Skip to content

Instantly share code, notes, and snippets.

Last active February 16, 2025 08:31
Show Gist options
  • Save piyushgarg-dev/8b14c87c8ff4d626ecbc747b6b9fc57f to your computer and use it in GitHub Desktop.
Save piyushgarg-dev/8b14c87c8ff4d626ecbc747b6b9fc57f to your computer and use it in GitHub Desktop.

Node.js Deployment

Steps to deploy a Node.js app to DigitalOcean using PM2, NGINX as a reverse proxy and an SSL from LetsEncrypt

1. Create Free AWS Account

Create free AWS Account at

2. Create and Lauch an EC2 instance and SSH into machine

I would be creating a t2.medium ubuntu machine for this demo.

3. Install Node and NPM

curl -sL | sudo -E bash -
sudo apt install nodejs

node --version

4. Clone your project from Github

git clone

5. Install dependencies and test app

sudo npm i pm2 -g
pm2 start index

# Other pm2 commands
pm2 show app
pm2 status
pm2 restart app
pm2 stop app
pm2 logs (Show log stream)
pm2 flush (Clear logs)

# To make sure app starts when reboot
pm2 startup ubuntu

6. Setup Firewall

sudo ufw enable
sudo ufw status
sudo ufw allow ssh (Port 22)
sudo ufw allow http (Port 80)
sudo ufw allow https (Port 443)

7. Install NGINX and configure

sudo apt install nginx

sudo nano /etc/nginx/sites-available/default

Add the following to the location part of the server block


    location / {
        proxy_pass http://localhost:8001; #whatever port your app runs on
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_cache_bypass $http_upgrade;
# Check NGINX config
sudo nginx -t

# Restart NGINX
sudo nginx -s reload

8. Add SSL with LetsEncrypt

sudo add-apt-repository ppa:certbot/certbot
sudo apt-get update
sudo apt-get install python3-certbot-nginx
sudo certbot --nginx -d -d

# Only valid for 90 days, test the renewal process with
certbot renew --dry-run
Copy link

ya it is working in other browser but not in chrome, please help me i have been struck in this more 2 months,

it is connected to port 80

sites-available file with the default


this is error log
listen 80

it will be great help . Thanks!

Copy link

I ran the "sudo certbot --nginx -d" command but I keep on running into the following error :
Do help me out not able to find much online

Copy link

agaur79 commented Jan 8, 2024

@piyushgarg-dev - Thanks for summarizing this in detail, really appreciate you making this document.
I would to add one point that made me a little bit of struggle, I hope this will help other people.

We need to enable the HTTPS port 443 in the AWS security group so that it is accessible to the outside world.
It took me a lot of time to figure it out.

Copy link

@agaur79 Exactly, I stuck there too, thanks for the comment

Copy link

ya it is working in other browser but not in chrome, please help me i have been struck in this more 2 months,

it is connected to port 80 image

sites-available file with the default image


this is error log image listen 80 image

it will be great help . Thanks!

You can check this ufw settings.
Also do read that warning before enabling the ufw

Copy link

I ran the "sudo certbot --nginx -d" command but I keep on running into the following error : image image Do help me out not able to find much online

Could you check the version of Ubuntu and run the command accordingly?

Copy link


It is showing me this error .How to resolve ?

Copy link


It is showing me this error .How to resolve ?

Brother u are not ugin lastest nodejs version
curl -fsSL | sudo bash -
sudo apt-get install -y nodejs

This will work surely

Copy link

ya it is working in other browser but not in chrome, please help me i have been struck in this more 2 months,

it is connected to port 80 image

sites-available file with the default image


this is error log image listen 80 image

it will be great help . Thanks!

Yes have u got the soluttion i am haing the EXACT same problem please help brother

Copy link

ya it is working in other browser but not in chrome, please help me i have been struck in this more 2 months,

it is connected to port 80 image

sites-available file with the default image


this is error log image listen 80 image

it will be great help . Thanks!

root /var/www/html;

    # Add index.php to the list if you are using PHP
    index index.html index.htm index.nginx-debian.html;


    location / {
alias /home/ubuntu/url-shortner;
try_files $uri $uri/ =404;


location /login {
proxy_pass http://localhost:8000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection 'upgrade';
proxy_set_header Host $host;
proxy_cache_bypass $http_upgrade;

Copy link

ravi-n4s commented May 5, 2024

if your machine SELinux (security enhanced linux), need to adjust the SELinux policies to allow Nginix to make the connection

Check the current SELinux policy for Nginx:
sudo getsebool -a | grep httpd

If httpd_can_network_connect is off, you can turn it on using the following command:
sudo setsebool -P httpd_can_network_connect 1

This command will allow Nginx to make network connections

Copy link

Anju12345hub commented May 6, 2024

$sudo certbot --nginx -d -d
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for and

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Type: dns
Detail: DNS problem: server failure at resolver looking up CAA for

Type: dns
Detail: DNS problem: server failure at resolver looking up CAA for

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.
-when i run the last command in this github ,I got this error.please help me to resolve this issue.

Copy link

how i could encrypt SSL for an ip address?

Copy link

anand-shete commented May 7, 2024

$sudo certbot --nginx -d -d Saving debug log to /var/log/letsencrypt/letsencrypt.log Requesting a certificate for and

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems: Domain: Type: dns Detail: DNS problem: server failure at resolver looking up CAA for

Domain: Type: dns Detail: DNS problem: server failure at resolver looking up CAA for

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet. -when i run the last command in this github ,I got this error.please help me to resolve this issue.

It seems like Certbot is having trouble authenticating your domains due to a DNS issue. The error message indicates that there is a problem with the DNS server's ability to look up the Certification Authority Authorization (CAA) records for the domains,, and
give your error prompt to chatgpt if doesn't work then stackoverflow if still doesn't then youtube.

Copy link

how i could encrypt SSL for an ip address?

just chatGPT and u will get all the command. just look it up and be cautious

Copy link

Here is ultimate solution 👍

After step 7 you need to add this step:

Reset everything, uninstall, and install.

sudo apt remove nginx
sudo aptinstall nginx

Create a file in the /etc/nginx/conf.d directory named domain‑name.conf (so in our example,
Run sudo nano /etc/nginx/conf.d/<domain‑name>.conf command

server {
	listen        80;
	server_name <>;
	location / {
		proxy_pass         http://localhost:3000;
		proxy_http_version 1.1;
		proxy_set_header   Upgrade $http_upgrade;
		proxy_set_header   Host $host;
		proxy_cache_bypass $http_upgrade;
		proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;
		proxy_set_header   X-Forwarded-Proto $scheme;

Save the file, then run this command to verify the syntax of your configuration and restart NGINX.
sudo nginx -t && sudo nginx -s reload

now you can go with step 8

Thanks me later 🥇

Copy link

rounakraj03 commented Jun 12, 2024

sudo certbot --nginx -d -d when i do this my site goes down and shows, 404 Not Found nginx/1.18.0 (Ubuntu) please help

Actually it is not working because in the inbound might didnt open port 443- which is for https!!!

(Hopefully that will solve the issue)

Copy link

Can we use only ec2 public (static) ip address instead of domain name ? and yes then what will be the process ?

Copy link

Can we use only ec2 public (static) ip address instead of domain name ? and yes then what will be the process ?

well it is possible. but, How you're gonna use it..

if you're making an app only for yourself i think then it will be fine. as even on free hosting platforms, they provide you a url for your app. as it is very hard to remember the ip address of the server. if you can remember that. then, you're good.

use freenom you'll get a domain name for free.

Copy link

freenom is always display domain not available ? any alternate option

Copy link

there are plenty's of domain available. join a hackathon which is sponsored by xyz. you'll a domain there, there are plenty of ways man. do google you'll get one for sure

Copy link

Hello everyone , recently I deployed nodejs application from these steps. I faced an issue after setting up ssl.. that my nginx was not able to read the certificate from certbort so i ended up giving read access to whole certbot folder under etc after it nginx was able to read the certificate but my domain was not working so I come to know that I have to add securtiy group for port 443 which is default for https and port 80 is http only. this security step is for those who is using aws ec2 or cloud machines to run the app.

Copy link

root@ubuntu-s-1vcpu-1gb-blr1-01:~# sudo certbot --nginx -d
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Type: unauthorized
Detail: 2a02:4780:11:1361:0:3136:f07e:8: Invalid response from 404

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Some challenges have failed.
Ask for help or search for solutions at See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

Copy link


Yes it relly happen

Copy link

I'm able to run my website on http, not https. Doesnt work at all for me ...
If there's any supportive discord ... im up to ... my discord username : hiyer63

Copy link

Mubtasimf443 commented Jan 24, 2025

Id you follow me on X Twitter I will also follow you .

This is a way to increase the network

Copy link

I am getting 502 BAD Gateway any one can help in resolving this?

Copy link

I am getting 502 BAD Gateway any one can help in resolving this?

can you provide your configuration so that it help to understand the actual issue happing.

Copy link

If anybody is getting 502 error , You can see My Nginx Config file what is successfully runing on production in aws ec2 instance

Visit My nginx config file :

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment