upaas publishes every mapped port on all host interfaces, which would expose the plain-HTTP admin UI and receiver. The section now says to add no port mapping, to put the app on the reverse proxy's Docker network, and that the proxy reaches it at the upaas container name on port 8080. TRUSTED_PROXIES is the proxy's address on that network; the log hint now points at a proxied request's line, since health-check lines show ::1. Model: opus-5-5
This commit is contained in:
@@ -736,8 +736,14 @@ credentials.
|
||||
[upaas](https://git.eeqj.de/sneak/upaas) builds the image from this
|
||||
repository's `Dockerfile` and runs it. The app needs:
|
||||
|
||||
- **Port:** container port `8080`. Leave `PORT` unset: the image's
|
||||
health check probes `8080`.
|
||||
- **Network and port:** add no port mapping in upaas. upaas publishes
|
||||
every mapped port on all interfaces of the host
|
||||
([upaas issue 113](https://git.eeqj.de/sneak/upaas/issues/113)),
|
||||
which would put the plain-HTTP admin UI and receiver there. Instead,
|
||||
set the app's Docker Network in upaas to your reverse proxy's Docker
|
||||
network; the proxy then reaches the app at `upaas-` followed by the
|
||||
app name, port `8080`. Leave `PORT` unset: the image's health check
|
||||
probes `8080`.
|
||||
- **Volume:** one host directory mounted at `/var/lib/webhooker`.
|
||||
upaas bind-mounts the host path it is given and does not create it,
|
||||
and the container does not start unless UID 1000 owns it (see
|
||||
@@ -752,10 +758,10 @@ repository's `Dockerfile` and runs it. The app needs:
|
||||
|
||||
- **Environment variables:**
|
||||
- `WEBHOOKER_ENVIRONMENT=prod`
|
||||
- `TRUSTED_PROXIES`: the address your reverse proxy connects from,
|
||||
as the container sees it; the `remoteIP` field of each
|
||||
`http request` log line shows it. See
|
||||
[Trusted proxies](#trusted-proxies).
|
||||
- `TRUSTED_PROXIES`: your reverse proxy's address on that Docker
|
||||
network. The `remoteIP` field of the `http request` log line for a
|
||||
request that came through the proxy shows it; the health check's
|
||||
own lines show `::1`. See [Trusted proxies](#trusted-proxies).
|
||||
- Leave `BIND_ADDRESS` and `DATA_DIR` unset: the image sets
|
||||
`BIND_ADDRESS` to `0.0.0.0`, and `DATA_DIR` defaults to
|
||||
`/var/lib/webhooker`.
|
||||
|
||||
Reference in New Issue
Block a user