All articles
DevOpsDec 15, 20257 min read

Zero-drama deployments on DigitalOcean with Nginx, PM2 and GitHub Actions

The exact production setup I use for Node apps: process management, reverse proxy, CI/CD runners, and the failure modes worth pre-empting.

01

One droplet, clear responsibilities

A single DigitalOcean Droplet is enough for many production Node apps — if you set it up right. My stack: Nginx terminates TLS and reverse-proxies to Node, PM2 manages Node processes with auto-restart, and Node.js/Express serves as the application server.

Nothing exotic — and that's the point. Every failure has an obvious place to look, making debugging a breeze.

02

CI/CD that a teammate can read

GitHub Actions builds the app, then a self-hosted runner pulls changes and reloads via PM2. The workflow has five stages: Build (`npm ci && npm run build`), Test (unit + integration tests, fail fast), Deploy (copy build artifacts to the droplet), Reload (`pm2 reload ecosystem.config.js`), and Health-check (hit `/health` endpoint, fail loudly if down).

  • `pm2 reload` instead of `restart` — zero-dropped-requests
  • Health-check step fails the deploy loudly rather than silently
  • Environment variables live on the server, never in the repo
  • Rollback is a single command: `pm2 restart ecosystem.config.js --env rollback`
03

The failures you'll actually hit (and how to fix them)

Permission mismatches on the runner user: fix by using `deploy` user with `sudo` for PM2 commands, but restrict SSH keys. Exhausted file descriptors: increase `ulimit -n 65535` in PM2 config. Nginx buffering large uploads: set `client_max_body_size 50M` and proxy buffering off for upload routes. Memory leaks in Node: use `node --max-old-space-size=512` and monitor with PM2's built-in metrics.

Each of these failures cost me an evening once, and each one is now a checklist item before go-live.

04

Blue-green deployments on a single droplet

Want zero-downtime without two droplets? Use Nginx to switch between two ports: deploy new version to port 3001 (staging), run smoke tests, then Nginx reload proxies to port 3001. The old version stays on port 3000, ready for instant rollback.

This strategy has saved my team during two critical incidents where the new version needed to be rolled back within 2 minutes.

05

Monitoring and alerting

Production-ready means proactive monitoring. I track PM2 metrics (CPU, memory, event loop lag), Uptime monitoring via UptimeRobot or Healthchecks.io, Error tracking through Sentry for exception alerts, and Log aggregation with Papertrail or ELK stack for centralized logs.

Set up alerts for: CPU > 80%, memory > 90%, and HTTP 5xx spikes. Early warning is the difference between a 5-minute fix and a 2-hour outage.


Written by

Tariq Mehmood

Full Stack MERN Developer

Work with me

Keep reading

Artificial Intelligence

Will AI Replace Developers in 2026? The Truth About the Future of Software Development

AI can now write code, debug applications, work across repositories, and handle complex development tasks. But will AI actually replace software developers? Here is what is really changing in software development in 2026.

Artificial Intelligence

AI Coding Agents in 2026: From Copilot to Autonomous Software Development

AI coding has moved beyond autocomplete. In 2026, developers are increasingly using agents to plan tasks, modify repositories, run tests, debug failures, and complete multi-step engineering work.

Cybersecurity

AI-Generated Code Security: How Developers Can Stay Safe in 2026

AI can accelerate development, but generated code can introduce security vulnerabilities. Learn how to build a safer AI-assisted development workflow with testing, code review, scanning, and human oversight.

Web Development

SvelteKit 3 vs Next.js in 2026: What Should Developers Choose?

SvelteKit 3 is challenging the dominant React framework approach with a simpler architecture and new RPC capabilities. Here is how SvelteKit and Next.js compare for modern web development.

Performance

Next.js 16.3 Performance Optimization Guide for 2026

A practical Next.js 16.3 performance guide covering Instant Navigations, Partial Prefetching, Server Components, caching, JavaScript delivery, and Core Web Vitals.

Engineering

AI Productivity in Software Engineering: How to Measure the Real Impact in 2026

AI adoption is widespread across software teams, but adoption alone does not prove productivity. Learn which engineering metrics can reveal whether AI is actually improving development.

React

React Performance in 2026: What Developers Should Actually Optimize

React performance optimization is changing with React Compiler, modern rendering patterns, Server Components, and better browser tooling. Here is what still matters.

Architecture

Modern Full-Stack JavaScript Architecture in 2026

Full-stack JavaScript applications are evolving around server rendering, API-driven systems, AI integrations, typed code, caching, and cloud deployment. Here is a practical architecture guide.

AI Engineering

MCP and AI Agents: Why Tool Connectivity Matters for Web Developers in 2026

AI agents are becoming more capable because they can interact with external tools and systems. Learn why MCP and tool connectivity are becoming important concepts for modern developers.

Web Development

Web Development Trends in 2026: 10 Changes Developers Need to Know

From AI coding agents and React Compiler to full-stack frameworks, security automation, and agent-ready applications, these are the web development trends shaping 2026.

AI Engineering

How to Build an AI-Ready Web Application in 2026

AI-ready applications need more than an API call. Learn how to design a modern web application with AI features, structured data, security, observability, evaluation, and scalable architecture.

Web Development

Next.js 16.3 Performance: How Instant Navigations and React Compiler Change Modern Web Apps

Next.js 16.3 brings instant navigations, partial prefetching, faster development, and deeper React Compiler integration. Here’s what developers should know about building faster React applications in 2026.

Engineering

React performance optimization: what actually moves the needle

Profiling data from a production React app — which optimizations cut real load time and interaction latency, and which ones were a waste of a sprint.

Engineering

TypeScript generics that make your APIs self-documenting

How I use generics, discriminated unions, and branded types to turn a TypeScript API layer into documentation that can't go stale.

Web Development

Structuring MERN APIs that survive production

How I lay out Express routes, Mongoose models, and role-based access so a MERN app stays readable after a year of feature requests.

AI Integration

Shipping AI agents that actually help customers

Lessons from building an OpenAI-powered chatbot and agent workflow for an industrial machinery business — grounding, RAG, and knowing when to hand off.

Cybersecurity

Next.js Security Update August 2026: What Developers Need to Know

Next.js is preparing a major security release for August 26, 2026. Here is what developers should know about the upcoming update, application security, dependency management, and production deployments.