>2. Configura\u00e7\u00e3o de infraestrutura (painel)<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Prepare toda a infraestrutura de rede na borda do painel antes de tocar no terminal de comandos. O tr\u00e1fego s\u00f3 ser\u00e1 distribu\u00eddo corretamente se as regras de balanceamento e seguran\u00e7a estiverem ativas.<\/span><\/p>\n<h3><b>Passo 1: Aloca\u00e7\u00e3o de IP P\u00fablico<\/b><\/h3>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acesse o painel do Locaweb Cloud, navegue at\u00e9 <\/span><b>Rede<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>VPC<\/b><span style=\"font-weight: 400;\"> e clique no nome da sua rede.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acesse a aba <\/span><b>Endere\u00e7os IP P\u00fablicos<\/b><span style=\"font-weight: 400;\"> e clique em <\/span><b>Obter um novo IP<\/b><span style=\"font-weight: 400;\">. Esse endere\u00e7o ser\u00e1 o ponto central de acesso da sua aplica\u00e7\u00e3o.<\/span><\/li>\n<\/ol>\n<h3><b>Passo 2: Configura\u00e7\u00e3o do Balanceamento de Carga<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">[Aviso!]<\/span><span style=\"font-weight: 400;\"> Um endere\u00e7o IP configurado com Balanceamento de Carga n\u00e3o pode utilizar NAT Est\u00e1tico simultaneamente. Certifique-se de manter essa op\u00e7\u00e3o desmarcada.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Acesse a aba <\/span><b>Balanceamento de Carga<\/b><span style=\"font-weight: 400;\"> do IP alocado e configure as regras de entrada:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Regra Principal (HTTPS):<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Nome:<\/b> <span style=\"font-weight: 400;\">LB-Octane-HTTPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Porta P\u00fablica \/ Privada:<\/b> <span style=\"font-weight: 400;\">443<\/span><span style=\"font-weight: 400;\"> (a termina\u00e7\u00e3o SSL ser\u00e1 feita pelo Nginx de cada VM).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Algoritmo:<\/b><span style=\"font-weight: 400;\"> Selecione <\/span><i><span style=\"font-weight: 400;\">Round-Robin<\/span><\/i><span style=\"font-weight: 400;\"> ou <\/span><i><span style=\"font-weight: 400;\">Least Connections<\/span><\/i><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Protocolo:<\/b><span style=\"font-weight: 400;\"> TCP. Vincule as duas inst\u00e2ncias de aplica\u00e7\u00e3o a esta regra.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Regra Auxiliar (HTTP):<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Nome:<\/b> <span style=\"font-weight: 400;\">LB-Octane-HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Porta P\u00fablica \/ Privada:<\/b> <span style=\"font-weight: 400;\">80<\/span><span style=\"font-weight: 400;\"> (necess\u00e1rio para a valida\u00e7\u00e3o do Certbot e redirecionamento de tr\u00e1fego).<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h3><b>Passo 3: Port Forwarding para acesso SSH (Administra\u00e7\u00e3o)<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Para administrar suas inst\u00e2ncias de forma segura sem expor a porta padr\u00e3o diretamente \u00e0 internet, acesse a aba <\/span><b>Encaminhamento de Portas<\/b><span style=\"font-weight: 400;\"> (<\/span><i><span style=\"font-weight: 400;\">Port Forwarding<\/span><\/i><span style=\"font-weight: 400;\">) e mapeie portas p\u00fablicas distintas para a porta privada 22 de cada m\u00e1quina:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>VM de Destino<\/b><\/td>\n<td><b>Protocolo<\/b><\/td>\n<td><b>Porta P\u00fablica<\/b><\/td>\n<td><b>Porta Privada<\/b><\/td>\n<td><b>Finalidade<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Inst\u00e2ncia de Aplica\u00e7\u00e3o 1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2201<\/span><\/td>\n<td><span style=\"font-weight: 400;\">22<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Acesso SSH \u00e0 VM 1<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Inst\u00e2ncia de Aplica\u00e7\u00e3o 2<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2202<\/span><\/td>\n<td><span style=\"font-weight: 400;\">22<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Acesso SSH \u00e0 VM 2<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h3><b>Passo 4: Libera\u00e7\u00e3o de Portas no Firewall<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Acesse a aba <\/span><b>Firewall<\/b><span style=\"font-weight: 400;\"> do IP p\u00fablico e autorize a entrada de tr\u00e1fego aplicando as seguintes regras:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Origem (CIDR)<\/b><\/td>\n<td><b>Porta<\/b><\/td>\n<td><b>Protocolo<\/b><\/td>\n<td><b>Finalidade<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">0.0.0.0\/0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">80<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Tr\u00e1fego HTTP p\u00fablico<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">0.0.0.0\/0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">443<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Tr\u00e1fego HTTPS p\u00fablico<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">&lt;SEU_IP_DE_ADMIN&gt;\/32<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2201<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SSH administrativo restrito da VM 1<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">&lt;SEU_IP_DE_ADMIN&gt;\/32<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2202<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SSH administrativo restrito da VM 2<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Substitua <\/span><span style=\"font-weight: 400;\"> pelo IP p\u00fablico fixo da sua rede de administra\u00e7\u00e3o corporativa. Restringir o CIDR reduz drasticamente a superf\u00edcie de ataques por for\u00e7a bruta na porta 22.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2><b>3. Configura\u00e7\u00e3o de sistema (Terminal)<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Realize os passos de prepara\u00e7\u00e3o do ambiente operacional em todas as inst\u00e2ncias de aplica\u00e7\u00e3o vinculadas ao balanceador. Acesse a primeira VM utilizando a porta mapeada no passo anterior:<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">Bash<\/span>\r\n\r\n<span style=\"font-weight: 400;\">ssh -i \/caminho\/sua-chave.key -p 2201 ubuntu@&lt;SEU_IP_PUBLICO&gt;<\/span><\/pre>\n<p>&nbsp;<\/p>\n<h3><b>3.1. Instala\u00e7\u00e3o de Depend\u00eancias e PHP<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Sincronize os \u00edndices de pacotes locais e instale o interpretador do PHP 8.2 e o servidor web Nginx:<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">Bash<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Atualiza os \u00edndices do sistema operacional e aplica corre\u00e7\u00f5es<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt update &amp;&amp; sudo apt upgrade -y<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Instala o Nginx, PHP CLI, runtime do Swoole e depend\u00eancias do Laravel<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt install -y nginx php8.2-cli php8.2-fpm php8.2-swoole php8.2-mysql php8.2-mbstring php8.2-xml php8.2-curl php8.2-bcmath unzip git<\/span>\r\n\r\n\r\n<\/pre>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">A extens\u00e3o <\/span><span style=\"font-weight: 400;\">php8.2-swoole<\/span><span style=\"font-weight: 400;\"> fornece as bibliotecas de alta performance escritas em C++, necess\u00e1rias para que o PHP trabalhe com I\/O ass\u00edncrono e corrotinas, que servem de alicerce para o Laravel Octane.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<p><span style=\"font-weight: 400;\">Baixe o utilit\u00e1rio oficial do Composer e mova o bin\u00e1rio para o PATH de execu\u00e7\u00e3o do sistema:<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">Bash<\/span>\r\n\r\n<span style=\"font-weight: 400;\">curl -sS https:\/\/getcomposer.org\/installer | php<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo mv composer.phar \/usr\/local\/bin\/composer<\/span><\/pre>\n<h2><b>4. Configura\u00e7\u00e3o do banco de dados: PostgreSQL \/ MySQL<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Para garantir o isolamento e eliminar o caos de opera\u00e7\u00f5es fragmentadas, o <\/span><b>banco de dados<\/b><span style=\"font-weight: 400;\"> deve rodar em uma VM dedicada dentro da sub-rede privada da VPC (ex.: IP <\/span><span style=\"font-weight: 400;\">10.1.1.10<\/span><span style=\"font-weight: 400;\">), aceitando conex\u00f5es apenas da sub-rede das aplica\u00e7\u00f5es (<\/span><span style=\"font-weight: 400;\">10.1.2.0\/24<\/span><span style=\"font-weight: 400;\">).<\/span><\/p>\n<h3><b>Passo 1: Instala\u00e7\u00e3o e Hardening do MySQL<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Acesse o terminal do seu servidor dedicado de banco de dados e instale o servi\u00e7o:<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">Bash<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt update &amp;&amp; sudo apt install -y mysql-server<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl enable --now mysql<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Dispara o assistente interativo de seguran\u00e7a e remo\u00e7\u00e3o de acessos an\u00f4nimos<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo mysql_secure_installation<\/span><\/pre>\n<p>&nbsp;<\/p>\n<h3><b>Passo 2: Configurar acesso na rede privada<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Abra o arquivo de parametriza\u00e7\u00e3o do MySQL para ajustar o endere\u00e7o de escuta, impedindo que a porta responda \u00e0 internet aberta:<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">Bash<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo nano \/etc\/mysql\/mysql.conf.d\/mysqld.cnf<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Configure a linha de monitoramento apontando exclusivamente para o IP privado da pr\u00f3pria inst\u00e2ncia de banco:<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">Ini, TOML<\/span>\r\n\r\n<span style=\"font-weight: 400;\">bind-address = 10.1.1.10<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">Bash<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl restart mysql<\/span><\/pre>\n<p>&nbsp;<\/p>\n<h3><b>Passo 3: Criar credenciais de produ\u00e7\u00e3o<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Abra o console do banco e crie o usu\u00e1rio restringindo os privil\u00e9gios de acesso ao barramento da sub-rede de aplica\u00e7\u00e3o:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">sudo mysql<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">SQL<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">-- Comandos executados no terminal administrativo do MySQL<\/span>\r\n\r\n<span style=\"font-weight: 400;\">CREATE DATABASE octane_app CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">-- Cria o usu\u00e1rio amarrado estritamente ao CIDR privado das inst\u00e2ncias web<\/span>\r\n\r\n<span style=\"font-weight: 400;\">CREATE USER 'octane_user'@'10.1.2.%' IDENTIFIED BY 'TROQUE_POR_UMA_SENHA_FORTE';<\/span>\r\n\r\n<span style=\"font-weight: 400;\">GRANT ALL PRIVILEGES ON octane_app.* TO 'octane_user'@'10.1.2.%';<\/span>\r\n\r\n<span style=\"font-weight: 400;\">FLUSH PRIVILEGES;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">EXIT;<\/span><\/pre>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">No painel do Locaweb Cloud, em Listas de Controle de Acesso (ACL) da VPC, certifique-se de validar a regra permitindo tr\u00e1fego TCP na porta 3306 apenas com origem no bloco <\/span><span style=\"font-weight: 400;\">10.1.2.0\/24<\/span><span style=\"font-weight: 400;\"> e negando qualquer outra requisi\u00e7\u00e3o.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2><b>5. Deploy da aplica\u00e7\u00e3o<\/b><\/h2>\n<h3><b>M\u00e9todo 1 (Recomendado): Docker + GitHub Actions<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A conteineriza\u00e7\u00e3o garante um ambiente reprodut\u00edvel e acelera o seu <\/span><i><span style=\"font-weight: 400;\">time-to-market<\/span><\/i><span style=\"font-weight: 400;\">. Instale o Docker nas inst\u00e2ncias web atrav\u00e9s do reposit\u00f3rio oficial assinado (nunca utilize scripts gen\u00e9ricos em produ\u00e7\u00e3o):<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">sudo apt-get update &amp;&amp; sudo apt-get install -y ca-certificates curl gnupg<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo install -m 0755 -d \/etc\/apt\/keyrings<\/span>\r\n\r\n<span style=\"font-weight: 400;\">curl -fsSL https:\/\/download.docker.com\/linux\/ubuntu\/gpg | sudo gpg --dearmor -o \/etc\/apt\/keyrings\/docker.gpg<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo chmod a+r \/etc\/apt\/keyrings\/docker.gpg<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">echo \"deb [arch=$(dpkg --print-architecture) signed-by=\/etc\/apt\/keyrings\/docker.gpg] https:\/\/download.docker.com\/linux\/ubuntu $(. \/etc\/os-release &amp;&amp; echo \"$VERSION_CODENAME\") stable\" | sudo tee \/etc\/apt\/sources.list.d\/docker.list &gt; \/dev\/null<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">sudo apt-get update &amp;&amp; sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl enable --now docker &amp;&amp; sudo usermod -aG docker $USER<\/span>\r\n\r\n\r\n<\/pre>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Lembre-se de fechar o terminal e reconectar via SSH para aplicar o seu grupo de usu\u00e1rio Docker sem o uso de <\/span><span style=\"font-weight: 400;\">sudo<\/span><span style=\"font-weight: 400;\">.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<p><span style=\"font-weight: 400;\">Salve o <\/span><span style=\"font-weight: 400;\">Dockerfile<\/span><span style=\"font-weight: 400;\"> na raiz do seu projeto local configurado para rodar com Swoole na porta interna 8000:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Dockerfile<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">FROM php:8.2-cli<\/span>\r\n\r\n<span style=\"font-weight: 400;\">RUN apt-get update &amp;&amp; apt-get install -y libzip-dev unzip git \\<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0&amp;&amp; docker-php-ext-install pdo_mysql bcmath \\<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0&amp;&amp; pecl install swoole &amp;&amp; docker-php-ext-enable swoole<\/span>\r\n\r\n<span style=\"font-weight: 400;\">COPY --from=composer:2 \/usr\/bin\/composer \/usr\/bin\/composer<\/span>\r\n\r\n<span style=\"font-weight: 400;\">WORKDIR \/app<\/span>\r\n\r\n<span style=\"font-weight: 400;\">COPY . \/app<\/span>\r\n\r\n<span style=\"font-weight: 400;\">RUN composer install --no-dev --optimize-autoloader<\/span>\r\n\r\n<span style=\"font-weight: 400;\">EXPOSE 8000<\/span>\r\n\r\n<span style=\"font-weight: 400;\">CMD [\"php\", \"artisan\", \"octane:start\", \"--server=swoole\", \"--host=0.0.0.0\", \"--port=8000\", \"--workers=4\", \"--max-requests=1000\"]<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Ative a esteira automatizada salvando o workflow <\/span><span style=\"font-weight: 400;\">.github\/workflows\/deploy.yml<\/span><span style=\"font-weight: 400;\"> no seu GitHub, alimentando os Secrets (<\/span><span style=\"font-weight: 400;\">SSH_HOST<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">SSH_PORT<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">SSH_USER<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">SSH_KEY<\/span><span style=\"font-weight: 400;\">) para realizar o deploy em formato autosservi\u00e7o (PLG) a cada push na branch main.<\/span><\/p>\n<h3><b>M\u00e9todo 2: Deploy manual<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Caso opte por rodar direto na m\u00e1quina, clone o projeto no diret\u00f3rio <\/span><span style=\"font-weight: 400;\">\/var\/www\/html\/aplicacao<\/span><span style=\"font-weight: 400;\">, rode o comando <\/span><span style=\"font-weight: 400;\">composer install &#8211;no-dev &#8211;optimize-autoloader<\/span><span style=\"font-weight: 400;\"> e configure a inicializa\u00e7\u00e3o cont\u00ednua criando um servi\u00e7o do systemd:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">sudo nano \/etc\/systemd\/system\/octane.service<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Ini, TOML<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">[Unit]<\/span>\r\n\r\n<span style=\"font-weight: 400;\">Description=Laravel Octane Server<\/span>\r\n\r\n<span style=\"font-weight: 400;\">After=network.target<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">[Service]<\/span>\r\n\r\n<span style=\"font-weight: 400;\">Type=simple<\/span>\r\n\r\n<span style=\"font-weight: 400;\">User=www-data<\/span>\r\n\r\n<span style=\"font-weight: 400;\">Group=www-data<\/span>\r\n\r\n<span style=\"font-weight: 400;\">WorkingDirectory=\/var\/www\/html\/aplicacao<\/span>\r\n\r\n<span style=\"font-weight: 400;\">ExecStart=\/usr\/bin\/php artisan octane:start --server=swoole --host=127.0.0.1 --port=8000 --workers=4 --task-workers=4 --max-requests=1000<\/span>\r\n\r\n<span style=\"font-weight: 400;\">Restart=always<\/span>\r\n\r\n<span style=\"font-weight: 400;\">RestartSec=5<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">[Install]<\/span>\r\n\r\n<span style=\"font-weight: 400;\">WantedBy=multi-user.target<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">sudo systemctl daemon-reload &amp;&amp; sudo systemctl enable --now octane<\/span><\/pre>\n<p>&nbsp;<\/p>\n<h2><b>6. Configura\u00e7\u00e3o do Nginx (Proxy Reverso) e HTTPS<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">O Nginx receber\u00e1 as conex\u00f5es repassadas pela borda da infraestrutura e encaminhar\u00e1 o tr\u00e1fego interno para o processo Octane rodando na mem\u00f3ria.<\/span><\/p>\n<h3><b>Passo 1: Configurar Proxy Reverso<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Crie o arquivo de configura\u00e7\u00e3o do site no diret\u00f3rio do Nginx:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">sudo nano \/etc\/nginx\/sites-available\/octane.conf<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Nginx<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">server {<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0listen 80;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0server_name seu-dominio.com.br www.seu-dominio.com.br;<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0location \/ {<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_pass http:\/\/127.0.0.1:8000;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header Host $http_host;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header X-Real-IP $remote_addr;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header X-Forwarded-Proto $scheme;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_http_version 1.1;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header Upgrade $http_upgrade;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header Connection \"upgrade\";<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0}<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0# Cache e entrega direta de est\u00e1ticos via Nginx para poupar a RAM da aplica\u00e7\u00e3o<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0location ~* \\.(jpg|jpeg|gif|png|css|js|ico|webp|svg|woff2)$ {<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0root \/var\/www\/html\/aplicacao\/public;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0expires max;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0access_log off;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0}<\/span>\r\n\r\n<span style=\"font-weight: 400;\">}<\/span>\r\n\r\n\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">sudo ln -s \/etc\/nginx\/sites-available\/octane.conf \/etc\/nginx\/sites-enabled\/<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo nginx -t &amp;&amp; sudo systemctl reload nginx<\/span><\/pre>\n<h3><b>Passo 2: Termina\u00e7\u00e3o SSL com Let&#8217;s Encrypt<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Como o balanceador de carga encaminha as requisi\u00e7\u00f5es da porta 443 TCP diretamente para as inst\u00e2ncias, emita o <\/span><b>certificado SSL<\/b><span style=\"font-weight: 400;\"> na ponta de cada m\u00e1quina:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">sudo apt install -y certbot python3-certbot-nginx<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo certbot --nginx -d seu-dominio.com.br -d www.seu-dominio.com.br<\/span><\/pre>\n<p>&nbsp;<\/p>\n<h2><b>7. Valida\u00e7\u00e3o<\/b><\/h2>\n<h3><b>Verifica\u00e7\u00e3o de Residente em Mem\u00f3ria<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Valide localmente nas VMs se o container do Docker ou o servi\u00e7o do systemd est\u00e3o ativos e escutando a porta interna correta:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Para deploys manuais:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl status octane<\/span>\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Para deploys via Docker:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">docker ps<\/span>\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Testa a resposta local da aplica\u00e7\u00e3o (Deve retornar HTTP 200 OK)<\/span>\r\n\r\n<span style=\"font-weight: 400;\">curl -I http:\/\/127.0.0.1:8000<\/span><\/pre>\n<h3><b>Teste externo e isolamento<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A partir do prompt do seu computador de desenvolvimento local, envie requisi\u00e7\u00f5es externas para testar a topologia e certificar-se do isolamento completo do banco:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Valida a entrega final criptografada via Load Balancer e Nginx<\/span>\r\n\r\n<span style=\"font-weight: 400;\">curl -I https:\/\/seu-dominio.com.br<\/span>\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Deve falhar por timeout, atestando o isolamento da porta 3306 na internet<\/span>\r\n\r\n<span style=\"font-weight: 400;\">nc -zv &lt;SEU_IP_PUBLICO&gt; 3306<\/span><\/pre>\n<h2><b>8. Solu\u00e7\u00e3o de problemas (Troubleshooting)<\/b><\/h2>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Erro 502 Bad Gateway ao carregar o dom\u00ednio:<\/b><span style=\"font-weight: 400;\"> O Nginx est\u00e1 ativo, mas o motor do Octane na porta 8000 caiu ou falhou no boot. Analise as falhas de c\u00f3digo inspecionando o log de inicializa\u00e7\u00e3o com <\/span><span style=\"font-weight: 400;\">sudo journalctl -u octane -n 50 &#8211;no-pager<\/span><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Conex\u00e3o administrativa SSH sofrendo quedas por timeout:<\/b><span style=\"font-weight: 400;\"> Certifique-se de realizar o acesso informando a porta p\u00fablica correta configurada no seu <\/span><i><span style=\"font-weight: 400;\">Port Forwarding<\/span><\/i><span style=\"font-weight: 400;\"> (<\/span><span style=\"font-weight: 400;\">-p 2201<\/span><span style=\"font-weight: 400;\"> ou <\/span><span style=\"font-weight: 400;\">-p 2202<\/span><span style=\"font-weight: 400;\">) e valide se o seu IP atual n\u00e3o mudou na regra de Firewall.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Mensagens de erro SQLSTATE[HY000] [2002] Connection refused:<\/b><span style=\"font-weight: 400;\"> Indica que as inst\u00e2ncias web n\u00e3o alcan\u00e7am a base de dados. Revise se o <\/span><span style=\"font-weight: 400;\">bind-address<\/span><span style=\"font-weight: 400;\"> do arquivo <\/span><span style=\"font-weight: 400;\">mysqld.cnf<\/span><span style=\"font-weight: 400;\"> na VM de banco est\u00e1 salvo com o IP privado correto e confira as regras de ACL na VPC.<\/span><\/li>\n<\/ul>\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Pronto!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tSua arquitetura Laravel Octane de alta performance foi implementada com sucesso no Locaweb Cloud. Sua opera\u00e7\u00e3o est\u00e1 centralizada, balanceada e pronta para escalar na nuvem com m\u00e1xima velocidade.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Conhe\u00e7a!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Seus servidores web rodam em mem\u00f3ria de forma ultra veloz, mas a sua aplica\u00e7\u00e3o precisa interagir com os clientes de forma automatizada. Conhe\u00e7a as vantagens de integrar o <\/span><a href=\"https:\/\/www.locaweb.com.br\/smtp-locaweb\/\"><b>SMTP Locaweb<\/b><\/a><span style=\"font-weight: 400;\">, nossa infraestrutura nacional focada na entrega \u00e1gil de notifica\u00e7\u00f5es do sistema, e garanta o envio de emails transacionais sem travar a performance da sua API!<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n","protected":false},"excerpt":{"rendered":"<p>1. Pr\u00e9-requisitos Para garantir a efici\u00eancia t\u00e9cnica e colocar seu projeto no ar rapidamente, valide os seguintes requisitos antes de iniciar as configura\u00e7\u00f5es: Conta ativa no painel do Locaweb Cloud (Apache CloudStack). Duas M\u00e1quinas Virtuais (VMs) em execu\u00e7\u00e3o com Ubuntu 22.04 LTS na mesma rede VPC. Uma terceira VM (ou&#8230;<\/p>\n","protected":false},"author":29,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"footnotes":""},"ht-kb-category":[666],"ht-kb-tag":[],"class_list":["post-38784","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-locaweb-cloud"],"_links":{"self":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/38784","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/comments?post=38784"}],"version-history":[{"count":1,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/38784\/revisions"}],"predecessor-version":[{"id":38791,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/38784\/revisions\/38791"}],"wp:attachment":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/media?parent=38784"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb-category?post=38784"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb-tag?post=38784"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}