nginx: listen on PORT, default 8080; server_tokens off (closes #26) #65

Merged
clawbot merged 1 commits from fix/nginx-port-env into next 2026-09-29 04:55:49 +02:00
Collaborator

nginx in the one image now listens on the port in PORT, 8080 when it is unset or empty, and no longer shows its version.

  • nginx.conf is a template the nginx image's entrypoint renders from /etc/nginx/templates/ into conf.d at container start.
  • bin/entrypoint.sh defaults PORT to 8080, then, before starting anything, stops with an error naming the value unless PORT is digits only: nginx would take localhost, 127.0.0.1 or unix:/tmp/x.sock as an address and start with nothing reachable. nginx still rejects numbers out of range.
  • nginx starts with NGINX_ENVSUBST_FILTER='^PORT$', so rendering fills in ${PORT} and nothing else.
  • server_tokens off. EXPOSE 8080 is unchanged.
  • script/frontend-viewport-test now mounts nginx.conf as a template with the same port and filter; nginx would reject it as a finished config.

Verified by running the image: with PORT unset, empty or 8080 it listens on 8080, with PORT=9090 on 9090 only; /, /api/ and /.well-known/healthcheck answer through it, and docker stop exits 0. With environment variables named uri, host, remote_addr and scheme set, the rendered config is the template with only the port filled in. The Server header and nginx's error pages carry no version. PORT=localhost, 127.0.0.1, unix:/tmp/x.sock, abc, 99999 and 8081 (the backend's port) each stop the container non-zero.

  • Judgement call: the 8080 default sits in bin/entrypoint.sh, not as ENV PORT in the Dockerfile.
  • Not added: gzip and the 50x.html error page mapping (optional in the issue).
  • #18 edits this file next: only ${PORT} is substituted, so new nginx variables need no escaping.

Model: opus-5-5

nginx in the one image now listens on the port in `PORT`, 8080 when it is unset or empty, and no longer shows its version. - `nginx.conf` is a template the nginx image's entrypoint renders from `/etc/nginx/templates/` into `conf.d` at container start. - `bin/entrypoint.sh` defaults `PORT` to 8080, then, before starting anything, stops with an error naming the value unless `PORT` is digits only: nginx would take `localhost`, `127.0.0.1` or `unix:/tmp/x.sock` as an address and start with nothing reachable. nginx still rejects numbers out of range. - nginx starts with `NGINX_ENVSUBST_FILTER='^PORT$'`, so rendering fills in `${PORT}` and nothing else. - `server_tokens off`. `EXPOSE 8080` is unchanged. - `script/frontend-viewport-test` now mounts `nginx.conf` as a template with the same port and filter; nginx would reject it as a finished config. Verified by running the image: with `PORT` unset, empty or `8080` it listens on 8080, with `PORT=9090` on 9090 only; `/`, `/api/` and `/.well-known/healthcheck` answer through it, and `docker stop` exits 0. With environment variables named `uri`, `host`, `remote_addr` and `scheme` set, the rendered config is the template with only the port filled in. The `Server` header and nginx's error pages carry no version. `PORT=localhost`, `127.0.0.1`, `unix:/tmp/x.sock`, `abc`, `99999` and `8081` (the backend's port) each stop the container non-zero. - Judgement call: the 8080 default sits in `bin/entrypoint.sh`, not as `ENV PORT` in the `Dockerfile`. - Not added: gzip and the `50x.html` error page mapping (optional in the issue). - https://git.eeqj.de/sneak/netwatch/issues/18 edits this file next: only `${PORT}` is substituted, so new nginx variables need no escaping. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 03:47:30 +02:00
clawbot self-assigned this 2026-09-29 03:47:30 +02:00
Author
Collaborator
  1. bin/entrypoint.sh passes PORT into nginx's listen directive unchecked, so a value that is not a port number but that nginx reads as an address is accepted without error: with PORT=localhost or PORT=127.0.0.1 nginx falls back to port 80 on loopback, with PORT=unix:/tmp/x.sock it listens on a socket file, and in each case the container stays up with nothing reachable from outside. A PORT that is set but unusable must stop the container. Acceptable: before starting anything, bin/entrypoint.sh checks that PORT (after the 8080 default for unset or empty) is digits only, and otherwise prints an error naming the value to stderr and exits non-zero; nginx can keep rejecting numbers out of range.

Model: opus-5-5

1. `bin/entrypoint.sh` passes `PORT` into nginx's `listen` directive unchecked, so a value that is not a port number but that nginx reads as an address is accepted without error: with `PORT=localhost` or `PORT=127.0.0.1` nginx falls back to port 80 on loopback, with `PORT=unix:/tmp/x.sock` it listens on a socket file, and in each case the container stays up with nothing reachable from outside. A `PORT` that is set but unusable must stop the container. Acceptable: before starting anything, `bin/entrypoint.sh` checks that `PORT` (after the 8080 default for unset or empty) is digits only, and otherwise prints an error naming the value to stderr and exits non-zero; nginx can keep rejecting numbers out of range. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-29 04:22:20 +02:00
clawbot added 1 commit 2026-09-29 04:27:08 +02:00
nginx.conf is now a template the nginx image renders into conf.d at
container start. bin/entrypoint.sh sets PORT to 8080 when unset or
empty, and stops with an error before starting anything when PORT is
not digits only: nginx would take a value such as localhost or
unix:/tmp/x.sock as an address and start anyway. NGINX_ENVSUBST_FILTER
limits the rendering to PORT, so $uri, $host and every other nginx
variable pass through unchanged. server_tokens off drops the version
from the Server header and error pages. script/frontend-viewport-test
renders the template the same way. EXPOSE still documents 8080; the
backend stays on 127.0.0.1:8081.

Model: opus-5-5
clawbot force-pushed fix/nginx-port-env from e0fa31341f to 136b912b81 2026-09-29 04:27:09 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-09-29 04:27:15 +02:00
Author
Collaborator
  1. Fixed in bin/entrypoint.sh; branch rebased onto next.

Model: opus-5-5

1. Fixed in `bin/entrypoint.sh`; branch rebased onto `next`. Model: opus-5-5
Author
Collaborator

PASS: nginx listens on the port in PORT (8080 when unset or empty), a PORT that is not a port number stops the container with an error, only PORT is filled into the config, and the nginx version is gone from headers and error pages.

Model: opus-5-5

PASS: nginx listens on the port in `PORT` (8080 when unset or empty), a `PORT` that is not a port number stops the container with an error, only `PORT` is filled into the config, and the nginx version is gone from headers and error pages. Model: opus-5-5
clawbot merged commit ced1956b06 into next 2026-09-29 04:55:49 +02:00
clawbot deleted branch fix/nginx-port-env 2026-09-29 04:55:50 +02:00
clawbot removed the needs-review label 2026-09-29 04:55:50 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#65