check / check (push) Successful in 15s
nginx trusted X-Forwarded-For from every RFC1918 address, so a client reaching it from one could write a new address on each request and get a fresh rate-limit allowance. The container's TRUSTED_PROXIES now names the reverse proxies nginx trusts, none by default. bin/entrypoint.sh makes each entry a CIDR, checks it with the new "netwatch-server check-cidr", which runs the server's own TRUSTED_PROXIES parsing, and writes one set_real_ip_from line per entry into /etc/nginx/trusted-proxies.conf, which nginx.conf includes. The backend is started with TRUSTED_PROXIES=127.0.0.1/32, since nginx is its only client. The viewport test mounts an empty file there. Model: opus-5-5
59 lines
1.3 KiB
Go
59 lines
1.3 KiB
Go
// Package main is the entry point for netwatch-server.
|
|
package main
|
|
|
|
import (
|
|
"fmt"
|
|
"os"
|
|
|
|
"sneak.berlin/go/netwatch/internal/config"
|
|
"sneak.berlin/go/netwatch/internal/globals"
|
|
"sneak.berlin/go/netwatch/internal/handlers"
|
|
"sneak.berlin/go/netwatch/internal/healthcheck"
|
|
"sneak.berlin/go/netwatch/internal/logger"
|
|
"sneak.berlin/go/netwatch/internal/middleware"
|
|
"sneak.berlin/go/netwatch/internal/reportbuf"
|
|
"sneak.berlin/go/netwatch/internal/server"
|
|
|
|
"go.uber.org/fx"
|
|
)
|
|
|
|
//nolint:gochecknoglobals // set via ldflags at build time
|
|
var (
|
|
Appname = "netwatch-server"
|
|
Version string
|
|
Buildarch string
|
|
)
|
|
|
|
func main() {
|
|
// "netwatch-server check-cidr CIDR" exits 1, with the error, if
|
|
// this server would refuse CIDR in its TRUSTED_PROXIES.
|
|
// bin/entrypoint.sh runs it on each entry it gives nginx.
|
|
if len(os.Args) == 3 && os.Args[1] == "check-cidr" {
|
|
_, err := middleware.ParseTrustedProxies(os.Args[2:])
|
|
if err != nil {
|
|
fmt.Fprintln(os.Stderr, err)
|
|
os.Exit(1)
|
|
}
|
|
|
|
return
|
|
}
|
|
|
|
globals.Appname = Appname
|
|
globals.Version = Version
|
|
globals.Buildarch = Buildarch
|
|
|
|
fx.New(
|
|
fx.Provide(
|
|
config.New,
|
|
globals.New,
|
|
handlers.New,
|
|
healthcheck.New,
|
|
logger.New,
|
|
middleware.New,
|
|
reportbuf.New,
|
|
server.New,
|
|
),
|
|
fx.Invoke(func(*server.Server) {}),
|
|
).Run()
|
|
}
|