{"id":38785,"date":"2026-07-08T10:25:07","date_gmt":"2026-07-08T13:25:07","guid":{"rendered":"https:\/\/www.locaweb.com.br\/ajuda\/?post_type=ht_kb&#038;p=38785"},"modified":"2026-07-08T11:42:32","modified_gmt":"2026-07-08T14:42:32","slug":"pipeline-de-ci-cd-para-java-spring-boot-no-locaweb-cloud-2","status":"publish","type":"ht_kb","link":"https:\/\/www.locaweb.com.br\/ajuda\/wiki\/pipeline-de-ci-cd-para-java-spring-boot-no-locaweb-cloud-2\/","title":{"rendered":"Pipeline de CI\/CD para Java Spring Boot: Deploy com Docker e GitHub Actions no Locaweb Cloud"},"content":{"rendered":"<h1><b>\u00a0<\/b><\/h1>\n<p><span style=\"font-weight: 400;\">    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Informa\u00e7\u00e3o!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tNeste tutorial, voc\u00ea aprender\u00e1 a configurar uma M\u00e1quina Virtual (VM) no Locaweb Cloud como um Docker Host, a provisionar um banco de dados PostgreSQL isolado e a estruturar um workflow no GitHub Actions para automatizar o build e o deploy seguro de uma aplica\u00e7\u00e3o Java Spring Boot.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A orquestra\u00e7\u00e3o de deploys para aplica\u00e7\u00f5es corporativas exige consist\u00eancia, rastreabilidade e elimina\u00e7\u00e3o de falhas humanas. O Java Spring Boot, padr\u00e3o indiscut\u00edvel no desenvolvimento de software corporativo, beneficia-se profundamente de processos de Integra\u00e7\u00e3o Cont\u00ednua e Entrega Cont\u00ednua (CI\/CD) aliados \u00e0 conteineriza\u00e7\u00e3o.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Pr\u00e9-requisitos<\/b><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Para acompanhar a implementa\u00e7\u00e3o arquitetural deste guia, certifique-se de cumprir os seguintes requisitos:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Conta ativa no Locaweb Cloud:<\/b><span style=\"font-weight: 400;\"> com acesso liberado ao<\/span><a href=\"https:\/\/painel-cloud.locaweb.com.br\"> <span style=\"font-weight: 400;\">painel de controle<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Chave de autentica\u00e7\u00e3o SSH:<\/b><span style=\"font-weight: 400;\"> uma chave privada SSH (arquivo .key ou .pem) gerada e com a respectiva chave p\u00fablica cadastrada no painel do Locaweb Cloud. No seu terminal local, ajuste a permiss\u00e3o da chave privada com chmod 400 sua-chave.key.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Conhecimento b\u00e1sico de terminal:<\/b><span style=\"font-weight: 400;\"> familiaridade com navega\u00e7\u00e3o de diret\u00f3rios e uso do gerenciador de pacotes em ambientes Linux.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>(Opcional) Dom\u00ednio pr\u00f3prio:<\/b><span style=\"font-weight: 400;\"> um dom\u00ednio ou subdom\u00ednio apontando para o IP p\u00fablico da VM de aplica\u00e7\u00e3o, necess\u00e1rio para emitir um certificado HTTPS gratuito com Let&#8217;s Encrypt.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Informa\u00e7\u00e3o!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tEst\u00e1 com d\u00favidas sobre como come\u00e7ar no Locaweb Cloud? Acesse nosso<\/span><a href=\"https:\/\/www.locaweb.com.br\/ajuda\/wiki\/por-onde-comecar-no-locaweb-cloud\/\"> <span style=\"font-weight: 400;\">tutorial de apoio<\/span><\/a><span style=\"font-weight: 400;\">.     \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t<\/span><\/p>\n<h2><b>2.\u00a0 Configura\u00e7\u00e3o de infraestrutura (painel)<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A base de uma aplica\u00e7\u00e3o segura \u00e9 o isolamento de rede. Criaremos uma Virtual Private Cloud (VPC) para abrigar nossos servidores, garantindo que o banco de dados n\u00e3o seja exposto diretamente \u00e0 internet.<\/span><\/p>\n<h3><b>2.1. Cria\u00e7\u00e3o da Rede VPC e Tiers<\/b><\/h3>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Navegue at\u00e9 <\/span><b>Rede<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>VPC<\/b><span style=\"font-weight: 400;\"> no painel do Locaweb Cloud e clique em <\/span><b>Adicionar VPC<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defina o bloco CIDR principal (exemplo: 10.0.0.0\/16) e selecione a Oferta de VPC adequada ao seu projeto.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dentro da nova VPC, acesse a aba <\/span><b>Redes<\/b><span style=\"font-weight: 400;\"> e clique em <\/span><b>Adicionar novo tier<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Crie um tier chamado Tier-Aplicacao (exemplo de CIDR: 10.0.1.0\/24) para o servidor da aplica\u00e7\u00e3o Spring Boot e outro chamado Tier-BancoDados (exemplo de CIDR: 10.0.2.0\/24) para o PostgreSQL.<\/span><\/li>\n<\/ol>\n<h3><b>2.2. Provisionamento das m\u00e1quinas virtuais (VMs)<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Ser\u00e3o necess\u00e1rias duas inst\u00e2ncias: uma para o banco de dados e outra para a aplica\u00e7\u00e3o.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Navegue at\u00e9 <\/span><b>Computa\u00e7\u00e3o<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>VMs<\/b><span style=\"font-weight: 400;\"> e clique em <\/span><b>Adicionar VM<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>VM de Banco de Dados:<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Template:<\/b><span style=\"font-weight: 400;\"> selecione Ubuntu 22.04 LTS.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Oferta:<\/b><span style=\"font-weight: 400;\"> escolha um plano com recursos de CPU e RAM otimizados para banco de dados (exemplo: 4 vCPUs, 8 GB de RAM).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Rede:<\/b><span style=\"font-weight: 400;\"> conecte ao Tier-BancoDados.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Chave SSH:<\/b><span style=\"font-weight: 400;\"> selecione a sua chave p\u00fablica previamente cadastrada.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Disco secund\u00e1rio:<\/b><span style=\"font-weight: 400;\"> durante a cria\u00e7\u00e3o, adicione um Datadisk (exemplo: 50 GB) que ser\u00e1 usado para persistir os dados do PostgreSQL.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>VM da Aplica\u00e7\u00e3o:<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Repita o processo, escolhendo um plano adequado para a carga do seu projeto (exemplo: 2 vCPUs, 4 GB de RAM).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Template:<\/b><span style=\"font-weight: 400;\"> Ubuntu 22.04 LTS.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Rede:<\/b><span style=\"font-weight: 400;\"> conecte ao Tier-Aplicacao.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Chave SSH:<\/b><span style=\"font-weight: 400;\"> selecione a mesma chave p\u00fablica cadastrada.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h3><b>2.3. IPs P\u00fablicos, encaminhamento de porta e regras de Firewall<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A VM de banco de dados permanecer\u00e1 isolada, comunicando-se apenas com a VM da aplica\u00e7\u00e3o via IP privado. Para a VM da aplica\u00e7\u00e3o receber tr\u00e1fego web:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acesse <\/span><b>Rede<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>VPC<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>[Sua VPC]<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>IPs P\u00fablicos<\/b><span style=\"font-weight: 400;\"> e clique em <\/span><b>Obter um novo IP<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Selecione o IP adquirido e v\u00e1 para a aba <\/span><b>Encaminhamento de porta<\/b><span style=\"font-weight: 400;\">. Crie regras direcionando as portas p\u00fablicas para a VM da aplica\u00e7\u00e3o conforme a tabela abaixo:<\/span><\/li>\n<\/ol>\n<table>\n<tbody>\n<tr>\n<td><b>Porta p\u00fablica<\/b><\/td>\n<td><b>Porta privada<\/b><\/td>\n<td><b>Protocolo<\/b><\/td>\n<td><b>Destino<\/b><\/td>\n<td><b>Finalidade<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">22<\/span><\/td>\n<td><span style=\"font-weight: 400;\">22<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">VM-SpringBoot<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Acesso SSH<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">8080<\/span><\/td>\n<td><span style=\"font-weight: 400;\">8080<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">VM-SpringBoot<\/span><\/td>\n<td><span style=\"font-weight: 400;\">API Spring Boot<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">80<\/span><\/td>\n<td><span style=\"font-weight: 400;\">80<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">VM-SpringBoot<\/span><\/td>\n<td><span style=\"font-weight: 400;\">HTTP (Let&#8217;s Encrypt)<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">443<\/span><\/td>\n<td><span style=\"font-weight: 400;\">443<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">VM-SpringBoot<\/span><\/td>\n<td><span style=\"font-weight: 400;\">HTTPS<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Na aba <\/span><b>Firewall<\/b><span style=\"font-weight: 400;\">, adicione regras de entrada liberando o tr\u00e1fego de entrada (<\/span><i><span style=\"font-weight: 400;\">inbound<\/span><\/i><span style=\"font-weight: 400;\">) para as portas 22, 80, 443 e 8080. Para a porta 22 (SSH), recomendamos fortemente restringir o CIDR de origem ao IP da sua rede de administra\u00e7\u00e3o (exemplo: &lt;SEU_IP_DE_ESCRITORIO&gt;\/32), em vez de liberar 0.0.0.0\/0.<\/span><\/li>\n<\/ol>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Aviso!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">A porta do banco de dados (PostgreSQL, 5432) NUNCA deve constar no encaminhamento de porta nem em regra de Firewall voltada para a internet. O acesso ao banco ocorre exclusivamente pela rede privada da VPC, entre o Tier-Aplicacao e o Tier-BancoDados.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h3><b>2.4. ACL de rede entre os Tiers<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Para que a VM da aplica\u00e7\u00e3o alcance o banco de dados pela rede privada, configure a ACL da VPC permitindo o tr\u00e1fego da sub-rede de aplica\u00e7\u00e3o at\u00e9 a porta do PostgreSQL:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Origem (CIDR)<\/b><\/td>\n<td><b>Destino<\/b><\/td>\n<td><b>Protocolo<\/b><\/td>\n<td><b>Porta<\/b><\/td>\n<td><b>A\u00e7\u00e3o<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">10.0.1.0\/24 (Tier-Aplicacao)<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Tier-BancoDados<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">5432<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Permitir<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">0.0.0.0\/0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Tier-BancoDados<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">5432<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Negar<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<h2><b>3. Prepara\u00e7\u00e3o do disco de dados na VM de banco de dados<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Para que os dados do PostgreSQL sobrevivam a reinicializa\u00e7\u00f5es e recria\u00e7\u00f5es da inst\u00e2ncia, vamos formatar e montar o disco secund\u00e1rio de forma persistente. Acesse a VM de banco de dados via SSH (fazendo um salto a partir da VM de aplica\u00e7\u00e3o, j\u00e1 que o banco n\u00e3o possui IP p\u00fablico) e execute:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Lista os discos dispon\u00edveis para identificar o disco secund\u00e1rio \r\n(geralmente \/dev\/vdb)<\/span>\r\n<span style=\"font-weight: 400;\">lsblk<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Cria o sistema de arquivos ext4 no disco secund\u00e1rio identificado<\/span>\r\n<span style=\"font-weight: 400;\"> sudo mkfs.ext4 \/dev\/vdb<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Cria o ponto de montagem onde os dados do PostgreSQL \r\n<\/span>ser\u00e3o armazenados \r\n\r\n<span style=\"font-weight: 400;\">sudo mkdir -p \/mnt\/dados<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Em vez de referenciar o disco pelo nome do dispositivo, usamos o UUID est\u00e1vel no \/etc\/fstab:<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">Bash<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Exibe o UUID do disco secund\u00e1rio<\/span>\r\n<span style=\"font-weight: 400;\">sudo blkid \/dev\/vdb<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Copie o valor de UUID exibido na sa\u00edda<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Adiciona a montagem permanente usando o UUID (substitua )<\/span>\r\n<span style=\"font-weight: 400;\">echo 'UUID=\u00a0 \/mnt\/dados\u00a0 ext4\u00a0 defaults,nofail,noatime\u00a0 0\u00a0 2' \r\n| sudo tee -a \/etc\/fstab<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Monta todos os pontos definidos no fstab e confirma o resultado<\/span>\r\n<span style=\"font-weight: 400;\">sudo mount -a<\/span>\r\n<span style=\"font-weight: 400;\">df -h \/mnt\/dados<\/span>\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">O par\u00e2metro nofail impede que a VM falhe na inicializa\u00e7\u00e3o caso o disco n\u00e3o esteja dispon\u00edvel, e noatime reduz a escrita de metadados, melhorando o desempenho do banco. O campo final 2 indica a ordem de verifica\u00e7\u00e3o do sistema de arquivos no boot.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<h2><b>4. Configura\u00e7\u00e3o do banco de dados: PostgreSQL<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Como estamos operando em IaaS, o banco de dados \u00e9 configurado dentro da VM designada no Tier-BancoDados. Ainda conectado a essa VM via SSH, instale o PostgreSQL:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Atualiza a lista de pacotes e instala o servidor PostgreSQL e<\/span>\r\n<span style=\"font-weight: 400;\"> utilit\u00e1rios extras<\/span>\r\n<span style=\"font-weight: 400;\"> sudo apt update &amp;&amp; sudo apt install postgresql postgresql-contrib -y<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Habilita o servi\u00e7o para iniciar junto com o sistema e o inicia<\/span>\r\n<span style=\"font-weight: 400;\"> imediatamente<\/span>\r\n<span style=\"font-weight: 400;\">sudo systemctl enable --now postgresql<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Confirme a vers\u00e3o instalada para localizar corretamente os arquivos de configura\u00e7\u00e3o:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Exibe a vers\u00e3o instalada; o n\u00famero comp\u00f5e o caminho dos \r\narquivos de configura\u00e7\u00e3o<\/span>\r\n<span style=\"font-weight: 400;\">psql --version<\/span>\r\n<\/pre>\n<h3><b>4.1. Apontando o PostgreSQL para o banco e rede privada<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Abra o arquivo de configura\u00e7\u00e3o principal para permitir que o PostgreSQL aceite conex\u00f5es na interface da rede privada da Tier:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">sudo nano \/etc\/postgresql\/14\/main\/postgresql.conf<\/span>\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">Altere a linha correspondente para escutar em todas as interfaces:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Snippet de c\u00f3digo<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">listen_addresses = '*'<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Para elevar a seguran\u00e7a, configure restri\u00e7\u00f5es diretamente no banco de dados, definindo quais origens possuem permiss\u00e3o para autentica\u00e7\u00e3o. Edite o arquivo de autentica\u00e7\u00e3o de host (HBA) para aceitar conex\u00f5es apenas da Tier-Publica-Web (10.0.1.0\/24):<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">\r\nsudo nano \/etc\/postgresql\/14\/main\/pg_hba.conf<\/span>\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">Adicione a seguinte linha ao final do arquivo para liberar a autentica\u00e7\u00e3o criptografada somente para a sub-rede da aplica\u00e7\u00e3o:<\/span><\/p>\n<p>Snippet de c\u00f3digo<\/p>\n<pre><span style=\"font-weight: 400;\"># TYPE\u00a0 DATABASE\u00a0 \u00a0 \u00a0 \u00a0 USER\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 ADDRESS \u00a0 \u00a0 \u00a0 \u00a0  \u00a0 \u00a0 METHOD<\/span>\r\n\r\n<span style=\"font-weight: 400;\">host\u00a0 \u00a0 all \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 all \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 10.0.1.0\/24 \u00a0 \u00a0 \u00a0 scram-sha-256<\/span>\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<h3><b>4.2. Cria\u00e7\u00e3o das credenciais da aplica\u00e7\u00e3o<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Acesse o prompt administrativo do PostgreSQL para criar a estrutura do projeto:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Acessa o prompt administrativo do PostgreSQL como o \r\nusu\u00e1rio do sistema \"postgres\"<\/span>\r\n<span style=\"font-weight: 400;\">sudo -u postgres psql<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">No prompt do psql, execute os comandos abaixo:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">SQL<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">-- Cria o banco de dados da aplica\u00e7\u00e3o<\/span>\r\n\r\n<span style=\"font-weight: 400;\">CREATE DATABASE app_db;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\">-- Cria o usu\u00e1rio da aplica\u00e7\u00e3o com senha criptografada\r\n (use uma senha forte real)<\/span>\r\n\r\n<span style=\"font-weight: 400;\">CREATE USER spring_user WITH ENCRYPTED PASSWORD '';<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\">-- Concede todos os privil\u00e9gios sobre o banco ao usu\u00e1rio criado<\/span>\r\n\r\n<span style=\"font-weight: 400;\">GRANT ALL PRIVILEGES ON DATABASE app_db TO spring_user;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\">-- Sai do prompt do psql<\/span><span style=\"font-weight: 400;\">\\q<\/span>\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Aviso!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<\/span><span style=\"font-weight: 400;\">Certifique-se de alterar o placeholder por uma credencial robusta de sua escolha para proteger a integridade dos dados da sua empresa.     \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">Reinicie o servi\u00e7o para aplicar as configura\u00e7\u00f5es e encerre a sess\u00e3o na VM de dados:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Reinicia o PostgreSQL para carregar as novas configura\u00e7\u00f5es<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl restart postgresql<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Encerra a sess\u00e3o na VM-Postgres e volta ao terminal da VM Web<\/span>\r\n\r\n<span style=\"font-weight: 400;\">exit\u00a0<\/span><\/pre>\n<h3><b>4.3. Configura\u00e7\u00e3o do application.properties<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">No arquivo src\/main\/resources\/application.properties do seu projeto Java, estruture a string de conex\u00e3o apontando para o IP privado da camada de dados. Recomenda-se a externaliza\u00e7\u00e3o das credenciais de acesso utilizando vari\u00e1veis de ambiente.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Properties<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Conex\u00e3o isolada via rede interna da VPC (Tier Web -&gt; Tier DB)<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Substitua 10.0.2.5 pelo IP privado real da VM-Postgres<\/span>\r\n\r\n<span style=\"font-weight: 400;\">spring.datasource.url=jdbc:postgresql:\/\/10.0.2.5:5432\/app_db<\/span>\r\n\r\n<span style=\"font-weight: 400;\">spring.datasource.username=spring_user<\/span>\r\n\r\n<span style=\"font-weight: 400;\">spring.datasource.password=${DB_PASSWORD}<\/span>\r\n\r\n<span style=\"font-weight: 400;\">spring.datasource.driver-class-name=org.postgresql.Driver<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Estrat\u00e9gia de gera\u00e7\u00e3o de schema do Hibernate<\/span>\r\n\r\n<span style=\"font-weight: 400;\">spring.jpa.hibernate.ddl-auto=update<\/span>\r\n\r\n<span style=\"font-weight: 400;\">spring.jpa.properties.hibernate.dialect=org.hibernate.dialect.\r\nPostgreSQLDialCore<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Porta de exposi\u00e7\u00e3o da aplica\u00e7\u00e3o<\/span>\r\n\r\n<span style=\"font-weight: 400;\">server.port=8080<\/span>\r\n<\/pre>\n<h3><b>4.4. Configura\u00e7\u00e3o do Dockerfile no projeto Spring Boot<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Crie um arquivo chamado Dockerfile na raiz do projeto Spring Boot para empacotar o artefato de maneira enxuta:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Dockerfile<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Imagem base enxuta com Java 17<\/span>\r\n\r\n<span style=\"font-weight: 400;\">FROM eclipse-temurin:17-jre-alpine<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Diret\u00f3rio de trabalho dentro do container<\/span>\r\n\r\n<span style=\"font-weight: 400;\">WORKDIR \/app<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Copia o artefato gerado pelo build para dentro da imagem<\/span>\r\n\r\n<span style=\"font-weight: 400;\">COPY target\/app.jar app.jar<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Porta exposta pela aplica\u00e7\u00e3o<\/span>\r\n\r\n<span style=\"font-weight: 400;\">EXPOSE 8080<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Comando de inicializa\u00e7\u00e3o da aplica\u00e7\u00e3o<\/span>\r\n\r\n<span style=\"font-weight: 400;\">ENTRYPOINT [\"java\", \"-jar\", \"app.jar\"]<\/span>\r\n<\/pre>\n<h2><b>5. Deploy da aplica\u00e7\u00e3o (dois m\u00e9todos)<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Com a infraestrutura de rede isolada e o banco de dados configurado, voc\u00ea tem total autonomia para escolher a estrat\u00e9gia de publica\u00e7\u00e3o que melhor atenda ao fluxo operacional da sua equipe.<\/span><\/p>\n<h3><b>M\u00e9todo 1: CI\/CD automatizado com Docker e GitHub Actions<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Este \u00e9 o m\u00e9todo moderno recomendado. A cada push na branch main, o GitHub Actions compila a aplica\u00e7\u00e3o, gera a imagem Docker e dispara o deploy automatizado na VM via SSH, eliminando gargalos manuais.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">No seu reposit\u00f3rio do GitHub, acesse <\/span><b>Settings<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>Secrets and variables<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>Actions<\/b><span style=\"font-weight: 400;\"> e cadastre os seguintes Repository Secrets:<\/span>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">SSH_HOST: o IP p\u00fablico da sua VPC no Locaweb Cloud.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">SSH_USER: o usu\u00e1rio de acesso remoto do servidor (exemplo: ubuntu).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">SSH_KEY: o conte\u00fado completo do seu arquivo de chave privada SSH.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Estruture o arquivo de workflow em .github\/workflows\/deploy.yml:<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">YAML<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">name: Deploy Spring Boot na Locaweb Cloud<\/span>\r\n<span style=\"font-weight: 400;\">\u00a0\r\n<\/span>\r\n\r\n<span style=\"font-weight: 400;\">on:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0push:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0branches: [ main ]<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\">jobs:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0deploy:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0runs-on: ubuntu-latest<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0steps:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0- name: Checkout do c\u00f3digo<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0uses: actions\/checkout@v4<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0- name: Configurar JDK 17<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0uses: actions\/setup-java@v4<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0with:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0distribution: temurin<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0java-version: '17'<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0- name: Compilar a aplica\u00e7\u00e3o com Maven<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0run: mvn -B clean package -DskipTests<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0- name: Deploy via SSH na VM Web<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0uses: appleboy\/ssh-action@v1.0.3<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0with:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0host: ${{ secrets.SSH_HOST }}<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0username: ${{ secrets.SSH_USER }}<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0key: ${{ secrets.SSH_KEY }}<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0script: |<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0cd \/home\/ubuntu\/app<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0git pull origin main<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0docker build -t spring-app .<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0docker stop spring-app || true<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0docker rm spring-app || true<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0docker run -d --name spring-app --restart always -p \r\n8080:8080 spring-app<\/span><\/pre>\n<h3><b>M\u00e9todo 2: Deploy manual com systemd<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Caso sua opera\u00e7\u00e3o ainda n\u00e3o utilize pipelines automatizados, envie o arquivo app.jar local para a VM Web via SCP:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Copia o app.jar da m\u00e1quina local para o diret\u00f3rio home na VM Web<\/span>\r\n\r\n<span style=\"font-weight: 400;\">scp -i sua_chave.key app.jar ubuntu@:\/home\/ubuntu\/app.jar<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Para garantir que a aplica\u00e7\u00e3o continue rodando em segundo plano e reinicie sozinha em caso de falhas, configure-a como um servi\u00e7o gerenciado pelo systemd. Crie o arquivo de unidade:<br \/>\n<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">\u00a0sudo nano \/etc\/systemd\/system\/springboot.service \u00a0<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Adicione o conte\u00fado abaixo no arquivo:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Ini, TOML<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">[Unit]<\/span>\r\n\r\n<span style=\"font-weight: 400;\">Description=Aplicacao Spring Boot<\/span>\r\n\r\n<span style=\"font-weight: 400;\">After=network.target<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\">[Service]<\/span>\r\n\r\n<span style=\"font-weight: 400;\">User=ubuntu<\/span>\r\n\r\n<span style=\"font-weight: 400;\">WorkingDirectory=\/home\/ubuntu<\/span>\r\n\r\n<span style=\"font-weight: 400;\">ExecStart=\/usr\/bin\/java -jar \/home\/ubuntu\/app.jar<\/span>\r\n\r\n<span style=\"font-weight: 400;\">SuccessExitStatus=143<\/span>\r\n\r\n<span style=\"font-weight: 400;\">Restart=always<\/span>\r\n\r\n<span style=\"font-weight: 400;\">RestartSec=10<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\">[Install]<\/span>\r\n\r\n<span style=\"font-weight: 400;\">WantedBy=multi-user.target<\/span>\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">Recarregue os daemons e inicialize o servi\u00e7o:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Recarrega o systemd para reconhecer o novo arquivo de servi\u00e7o<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl daemon-reload<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Habilita a aplica\u00e7\u00e3o para iniciar no boot e a inicia imediatamente<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl enable --now springboot<\/span><\/pre>\n<h2><b>6. Configura\u00e7\u00e3o de HTTPS com Let&#8217;s Encrypt<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Para garantir total privacidade no tr\u00e1fego de dados e eliminar alertas de seguran\u00e7a, configure o Nginx como proxy reverso gerenciando o certificado SSL gratuito do Let&#8217;s Encrypt. Na VM Web, execute:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Instala o servidor web Nginx e o cliente Certbot<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt update &amp;&amp; sudo apt install -y nginx certbot \r\npython3-certbot-nginx<\/span>\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Cria o arquivo de configura\u00e7\u00e3o do Nginx para a aplica\u00e7\u00e3o<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo nano \/etc\/nginx\/sites-available\/springboot.conf<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Adicione as regras de proxy direcionando as requisi\u00e7\u00f5es para a porta 8080:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Nginx<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">server {<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0listen 80;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0server_name seu-dominio.com.br;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0location \/ {<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_pass http:\/\/127.0.0.1:8080;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header Host $host;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header X-Real-IP $remote_addr;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header X-Forwarded-Proto $scheme;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0}<\/span>\r\n\r\n<span style=\"font-weight: 400;\">}<\/span>\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">Ative o site, valide as configura\u00e7\u00f5es e emita o certificado digital:<\/span><\/p>\n<p>Bash<\/p>\n<pre><span style=\"font-weight: 400;\"># Cria o link simb\u00f3lico que ativa o site no Nginx<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo ln -s \/etc\/nginx\/sites-available\/springboot.conf \r\n\/etc\/nginx\/sites-enabled\/<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Testa a sintaxe da configura\u00e7\u00e3o do Nginx antes de aplicar<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo nginx -t<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Recarrega o Nginx aplicando a nova configura\u00e7\u00e3o<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl reload nginx<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Gera e instala o certificado TLS para o dom\u00ednio \r\n(substitua pelo seu dom\u00ednio real)<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo certbot --nginx -d seu-dominio.com.br<\/span>\r\n<\/pre>\n<h2><b>7. Valida\u00e7\u00e3o\u00a0<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A valida\u00e7\u00e3o atesta a resili\u00eancia do bloqueio e o sucesso da topologia de rede implementada em formato IaaS.<\/span><\/p>\n<h3><b>7.1. Teste interno na VM Web<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Conectado \u00e0 VM-SpringBoot, valide se a aplica\u00e7\u00e3o est\u00e1 respondendo localmente:<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><br \/>\nBash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Confirma que o servi\u00e7o da aplica\u00e7\u00e3o est\u00e1 ativo e rodando<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl status springboot<\/span><span style=\"font-weight: 400;\">\u00a0<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Faz uma requisi\u00e7\u00e3o local ao endpoint de sa\u00fade da aplica\u00e7\u00e3o<\/span>\r\n\r\n<span style=\"font-weight: 400;\">curl -I http:\/\/localhost:8080\/api\/health<\/span>\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<\/span><span style=\"font-weight: 400;\">O resultado esperado do comando curl \u00e9 o status HTTP\/1.1 200 OK, confirmando que a aplica\u00e7\u00e3o inicializou corretamente na porta 8080.<\/span><span style=\"font-weight: 400;\">    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t<\/span><\/p>\n<h3><b>7.2. Teste externo da aplica\u00e7\u00e3o (m\u00e1quina local)<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A partir do terminal do seu computador local, fa\u00e7a uma requisi\u00e7\u00e3o externa utilizando o IP p\u00fablico da VPC:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">curl -I http:\/\/:8080\/api\/health<\/span>\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Se o HTTPS j\u00e1 estiver configurado, valide a seguran\u00e7a da rota executando curl -I https:\/\/seu-dominio.com.br\/api\/health.<\/span><\/p>\n<h3><b>7.3. Teste de isolamento do banco de dados (cr\u00edtico)<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Este \u00e9 o teste que comprova a seguran\u00e7a da arquitetura. A partir da sua m\u00e1quina local, tente for\u00e7ar uma conex\u00e3o direta ao banco de dados pela internet p\u00fablica:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">psql -h -U spring_user -d app_db -p 5432<\/span>\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">O resultado esperado \u00e9 um erro de tempo limite esgotado (Connection timed out). Como n\u00e3o existe Port Forwarding para a porta 5432 e a ACL da Tier DB s\u00f3 aceita o bloco 10.0.1.0\/24, o Roteador Virtual do Locaweb Cloud descarta os pacotes automaticamente.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t<\/span><\/p>\n<h2><b>8. Solu\u00e7\u00e3o de problemas (Troubleshooting)<\/b><\/h2>\n<p>    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Aviso!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Caso encontre barreiras ou falhas de conectividade no ecossistema, consulte as rotinas de resolu\u00e7\u00e3o abaixo:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Cen\u00e1rio 1: Erro de chave p\u00fablica ou permiss\u00e3o SSH negada<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Sintoma:<\/b><span style=\"font-weight: 400;\"> o terminal retorna a mensagem <\/span><span style=\"font-weight: 400;\">Permission denied (publickey)<\/span><span style=\"font-weight: 400;\"> durante o acesso.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Causa:<\/b><span style=\"font-weight: 400;\"> as permiss\u00f5es do arquivo da chave privada est\u00e3o abertas demais no sistema local.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Solu\u00e7\u00e3o:<\/b><span style=\"font-weight: 400;\"> execute o comando <\/span><span style=\"font-weight: 400;\">chmod 400 sua_chave.key<\/span><span style=\"font-weight: 400;\"> na sua m\u00e1quina local para restringir o acesso de leitura antes de refazer a conex\u00e3o.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Cen\u00e1rio 2: Instabilidade no acesso externo (Connection timed out)<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Sintoma:<\/b><span style=\"font-weight: 400;\"> o teste local via <\/span><span style=\"font-weight: 400;\">localhost<\/span><span style=\"font-weight: 400;\"> funciona, mas as requisi\u00e7\u00f5es externas pelo IP p\u00fablico falham.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Causa:<\/b><span style=\"font-weight: 400;\"> falta de correspond\u00eancia ou aus\u00eancia de regras de Port Forwarding e Firewall para a porta 8080 no painel da VPC.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Solu\u00e7\u00e3o:<\/b><span style=\"font-weight: 400;\"> acesse as abas de rede na Central do Cliente, confirme se a porta p\u00fablica 8080 possui um apontamento ativo para a porta privada 8080 da VM e verifique se a regra correspondente foi liberada no Firewall.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Cen\u00e1rio 3: A aplica\u00e7\u00e3o Java n\u00e3o consegue se conectar ao PostgreSQL<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Sintoma:<\/b><span style=\"font-weight: 400;\"> as mensagens nos logs do Spring Boot indicam erros de rejei\u00e7\u00e3o ou recusa de conex\u00e3o (<\/span><span style=\"font-weight: 400;\">Connection refused<\/span><span style=\"font-weight: 400;\">) na porta 5432.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Causa:<\/b><span style=\"font-weight: 400;\"> o PostgreSQL est\u00e1 configurado para escutar apenas conex\u00f5es locais ou as regras do arquivo <\/span><span style=\"font-weight: 400;\">pg_hba.conf<\/span><span style=\"font-weight: 400;\"> n\u00e3o cobrem o bloco da Tier Web.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Solu\u00e7\u00e3o:<\/b><span style=\"font-weight: 400;\"> acesse a VM de dados, certifique-se de que a linha <\/span><span style=\"font-weight: 400;\">listen_addresses = &#8216;*&#8217;<\/span><span style=\"font-weight: 400;\"> est\u00e1 ativa no arquivo <\/span><span style=\"font-weight: 400;\">postgresql.conf<\/span><span style=\"font-weight: 400;\">, valide a linha de libera\u00e7\u00e3o do bloco <\/span><span style=\"font-weight: 400;\">10.0.1.0\/24<\/span><span style=\"font-weight: 400;\"> no <\/span><span style=\"font-weight: 400;\">pg_hba.conf<\/span><span style=\"font-weight: 400;\"> e reinicie o servi\u00e7o com <\/span><span style=\"font-weight: 400;\">sudo systemctl restart postgresql.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Pronto!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tSua arquitetura profissional de rede isolada em duas camadas (Two-Tier) foi implementada com sucesso no Locaweb Cloud! Utilizando VPC, Tiers dedicadas e Network ACLs expl\u00edcitas, o banco de dados da sua aplica\u00e7\u00e3o est\u00e1 completamente protegido contra amea\u00e7as externas, comunicando-se de forma invis\u00edvel pelo backbone de alta performance da plataforma.<\/p>\n<p><span style=\"font-weight: 400;\">    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t<\/span><\/p>\n<p><span style=\"font-weight: 400;\">    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Conhe\u00e7a! <\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">Para proteger a identidade da sua marca e profissionalizar o contato com seus clientes?<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">Conhe\u00e7a os planos de<\/span><a href=\"https:\/\/www.locaweb.com.br\/email-profissional\/\"> <b>Email Profissional<\/b><\/a><span style=\"font-weight: 400;\"> e<\/span><a href=\"https:\/\/www.locaweb.com.br\/registro-de-dominio-web\/\"> <b>Registro de Dom\u00ednio<\/b><\/a><span style=\"font-weight: 400;\"> da Locaweb e centralize sua presen\u00e7a digital no mesmo ecossistema com o melhor custo-benef\u00edcio.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0 A orquestra\u00e7\u00e3o de deploys para aplica\u00e7\u00f5es corporativas exige consist\u00eancia, rastreabilidade e elimina\u00e7\u00e3o de falhas humanas. O Java Spring Boot, padr\u00e3o indiscut\u00edvel no desenvolvimento de software corporativo, beneficia-se profundamente de processos de Integra\u00e7\u00e3o Cont\u00ednua e Entrega Cont\u00ednua (CI\/CD) aliados \u00e0 conteineriza\u00e7\u00e3o. Pr\u00e9-requisitos Para acompanhar a implementa\u00e7\u00e3o arquitetural deste guia, certifique-se&#8230;<\/p>\n","protected":false},"author":55,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"footnotes":""},"ht-kb-category":[666],"ht-kb-tag":[],"class_list":["post-38785","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-locaweb-cloud"],"_links":{"self":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/38785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/comments?post=38785"}],"version-history":[{"count":7,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/38785\/revisions"}],"predecessor-version":[{"id":38796,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/38785\/revisions\/38796"}],"wp:attachment":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/media?parent=38785"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb-category?post=38785"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb-tag?post=38785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}