# Deploying ANish 24 on Orange Host (shared hosting, cPanel + MySQL/MariaDB)

Orange Host has confirmed: no PostgreSQL, no VPS or Docker. They do offer MySQL/MariaDB, **Setup Node.js App** (Node 18.20.8 and 20.20.2), cron jobs every 5 minutes, free AutoSSL, and a one-month trial with a refund if it doesn't work. The app now runs on MariaDB/MySQL, so it fits.

Result: `https://school.aromanish.com`. Your main aromanish.com site is not touched.

**Know the limits.** The Micro plan has 1 CPU core, 1 GB RAM, 20 processes and 5 GB disk, shared with your website. That suits a pilot with one to a few schools. If you see slowness or "resource limit" errors, or have many schools, move to a VPS (`DEPLOY.md`). Your data moves with a normal database export.

**Security difference.** MySQL has no row-level security, so school separation now depends on the school_id filter in every query. It is written that way, but it has not been tested. Run the tests before real data (see the end of this guide).

## 1. Create the subdomain
cPanel > **Domains** > **Create A New Domain**: `school.aromanish.com`. Untick "Share document root" and use a new empty folder. The DNS record is added automatically because the site is hosted with them. AutoSSL issues the free certificate (minutes to a few hours). HTTPS is needed for phone install.

## 2. Create the database
cPanel > **MySQL Databases** (or the Wizard):
1. Create a database `anish24` (cPanel adds your prefix, e.g. `cpuser_anish24`).
2. Create a user, e.g. `anish`, with a password of letters and numbers only.
3. Add the user to the database with **ALL PRIVILEGES**.
Ask Orange Host (or check phpMyAdmin) for the server version. You need MariaDB 10.2+ or MySQL 5.7+.

## 3. Upload the app
cPanel > **File Manager**: go to your home folder (NOT `public_html`), upload `anish24-api.zip`, extract it. You should have `/home/cpuser/anish24-api`.

## 4. Create the Node.js app
cPanel > **Setup Node.js App** > **Create Application**:
- Node.js version: **20.20.2**
- Mode: Production
- Application root: `anish24-api`
- Application URL: `school.aromanish.com`
- Application startup file: `src/server.js`

Click **Create**, then **Run NPM Install**.

## 5. Settings file
In File Manager copy `.env.cpanel.example` to `.env` inside `anish24-api` and fill it in: the `DATABASE_URL` with your real prefixed names, and a random `JWT_SECRET` of 48+ characters. Set the file permission to 600.

## 6. Create the tables
On the Node.js app page: **Run JS script** > `migrate` (or in cPanel Terminal, enter the app's virtual environment, then `npm run migrate`).
Expected: lines starting `Applied`, then `Database is up to date`. Safe to repeat. Run it after every update.
If it fails, send me the exact message.

## 7. Create your school and first admin
Terminal: `node scripts/create-school.js "School Name" 03XXXXXXXXX`
No terminal? Temporarily add to `.env`: `SCHOOL_NAME=...`, `ADMIN_PHONE=03...`, `ONBOARD_TO_FILE=1`. Run script `onboard`, read `onboard-output.txt` in the app folder, then **delete that file** and remove those three lines.
Open `https://school.aromanish.com/?school=SCHOOL_ID`, sign in, choose a new password. (Never run `seed.js` on a real school.)

## 8. Start and check
Node.js app page > **Restart**. Open `https://school.aromanish.com/health`: it should show `{"ok":true}`. On an error page, read `stderr.log` in the app folder.

## 9. Alerts through cron
Shared hosting can't keep a background worker running. cPanel > **Cron Jobs**, every 5 minutes:
```
/home/cpuser/nodevenv/anish24-api/20/bin/node /home/cpuser/anish24-api/src/worker.js --once >> /home/cpuser/anish24-alerts.log 2>&1
```
Replace `cpuser`. The exact path is on the Node.js app page ("Enter to the virtual environment" command). Alerts go out within about 5 minutes. Keep `ALERTS_PROVIDER=console` until WhatsApp/SMS are ready, then set `live`.

## 10. Backups
Orange Host says account backups include MySQL/MariaDB databases. Also: before real data, download a database export from phpMyAdmin and test importing it into a spare database. Repeat regularly and keep copies off the hosting account.

## 11. Updating
Upload new files, **Run NPM Install** if `package.json` changed, run `migrate`, then **Restart**.

## Before real students' data
Have the school-separation, role and payment rules checked by automated tests (I can write them). Student records are children's personal data: limit admin accounts and keep backups private.
