Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
01049aae4e |
@@ -315,10 +315,7 @@ exec chpst -u app:app /usr/local/bin/app \
|
|||||||
health check passes while `smallwebwaf` answers and the app accepts
|
health check passes while `smallwebwaf` answers and the app accepts
|
||||||
connections. `SWWAF_LISTEN_ADDR` can move `smallwebwaf` to another port, which
|
connections. `SWWAF_LISTEN_ADDR` can move `smallwebwaf` to another port, which
|
||||||
the app then leaves free instead; the health check follows it, and traefik's
|
the app then leaves free instead; the health check follows it, and traefik's
|
||||||
labels must point at it. The address part of `SWWAF_LISTEN_ADDR` stays empty
|
labels must point at it.
|
||||||
(for example `:9000`, never `127.0.0.1:9000`), so `smallwebwaf` keeps
|
|
||||||
listening on every address: traefik reaches it on the container's address, and
|
|
||||||
the health check on `127.0.0.1`.
|
|
||||||
- `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`. Mount a volume
|
- `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`. Mount a volume
|
||||||
there to keep bans and client history when a deploy replaces the container;
|
there to keep bans and client history when a deploy replaces the container;
|
||||||
without one, it still starts.
|
without one, it still starts.
|
||||||
|
|||||||
@@ -1273,13 +1273,10 @@ its health check, metrics and ban management are all on that listener, under
|
|||||||
`/_smallwebwaf/` (see "Admin endpoints"). `SWWAF_LISTEN_ADDR` may set another
|
`/_smallwebwaf/` (see "Admin endpoints"). `SWWAF_LISTEN_ADDR` may set another
|
||||||
port: the image's health check takes its port from that setting, and traefik's
|
port: the image's health check takes its port from that setting, and traefik's
|
||||||
port label (`traefik.http.services.<name>.loadbalancer.server.port`) must name
|
port label (`traefik.http.services.<name>.loadbalancer.server.port`) must name
|
||||||
the same port, and the app must leave that port free. The address part of
|
the same port. The app must leave that port free. It listens on `127.0.0.1:8081`
|
||||||
`SWWAF_LISTEN_ADDR` stays empty (for example `:9000`, never `127.0.0.1:9000`),
|
only, so that nothing outside the container reaches it except through
|
||||||
so `smallwebwaf` keeps listening on every address: traefik reaches it on the
|
`smallwebwaf`: an app that listens on every address can be reached around
|
||||||
container's address, and the health check on `127.0.0.1`. The app listens on
|
`smallwebwaf` by anything that reaches the container.
|
||||||
`127.0.0.1:8081` only, so that nothing outside the container reaches it except
|
|
||||||
through `smallwebwaf`: an app that listens on every address can be reached
|
|
||||||
around `smallwebwaf` by anything that reaches the container.
|
|
||||||
|
|
||||||
State: `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`
|
State: `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`
|
||||||
(`SWWAF_STATE_DIR`), a directory of its own beside the app's data, which the app
|
(`SWWAF_STATE_DIR`), a directory of its own beside the app's data, which the app
|
||||||
|
|||||||
Reference in New Issue
Block a user