Reach the upaas app over a Docker network, not a port mapping
check / check (push) Successful in 7s

upaas publishes every mapped port on all host interfaces, which would
expose the plain-HTTP admin UI and receiver. The section now says to
add no port mapping, to put the app on the reverse proxy's Docker
network, and that the proxy reaches it at the upaas container name on
port 8080.

TRUSTED_PROXIES is the proxy's address on that network; the log hint
now points at a proxied request's line, since health-check lines show
::1.

Model: opus-5-5
This commit is contained in:
2026-09-28 10:04:29 +00:00
parent c012cd6898
commit 8fa7dfae53
+12 -6
View File
@@ -736,8 +736,14 @@ credentials.
[upaas](https://git.eeqj.de/sneak/upaas) builds the image from this [upaas](https://git.eeqj.de/sneak/upaas) builds the image from this
repository's `Dockerfile` and runs it. The app needs: repository's `Dockerfile` and runs it. The app needs:
- **Port:** container port `8080`. Leave `PORT` unset: the image's - **Network and port:** add no port mapping in upaas. upaas publishes
health check probes `8080`. every mapped port on all interfaces of the host
([upaas issue 113](https://git.eeqj.de/sneak/upaas/issues/113)),
which would put the plain-HTTP admin UI and receiver there. Instead,
set the app's Docker Network in upaas to your reverse proxy's Docker
network; the proxy then reaches the app at `upaas-` followed by the
app name, port `8080`. Leave `PORT` unset: the image's health check
probes `8080`.
- **Volume:** one host directory mounted at `/var/lib/webhooker`. - **Volume:** one host directory mounted at `/var/lib/webhooker`.
upaas bind-mounts the host path it is given and does not create it, upaas bind-mounts the host path it is given and does not create it,
and the container does not start unless UID 1000 owns it (see and the container does not start unless UID 1000 owns it (see
@@ -752,10 +758,10 @@ repository's `Dockerfile` and runs it. The app needs:
- **Environment variables:** - **Environment variables:**
- `WEBHOOKER_ENVIRONMENT=prod` - `WEBHOOKER_ENVIRONMENT=prod`
- `TRUSTED_PROXIES`: the address your reverse proxy connects from, - `TRUSTED_PROXIES`: your reverse proxy's address on that Docker
as the container sees it; the `remoteIP` field of each network. The `remoteIP` field of the `http request` log line for a
`http request` log line shows it. See request that came through the proxy shows it; the health check's
[Trusted proxies](#trusted-proxies). own lines show `::1`. See [Trusted proxies](#trusted-proxies).
- Leave `BIND_ADDRESS` and `DATA_DIR` unset: the image sets - Leave `BIND_ADDRESS` and `DATA_DIR` unset: the image sets
`BIND_ADDRESS` to `0.0.0.0`, and `DATA_DIR` defaults to `BIND_ADDRESS` to `0.0.0.0`, and `DATA_DIR` defaults to
`/var/lib/webhooker`. `/var/lib/webhooker`.