upaas publishes every mapped port on all host interfaces, which would expose the plain-HTTP admin UI and receiver. The section now says to add no port mapping, to put the app on the reverse proxy's Docker network, and that the proxy reaches it at the upaas container name on port 8080. TRUSTED_PROXIES is the proxy's address on that network; the log hint now points at a proxied request's line, since health-check lines show ::1. Model: opus-5-5
This commit is contained in:
@@ -736,8 +736,14 @@ credentials.
|
|||||||
[upaas](https://git.eeqj.de/sneak/upaas) builds the image from this
|
[upaas](https://git.eeqj.de/sneak/upaas) builds the image from this
|
||||||
repository's `Dockerfile` and runs it. The app needs:
|
repository's `Dockerfile` and runs it. The app needs:
|
||||||
|
|
||||||
- **Port:** container port `8080`. Leave `PORT` unset: the image's
|
- **Network and port:** add no port mapping in upaas. upaas publishes
|
||||||
health check probes `8080`.
|
every mapped port on all interfaces of the host
|
||||||
|
([upaas issue 113](https://git.eeqj.de/sneak/upaas/issues/113)),
|
||||||
|
which would put the plain-HTTP admin UI and receiver there. Instead,
|
||||||
|
set the app's Docker Network in upaas to your reverse proxy's Docker
|
||||||
|
network; the proxy then reaches the app at `upaas-` followed by the
|
||||||
|
app name, port `8080`. Leave `PORT` unset: the image's health check
|
||||||
|
probes `8080`.
|
||||||
- **Volume:** one host directory mounted at `/var/lib/webhooker`.
|
- **Volume:** one host directory mounted at `/var/lib/webhooker`.
|
||||||
upaas bind-mounts the host path it is given and does not create it,
|
upaas bind-mounts the host path it is given and does not create it,
|
||||||
and the container does not start unless UID 1000 owns it (see
|
and the container does not start unless UID 1000 owns it (see
|
||||||
@@ -752,10 +758,10 @@ repository's `Dockerfile` and runs it. The app needs:
|
|||||||
|
|
||||||
- **Environment variables:**
|
- **Environment variables:**
|
||||||
- `WEBHOOKER_ENVIRONMENT=prod`
|
- `WEBHOOKER_ENVIRONMENT=prod`
|
||||||
- `TRUSTED_PROXIES`: the address your reverse proxy connects from,
|
- `TRUSTED_PROXIES`: your reverse proxy's address on that Docker
|
||||||
as the container sees it; the `remoteIP` field of each
|
network. The `remoteIP` field of the `http request` log line for a
|
||||||
`http request` log line shows it. See
|
request that came through the proxy shows it; the health check's
|
||||||
[Trusted proxies](#trusted-proxies).
|
own lines show `::1`. See [Trusted proxies](#trusted-proxies).
|
||||||
- Leave `BIND_ADDRESS` and `DATA_DIR` unset: the image sets
|
- Leave `BIND_ADDRESS` and `DATA_DIR` unset: the image sets
|
||||||
`BIND_ADDRESS` to `0.0.0.0`, and `DATA_DIR` defaults to
|
`BIND_ADDRESS` to `0.0.0.0`, and `DATA_DIR` defaults to
|
||||||
`/var/lib/webhooker`.
|
`/var/lib/webhooker`.
|
||||||
|
|||||||
Reference in New Issue
Block a user