{"id":38792,"date":"2026-07-08T11:23:35","date_gmt":"2026-07-08T14:23:35","guid":{"rendered":"https:\/\/www.locaweb.com.br\/ajuda\/?post_type=ht_kb&#038;p=38792"},"modified":"2026-07-08T11:23:35","modified_gmt":"2026-07-08T14:23:35","slug":"hospedagem-do-hermes-via-containers-no-locaweb-cloud","status":"publish","type":"ht_kb","link":"https:\/\/www.locaweb.com.br\/ajuda\/wiki\/hospedagem-do-hermes-via-containers-no-locaweb-cloud\/","title":{"rendered":"Hospedagem do Hermes via Containers no Locaweb Cloud"},"content":{"rendered":"    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Informa\u00e7\u00e3o!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Neste tutorial, voc\u00ea aprender\u00e1 a estruturar, configurar e realizar o deploy de uma aplica\u00e7\u00e3o conteinerizada (Hermes) utilizando a infraestrutura resiliente do Locaweb Cloud, garantindo isolamento de rede e persist\u00eancia de dados.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">O Hermes \u00e9 um backend de mensageria em Node.js. Este guia assume uma aplica\u00e7\u00e3o conteinerizada via Git (com <\/span><span style=\"font-weight: 400;\">Dockerfile<\/span><span style=\"font-weight: 400;\"> e <\/span><span style=\"font-weight: 400;\">docker-compose.yml<\/span><span style=\"font-weight: 400;\">) e banco PostgreSQL. Se usar imagens p\u00fablicas, basta referenci\u00e1-las no Compose; a topologia \u00e9 a mesma.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2><b>Pr\u00e9-requisitos<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Para acompanhar a implementa\u00e7\u00e3o arquitetural deste guia, certifique-se de cumprir os seguintes requisitos:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Conta ativa no Locaweb Cloud:<\/b><span style=\"font-weight: 400;\"> com acesso liberado ao <\/span><a href=\"https:\/\/painel-cloud.locaweb.com.br\"><span style=\"font-weight: 400;\">painel de controle<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Chave de autentica\u00e7\u00e3o SSH:<\/b><span style=\"font-weight: 400;\"> uma chave privada SSH (arquivo <\/span><span style=\"font-weight: 400;\">.key<\/span><span style=\"font-weight: 400;\"> ou <\/span><span style=\"font-weight: 400;\">.pem<\/span><span style=\"font-weight: 400;\">) gerada e com a respectiva chave p\u00fablica cadastrada no painel do Locaweb Cloud. No seu terminal local, ajuste a permiss\u00e3o da chave privada com <\/span><span style=\"font-weight: 400;\">chmod 400 sua-chave.key<\/span><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Conhecimento b\u00e1sico de terminal:<\/b><span style=\"font-weight: 400;\"> familiaridade com navega\u00e7\u00e3o de diret\u00f3rios e uso do gerenciador de pacotes em ambientes Linux.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>(Opcional) Dom\u00ednio pr\u00f3prio:<\/b><span style=\"font-weight: 400;\"> um dom\u00ednio ou subdom\u00ednio apontando para o IP p\u00fablico da VM de aplica\u00e7\u00e3o, necess\u00e1rio para emitir um certificado HTTPS gratuito com Let&#8217;s Encrypt.<\/span><\/li>\n<\/ul>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Est\u00e1 com d\u00favidas sobre como come\u00e7ar no Locaweb Cloud? Acesse nosso <\/span><a href=\"https:\/\/www.locaweb.com.br\/ajuda\/wiki\/por-onde-comecar-no-locaweb-cloud\/\"><span style=\"font-weight: 400;\">tutorial de apoio<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2><b>2. Configura\u00e7\u00e3o de infraestrutura (painel)<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A base de uma aplica\u00e7\u00e3o segura \u00e9 o isolamento de rede. Criaremos uma Virtual Private Cloud (VPC) para abrigar nossos servidores, garantindo que o banco de dados n\u00e3o seja exposto diretamente \u00e0 internet.<\/span><\/p>\n<h3><b>2.1. Cria\u00e7\u00e3o da Rede VPC e Tiers<\/b><\/h3>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Navegue at\u00e9 <\/span><b>Rede<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>VPC<\/b><span style=\"font-weight: 400;\"> no painel do Locaweb Cloud e clique em <\/span><b>Adicionar VPC<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defina o bloco CIDR principal (exemplo: <\/span><span style=\"font-weight: 400;\">10.0.0.0\/16<\/span><span style=\"font-weight: 400;\">) e selecione a Oferta de VPC adequada ao seu projeto.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dentro da nova VPC, acesse a aba <\/span><b>Redes<\/b><span style=\"font-weight: 400;\"> e clique em <\/span><b>Adicionar novo tier<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Crie um tier chamado <\/span><span style=\"font-weight: 400;\">Tier-Aplicacao<\/span><span style=\"font-weight: 400;\"> (exemplo de CIDR: <\/span><span style=\"font-weight: 400;\">10.0.1.0\/24<\/span><span style=\"font-weight: 400;\">) para o servidor do Hermes e outro chamado <\/span><span style=\"font-weight: 400;\">Tier-BancoDados<\/span><span style=\"font-weight: 400;\"> (exemplo de CIDR: <\/span><span style=\"font-weight: 400;\">10.0.2.0\/24<\/span><span style=\"font-weight: 400;\">) para o PostgreSQL.<\/span><\/li>\n<\/ol>\n<h3><b>2.2. Provisionamento das M\u00e1quinas Virtuais (VMs)<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Ser\u00e3o necess\u00e1rias duas inst\u00e2ncias: uma para o banco de dados e outra para a aplica\u00e7\u00e3o.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Navegue at\u00e9 <\/span><b>Computa\u00e7\u00e3o<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>VMs<\/b><span style=\"font-weight: 400;\"> e clique em <\/span><b>Adicionar VM<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>VM de Banco de Dados:<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Template:<\/b><span style=\"font-weight: 400;\"> selecione Ubuntu 22.04 LTS.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Oferta:<\/b><span style=\"font-weight: 400;\"> escolha um plano com recursos de CPU e RAM otimizados para banco de dados (exemplo: 4 vCPUs, 8 GB de RAM).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Rede:<\/b><span style=\"font-weight: 400;\"> conecte ao <\/span><span style=\"font-weight: 400;\">Tier-BancoDados<\/span><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Chave SSH:<\/b><span style=\"font-weight: 400;\"> selecione a sua chave p\u00fablica previamente cadastrada.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Disco secund\u00e1rio:<\/b><span style=\"font-weight: 400;\"> durante a cria\u00e7\u00e3o, adicione um Datadisk (ex.: 50 GB) que ser\u00e1 usado para persistir os dados do PostgreSQL.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>VM da Aplica\u00e7\u00e3o (Hermes):<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Repita o processo, escolhendo um plano adequado para a carga do Hermes (exemplo: 2 vCPUs, 4 GB de RAM).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Template:<\/b><span style=\"font-weight: 400;\"> Ubuntu 22.04 LTS.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Rede:<\/b><span style=\"font-weight: 400;\"> conecte ao <\/span><span style=\"font-weight: 400;\">Tier-Aplicacao<\/span><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Chave SSH:<\/b><span style=\"font-weight: 400;\"> selecione a mesma chave p\u00fablica cadastrada.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h3><b>2.3. IPs P\u00fablicos, encaminhamento de porta e regras de Firewall<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A VM de banco de dados permanecer\u00e1 isolada, comunicando-se apenas com a VM da aplica\u00e7\u00e3o via IP privado. Para a VM do Hermes receber tr\u00e1fego web:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acesse <\/span><b>Rede<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>VPC<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>[Sua VPC]<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>IPs P\u00fablicos<\/b><span style=\"font-weight: 400;\"> e clique em <\/span><b>Obter um novo IP<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Selecione o IP adquirido e v\u00e1 para a aba <\/span><b>Encaminhamento de porta<\/b><span style=\"font-weight: 400;\">. Crie regras direcionando as portas p\u00fablicas para a VM do Hermes conforme a tabela abaixo:<\/span><\/li>\n<\/ol>\n<table>\n<tbody>\n<tr>\n<td><b>Porta p\u00fablica<\/b><\/td>\n<td><b>Porta privada<\/b><\/td>\n<td><b>Protocolo<\/b><\/td>\n<td><b>Destino<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">80 (HTTP)<\/span><\/td>\n<td><span style=\"font-weight: 400;\">80<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">VM do Hermes<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">443 (HTTPS)<\/span><\/td>\n<td><span style=\"font-weight: 400;\">443<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">VM do Hermes<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">22 (SSH)<\/span><\/td>\n<td><span style=\"font-weight: 400;\">22<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">VM do Hermes<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Na aba <\/span><b>Firewall<\/b><span style=\"font-weight: 400;\">, adicione regras de entrada liberando o tr\u00e1fego TCP nas portas 80, 443 e 22. Para a porta 22 (SSH), recomendamos fortemente restringir o CIDR de origem ao IP da sua rede de administra\u00e7\u00e3o (exemplo: <\/span><span style=\"font-weight: 400;\">&lt;SEU_IP_ADMIN&gt;\/32<\/span><span style=\"font-weight: 400;\">), em vez de liberar <\/span><span style=\"font-weight: 400;\">0.0.0.0\/0<\/span><span style=\"font-weight: 400;\">.<\/span><\/li>\n<\/ol>\n    \t\t<div class=\"hts-messages hts-messages--danger  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Aten\u00e7\u00e3o!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tA porta do PostgreSQL (5432) nunca deve constar no Encaminhamento de Porta nem em regra de Firewall voltada para a internet. O acesso ao banco ocorre exclusivamente pela rede privada da VPC, entre o Tier-Aplicacao e o Tier-BancoDados. Deix\u00e1-la aberta exp\u00f5e sua infraestrutura a vulnerabilidades cr\u00edticas.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h3><b>1.4. ACL de rede entre os Tiers<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Para que a VM da aplica\u00e7\u00e3o alcance o banco de dados pela rede privada, configure a ACL da VPC permitindo o tr\u00e1fego da sub-rede de aplica\u00e7\u00e3o at\u00e9 a porta do PostgreSQL:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Origem (CIDR)<\/b><\/td>\n<td><b>Destino<\/b><\/td>\n<td><b>Protocolo<\/b><\/td>\n<td><b>Porta<\/b><\/td>\n<td><b>A\u00e7\u00e3o<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">10.0.1.0\/24 (Tier-Aplicacao)<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Tier-BancoDados<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">5432<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Permitir<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">0.0.0.0\/0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Tier-BancoDados<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TCP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">5432<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Negar<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h2><b>3. Prepara\u00e7\u00e3o do disco de dados na VM de banco de dados<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Para que os dados do PostgreSQL sobrevivam a reinicializa\u00e7\u00f5es e recria\u00e7\u00f5es da inst\u00e2ncia, vamos formatar e montar o disco secund\u00e1rio de forma persistente. Acesse a VM de banco de dados via SSH (fazendo um salto a partir da VM de aplica\u00e7\u00e3o, j\u00e1 que o banco n\u00e3o possui IP p\u00fablico) e execute os comandos:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Lista os discos dispon\u00edveis para identificar o disco secund\u00e1rio (geralmente \/dev\/vdb)<\/span>\r\n\r\n<span style=\"font-weight: 400;\">lsblk<\/span>\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Cria o sistema de arquivos ext4 no disco secund\u00e1rio identificado<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo mkfs.ext4 \/dev\/vdb<\/span>\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Cria o ponto de montagem onde os dados do PostgreSQL ser\u00e3o armazenados<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo mkdir -p \/mnt\/dados<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Em vez de referenciar o disco pelo nome do dispositivo (que pode mudar de ordem entre reinicializa\u00e7\u00f5es), usamos o UUID est\u00e1vel no <\/span><span style=\"font-weight: 400;\">\/etc\/fstab<\/span><span style=\"font-weight: 400;\">:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Exibe o UUID do disco secund\u00e1rio<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo blkid \/dev\/vdb<\/span>\r\n\r\n<span style=\"font-weight: 400;\"># Copie o valor de UUID exibido na sa\u00edda<\/span>\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Adiciona a montagem permanente usando o UUID (substitua &lt;SEU_UUID&gt;)<\/span>\r\n\r\n<span style=\"font-weight: 400;\">echo 'UUID=&lt;SEU_UUID&gt;\u00a0 \/mnt\/dados\u00a0 ext4\u00a0 defaults,nofail,noatime\u00a0 0\u00a0 2' | sudo tee -a \/etc\/fstab<\/span>\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Monta todos os pontos definidos no fstab e confirma o resultado<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo mount -a<\/span>\r\n\r\n<span style=\"font-weight: 400;\">df -h \/mnt\/dados<\/span><\/pre>\n<p>&nbsp;<\/p>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">O par\u00e2metro <\/span><span style=\"font-weight: 400;\">nofail<\/span><span style=\"font-weight: 400;\"> impede que a VM falhe na inicializa\u00e7\u00e3o caso o disco n\u00e3o esteja dispon\u00edvel, e <\/span><span style=\"font-weight: 400;\">noatime<\/span><span style=\"font-weight: 400;\"> reduz a escrita de metadados, melhorando o desempenho do banco. O campo final <\/span><span style=\"font-weight: 400;\">2<\/span><span style=\"font-weight: 400;\"> indica a ordem de verifica\u00e7\u00e3o do sistema de arquivos no boot.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2><b>4. Configura\u00e7\u00e3o do banco de dados no Locaweb Cloud<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Como estamos operando em IaaS, o banco de dados \u00e9 configurado dentro da VM designada no <\/span><span style=\"font-weight: 400;\">Tier-BancoDados<\/span><span style=\"font-weight: 400;\">. Ainda conectado a essa VM via SSH, instale o PostgreSQL:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Atualiza os reposit\u00f3rios locais para garantir o download das vers\u00f5es mais recentes<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt-get update<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Instala o servidor PostgreSQL e pacotes adicionais<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt-get install -y postgresql postgresql-contrib<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Inicia o servi\u00e7o e garante sua execu\u00e7\u00e3o autom\u00e1tica na inicializa\u00e7\u00e3o do sistema<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl enable --now postgresql<\/span>\r\n\r\n\r\n<\/pre>\n<h3><b>4.1. Apontando o PostgreSQL para o disco persistente<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Para armazenar os dados no disco secund\u00e1rio montado em <\/span><span style=\"font-weight: 400;\">\/mnt\/dados<\/span><span style=\"font-weight: 400;\">, mova o diret\u00f3rio de dados do PostgreSQL:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Para o servi\u00e7o antes de mover os dados<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl stop postgresql<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Move o diret\u00f3rio de dados padr\u00e3o para o disco persistente (ajuste a vers\u00e3o se necess\u00e1rio)<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo rsync -av \/var\/lib\/postgresql\/14\/main\/ \/mnt\/dados\/postgresql\/<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Ajusta o dono do novo diret\u00f3rio para o usu\u00e1rio do PostgreSQL<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo chown -R postgres:postgres \/mnt\/dados\/postgresql<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Edite o arquivo de configura\u00e7\u00e3o para apontar o <\/span><span style=\"font-weight: 400;\">data_directory<\/span><span style=\"font-weight: 400;\"> para o novo local e habilitar a escuta na rede privada:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">sudo nano \/etc\/postgresql\/14\/main\/postgresql.conf<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Ajuste as linhas a seguir no arquivo:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Snippet de c\u00f3digo<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">data_directory = '\/mnt\/dados\/postgresql'<\/span>\r\n\r\n<span style=\"font-weight: 400;\">listen_addresses = '10.0.2.X' \u00a0 # IP privado da VM de Banco de Dados no Tier-BancoDados<\/span><\/pre>\n<p>&nbsp;<\/p>\n<h3><b>4.2. Cria\u00e7\u00e3o do usu\u00e1rio, do banco e regra de acesso<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Crie o usu\u00e1rio e o banco que o Hermes utilizar\u00e1:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Acessa o console administrativo do PostgreSQL<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo -u postgres psql<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">No prompt do <\/span><span style=\"font-weight: 400;\">psql<\/span><span style=\"font-weight: 400;\">, execute os comandos de infraestrutura:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">SQL<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">CREATE DATABASE hermes_db;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">CREATE USER hermes_user WITH ENCRYPTED PASSWORD 'SUA_SENHA_FORTE_AQUI';<\/span>\r\n\r\n<span style=\"font-weight: 400;\">GRANT ALL PRIVILEGES ON DATABASE hermes_db TO hermes_user;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\\q<\/span><\/pre>\n<p>&nbsp;<\/p>\n    \t\t<div class=\"hts-messages hts-messages--danger  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Aviso!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t\u00a0A senha acima \u00e9 meramente demonstrativa. Certifique-se de definir uma credencial forte e exclusiva para proteger os dados confidenciais do seu ecossistema.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<p><span style=\"font-weight: 400;\">Em seguida, restrinja o acesso de rede para que apenas a sub-rede de aplica\u00e7\u00e3o possa se conectar. Edite o arquivo de controle de acesso:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">sudo nano \/etc\/postgresql\/14\/main\/pg_hba.conf<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Adicione a linha abaixo, liberando conex\u00f5es apenas da sub-rede do <\/span><span style=\"font-weight: 400;\">Tier-Aplicacao<\/span><span style=\"font-weight: 400;\">:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Snippet de c\u00f3digo<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Permite conex\u00f5es criptografadas apenas da sub-rede da aplica\u00e7\u00e3o<\/span>\r\n\r\n<span style=\"font-weight: 400;\">host\u00a0 \u00a0 hermes_db\u00a0 \u00a0 hermes_user\u00a0 \u00a0 10.0.1.0\/24\u00a0 \u00a0 scram-sha-256<\/span>\r\n\r\n\r\n<\/pre>\n<p><span style=\"font-weight: 400;\">Aplique as altera\u00e7\u00f5es reiniciando o servi\u00e7o:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Reinicia o PostgreSQL para carregar o novo data_directory e as regras de acesso<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl restart postgresql<\/span><\/pre>\n<p>&nbsp;<\/p>\n<h2><b>5. Configura\u00e7\u00e3o do sistema e Docker (passo a passo no Terminal)<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Agora, configuraremos o ambiente de execu\u00e7\u00e3o do Hermes na VM de aplica\u00e7\u00e3o conectada ao <\/span><span style=\"font-weight: 400;\">Tier-Aplicacao<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h3><b>5.1. Acesso remoto<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Conecte-se \u00e0 VM de aplica\u00e7\u00e3o usando a chave SSH configurada e o IP p\u00fablico mapeado. Substitua o caminho da chave e o IP pelos seus valores correspondentes:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Conecta \u00e0 VM de aplica\u00e7\u00e3o via SSH usando a chave privada<\/span>\r\n\r\n<span style=\"font-weight: 400;\">ssh -i \/caminho\/para\/sua\/chave.key ubuntu@&lt;SEU_IP_PUBLICO&gt;<\/span><\/pre>\n<h3><b><br \/>\n<\/b><b>5.2. Instala\u00e7\u00e3o do ambiente de Containers<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Utilizaremos Docker para garantir a portabilidade e a consist\u00eancia do ambiente do Hermes. A instala\u00e7\u00e3o \u00e9 feita pelo reposit\u00f3rio oficial do Docker, garantindo pacotes assinados e atualiza\u00e7\u00f5es controladas:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Atualiza o \u00edndice de pacotes e instala depend\u00eancias para reposit\u00f3rios HTTPS<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt-get update<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt-get install -y ca-certificates curl gnupg<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Cria o diret\u00f3rio oficial de chaves do APT<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo install -m 0755 -d \/etc\/apt\/keyrings<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Adiciona a chave GPG oficial do Docker para verifica\u00e7\u00e3o de assinaturas<\/span>\r\n\r\n<span style=\"font-weight: 400;\">curl -fsSL https:\/\/download.docker.com\/linux\/ubuntu\/gpg | sudo gpg --dearmor -o \/etc\/apt\/keyrings\/docker.gpg<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo chmod a+r \/etc\/apt\/keyrings\/docker.gpg<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Adiciona o reposit\u00f3rio est\u00e1vel do Docker ao sistema<\/span>\r\n\r\n<span style=\"font-weight: 400;\">echo \\<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\"deb [arch=$(dpkg --print-architecture) signed-by=\/etc\/apt\/keyrings\/docker.gpg] https:\/\/download.docker.com\/linux\/ubuntu \\<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0$(. \/etc\/os-release &amp;&amp; echo \"$VERSION_CODENAME\") stable\" | \\<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0sudo tee \/etc\/apt\/sources.list.d\/docker.list &gt; \/dev\/null<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Instala o Docker Engine, a CLI e o plugin do Docker Compose<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt-get update<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Habilita o Docker para iniciar junto com o sistema<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl enable --now docker<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Adiciona o usu\u00e1rio atual ao grupo docker para executar comandos sem 'sudo'<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo usermod -aG docker $USER<\/span>\r\n\r\n\r\n<\/pre>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Ap\u00f3s a execu\u00e7\u00e3o do \u00faltimo comando, encerre a sess\u00e3o SSH e reconecte-se \u00e0 m\u00e1quina para que a nova permiss\u00e3o de grupo entre em vigor. Voc\u00ea pode confirmar que o Docker est\u00e1 funcionando sem a necessidade de <\/span><span style=\"font-weight: 400;\">sudo<\/span><span style=\"font-weight: 400;\"> executando o comando <\/span><span style=\"font-weight: 400;\">docker run hello-world<\/span><span style=\"font-weight: 400;\">.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2><b>5. Estrat\u00e9gias de deploy do Hermes<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Com a infraestrutura pronta, voc\u00ea possui total autonomia para optar pela abordagem de deploy mais alinhada ao tempo de mercado (time-to-market) do seu fluxo de desenvolvimento.<\/span><\/p>\n<h3><b>Abordagem A: M\u00e9todo manual via Git Pull (Tradicional)<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Indicado para arquiteturas simples ou fases iniciais de valida\u00e7\u00e3o:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Cria o diret\u00f3rio da aplica\u00e7\u00e3o e clona o reposit\u00f3rio oficial do Hermes<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo mkdir -p \/opt\/hermes &amp;&amp; sudo chown $USER:$USER \/opt\/hermes<\/span>\r\n\r\n<span style=\"font-weight: 400;\">cd \/opt\/hermes<\/span>\r\n\r\n<span style=\"font-weight: 400;\">git clone https:\/\/github.com\/seu-usuario\/hermes.git .<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Cria e edita o arquivo de vari\u00e1veis de ambiente (.env) com a string de conex\u00e3o do banco<\/span>\r\n\r\n<span style=\"font-weight: 400;\">cat &lt;&lt;EOF &gt; .env<\/span>\r\n\r\n<span style=\"font-weight: 400;\">DB_HOST=10.0.2.X\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 # IP privado da VM de Banco de Dados na Locaweb Cloud<\/span>\r\n\r\n<span style=\"font-weight: 400;\">DB_PORT=5432<\/span>\r\n\r\n<span style=\"font-weight: 400;\">DB_USER=hermes_user<\/span>\r\n\r\n<span style=\"font-weight: 400;\">DB_PASS=SUA_SENHA_FORTE_AQUI<\/span>\r\n\r\n<span style=\"font-weight: 400;\">DB_NAME=hermes_db<\/span>\r\n\r\n<span style=\"font-weight: 400;\">DATABASE_URL=postgresql:\/\/hermes_user:SUA_SENHA_FORTE_AQUI@10.0.2.X:5432\/hermes_db<\/span>\r\n\r\n<span style=\"font-weight: 400;\">EOF<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Sobe os containers em modo detached (segundo plano)<\/span>\r\n\r\n<span style=\"font-weight: 400;\">docker compose up -d<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">O comando <\/span><span style=\"font-weight: 400;\">docker compose up -d<\/span><span style=\"font-weight: 400;\"> l\u00ea o arquivo <\/span><span style=\"font-weight: 400;\">docker-compose.yml<\/span><span style=\"font-weight: 400;\"> do projeto, efetua o pull das imagens necess\u00e1rias e orquestra a execu\u00e7\u00e3o dos containers de forma automatizada. As vari\u00e1veis definidas em <\/span><span style=\"font-weight: 400;\">.env<\/span><span style=\"font-weight: 400;\"> (incluindo a <\/span><span style=\"font-weight: 400;\">DATABASE_URL<\/span><span style=\"font-weight: 400;\">) s\u00e3o lidas pelo Hermes para estabelecer a comunica\u00e7\u00e3o direta com o PostgreSQL no <\/span><span style=\"font-weight: 400;\">Tier-BancoDados<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h3><b>Abordagem B: M\u00e9todo moderno via GitHub Actions (CI\/CD Autom\u00e1tico)<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Para ambientes de produ\u00e7\u00e3o profissionais, recomenda-se automatizar a entrega. A principal vantagem \u00e9 eliminar tarefas repetitivas: toda altera\u00e7\u00e3o validada na branch principal \u00e9 publicada na plataforma de forma consistente e est\u00e1vel, reduzindo drasticamente falhas manuais.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">No seu reposit\u00f3rio do GitHub, acesse <\/span><b>Settings<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>Secrets and variables<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>Actions<\/b><span style=\"font-weight: 400;\"> e cadastre as seguintes chaves de seguran\u00e7a (Secrets):<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HOST_IP<\/span><span style=\"font-weight: 400;\">: o endere\u00e7o IP p\u00fablico da sua VM de aplica\u00e7\u00e3o.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH_USER<\/span><span style=\"font-weight: 400;\">: o usu\u00e1rio de acesso do sistema operacional (exemplo: <\/span><span style=\"font-weight: 400;\">ubuntu<\/span><span style=\"font-weight: 400;\">).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH_KEY<\/span><span style=\"font-weight: 400;\">: o conte\u00fado completo da sua chave privada SSH.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Em seguida, crie o arquivo de automa\u00e7\u00e3o estruturado em <\/span><span style=\"font-weight: 400;\">.github\/workflows\/deploy.yml<\/span><span style=\"font-weight: 400;\">:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">YAML<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">name: Deploy Hermes to Locaweb Cloud<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">on:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0push:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0branches: [ \"main\" ]<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">jobs:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0deploy:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0runs-on: ubuntu-latest<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0steps:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0- name: Checkout do c\u00f3digo<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0uses: actions\/checkout@v4<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0- name: Executar comandos via SSH<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0uses: appleboy\/ssh-action@v1.0.3<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0with:<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0host: ${{ secrets.HOST_IP }}<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0username: ${{ secrets.SSH_USER }}<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0key: ${{ secrets.SSH_KEY }}<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0script: |<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0cd \/opt\/hermes<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0git pull origin main<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0docker compose pull<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0docker compose up -d --remove-orphans<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Essa estrat\u00e9gia garante agilidade e efici\u00eancia total, assegurando que o seu c\u00f3digo vire neg\u00f3cio em tempo recorde assim que passar pelo reposit\u00f3rio Git.<\/span><\/p>\n<h2><b>7. Configura\u00e7\u00e3o de HTTPS com Let&#8217;s Encrypt<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Expor o Hermes apenas atrav\u00e9s do protocolo HTTP coloca os dados trafegados em risco. O ideal \u00e9 implementar uma barreira de seguran\u00e7a com o Nginx atuando como proxy reverso na frente da aplica\u00e7\u00e3o para emitir um certificado gratuito com o Let&#8217;s Encrypt. Na VM de aplica\u00e7\u00e3o, execute:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Instala o Nginx, o Certbot e o plugin de integra\u00e7\u00e3o com o Nginx<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt-get update<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo apt-get install -y nginx certbot python3-certbot-nginx<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Crie o arquivo de configura\u00e7\u00e3o do site, encaminhando as requisi\u00e7\u00f5es para o container do Hermes (ajuste a porta interna conforme o mapeamento do seu <\/span><span style=\"font-weight: 400;\">docker-compose.yml<\/span><span style=\"font-weight: 400;\">):<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">sudo nano \/etc\/nginx\/sites-available\/hermes.conf<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Insira o conte\u00fado estruturado abaixo:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Nginx<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">server {<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0listen 80;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0server_name &lt;SEU_DOMINIO&gt;;<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0location \/ {<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_pass http:\/\/localhost:3000;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header Host $host;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header X-Real-IP $remote_addr;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0proxy_set_header X-Forwarded-Proto $scheme;<\/span>\r\n\r\n<span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0}<\/span>\r\n\r\n<span style=\"font-weight: 400;\">}<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">Ative as configura\u00e7\u00f5es no Nginx e emita o certificado de seguran\u00e7a:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Habilita o site e remove o site padr\u00e3o para evitar conflitos na camada de rede<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo ln -s \/etc\/nginx\/sites-available\/hermes.conf \/etc\/nginx\/sites-enabled\/<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo rm -f \/etc\/nginx\/sites-enabled\/default<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Testa a configura\u00e7\u00e3o e recarrega o servi\u00e7o do Nginx<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo nginx -t<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo systemctl reload nginx<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Emite e instala o certificado SSL, ativando o redirecionamento autom\u00e1tico de HTTP para HTTPS<\/span>\r\n\r\n<span style=\"font-weight: 400;\">sudo certbot --nginx -d &lt;SEU_DOMINIO&gt;<\/span><\/pre>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">O Certbot configura de forma automatizada e invis\u00edvel a rotina de renova\u00e7\u00e3o peri\u00f3dica do certificado SSL. Voc\u00ea pode validar se o fluxo autom\u00e1tico est\u00e1 operando sem falhas executando o comando <\/span><span style=\"font-weight: 400;\">sudo certbot renew &#8211;dry-run<\/span><span style=\"font-weight: 400;\">.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2><b>8. Valida\u00e7\u00e3o<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Para confirmar o sucesso na orquestra\u00e7\u00e3o dos recursos de IaaS e garantir que a sua opera\u00e7\u00e3o est\u00e1 centralizada e rodando sem gargalos, execute os testes de valida\u00e7\u00e3o t\u00e9cnica descritos a seguir.<\/span><\/p>\n<h3><b>8.1. Testes internos na VM de aplica\u00e7\u00e3o<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Lista os containers em execu\u00e7\u00e3o; o status deve indicar \"Up\"<\/span>\r\n\r\n<span style=\"font-weight: 400;\">docker ps<\/span>\r\n\r\n\r\n\r\n\r\n<span style=\"font-weight: 400;\"># Verifica os cabe\u00e7alhos de resposta da aplica\u00e7\u00e3o localmente<\/span>\r\n\r\n<span style=\"font-weight: 400;\">curl -I http:\/\/localhost:3000<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">O comando <\/span><span style=\"font-weight: 400;\">docker ps<\/span><span style=\"font-weight: 400;\"> deve listar o container do Hermes ativo. O <\/span><span style=\"font-weight: 400;\">curl<\/span><span style=\"font-weight: 400;\"> deve retornar o c\u00f3digo de status esperado pela aplica\u00e7\u00e3o (como <\/span><span style=\"font-weight: 400;\">HTTP\/1.1 200 OK<\/span><span style=\"font-weight: 400;\">). Para auditar a integridade t\u00e9cnica e monitorar a conex\u00e3o com o PostgreSQL em tempo real:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Acompanha os logs do container em tempo real (-f mant\u00e9m a leitura ativa)<\/span>\r\n\r\n<span style=\"font-weight: 400;\">docker logs -f hermes_app_container<\/span><\/pre>\n<h3><b>8.2. Teste externo a partir da sua m\u00e1quina local<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A partir do seu computador de administra\u00e7\u00e3o conectado \u00e0 internet, valide o acesso p\u00fablico seguro atrav\u00e9s da URL do seu dom\u00ednio pr\u00f3prio:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># Verifica a resposta HTTPS a partir da internet<\/span>\r\n\r\n<span style=\"font-weight: 400;\">curl -I https:\/\/&lt;SEU_DOMINIO&gt;<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">A resposta esperada \u00e9 um cabe\u00e7alho <\/span><span style=\"font-weight: 400;\">HTTP\/2 200<\/span><span style=\"font-weight: 400;\">, exibindo as propriedades do TLS e atestando que o encaminhamento de portas e o Firewall est\u00e3o operando perfeitamente.<\/span><\/p>\n<h3><b>8.3. Teste de isolamento do banco de dados<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Para certificar-se de que a camada de dados n\u00e3o sofre com a exposi\u00e7\u00e3o a acessos maliciosos externos, realize uma checagem de portas a partir da sua m\u00e1quina local direcionada ao IP p\u00fablico da infraestrutura:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bash<\/span><\/p>\n<pre><span style=\"font-weight: 400;\"># A conex\u00e3o DEVE falhar (timeout), comprovando o isolamento do banco<\/span>\r\n\r\n<span style=\"font-weight: 400;\">nc -vz &lt;SEU_IP_PUBLICO&gt; 5432<\/span><\/pre>\n<p><span style=\"font-weight: 400;\">O resultado esperado \u00e9 um esgotamento de tempo de conex\u00e3o (<\/span><span style=\"font-weight: 400;\">Connection timed out<\/span><span style=\"font-weight: 400;\">). Caso a conex\u00e3o seja bem-sucedida, revise imediatamente as parametriza\u00e7\u00f5es de Firewall no painel, pois o banco estar\u00e1 vulner\u00e1vel.<\/span><\/p>\n<h2><b>9. Solu\u00e7\u00e3o de problemas (Troubleshooting)<\/b><\/h2>\n    \t\t<div class=\"hts-messages hts-messages--danger  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Aviso!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tDiante de incidentes t\u00e9cnicos ou instabilidades nas aplica\u00e7\u00f5es, siga as rotinas de verifica\u00e7\u00e3o abaixo para debugar e restabelecer a fluidez do ecossistema de forma aut\u00f4noma.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Permiss\u00e3o SSH negada<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Sintoma:<\/b><span style=\"font-weight: 400;\"> o terminal exibe a mensagem <\/span><span style=\"font-weight: 400;\">Permission denied (publickey)<\/span><span style=\"font-weight: 400;\"> durante o acesso remoto.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Causa:<\/b><span style=\"font-weight: 400;\"> as permiss\u00f5es do arquivo de chave privada est\u00e3o excessivamente abertas no computador local ou o par p\u00fablico associado n\u00e3o corresponde ao cadastrado na VM.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Solu\u00e7\u00e3o:<\/b><span style=\"font-weight: 400;\"> execute o comando <\/span><span style=\"font-weight: 400;\">chmod 400 sua-chave.key<\/span><span style=\"font-weight: 400;\"> no seu terminal e certifique-se de especificar o usu\u00e1rio master correto (<\/span><span style=\"font-weight: 400;\">ubuntu<\/span><span style=\"font-weight: 400;\">) no comando de conex\u00e3o.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Aplica\u00e7\u00e3o inacess\u00edvel atrav\u00e9s da internet<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Sintoma:<\/b><span style=\"font-weight: 400;\"> o comando <\/span><span style=\"font-weight: 400;\">curl -I https:\/\/&lt;SEU_DOMINIO&gt;<\/span><span style=\"font-weight: 400;\"> atinge tempo limite (<\/span><span style=\"font-weight: 400;\">timeout<\/span><span style=\"font-weight: 400;\">), mas o tr\u00e1fego interno em <\/span><span style=\"font-weight: 400;\">http:\/\/localhost:3000<\/span><span style=\"font-weight: 400;\"> funciona dentro da VM.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Causa:<\/b><span style=\"font-weight: 400;\"> aus\u00eancia de regras de Encaminhamento de Porta ou Firewall para as portas 80\/443 no painel administrativo, ou atraso na propaga\u00e7\u00e3o de DNS do dom\u00ednio.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Solu\u00e7\u00e3o:<\/b><span style=\"font-weight: 400;\"> acesse as abas de rede no painel do Locaweb Cloud, valide se as portas 80 e 443 est\u00e3o direcionadas para o IP privado da VM do Hermes e execute um diagn\u00f3stico de rede com <\/span><span style=\"font-weight: 400;\">dig &lt;SEU_DOMINIO&gt;<\/span><span style=\"font-weight: 400;\"> para conferir o apontamento.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Container do Hermes apresenta falhas ao conectar ao PostgreSQL<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Sintoma:<\/b><span style=\"font-weight: 400;\"> o comando <\/span><span style=\"font-weight: 400;\">docker logs<\/span><span style=\"font-weight: 400;\"> indica erros intermitentes de conex\u00e3o com a base de dados (<\/span><span style=\"font-weight: 400;\">timeout<\/span><span style=\"font-weight: 400;\"> ou autentica\u00e7\u00e3o rejeitada).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Causa:<\/b><span style=\"font-weight: 400;\"> o par\u00e2metro <\/span><span style=\"font-weight: 400;\">listen_addresses<\/span><span style=\"font-weight: 400;\"> no banco n\u00e3o engloba a rede privada, as chaves do <\/span><span style=\"font-weight: 400;\">pg_hba.conf<\/span><span style=\"font-weight: 400;\"> barram a origem ou as regras de ACL da VPC impedem o tr\u00e1fego na porta 5432.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Solu\u00e7\u00e3o:<\/b><span style=\"font-weight: 400;\"> valide as linhas do <\/span><span style=\"font-weight: 400;\">postgresql.conf<\/span><span style=\"font-weight: 400;\"> e <\/span><span style=\"font-weight: 400;\">pg_hba.conf<\/span><span style=\"font-weight: 400;\"> no servidor de dados, certifique-se de reiniciar o servi\u00e7o do PostgreSQL e confira a tabela de ACL da VPC liberando o tr\u00e1fego entre as sub-redes.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Container em estado de encerramento (&#8220;Exited&#8221;)<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Sintoma:<\/b><span style=\"font-weight: 400;\"> o comando <\/span><span style=\"font-weight: 400;\">docker ps -a<\/span><span style=\"font-weight: 400;\"> indica que a aplica\u00e7\u00e3o encerrou a execu\u00e7\u00e3o abruptamente.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Causa:<\/b><span style=\"font-weight: 400;\"> parametriza\u00e7\u00e3o incorreta de vari\u00e1veis de ambiente no arquivo <\/span><span style=\"font-weight: 400;\">.env<\/span><span style=\"font-weight: 400;\"> ou aus\u00eancia da propriedade <\/span><span style=\"font-weight: 400;\">DATABASE_URL<\/span><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Solu\u00e7\u00e3o:<\/b><span style=\"font-weight: 400;\"> inspecione os logs t\u00e9cnicos com <\/span><span style=\"font-weight: 400;\">docker logs hermes_app_container<\/span><span style=\"font-weight: 400;\">, realize as corre\u00e7\u00f5es necess\u00e1rias nas strings do arquivo <\/span><span style=\"font-weight: 400;\">.env<\/span><span style=\"font-weight: 400;\"> e execute novamente o deploy com <\/span><span style=\"font-weight: 400;\">docker compose up -d<\/span><span style=\"font-weight: 400;\">.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n    \t\t<div class=\"hts-messages hts-messages--success  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Pronto!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tO ambiente seguro e de alta performance para hospedar o Hermes no Locaweb Cloud foi orquestrado com sucesso! Isolamos a camada de dados atrav\u00e9s das Tiers da VPC, aplicamos pol\u00edticas restritas de firewall, persistimos os dados em disco dedicado com montagem est\u00e1vel por UUID, padronizamos a entrega com Docker e protegemos o tr\u00e1fego com HTTPS via Let&#8217;s Encrypt. Tudo isso mantendo a previsibilidade or\u00e7ament\u00e1ria da sua empresa.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Conhe\u00e7a!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Quer proteger a identidade da sua marca e profissionalizar o contato com seus clientes? Conhe\u00e7a os planos de <\/span><a href=\"https:\/\/www.locaweb.com.br\/email-profissional\/\"><b>Email Profissional<\/b><\/a><span style=\"font-weight: 400;\"> e <\/span><a href=\"https:\/\/www.locaweb.com.br\/registro-de-dominio-web\/\"><b>Registro de Dom\u00ednio<\/b><\/a><span style=\"font-weight: 400;\"> da Locaweb e centralize sua presen\u00e7a digital no mesmo ecossistema com o melhor custo-benef\u00edcio.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n","protected":false},"excerpt":{"rendered":"<p>Pr\u00e9-requisitos Para acompanhar a implementa\u00e7\u00e3o arquitetural deste guia, certifique-se de cumprir os seguintes requisitos: Conta ativa no Locaweb Cloud: com acesso liberado ao painel de controle. Chave de autentica\u00e7\u00e3o SSH: uma chave privada SSH (arquivo .key ou .pem) gerada e com a respectiva chave p\u00fablica cadastrada no painel do Locaweb&#8230;<\/p>\n","protected":false},"author":29,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"footnotes":""},"ht-kb-category":[666],"ht-kb-tag":[],"class_list":["post-38792","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-locaweb-cloud"],"_links":{"self":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/38792","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/comments?post=38792"}],"version-history":[{"count":1,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/38792\/revisions"}],"predecessor-version":[{"id":38795,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/38792\/revisions\/38795"}],"wp:attachment":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/media?parent=38792"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb-category?post=38792"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb-tag?post=38792"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}