Day 10: From 32.196.145.76:3000 to sirvickcloud9.online — How I Hosted My DevOps Portfolio Like a Real Cloud Engineer




For 9 days I have been sharing NGold — my Netflix clone — on an IP address. Yesterday someone on Instagram asked me: "SirVick, do you actually know networking or just docker run?" That question hit me. Because he was right. Sharing 32.196.145.76:3000 is not        DevOps. It is just running a container.

So I stopped everything and built what you now see at sirvickcloud9.online. This is not a template portfolio. This is infrastructure.

If you open the site today you will see three sections I built: 

Top hero says "Building Reliable Systems — DevOps & Cloud Solutions. I'm Uko Sirvick, an entry-level Cloud, DevOps and System Administration professional learning by building practical infrastructure, automation and deployment projects." 

Second section says "Turning ideas into scalable infrastructure. I enjoy solving technical problems, learning cloud technologies and building systems that are secure, reliable and easier to maintain. My current focus includes AWS Cloud, DevOps, Linux, networking, system administration and CI/CD automation." 

Third section is "Tools & Technologies" — AWS, Linux/Ubuntu, Git, GitHub, GitHub Actions, Docker, Kubernetes, Terraform, Jenkins, Nginx, Networking, Datadog.

But what you don't see is what makes this DevOps. Behind sirvickcloud9.online is everything they asked me about: VPC, Subnet, Internet Gateway, NAT Gateway, Nginx Reverse Proxy, SSL, and GitHub Actions CI/CD.


Figure 2: Day 10 Production Architecture for sirvickcloud9.online — Internet → Route 53 → IGW → VPC Public Subnet (10.0.1.0/24) → EC2 with Nginx Reverse Proxy (SSL Certbot) → UFW (22,80,443) + Fail2ban → Docker Container 127.0.0.1:3000. Deployed via GitHub Actions CI/CD → Docker Hub.


Let me break it down with the Port Harcourt compound analogy I used on Day 8.

VPC is the compound. When I launched my EC2, AWS put it inside a VPC — my fenced land. Inside that land I have subnets — rooms. My EC2 is in a public subnet. What makes it public? Route Table. I ran aws ec2 describe-route-tables and saw 0.0.0.0/0 -> igw-xxxxxxxx. That means any traffic with no specific route goes to Internet Gateway. IGW is the main gate of the compound that connects our private land to the outside world internet. Without IGW, no one can reach sirvickcloud9.online even if Nginx is running.

I also learned about private subnet. My database — if I had RDS — would be in private subnet where route table does NOT have IGW. Instead it has NAT Gateway. NAT is like a window in a private room: you inside can look out and download updates from internet, but outsiders cannot look in or enter. That is why on Day 8 I stopped my EC2 that had port 3000 open to 0.0.0.0/0 — I was exposing my private room directly through main gate.

How sirvickcloud9.online is hosted correctly:

Step 1:  Elastic IP. I allocated Elastic IP in AWS EC2 Console and associated to my instance. Why? Because every time you stop/start EC2, AWS gives you new public IP. If I used random IP for A Record, my domain would break every morning. Elastic IP stays same forever. Cost is free if attached to running instance. My old IP 32.196.145.76 is now replaced by Elastic IP.

Step 2:  DNS A Record. On Namecheap where I bought sirvickcloud9.online, I created A Record Host @ Value [My Elastic IP]. And CNAME www to @. After 5 minutes, nslookup sirvickcloud9.online started returning my Elastic IP. That connects domain name to compound gate.

Step 3:  Nginx Reverse Proxy — the receptionist. I SSHed and installed Nginx: sudo apt install nginx -y. Then I created config /etc/nginx/sites-available/sirvickcloud9.online:javascriptserver

{

    listen 80;

    server_name sirvickcloud9.online www.sirvickcloud9.online;

    location / {

        proxy_pass http://127.0.0.1:3000;

        proxy_set_header Host $host;

        proxy_set_header X-Real-IP $remote_addr;

        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

    }

}

Critical change: My Docker now runs docker run -d -p 127.0.0.1:3000:3000 --restart unless-stopped --name portfolio. Note 127.0.0.1:3000:3000 not 0.0.0.0:3000:3000. This means portfolio container only listens inside EC2, not to internet. Only Nginx can talk to it. Then I closed port 3000 in Security Group — only 80, 443, 22 allowed. This fixed the AWS attack alert from Day 7.

Step 4: SSL with Let's Encrypt. I ran sudo certbot --nginx -d sirvickcloud9.online -d www.sirvickcloud9.online and chose Redirect HTTP to HTTPS. Now https shows green lock. No more "Not Secure". Google trusts it.

Step 5:  CI/CD so I never SSH again. I created .github/workflows/deploy.yml in my portfolio GitHub repo. I stored secrets in GitHub Settings > Secrets: EC2_HOST = my Elastic IP, EC2_SSH_KEY = my private .pem, DOCKER_USERNAME. The workflow builds and pushes to Docker Hub, then SSH into EC2 and restarts container and reloads Nginx.

Now my workflow is: Edit code in VS Code in Port Harcourt -> git push origin main -> GitHub Actions robot builds and deploys -> sirvickcloud9.online updates in 90 seconds. No SSH, no manual docker pull.

This is what Day 10 taught me: DevOps is not about running containers. It is about hiding them behind proper networking. Your users should never see IP:port. They should see domain with SSL, served by Nginx, running in public subnet with IGW, with private resources hidden behind NAT, and deployed automatically.

My site is live again. Not at 32.196.145.76:3000, but at sirvickcloud9.online. Professional link for LinkedIn, CV, and clients.

Tomorrow Day 11: I will talk about the container clusters of Kubernetes in docker. How it can help make deployment and container running easy.

Have you hosted your own portfolio on EC2 with Nginx? What did you use for SSL?


Also read: How I locked Down my NGold VPC After Attack         https://sirvick-deployments.blogspot.com/2026/10/route-tables-security-groups-are-real.html

Comments

Popular posts from this blog

How I Fixed GitHub Error: failed to push some refs to github.com in 2026

How I Deployed Netflix Clone (NGold) to AWS EC2 - Live at 32.196.145.76:3000 [Docker + Nginx Guide]

Understanding Linux Environment — The Real Engine Behind My AWS Cloud Deployment