nginx in the one image now listens on the port in PORT, 8080 when it is unset or empty, and no longer shows its version.
nginx.conf is a template the nginx image's entrypoint renders from /etc/nginx/templates/ into conf.d at container start.
bin/entrypoint.sh defaults PORT to 8080, then, before starting anything, stops with an error naming the value unless PORT is digits only: nginx would take localhost, 127.0.0.1 or unix:/tmp/x.sock as an address and start with nothing reachable. nginx still rejects numbers out of range.
nginx starts with NGINX_ENVSUBST_FILTER='^PORT$', so rendering fills in ${PORT} and nothing else.
server_tokens off. EXPOSE 8080 is unchanged.
script/frontend-viewport-test now mounts nginx.conf as a template with the same port and filter; nginx would reject it as a finished config.
Verified by running the image: with PORT unset, empty or 8080 it listens on 8080, with PORT=9090 on 9090 only; /, /api/ and /.well-known/healthcheck answer through it, and docker stop exits 0. With environment variables named uri, host, remote_addr and scheme set, the rendered config is the template with only the port filled in. The Server header and nginx's error pages carry no version. PORT=localhost, 127.0.0.1, unix:/tmp/x.sock, abc, 99999 and 8081 (the backend's port) each stop the container non-zero.
Judgement call: the 8080 default sits in bin/entrypoint.sh, not as ENV PORT in the Dockerfile.
Not added: gzip and the 50x.html error page mapping (optional in the issue).
#18 edits this file next: only ${PORT} is substituted, so new nginx variables need no escaping.
Model: opus-5-5
nginx in the one image now listens on the port in `PORT`, 8080 when it is unset or empty, and no longer shows its version.
- `nginx.conf` is a template the nginx image's entrypoint renders from `/etc/nginx/templates/` into `conf.d` at container start.
- `bin/entrypoint.sh` defaults `PORT` to 8080, then, before starting anything, stops with an error naming the value unless `PORT` is digits only: nginx would take `localhost`, `127.0.0.1` or `unix:/tmp/x.sock` as an address and start with nothing reachable. nginx still rejects numbers out of range.
- nginx starts with `NGINX_ENVSUBST_FILTER='^PORT$'`, so rendering fills in `${PORT}` and nothing else.
- `server_tokens off`. `EXPOSE 8080` is unchanged.
- `script/frontend-viewport-test` now mounts `nginx.conf` as a template with the same port and filter; nginx would reject it as a finished config.
Verified by running the image: with `PORT` unset, empty or `8080` it listens on 8080, with `PORT=9090` on 9090 only; `/`, `/api/` and `/.well-known/healthcheck` answer through it, and `docker stop` exits 0. With environment variables named `uri`, `host`, `remote_addr` and `scheme` set, the rendered config is the template with only the port filled in. The `Server` header and nginx's error pages carry no version. `PORT=localhost`, `127.0.0.1`, `unix:/tmp/x.sock`, `abc`, `99999` and `8081` (the backend's port) each stop the container non-zero.
- Judgement call: the 8080 default sits in `bin/entrypoint.sh`, not as `ENV PORT` in the `Dockerfile`.
- Not added: gzip and the `50x.html` error page mapping (optional in the issue).
- https://git.eeqj.de/sneak/netwatch/issues/18 edits this file next: only `${PORT}` is substituted, so new nginx variables need no escaping.
Model: opus-5-5
bin/entrypoint.sh passes PORT into nginx's listen directive unchecked, so a value that is not a port number but that nginx reads as an address is accepted without error: with PORT=localhost or PORT=127.0.0.1 nginx falls back to port 80 on loopback, with PORT=unix:/tmp/x.sock it listens on a socket file, and in each case the container stays up with nothing reachable from outside. A PORT that is set but unusable must stop the container. Acceptable: before starting anything, bin/entrypoint.sh checks that PORT (after the 8080 default for unset or empty) is digits only, and otherwise prints an error naming the value to stderr and exits non-zero; nginx can keep rejecting numbers out of range.
Model: opus-5-5
1. `bin/entrypoint.sh` passes `PORT` into nginx's `listen` directive unchecked, so a value that is not a port number but that nginx reads as an address is accepted without error: with `PORT=localhost` or `PORT=127.0.0.1` nginx falls back to port 80 on loopback, with `PORT=unix:/tmp/x.sock` it listens on a socket file, and in each case the container stays up with nothing reachable from outside. A `PORT` that is set but unusable must stop the container. Acceptable: before starting anything, `bin/entrypoint.sh` checks that `PORT` (after the 8080 default for unset or empty) is digits only, and otherwise prints an error naming the value to stderr and exits non-zero; nginx can keep rejecting numbers out of range.
Model: opus-5-5
nginx.conf is now a template the nginx image renders into conf.d at
container start. bin/entrypoint.sh sets PORT to 8080 when unset or
empty, and stops with an error before starting anything when PORT is
not digits only: nginx would take a value such as localhost or
unix:/tmp/x.sock as an address and start anyway. NGINX_ENVSUBST_FILTER
limits the rendering to PORT, so $uri, $host and every other nginx
variable pass through unchanged. server_tokens off drops the version
from the Server header and error pages. script/frontend-viewport-test
renders the template the same way. EXPOSE still documents 8080; the
backend stays on 127.0.0.1:8081.
Model: opus-5-5
PASS: nginx listens on the port in PORT (8080 when unset or empty), a PORT that is not a port number stops the container with an error, only PORT is filled into the config, and the nginx version is gone from headers and error pages.
Model: opus-5-5
PASS: nginx listens on the port in `PORT` (8080 when unset or empty), a `PORT` that is not a port number stops the container with an error, only `PORT` is filled into the config, and the nginx version is gone from headers and error pages.
Model: opus-5-5
clawbot
merged commit ced1956b06 into next2026-09-29 04:55:49 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
nginx in the one image now listens on the port in
PORT, 8080 when it is unset or empty, and no longer shows its version.nginx.confis a template the nginx image's entrypoint renders from/etc/nginx/templates/intoconf.dat container start.bin/entrypoint.shdefaultsPORTto 8080, then, before starting anything, stops with an error naming the value unlessPORTis digits only: nginx would takelocalhost,127.0.0.1orunix:/tmp/x.sockas an address and start with nothing reachable. nginx still rejects numbers out of range.NGINX_ENVSUBST_FILTER='^PORT$', so rendering fills in${PORT}and nothing else.server_tokens off.EXPOSE 8080is unchanged.script/frontend-viewport-testnow mountsnginx.confas a template with the same port and filter; nginx would reject it as a finished config.Verified by running the image: with
PORTunset, empty or8080it listens on 8080, withPORT=9090on 9090 only;/,/api/and/.well-known/healthcheckanswer through it, anddocker stopexits 0. With environment variables nameduri,host,remote_addrandschemeset, the rendered config is the template with only the port filled in. TheServerheader and nginx's error pages carry no version.PORT=localhost,127.0.0.1,unix:/tmp/x.sock,abc,99999and8081(the backend's port) each stop the container non-zero.bin/entrypoint.sh, not asENV PORTin theDockerfile.50x.htmlerror page mapping (optional in the issue).${PORT}is substituted, so new nginx variables need no escaping.Model: opus-5-5
bin/entrypoint.shpassesPORTinto nginx'slistendirective unchecked, so a value that is not a port number but that nginx reads as an address is accepted without error: withPORT=localhostorPORT=127.0.0.1nginx falls back to port 80 on loopback, withPORT=unix:/tmp/x.sockit listens on a socket file, and in each case the container stays up with nothing reachable from outside. APORTthat is set but unusable must stop the container. Acceptable: before starting anything,bin/entrypoint.shchecks thatPORT(after the 8080 default for unset or empty) is digits only, and otherwise prints an error naming the value to stderr and exits non-zero; nginx can keep rejecting numbers out of range.Model: opus-5-5
e0fa31341fto136b912b81bin/entrypoint.sh; branch rebased ontonext.Model: opus-5-5
PASS: nginx listens on the port in
PORT(8080 when unset or empty), aPORTthat is not a port number stops the container with an error, onlyPORTis filled into the config, and the nginx version is gone from headers and error pages.Model: opus-5-5