Skip to content

System Overview & VPS Topology

The Planovi VPS Infrastructure (planovi-vps) manages the production and development infrastructure hosted on a dedicated Hostinger Cloud VPS instance (191.218.165.149). It provides containerized execution for all core Planovi backend services, API gateways, databases, reverse proxying, and CI/CD webhooks.


🖥️ Server Baseline & Hardware Specifications

ComponentProduction Configuration
ProviderHostinger Cloud VPS
Public IPv4191.218.165.149
Operating SystemUbuntu 24.04 LTS (x86_64)
Compute Resources4 vCPU cores, 16 GB RAM
Storage Subsystem200 GB NVMe SSD Storage
Container EngineDocker Engine 26.x + Docker Compose v2.x
Ingress ControllerNginx Alpine Reverse Proxy (vps-proxy)
Network ArchitectureCustom Docker Bridge Network (vps-network)

🏗️ End-to-End System Architecture

Incoming public traffic passes through Cloudflare edge DNS and proxies before entering the Nginx reverse proxy on the Hostinger VPS. Nginx terminates SSL using Cloudflare Wildcard certificates (*.planovi.app), applies dynamic IP whitelist restrictions for administrative interfaces, and proxies traffic to the internal Docker network.

flowchart TD
    CF["🌐 Cloudflare DNS & Edge SSL (*.planovi.app)"] --> NGINX["🛡️ vps-proxy (Nginx Alpine :80/:443)"]

    subgraph Admin_Restricted ["Restricted Access (IP Whitelist)"]
        NGINX -->|"supabase-studio.planovi.app"| STUDIO["📊 Supabase Studio (:3000)"]
        NGINX -->|"dev-supabase-studio.planovi.app"| STUDIODEV["📊 Supabase Studio DEV (:3000)"]
        NGINX -->|"docs.planovi.app / dev-docs"| DOCS["📚 Docs Portal (Cloudflare Pages Proxy)"]
    end

    subgraph APIs_and_Gateways ["Public APIs & Gateway Services"]
        NGINX -->|"api.planovi.app/deploy-webhook"| DEPLOYER["⚡ vps-deployer (:9000)"]
        NGINX -->|"api.planovi.app/*"| KONG["🚪 Supabase Kong Gateway (:8000)"]
        NGINX -->|"dev-api.planovi.app/*"| KONGDEV["🚪 Supabase Kong Gateway DEV (:8000)"]
        KONG --> AUTH["🔑 Supabase Auth (:9999)"]
        KONG --> REST["⚡ PostgREST (:3000)"]
        KONG --> STORAGE["📁 Storage API (:5000)"]
        KONG --> EDGE["⚡ Edge Runtime (:9000)"]
    end

    subgraph IoT_Telemetry ["Isolated IoT Telemetry Engine (mTLS)"]
        NGINX -->|"telemetry.planovi.app"| EDGERR_PROD["⚡ Edge Runtime PROD (:9000)"]
        NGINX -->|"dev-telemetry.planovi.app"| EDGERR_DEV["⚡ Edge Runtime DEV (:9000)"]
    end

    subgraph Web_and_Microservices ["Web Applications & Microservices"]
        NGINX -->|"cloud.planovi.app"| CONV_PROD["🔄 Converters API PROD (:8000)"]
        NGINX -->|"dev-cloud.planovi.app"| CONV_DEV["🔄 Converters API DEV (:8000)"]
        NGINX -->|"dealflow.planovi.app / scheduler"| PHP["🐘 PHP 8.3 Microservices (:80)"]
        NGINX -->|"panel.planovi.app / dev-panel"| FLUTTER["📱 Flutter Web Application"]
    end

    REST --> PG["💾 PostgreSQL 15 (supabase-db :5432)"]
    EDGE --> PG
    CONV_PROD --> PG

📁 Server Directory Hierarchy

The server filesystem strictly separates infrastructure definitions (/opt/vps-stack) from application codebases (/opt/vps-apps):

/
├── opt/
│ ├── vps-stack/ # 🛡️ INFRASTRUCTURE & CONTAINER ORCHESTRATION
│ │ ├── docker-compose.yml # Master Docker Compose configuration
│ │ ├── .env # Production secrets (Managed in PA Management)
│ │ ├── cloudflare-ssl/ # Cloudflare Origin SSL & Device CA certificates
│ │ ├── deployer/ # CI/CD Webhook deployer service
│ │ ├── php-app/ # PHP 8.3 microservices container runtime
│ │ ├── proxy/ # Nginx configuration, vhosts, and IP whitelists
│ │ ├── scripts/ # Automated maintenance, backup, and health check scripts
│ │ ├── supabase/ # Deno Edge Functions code directories
│ │ └── backups/ # Nightly compressed PostgreSQL database dumps
│ │
│ └── vps-apps/ # 🚀 APPLICATION SOURCE CODE (Automated git-pull)
│ ├── webpage/ # Public landing website (dev / prod)
│ ├── microservices/ # PHP dealflow and scheduler apps (dev / prod)
│ ├── flutter-app/ # Flutter Web dashboard builds (dev / prod)
│ ├── converters/ # Converter FastAPI microservices (dev / prod)
│ └── backend/ # Edge Functions repository (dev / prod)

⚙️ Kernel & Network Tuning (sysctl-tuning.conf)

High-throughput telemetry ingestion from IoT devices and concurrent database connections require optimized Linux kernel parameters. The host VPS applies the following settings in /etc/sysctl.d/99-planovi-vps.conf:

# Virtual Memory & Swappiness Optimization
vm.swappiness = 10
vm.vfs_cache_pressure = 50
vm.dirty_background_ratio = 5
vm.dirty_ratio = 10
# Network Core Socket Buffers
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
net.core.somaxconn = 65535
net.core.netdev_max_backlog = 10000
# TCP Congestion Control & Performance
net.ipv4.tcp_rmem = 4096 87380 16777216
net.ipv4.tcp_wmem = 4096 65536 16777216
net.ipv4.tcp_congestion_control = bbr
net.ipv4.tcp_fastopen = 3
net.ipv4.tcp_tw_reuse = 1
net.ipv4.tcp_fin_timeout = 15
# Connection Tracking Limits for Docker NAT
net.netfilter.nf_conntrack_max = 262144

These parameters prevent socket starvation during peak telemetry reporting cycles and ensure maximum efficiency under sustained network load.