diff --git a/CHANGELOG.md b/CHANGELOG.md index c1c11f9..32d3193 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,14 @@ +## adventurelog: photos render — the backend's own paths go to the backend (2026-09-13, R-483) + +The operator measured it in a browser: on his k3s install a photo uploads and renders; on demo-hp it +uploads and renders as a broken "Uploaded content". The diff against `homelab-manifests`'s +`adventurelog-system/adventurelog.yaml`: its ingress sends `/media`, `/static`, `/admin` and +`/accounts` to the backend and only `/` to the frontend; the catalog template sent every path to the +frontend, which does not serve `/media`, so every photo URL was a 404. Now the backend service carries +its own traefik router for those four prefixes (priority 20; the frontend router is priority 10). The +frontend's `/api` and `/auth` proxy stays as it is — that is also the k3s shape. Nothing else differed +(`PUBLIC_URL`, `CSRF_TRUSTED_ORIGINS`, `ORIGIN`, `BODY_SIZE_LIMIT` all match). No version moved. + ## catalog-since gate: an image move must bump catalog_since (2026-09-13, R-452) `scripts/check-catalog-since.py`, fifth gate in `catalog_gates.py` (fast, git-history, `--range A..B` diff --git a/templates/adventurelog/docker-compose.yml b/templates/adventurelog/docker-compose.yml index 09d0996..13bf5f9 100644 --- a/templates/adventurelog/docker-compose.yml +++ b/templates/adventurelog/docker-compose.yml @@ -35,6 +35,20 @@ services: networks: - traefik-public - adventurelog-internal + # R-483: the backend serves the uploaded photos (/media), Django's static files, the admin and the + # account pages ITSELF; the frontend does not proxy them. With every path routed to the frontend an + # uploaded photo rendered as a broken "Uploaded content" (measured 2026-09-13 on demo-hp; the + # operator's k3s install routes exactly these four prefixes to the backend and renders photos). + # Higher priority than the frontend router, same host. + labels: + - "traefik.enable=true" + - "traefik.http.routers.adventurelog-backend.rule=Host(`${SUBDOMAIN}.${DOMAIN}`) && (PathPrefix(`/media`) || PathPrefix(`/static`) || PathPrefix(`/admin`) || PathPrefix(`/accounts`))" + - "traefik.http.routers.adventurelog-backend.priority=20" + - "traefik.http.routers.adventurelog-backend.entrypoints=websecure" + - "traefik.http.routers.adventurelog-backend.tls=true" + - "traefik.http.routers.adventurelog-backend.tls.certresolver=letsencrypt" + - "traefik.http.routers.adventurelog-backend.service=adventurelog-backend" + - "traefik.http.services.adventurelog-backend.loadbalancer.server.port=8000" deploy: resources: limits: @@ -83,6 +97,7 @@ services: labels: - "traefik.enable=true" - "traefik.http.routers.adventurelog.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)" + - "traefik.http.routers.adventurelog.priority=10" - "traefik.http.routers.adventurelog.entrypoints=websecure" - "traefik.http.routers.adventurelog.tls=true" - "traefik.http.routers.adventurelog.tls.certresolver=letsencrypt"