Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0cc4bf0cb7 |
@@ -315,7 +315,10 @@ exec chpst -u app:app /usr/local/bin/app \
|
|||||||
health check passes while `smallwebwaf` answers and the app accepts
|
health check passes while `smallwebwaf` answers and the app accepts
|
||||||
connections. `SWWAF_LISTEN_ADDR` can move `smallwebwaf` to another port, which
|
connections. `SWWAF_LISTEN_ADDR` can move `smallwebwaf` to another port, which
|
||||||
the app then leaves free instead; the health check follows it, and traefik's
|
the app then leaves free instead; the health check follows it, and traefik's
|
||||||
labels must point at it.
|
labels must point at it. The address part of `SWWAF_LISTEN_ADDR` stays empty
|
||||||
|
(for example `:9000`, never `127.0.0.1:9000`), so `smallwebwaf` keeps
|
||||||
|
listening on every address: traefik reaches it on the container's address, and
|
||||||
|
the health check on `127.0.0.1`.
|
||||||
- `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`. Mount a volume
|
- `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`. Mount a volume
|
||||||
there to keep bans and client history when a deploy replaces the container;
|
there to keep bans and client history when a deploy replaces the container;
|
||||||
without one, it still starts.
|
without one, it still starts.
|
||||||
|
|||||||
@@ -1273,10 +1273,13 @@ its health check, metrics and ban management are all on that listener, under
|
|||||||
`/_smallwebwaf/` (see "Admin endpoints"). `SWWAF_LISTEN_ADDR` may set another
|
`/_smallwebwaf/` (see "Admin endpoints"). `SWWAF_LISTEN_ADDR` may set another
|
||||||
port: the image's health check takes its port from that setting, and traefik's
|
port: the image's health check takes its port from that setting, and traefik's
|
||||||
port label (`traefik.http.services.<name>.loadbalancer.server.port`) must name
|
port label (`traefik.http.services.<name>.loadbalancer.server.port`) must name
|
||||||
the same port. The app must leave that port free. It listens on `127.0.0.1:8081`
|
the same port, and the app must leave that port free. The address part of
|
||||||
only, so that nothing outside the container reaches it except through
|
`SWWAF_LISTEN_ADDR` stays empty (for example `:9000`, never `127.0.0.1:9000`),
|
||||||
`smallwebwaf`: an app that listens on every address can be reached around
|
so `smallwebwaf` keeps listening on every address: traefik reaches it on the
|
||||||
`smallwebwaf` by anything that reaches the container.
|
container's address, and the health check on `127.0.0.1`. The app listens on
|
||||||
|
`127.0.0.1:8081` only, so that nothing outside the container reaches it except
|
||||||
|
through `smallwebwaf`: an app that listens on every address can be reached
|
||||||
|
around `smallwebwaf` by anything that reaches the container.
|
||||||
|
|
||||||
State: `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`
|
State: `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`
|
||||||
(`SWWAF_STATE_DIR`), a directory of its own beside the app's data, which the app
|
(`SWWAF_STATE_DIR`), a directory of its own beside the app's data, which the app
|
||||||
|
|||||||
Reference in New Issue
Block a user