Introduction
This article is the second in a series of contributions dedicated to methodologies and software for the online publication of archaeological geographic data. Please refer to the specific article for an introduction to open source software for sharing geographic data online.
In this article we will take a very practical, hands-on approach to the process of installing the most recent version of GeoNode, whose source code is available in the corresponding GitHub repository. At the time of publishing this article (October 2022), the most recent available version of GeoNode is 4.0.0.
As is well known, GeoNode can be installed on various operating systems and platforms; however, a production environment with fairly high requirements is needed. Indeed, for the software to perform well, it requires a 64-bit architecture, 16GB of RAM, a 2.2GHz, 4-core processor, and a minimum of 30GB of disk space dedicated solely to the program.
This guide describes installation on a Linux operating system from the Debian family, specifically Ubuntu 20.4. This choice is due to the very widespread use today of Debian/Ubuntu operating systems in the server world, so it is quite likely that, if you purchase a VPS service, you will find yourself with one of these operating systems.
Finally, there are various ways to install GeoNode, and in this guide we will follow the one based on Docker, also recommended in the official guide. Docker is a software platform that makes it possible to build, test and deploy applications with maximum speed, since it packages software into standardized units called containers that provide everything needed for their correct execution, including libraries, system tools, code and the runtime. With Docker, it is possible to deploy and rescale the resources for an application in any environment, always keeping the executed code under control. In other words, with Docker it is possible to create execution environments that are entirely similar or identical across platforms (hardware and operating system) that may otherwise be very different from one another.
Requirements
To follow the installation process explained below, you will need to already have available a virtual or physical machine with the most recent version of Ubuntu preinstalled, namely version 20.10. You will need access to the machine’s terminal, since all the installation and configuration operations require terminal access. If it is a remote machine, you will therefore need ssh access. This guide does not cover the operating system installation phase or the initial login to the machine. There are now a great many cloud-based solutions, some quite inexpensive, that let you purchase a very efficient VPS (Virtual Private Server) service. For the sake of simplicity, among the many available options we can mention OVH Cloud and Hetzner, companies with which we have no affiliation beyond having used their services for projects of various scale.
Note
Some of the commands listed below require administrator-level system access to run. Such commands are easy to spot, as they are preceded by the word sudo, an acronym for the English phrase Super User Do. Depending on how the system is configured, running a command with sudo may prompt for a password. In some configurations, the root user is not asked for a password.
Installation guide
1. Installing generic dependencies
To work, GeoNode needs a number of generic software packages related to GIS functionality. Although generic, these libraries and software are nonetheless specialized, related to spatial visualization and analysis, and are therefore not available in Ubuntu’s main repository, called Main. A Linux repository can be thought of as a centralized registry where software and libraries are listed and made available for easy installation; for more on this topic, see the article (in English) available at the following address: https://itsfoss.com/ubuntu-repositories/.
1.1. Adding the UbuntuGIS repository
The required packages are maintained in the Ubuntugis repository. This is an official repository specialized for the GIS world that makes it easy to install the software and packages needed to work with geographic data. Among the many resources this repository provides access to, we can mention:
- the GDAL library, used for reading and writing numerous geographic data formats,
- GRASS,
- Mapnik,
- Leaflet, a JavaScript library for developing interactive geographic maps,
- Mapserver
- etc.
We add the repository to the list of available and enabled repositories:
sudo add-apt-repository ppa:ubuntugis/ppaAnd then we update the index:
sudo apt update –yRemember that -y stands for yes and makes it possible to suppress any confirmation prompts from the installer, answering yes to all of them.
1.2. Installing generic dependencies
We are now ready to install a series of packages and libraries needed for the GeoNode installation. Here too, we provide the default -y answer to speed up the installation process.
sudo apt install -y python3-gdal=3.3.2+dfsg-2~focal2 gdal-bin=3.3.2+dfsg-2~focal2 libgdal-dev=3.3.2+dfsg-2~focal2 python3-pip python3-dev python3-virtualenv python3-venv virtualenvwrapper libxml2 libxml2-dev gettext libxslt1-dev libjpeg-dev libpng-dev libpq-dev software-properties-common build-essential git unzip gcc zlib1g-dev libgeos-dev libproj-dev sqlite3 spatialite-bin libsqlite3-mod-spatialiteIn the command just entered, the various packages are listed separated by spaces. Among others, the command above will install:
- Python3-gdal, which allows Python to manipulate GDAL (Geospatial Data Abstraction Library) data,
- GEOS, which provides the system with fundamental geometric functions on spatial data,
- PROJ, for managing map projections and geospatial extensions
- SQLite,
- etc.
2. Installing Docker
As mentioned in the opening paragraphs, GeoNode will be installed as a Docker container, so it is essential to install the necessary preliminary packages. It is therefore necessary to enable the Universe repository, a standard Ubuntu repository which, similarly to the Main repository, contains FOSS (free and open source) software, but unlike Main it is not maintained by the Ubuntu developers, who do not guarantee regular security updates.
2.1 Adding the Universe repository
sudo add-apt-repository universeNext, we need to update the index:
sudo apt-get update –y2.2. Installing Docker’s dependencies
At this point we are ready to install Docker’s dependencies, including git and some packages for the security of the installation:
sudo apt-get install -y git-core git-buildpackage debhelper devscripts apt-transport-https ca-certificates curl gnupg-agent software-properties-common2.3. Installing Docker’s cryptographic key
We are almost ready to download Docker for Ubuntu from the official site; we just first need to download and install a verification cryptographic key that ensures the package to be installed is exactly the one officially released. We will use cURL to download the key and apt-key add to install it:
curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo apt-key add -2.4. Adding Docker’s specific repository
We can now add Docker’s repository and update the index:
sudo add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu focal stable"sudo apt-get update –y2.5 Installing Docker
And finally we can install Docker:
sudo apt-get install -y docker-ce docker-ce-cli containerd.io2.6. Installing Docker Compose
Unlike the official guide, which you can find at this link, the installation described here involves updating Docker Compose to version 1.29. Docker Compose is a tool developed to define and share applications made up of many containers:
curl -L "https://github.com/docker/compose/releases/download/1.29.2/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-composechmod +x /usr/local/bin/docker-composesudo usermod -aG docker ${USER}The three commands above, in order:
- download the package,
- make it executable, adding execute permissions (
+x) to the file, - add the current user (i.e. ours, the one performing the installation) to the
dockergroup (more information here),
3. Installing GeoNode
3.1. Creating the folder and configuring permissions
At this point we can install GeoNode, so we create the folder that will hold the installation (the -p option makes it possible to automatically create all the subfolders of the given path):
sudo mkdir -p /opt/geonode/The permissions of the folder just created and of the logged-in user ($USER) are configured as follows:
sudo usermod -a -G www-data $USERsudo chown -Rf $USER:www-data /opt/geonode/sudo chmod -Rf 775 /opt/geonode/In detail, the commands above make it possible to:
- add the
logged-in user ($USER)to thewww-datagroup, the same group used by the web server (apache) - change the owning user and primary group of the
/opt/geonodefolder; the new owning user will be thelogged-in user ($USER)and the new primary group will bewww-data - change the permissions of the
opt/geonodedirectory to775, which means the owner and members of the primary group can read, write and execute the files in the folder, while other users can only read and execute them.
At this point we move into the /opt folder and clone the official GeoNode repository there using git; specifically, we will install version 4.0.0post1 of GeoNode:
3.2. Downloading, installing and starting GeoNode
cd /opt/geonodegit clone https://github.com/GeoNode/geonode.git -b 4.0.0post1 .We move into the folder containing the program files and install (perform a build of) the software:
cd /opt/geonodedocker-compose build --no-cacheOnce the installation phase is complete, which takes a few minutes, the packages can be started and made active using the command.
docker-compose up –d4. Configuring GeoNode
At this point GeoNode is installed and running, but it needs to be configured with a few minimal, customized parameters for optimal use. GeoNode’s configuration is centralized and handled by a single file that contains the main settings in the form of simple variables, which are loaded when the program starts and are part of the execution environment.
The file is /opt/geonode/.env, and a simple text editor is all that is needed to modify it.
For simplicity, this guide will use nano, an editor that is often included in Linux installations.
4.1. Authentication and authorization system
To understand how to fill in some of these parameters, it is worth briefly explaining GeoNode’s authentication and authorization system and its relationship with the other components it uses for certain operations, such as GeoServer.
GeoNode has an authentication system based on the security system of Django, the framework used to build the software, which lets the program manage users, groups, roles and permissions, while other integrated components such as GeoServer have their own authentication system, which needs to be synchronized with GeoNode’s. GeoNode interacts with GeoServer using a security system based on the OAuth2 protocol; this allows users registered on GeoNode to access GeoServer directly.
GeoNode is enabled to act as an OAuth Provider to certify the authenticity of the user’s identity, thereby allowing the system to work in an isolated environment and allowing the software itself to authenticate private users managed by Django’s authentication subsystem.
So in the .env file we will find three entries related to the authentication system:
- OAUTH2_CLIENT_ID
- OAUTH2_CLIENT_SECRET
- SECRET_KEY
GeoNode’s installation normally assigns the following default values to these entries:
OAUTH2_CLIENT_ID=Jrchz2oPY3akmzndmgUTYrs9gczlgoV20YPSvqaVOAUTH2_CLIENT_SECRET=rCnp5txobUo83EpQEblM8fVj3QT5zb5qRfxNsuPzCqZaiRyIoxM4jdgMiZKFfePBHYXCLd7B8NlkfDBY9HKeIQPcy5Cp08KQNpRHQbjpLItDHv12GvkSeXp6OxaUETv3SECRET_KEY='myv-y4#7j-d*p-__@j#*3z@!y24fz8%^z2v6atuy4bo9vqr1_a'These values are also accessible through the graphical interface, in the admin area under Home > Django OAuth Toolkit > Applications > GeoServer, which we recommend changing once the installation is complete, both in the .env file and in the admin section.
For more information, you can read GeoNode’s specific chapter on the Authentication and Authorization system at this link.
Per aprire e modificare il file, eseguire:
nano /opt/geonode/.env4.1. The .env file
In the next paragraphs we will suggest a few changes to the .env file useful for customizing GeoNode, without claiming to be exhaustive.
Note: it is very important to keep the .env file secret in production, since it contains passwords, cryptographic keys and other sensitive data for your application.
Let’s start with a short list of the entries to change, and then give a complete version of the file after the changes.
GEONODE_LB_HOST_IP(around line 12 of the file): should be set to the domain name where the installation will be available. Purely as an example, we use a fake domain: geonode.example.comGEONODE_LB_PORT(around line 13 of the file): should be set to the port where the installation will be available. Normally, the default port for thehttpprotocol is 80, and it is often omitted. Purely as an example, we use port 80SITEURL(around line 35 of the file): should be set to the full URL of the domain where the installation will be available. To continue the previous example, we use a fake URL: https://geonode.example.comADMIN_EMAIL=admin@geonode.example.comDEFAULT_FROM_EMAIL='GeoNode <no-reply@geonode.example.com>'
The three settings related to OAUTH2_CLIENT_ID, OAUTH2_CLIENT_SECRET and SECRET_KEY were already discussed in the previous paragraph.
COMPOSE_PROJECT_NAME=geonodeDOCKERHOST=DOCKER_HOST_IP=DOCKER_ENV=productionDOCKER_API_VERSION="1.24"BACKUPS_VOLUME_DRIVER=localC_FORCE_ROOT=1FORCE_REINIT=falseINVOKE_LOG_STDOUT=trueDJANGO_SETTINGS_MODULE=geonode.settingsGEONODE_INSTANCE_NAME=geonodeGEONODE_LB_HOST_IP=geonode.example.comGEONODE_LB_PORT=80PUBLIC_PORT=80NGINX_BASE_URL=POSTGRES_USER=postgresPOSTGRES_PASSWORD=postgresGEONODE_DATABASE=geonodeGEONODE_DATABASE_PASSWORD=geonodeGEONODE_GEODATABASE=geonode_dataGEONODE_GEODATABASE_PASSWORD=geonode_dataGEONODE_DATABASE_SCHEMA=publicGEONODE_GEODATABASE_SCHEMA=publicDATABASE_HOST=dbDATABASE_PORT=5432DATABASE_URL=postgis://geonode:geonode@db:5432/geonodeGEODATABASE_URL=postgis://geonode_data:geonode_data@db:5432/geonode_dataGEONODE_DB_CONN_MAX_AGE=0GEONODE_DB_CONN_TOUT=5DEFAULT_BACKEND_DATASTORE=datastoreBROKER_URL=amqp://guest:guest@rabbitmq:5672/CELERY_BEAT_SCHEDULER=celery.beat:PersistentSchedulerASYNC_SIGNALS=True
SITEURL=https://geonode.example.com
ALLOWED_HOSTS=['django', '*']DEFAULT_BACKEND_UPLOADER=geonode.importerTIME_ENABLED=TrueMOSAIC_ENABLED=FalseHAYSTACK_SEARCH=FalseHAYSTACK_ENGINE_URL=http://elasticsearch:9200/HAYSTACK_ENGINE_INDEX_NAME=haystackHAYSTACK_SEARCH_RESULTS_PER_PAGE=200
HTTP_HOST=HTTPS_HOST=https://geonode.example.com
HTTP_PORT=80HTTPS_PORT=443
LETSENCRYPT_MODE=disabled
RESOLVER=127.0.0.11
GEOSERVER_WEB_UI_LOCATION=http://localhost/geoserver/GEOSERVER_PUBLIC_LOCATION=http://localhost/geoserver/GEOSERVER_LOCATION=http://geoserver:8080/geoserver/GEOSERVER_ADMIN_USER=adminGEOSERVER_ADMIN_PASSWORD=geoserver
OGC_REQUEST_TIMEOUT=30OGC_REQUEST_MAX_RETRIES=1OGC_REQUEST_BACKOFF_FACTOR=0.3OGC_REQUEST_POOL_MAXSIZE=10OGC_REQUEST_POOL_CONNECTIONS=10
ENABLE_JSONP=trueoutFormat=text/javascriptGEOSERVER_JAVA_OPTS="-Djava.awt.headless=true -Xms2G -Xmx4G -XX:+UnlockDiagnosticVMOptions -XX:+LogVMOutput -XX:LogFile=/var/log/jvm.log -XX:PerfDataSamplingInterval=500 -XX:SoftRefLRUPolicyMSPerMB=36000 -XX:-UseGCOverheadLimit -XX:+UseConcMarkSweepGC -XX:ParallelGCThreads=4 -Dfile.encoding=UTF8 -Djavax.servlet.request.encoding=UTF-8 -Djavax.servlet.response.encoding=UTF-8 -Duser.timezone=GMT -Dorg.geotools.shapefile.datetime=false -DGEOSERVER_CSRF_DISABLED=true -DPRINT_BASE_URL=http://geoserver:8080/geoserver/pdf -DALLOW_ENV_PARAMETRIZATION=true -Xbootclasspath/a:/usr/local/tomcat/webapps/geoserver/WEB-INF/lib/marlin-0.9.3-Unsafe.jar -Dsun.java2d.renderer=org.marlin.pisces.MarlinRenderingEngine"
ADMIN_USERNAME=adminADMIN_PASSWORD=adminADMIN_EMAIL=admin@geonode.example.com
EMAIL_ENABLE=FalseDJANGO_EMAIL_BACKEND=django.core.mail.backends.smtp.EmailBackendDJANGO_EMAIL_HOST=localhostDJANGO_EMAIL_PORT=25DJANGO_EMAIL_HOST_USER=DJANGO_EMAIL_HOST_PASSWORD=DJANGO_EMAIL_USE_TLS=FalseDJANGO_EMAIL_USE_SSL=FalseDEFAULT_FROM_EMAIL='GeoNode <no-reply@geonode.example.com>'
LOCKDOWN_GEONODE=FalseCORS_ALLOW_ALL_ORIGINS=TrueX_FRAME_OPTIONS="SAMEORIGIN"SESSION_EXPIRED_CONTROL_ENABLED=TrueDEFAULT_ANONYMOUS_VIEW_PERMISSION=TrueDEFAULT_ANONYMOUS_DOWNLOAD_PERMISSION=True
ACCOUNT_OPEN_SIGNUP=TrueACCOUNT_EMAIL_REQUIRED=TrueACCOUNT_APPROVAL_REQUIRED=FalseACCOUNT_CONFIRM_EMAIL_ON_GET=FalseACCOUNT_EMAIL_VERIFICATION=noneACCOUNT_EMAIL_CONFIRMATION_EMAIL=FalseACCOUNT_EMAIL_CONFIRMATION_REQUIRED=FalseACCOUNT_AUTHENTICATION_METHOD=username_emailAUTO_ASSIGN_REGISTERED_MEMBERS_TO_REGISTERED_MEMBERS_GROUP_NAME=True
OAUTH2_API_KEY=OAUTH2_CLIENT_ID=Jrchz2oPY3akmzndmgUTYrs9gczlgoV20YPSvqaVOAUTH2_CLIENT_SECRET=rCnp5txobUo83EpQEblM8fVj3QT5zb5qRfxNsuPzCqZaiRyIoxM4jdgMiZKFfePBHYXCLd7B8NlkfDBY9HKeIQPcy5Cp08KQNpRHQbjpLItDHv12GvkSeXp6OxaUETv3
API_LOCKDOWN=FalseTASTYPIE_APIKEY=
DEBUG=False
SECRET_KEY='myv-y4#7j-d*p-__@j#*3z@!y24fz8%^z2v6atuy4bo9vqr1_a'
STATIC_ROOT=/mnt/volumes/statics/static/MEDIA_ROOT=/mnt/volumes/statics/uploaded/GEOIP_PATH=/mnt/volumes/statics/geoip.db
CACHE_BUSTING_STATIC_ENABLED=False
MEMCACHED_ENABLED=FalseMEMCACHED_BACKEND=django.core.cache.backends.memcached.MemcachedCacheMEMCACHED_LOCATION=127.0.0.1:11211MEMCACHED_LOCK_EXPIRE=3600MEMCACHED_LOCK_TIMEOUT=10
MAX_DOCUMENT_SIZE=2CLIENT_RESULTS_LIMIT=5API_LIMIT_PER_PAGE=1000
GEONODE_CLIENT_LAYER_PREVIEW_LIBRARY=mapstoreMAPBOX_ACCESS_TOKEN=BING_API_KEY=GOOGLE_API_KEY=
MONITORING_ENABLED=TrueMONITORING_DATA_TTL=365USER_ANALYTICS_ENABLED=TrueUSER_ANALYTICS_GZIP=TrueCENTRALIZED_DASHBOARD_ENABLED=FalseMONITORING_SERVICE_NAME=local-geonodeMONITORING_HOST_NAME=geonode
MODIFY_TOPICCATEGORY=TrueAVATAR_GRAVATAR_SSL=TrueEXIF_ENABLED=TrueCREATE_LAYER=TrueFAVORITE_ENABLED=True
RESOURCE_PUBLISHING=FalseADMIN_MODERATE_UPLOADS=False
POSTGRESQL_MAX_CONNECTIONS=200
DEFAULT_MAX_UPLOAD_SIZE=5368709120DEFAULT_MAX_PARALLEL_UPLOADS_PER_USER=100
LDAP_ENABLED=FalseLDAP_SERVER_URL=ldap://<the_ldap_server>LDAP_BIND_DN=uid=ldapinfo,cn=users,dc=ad,dc=example,dc=orgLDAP_BIND_PASSWORD=<something_secret>LDAP_USER_SEARCH_DN=dc=ad,dc=example,dc=orgLDAP_USER_SEARCH_FILTERSTR=(&(uid=%(user)s)(objectClass=person))LDAP_GROUP_SEARCH_DN=cn=groups,dc=ad,dc=example,dc=orgLDAP_GROUP_SEARCH_FILTERSTR=(|(cn=abt1)(cn=abt2)(cn=abt3)(cn=abt4)(cn=abt5)(cn=abt6))LDAP_GROUP_PROFILE_MEMBER_ATTR=uniqueMember4.2. Restarting GeoNode
Once you have finished editing the .env file, you need to restart the services so that the new settings take effect:
docker-compose up –dProcedures for checking that the services started correctly
You can run some checks to verify that all the installed and enabled services are working correctly.
docker-compose psProvides a list of the containers in a Compose project, with their current status and exposed ports. More information: https://docs.docker.com/engine/reference/commandline/compose_ps/
docker-compose logs -f djangoDisplays the logs of the django framework on screen. The -f option makes it show changes to the file in real time, effectively “following” it (f = follow). To exit the view, use the CTRL+C combination.
More information on the docker-compose logs command is available in the official guide, at: https://docs.docker.com/engine/reference/commandline/compose_logs/.
docker-compose logs -f geoserverDisplays the geoserver logs on screen, updating them in real time.
docker-compose logs -f dbDisplays the database logs on screen, updating them in real time.
docker-compose logs -f geonodeDisplays the GeoNode logs on screen, updating them in real time.
References
Docker
- Docker, official website, https://www.docker.com/
- What is Docker? AWS, https://aws.amazon.com/it/docker/
- Docker on Wikipedia, https://it.wikipedia.org/wiki/Docker
- Official guide to Docker Compose, https://docs.docker.com/get-started/08_using_compose/
Geonode
- GeoNode, official website, https://geonode.org/
- GeoNode, on GitHub, https://github.com/GeoNode/geonode
- GeoNode, security system, https://docs.geonode.org/en/master/advanced/components/index.html
- OAuth protocol, https://it.wikipedia.org/wiki/OAuth
- Django, https://www.djangoproject.com/
Linux, Debian, Ubuntu
- Debian, official website in Italian, https://www.debian.org/index.it.html
- Linux on Wikipedia, https://it.wikipedia.org/wiki/Linux
- Ubuntu operating system, Italian website, https://www.ubuntu-it.org
- UbuntuGIS https://wiki.ubuntu.com/UbuntuGIS
- Guide to Linux repositories, https://itsfoss.com/ubuntu-repositories/
- Official manual for the nano text editor, https://linux.die.net/man/1/nano
Cloud provider
- Hetzner https://www.hetzner.com
- OVH Cloud, https://www.ovhcloud.com/it/


