nginx: listen on PORT, default 8080; server_tokens off (closes #26)
check / check (push) Successful in 11s
check / check (push) Successful in 11s
nginx.conf is now a template the nginx image renders into conf.d at container start. bin/entrypoint.sh gives nginx PORT, 8080 when unset or empty, and limits the rendering to PORT with NGINX_ENVSUBST_FILTER, so $uri, $host and every other nginx variable pass through unchanged. A PORT nginx cannot listen on stops the container non-zero. server_tokens off drops the version from the Server header and error pages. script/frontend-viewport-test renders the template the same way. EXPOSE still documents 8080; the backend stays on 127.0.0.1:8081. Model: opus-5-5
This commit is contained in:
+4
-1
@@ -68,8 +68,10 @@ FROM nginx@sha256:15e96e59aa3b0aada3a121296e3bce117721f42d88f5f64217ef4b18f458c6
|
|||||||
RUN addgroup -g 1000 -S netwatch && \
|
RUN addgroup -g 1000 -S netwatch && \
|
||||||
adduser -u 1000 -S netwatch -G netwatch
|
adduser -u 1000 -S netwatch -G netwatch
|
||||||
|
|
||||||
|
# At start-up the nginx image renders every template here into
|
||||||
|
# conf.d; bin/entrypoint.sh says how.
|
||||||
RUN rm /etc/nginx/conf.d/default.conf
|
RUN rm /etc/nginx/conf.d/default.conf
|
||||||
COPY nginx.conf /etc/nginx/conf.d/netwatch.conf
|
COPY nginx.conf /etc/nginx/templates/netwatch.conf.template
|
||||||
COPY --from=frontend /app/dist /usr/share/nginx/html
|
COPY --from=frontend /app/dist /usr/share/nginx/html
|
||||||
COPY --from=builder /src/netwatch-server /usr/local/bin/netwatch-server
|
COPY --from=builder /src/netwatch-server /usr/local/bin/netwatch-server
|
||||||
COPY bin/entrypoint.sh /usr/local/bin/entrypoint.sh
|
COPY bin/entrypoint.sh /usr/local/bin/entrypoint.sh
|
||||||
@@ -78,6 +80,7 @@ ENV DATA_DIR=/data/reports
|
|||||||
RUN mkdir -p /data/reports && chown -R netwatch:netwatch /data
|
RUN mkdir -p /data/reports && chown -R netwatch:netwatch /data
|
||||||
VOLUME /data
|
VOLUME /data
|
||||||
|
|
||||||
|
# The default public port; PORT changes it.
|
||||||
EXPOSE 8080
|
EXPOSE 8080
|
||||||
|
|
||||||
# The nginx image stops its container with SIGQUIT; the entrypoint
|
# The nginx image stops its container with SIGQUIT; the entrypoint
|
||||||
|
|||||||
@@ -23,6 +23,11 @@ latest run passes.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-09-29: nginx listens on `PORT` (issue #26), 8080 when unset: the nginx
|
||||||
|
image renders `nginx.conf` as a template at container start, filling in `PORT`
|
||||||
|
and no other variable. `server_tokens off` keeps the nginx version out of
|
||||||
|
responses. `script/frontend-viewport-test` renders the template the same way.
|
||||||
|
Gzip and a `50x.html` error page are not added
|
||||||
- 2026-09-28: one container image (issue #52): the root `Dockerfile` builds the
|
- 2026-09-28: one container image (issue #52): the root `Dockerfile` builds the
|
||||||
only image, and `Dockerfile.backend` is gone. nginx serves the frontend on
|
only image, and `Dockerfile.backend` is gone. nginx serves the frontend on
|
||||||
port 8080 and proxies `/api/` and `/.well-known/healthcheck` to the backend,
|
port 8080 and proxies `/api/` and `/.well-known/healthcheck` to the backend,
|
||||||
|
|||||||
+6
-1
@@ -23,7 +23,12 @@ backend=$!
|
|||||||
|
|
||||||
# nginx starts through the nginx image's own entrypoint, which applies
|
# nginx starts through the nginx image's own entrypoint, which applies
|
||||||
# the image's start-up configuration and then replaces itself with
|
# the image's start-up configuration and then replaces itself with
|
||||||
# nginx.
|
# nginx. Part of that start-up configuration renders nginx.conf into
|
||||||
|
# conf.d with nginx listening on PORT, the public port, 8080 unless
|
||||||
|
# set. NGINX_ENVSUBST_FILTER limits that rendering to PORT: a variable
|
||||||
|
# nginx itself uses, such as $uri, would otherwise be replaced by an
|
||||||
|
# environment variable of the same name.
|
||||||
|
PORT="${PORT:-8080}" NGINX_ENVSUBST_FILTER='^PORT$' \
|
||||||
/docker-entrypoint.sh nginx -g 'daemon off;' &
|
/docker-entrypoint.sh nginx -g 'daemon off;' &
|
||||||
nginx=$!
|
nginx=$!
|
||||||
|
|
||||||
|
|||||||
+7
-1
@@ -1,7 +1,13 @@
|
|||||||
|
# A template: the nginx image renders it into conf.d at container start,
|
||||||
|
# filling in PORT and nothing else. bin/entrypoint.sh sets PORT and that
|
||||||
|
# limit.
|
||||||
server {
|
server {
|
||||||
listen 8080;
|
listen ${PORT};
|
||||||
server_name _;
|
server_name _;
|
||||||
|
|
||||||
|
# Keep the nginx version out of the Server header and error pages.
|
||||||
|
server_tokens off;
|
||||||
|
|
||||||
root /usr/share/nginx/html;
|
root /usr/share/nginx/html;
|
||||||
index index.html;
|
index index.html;
|
||||||
|
|
||||||
|
|||||||
@@ -61,10 +61,13 @@ main() {
|
|||||||
# host.
|
# host.
|
||||||
docker network create --internal "$NETWORK" > /dev/null
|
docker network create --internal "$NETWORK" > /dev/null
|
||||||
|
|
||||||
|
# nginx.conf is a template: the image renders it over its own
|
||||||
|
# default.conf, with the same port and limit bin/entrypoint.sh uses.
|
||||||
docker run -d --rm --name "$SERVER" \
|
docker run -d --rm --name "$SERVER" \
|
||||||
--network "$NETWORK" --network-alias netwatch \
|
--network "$NETWORK" --network-alias netwatch \
|
||||||
|
-e PORT=8080 -e NGINX_ENVSUBST_FILTER='^PORT$' \
|
||||||
-v "$ROOT/dist:/usr/share/nginx/html:ro" \
|
-v "$ROOT/dist:/usr/share/nginx/html:ro" \
|
||||||
-v "$ROOT/nginx.conf:/etc/nginx/conf.d/default.conf:ro" \
|
-v "$ROOT/nginx.conf:/etc/nginx/templates/default.conf.template:ro" \
|
||||||
"$SERVER_IMAGE" > /dev/null
|
"$SERVER_IMAGE" > /dev/null
|
||||||
|
|
||||||
# The image's own entrypoint already exposes CDP on 9222 and passes
|
# The image's own entrypoint already exposes CDP on 9222 and passes
|
||||||
|
|||||||
Reference in New Issue
Block a user