From 8fa7dfae533b4efcf74e37f323a3d87f64072a61 Mon Sep 17 00:00:00 2001 From: sneak Date: Mon, 28 Sep 2026 10:04:29 +0000 Subject: [PATCH] Reach the upaas app over a Docker network, not a port mapping upaas publishes every mapped port on all host interfaces, which would expose the plain-HTTP admin UI and receiver. The section now says to add no port mapping, to put the app on the reverse proxy's Docker network, and that the proxy reaches it at the upaas container name on port 8080. TRUSTED_PROXIES is the proxy's address on that network; the log hint now points at a proxied request's line, since health-check lines show ::1. Model: opus-5-5 --- README.md | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/README.md b/README.md index 2a11d27..85275c4 100644 --- a/README.md +++ b/README.md @@ -736,8 +736,14 @@ credentials. [upaas](https://git.eeqj.de/sneak/upaas) builds the image from this repository's `Dockerfile` and runs it. The app needs: -- **Port:** container port `8080`. Leave `PORT` unset: the image's - health check probes `8080`. +- **Network and port:** add no port mapping in upaas. upaas publishes + every mapped port on all interfaces of the host + ([upaas issue 113](https://git.eeqj.de/sneak/upaas/issues/113)), + which would put the plain-HTTP admin UI and receiver there. Instead, + set the app's Docker Network in upaas to your reverse proxy's Docker + network; the proxy then reaches the app at `upaas-` followed by the + app name, port `8080`. Leave `PORT` unset: the image's health check + probes `8080`. - **Volume:** one host directory mounted at `/var/lib/webhooker`. upaas bind-mounts the host path it is given and does not create it, and the container does not start unless UID 1000 owns it (see @@ -752,10 +758,10 @@ repository's `Dockerfile` and runs it. The app needs: - **Environment variables:** - `WEBHOOKER_ENVIRONMENT=prod` - - `TRUSTED_PROXIES`: the address your reverse proxy connects from, - as the container sees it; the `remoteIP` field of each - `http request` log line shows it. See - [Trusted proxies](#trusted-proxies). + - `TRUSTED_PROXIES`: your reverse proxy's address on that Docker + network. The `remoteIP` field of the `http request` log line for a + request that came through the proxy shows it; the health check's + own lines show `::1`. See [Trusted proxies](#trusted-proxies). - Leave `BIND_ADDRESS` and `DATA_DIR` unset: the image sets `BIND_ADDRESS` to `0.0.0.0`, and `DATA_DIR` defaults to `/var/lib/webhooker`.