A website server runs one program: the starter site we put on it, or your own app. Everything else, the console, Files, SFTP, backups and the database, is the same panel as every other server.
A static site
A new website server already has a starter site running (app.py on Python, index.js on Node.js). It serves whatever is in the public folder:
- Open Files and go into
public(it is made on the first start). - Upload your site there, with
index.htmlat the top. Folders work as you would expect:public/about/index.htmlanswers at/about/. - That is all. No restart needed; the next visit gets the new files.
Hidden files (anything starting with a dot, like .env) are never served, and a folder without an index.html is a 404 rather than a list of its files.
An app
Replace the starter with your own program, or set Git repository in Startup and it is cloned on the next start (see deploying from Git). Whatever it is, it must listen on 0.0.0.0 and the port in the SERVER_PORT environment variable:
# Python, Flask
app.run(host="0.0.0.0", port=int(os.environ["SERVER_PORT"]))
// Node.js, Express
app.listen(process.env.SERVER_PORT, "0.0.0.0");
- Python:
requirements.txtinstalls on start. The file that runs isapp.py,main.pyor another single.pyat the top; set Startup > Start file to choose. For gunicorn or uvicorn, start them from your Python file. - Node.js:
package.jsoninstalls on start, and itsstartscript runs if there is one. Next.js and other frameworks with a build step can do"start": "next build && next start -p $SERVER_PORT -H 0.0.0.0". - Java: one runnable jar with its dependencies (Spring Boot's jar is one). Set
server.portfromSERVER_PORT.
Secrets go in a .env file at the top of the server (Files), never in the code. If your app stops, the console says why, the Crashes tab keeps it, and the server starts it again.
Your domain, with HTTPS
Until you add a domain, your site answers at the server's address and port from the Network tab, over plain HTTP, which is fine for trying it out. For HTTPS on your own domain, use the Website tab: add the domain, add the CNAME and TXT records it shows, and the certificate follows. The details are in your own domain, with HTTPS.
What a website server does not do
- PHP and WordPress. It runs Python, Node.js or Java programs, or serves plain files.
- Email for your domain. Keep it where it is; only your site's records point here.
- Ports 80 and 443 for your program. Your domain arrives on 443 and is passed to your port; your program never needs to listen on them.
Something here wrong or out of date? Tell us and it gets fixed.