Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0cc4bf0cb7 |
@@ -315,7 +315,10 @@ exec chpst -u app:app /usr/local/bin/app \
|
||||
health check passes while `smallwebwaf` answers and the app accepts
|
||||
connections. `SWWAF_LISTEN_ADDR` can move `smallwebwaf` to another port, which
|
||||
the app then leaves free instead; the health check follows it, and traefik's
|
||||
labels must point at it.
|
||||
labels must point at it. The address part of `SWWAF_LISTEN_ADDR` stays empty
|
||||
(for example `:9000`, never `127.0.0.1:9000`), so `smallwebwaf` keeps
|
||||
listening on every address: traefik reaches it on the container's address, and
|
||||
the health check on `127.0.0.1`.
|
||||
- `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`. Mount a volume
|
||||
there to keep bans and client history when a deploy replaces the container;
|
||||
without one, it still starts.
|
||||
|
||||
@@ -1273,10 +1273,13 @@ its health check, metrics and ban management are all on that listener, under
|
||||
`/_smallwebwaf/` (see "Admin endpoints"). `SWWAF_LISTEN_ADDR` may set another
|
||||
port: the image's health check takes its port from that setting, and traefik's
|
||||
port label (`traefik.http.services.<name>.loadbalancer.server.port`) must name
|
||||
the same port. The app must leave that port free. It listens on `127.0.0.1:8081`
|
||||
only, so that nothing outside the container reaches it except through
|
||||
`smallwebwaf`: an app that listens on every address can be reached around
|
||||
`smallwebwaf` by anything that reaches the container.
|
||||
the same port, and the app must leave that port free. The address part of
|
||||
`SWWAF_LISTEN_ADDR` stays empty (for example `:9000`, never `127.0.0.1:9000`),
|
||||
so `smallwebwaf` keeps listening on every address: traefik reaches it on the
|
||||
container's address, and the health check on `127.0.0.1`. The app listens on
|
||||
`127.0.0.1:8081` only, so that nothing outside the container reaches it except
|
||||
through `smallwebwaf`: an app that listens on every address can be reached
|
||||
around `smallwebwaf` by anything that reaches the container.
|
||||
|
||||
State: `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`
|
||||
(`SWWAF_STATE_DIR`), a directory of its own beside the app's data, which the app
|
||||
|
||||
Reference in New Issue
Block a user