build: one image, nginx in front of the backend on loopback (closes #52)
check / check (push) Successful in 12s
check / check (push) Successful in 12s
The root Dockerfile builds the only image; Dockerfile.backend is gone. Its stages: lint, a Go stage that runs the tests and builds netwatch-server, the node stage, and an nginx runtime. nginx serves dist/ on 8080 and proxies /api/ and /.well-known/healthcheck to the backend on 127.0.0.1:8081. bin/entrypoint.sh starts both, turns TERM or INT into a stop of both, and exits non-zero when either exits on its own. The backend runs as user netwatch and keeps reports on the /data volume. New setting BIND_ADDRESS (empty: every interface). STOPSIGNAL is SIGTERM, since the nginx image's SIGQUIT would miss the entrypoint. script/docker is the org model verbatim. Model: opus-5-5
This commit was merged in pull request #62.
This commit is contained in:
+19
@@ -25,4 +25,23 @@ server {
|
||||
expires 1y;
|
||||
add_header Cache-Control "public, immutable";
|
||||
}
|
||||
|
||||
# netwatch-server, the Go backend, runs in the same container and
|
||||
# listens on loopback only: bin/entrypoint.sh starts it on
|
||||
# 127.0.0.1:8081. These headers go with every request passed to it.
|
||||
# X-Forwarded-For carries only the client address, as resolved by
|
||||
# the real IP settings above, and not the chain the request came
|
||||
# with: the backend takes the first entry, which a client can write.
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
|
||||
location /api/ {
|
||||
proxy_pass http://127.0.0.1:8081;
|
||||
}
|
||||
|
||||
location = /.well-known/healthcheck {
|
||||
proxy_pass http://127.0.0.1:8081;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user