# Deployment guide (Ubuntu 22.04/24.04, nginx + PHP-FPM + MySQL + Redis)

## 1. Server packages
```bash
sudo apt install nginx mysql-server redis-server supervisor unzip git \
  php8.3-fpm php8.3-cli php8.3-mysql php8.3-mbstring php8.3-xml php8.3-curl php8.3-zip php8.3-intl php8.3-gd php8.3-bcmath php8.3-redis
curl -sS https://getcomposer.org/installer | php && sudo mv composer.phar /usr/local/bin/composer
```

## 2. Application
```bash
cd /var/www && sudo git clone <repo> infotics && cd infotics      # or upload the release zip
sudo chown -R $USER:www-data . && composer install --no-dev --optimize-autoloader
cp .env.production.example .env && php artisan key:generate --force   # then edit .env (DB, MAIL_*, APP_URL, …)
php artisan migrate --force
php artisan db:seed --force          # catalogue, exams, badges, FAQs, articles. Keep INFOTICS_SEED_DEMO=false
php artisan infotics:create-admin you@yourdomain.pk --name="Your Name"   # prints a password if --password is omitted
php artisan storage:link
php artisan infotics:build-assets   # bundle + minify the page stylesheets into one file (falls back to the source files if skipped)
php artisan optimize                 # config, route, view, event cache
sudo chown -R www-data:www-data storage bootstrap/cache && sudo chmod -R 775 storage bootstrap/cache
```
Re-run `php artisan optimize:clear && php artisan optimize` after every `.env` change or deploy.

## 3. Upload limits (videos/PDFs) — set all three
| Layer | Setting |
|---|---|
| PHP (`/etc/php/8.3/fpm/conf.d/99-uploads.ini`) | `upload_max_filesize=600M`, `post_max_size=610M`, `max_execution_time=300`, `memory_limit=512M` |
| nginx (server block) | `client_max_body_size 610m; client_body_timeout 300s; fastcgi_read_timeout 300s;` |
| App (`.env`) | `INFOTICS_VIDEO_MAX_MB=512`, `INFOTICS_FILE_MAX_MB=50` |
Restart php-fpm + nginx. The Admin/Trainer upload pages warn if the server limit is below the app limit. Behind Cloudflare the free plan limits request bodies to 100 MB — upload large videos via a DNS-only (grey cloud) hostname or use YouTube/Vimeo links in lessons.

## 4. nginx
Use `infra/docker/nginx.conf` as the base: root `/var/www/infotics/public`, `try_files $uri /index.php?$query_string`, `fastcgi_pass unix:/run/php/php8.3-fpm.sock`, deny dot-files except `.well-known`, long cache for `/assets/`. Issue TLS with `certbot --nginx`. Set `APP_URL=https://…`, `FORCE_HTTPS=true`, `SESSION_SECURE_COOKIE=true`.

## 5. Queue worker and scheduler
`/etc/supervisor/conf.d/infotics-worker.conf`
```
[program:infotics-worker]
command=php /var/www/infotics/artisan queue:work --sleep=1 --tries=3 --timeout=120 --max-jobs=500
user=www-data
autostart=true
autorestart=true
numprocs=2
process_name=%(program_name)s_%(process_num)02d
stopwaitsecs=130
redirect_stderr=true
stdout_logfile=/var/log/infotics-worker.log
```
Cron (`sudo crontab -u www-data -e`): `* * * * * cd /var/www/infotics && php artisan schedule:run >> /dev/null 2>&1`
After deploys: `sudo supervisorctl restart infotics-worker:*`.

## 6. Docker alternative
`docker compose -f infra/docker/docker-compose.enterprise.yml up -d --build` (app, nginx, MySQL, Redis, worker, scheduler). The image already includes `gd` and the upload limits. Copy `.env.production.example` to `infra/docker/.env.production` first.

## 7. Mail
Use a transactional SMTP provider. Set `MAIL_MAILER=smtp`, `MAIL_HOST/PORT/USERNAME/PASSWORD/ENCRYPTION`, `MAIL_FROM_ADDRESS=no-reply@yourdomain.pk`. Add SPF, DKIM and DMARC DNS records for the sending domain. Verify with `php artisan infotics:mail-test you@example.com`; failed mails appear in Admin → E-mail log and can be retried.

## 8. Backups & monitoring
Nightly `mysqldump` + copy of `storage/app/private` (videos, PDFs, resumes, payment proofs) off-server; test a restore. Health endpoint: `/up`. Watch `storage/logs/laravel.log` and the worker log; set `LOG_LEVEL=warning`.

## 9. Zero-downtime deploy sketch
`git pull && composer install --no-dev -o && php artisan migrate --force && php artisan infotics:build-assets && php artisan optimize && sudo supervisorctl restart infotics-worker:* && sudo systemctl reload php8.3-fpm`.
