nginx: listen on PORT, default 8080; server_tokens off (closes #26)
check / check (push) Successful in 15s
check / check (push) Successful in 15s
nginx.conf is now a template the nginx image renders into conf.d at container start. bin/entrypoint.sh sets PORT to 8080 when unset or empty, and stops with an error before starting anything when PORT is not digits only: nginx would take a value such as localhost or unix:/tmp/x.sock as an address and start anyway. NGINX_ENVSUBST_FILTER limits the rendering to PORT, so $uri, $host and every other nginx variable pass through unchanged. server_tokens off drops the version from the Server header and error pages. script/frontend-viewport-test renders the template the same way. EXPOSE still documents 8080; the backend stays on 127.0.0.1:8081. Model: opus-5-5
This commit was merged in pull request #65.
This commit is contained in:
+4
-1
@@ -68,8 +68,10 @@ FROM nginx@sha256:15e96e59aa3b0aada3a121296e3bce117721f42d88f5f64217ef4b18f458c6
|
||||
RUN addgroup -g 1000 -S netwatch && \
|
||||
adduser -u 1000 -S netwatch -G netwatch
|
||||
|
||||
# At start-up the nginx image renders every template here into
|
||||
# conf.d; bin/entrypoint.sh says how.
|
||||
RUN rm /etc/nginx/conf.d/default.conf
|
||||
COPY nginx.conf /etc/nginx/conf.d/netwatch.conf
|
||||
COPY nginx.conf /etc/nginx/templates/netwatch.conf.template
|
||||
COPY --from=frontend /app/dist /usr/share/nginx/html
|
||||
COPY --from=builder /src/netwatch-server /usr/local/bin/netwatch-server
|
||||
COPY bin/entrypoint.sh /usr/local/bin/entrypoint.sh
|
||||
@@ -78,6 +80,7 @@ ENV DATA_DIR=/data/reports
|
||||
RUN mkdir -p /data/reports && chown -R netwatch:netwatch /data
|
||||
VOLUME /data
|
||||
|
||||
# The default public port; PORT changes it.
|
||||
EXPOSE 8080
|
||||
|
||||
# The nginx image stops its container with SIGQUIT; the entrypoint
|
||||
|
||||
Reference in New Issue
Block a user