R-776: nextcloud sees each visitor behind the tunnel (trusted docker networks; 9202 checklist 3.6 re-measure owed)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 21:17:31 +02:00
parent 5f7bf7729e
commit 1d3af8edfb
+4
View File
@@ -32,6 +32,10 @@ services:
- NEXTCLOUD_TRUSTED_DOMAINS=${SUBDOMAIN}.${DOMAIN} nextcloud
- OVERWRITEPROTOCOL=https
- OVERWRITEHOST=${SUBDOMAIN}.${DOMAIN}
# R-776 (R-753, controller >= 0.286.0): the image's reverse-proxy.config.php turns this into trusted_proxies; Nextcloud
# then reads X-Forwarded-For from the RIGHT, so its brute-force throttle keys on each VISITOR instead of one bucket
# for the whole tunnel. 9202 re-measure owed (checklist 3.6).
- TRUSTED_PROXIES=172.16.0.0/12
- REDIS_HOST=nextcloud-redis
# App-email (managed relay). Injected by the controller only when app-email is on (global + per-app);
# empty SMTP_HOST keeps Nextcloud mail disabled. Nextcloud uses the plaintext :2526 listener