upaas publishes every mapped port on all host interfaces, which would
expose the plain-HTTP admin UI and receiver. The section now says to
add no port mapping, to put the app on the reverse proxy's Docker
network, and that the proxy reaches it at the upaas container name on
port 8080.
TRUSTED_PROXIES is the proxy's address on that network; the log hint
now points at a proxied request's line, since health-check lines show
::1.
Model: opus-5-5
Adds a short "Running under upaas" section to the README, next to
"Running with Docker": the container port, the data volume and the
commands that create it, the environment variables upaas should set,
the health check upaas reads after a deploy, and where the first-run
admin password appears and how to reset it.
upaas bind-mounts a host directory it does not create, and a
directory made by root stops the container at its data directory
lock. The section has the operator create the directory owned by
UID 1000 before the first deploy; the image is unchanged.
Model: opus-5-5