From 85556601238a0fe2c69c0249d2814b58983e59ba Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Sun, 13 Sep 2026 21:45:52 +0200 Subject: [PATCH] =?UTF-8?q?adventurelog:=20the=20backend=20router=20target?= =?UTF-8?q?s=20port=2080=20(nginx=20+=20X-Accel-Redirect),=20not=20gunicor?= =?UTF-8?q?n=20=E2=80=94=20photos=20came=20back=20empty=20(R-483)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- CHANGELOG.md | 5 ++++- templates/adventurelog/docker-compose.yml | 6 +++++- 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 32d3193..eaa866b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,7 +5,10 @@ uploads and renders as a broken "Uploaded content". The diff against `homelab-ma `adventurelog-system/adventurelog.yaml`: its ingress sends `/media`, `/static`, `/admin` and `/accounts` to the backend and only `/` to the frontend; the catalog template sent every path to the frontend, which does not serve `/media`, so every photo URL was a 404. Now the backend service carries -its own traefik router for those four prefixes (priority 20; the frontend router is priority 10). The +its own traefik router for those four prefixes (priority 20; the frontend router is priority 10). **Second cut the same evening:** the router must target port **80** — the backend image runs +nginx in front of gunicorn, and Django hands a photo back as an `X-Accel-Redirect` that only that +nginx serves; on port 8000 the first cut returned a 200 with an empty body (the operator's browser +still showed „Uploaded content"). The k3s service targets port 80 for the same reason. The frontend's `/api` and `/auth` proxy stays as it is — that is also the k3s shape. Nothing else differed (`PUBLIC_URL`, `CSRF_TRUSTED_ORIGINS`, `ORIGIN`, `BODY_SIZE_LIMIT` all match). No version moved. diff --git a/templates/adventurelog/docker-compose.yml b/templates/adventurelog/docker-compose.yml index 13bf5f9..eaff907 100644 --- a/templates/adventurelog/docker-compose.yml +++ b/templates/adventurelog/docker-compose.yml @@ -48,7 +48,11 @@ services: - "traefik.http.routers.adventurelog-backend.tls=true" - "traefik.http.routers.adventurelog-backend.tls.certresolver=letsencrypt" - "traefik.http.routers.adventurelog-backend.service=adventurelog-backend" - - "traefik.http.services.adventurelog-backend.loadbalancer.server.port=8000" + # Port 80, not 8000: the backend image runs nginx in front of gunicorn, and Django answers a + # /media request with an X-Accel-Redirect that ONLY that nginx can serve — straight to gunicorn + # (8000) the photo comes back as a 200 with an empty body (measured 2026-09-13). The k3s + # service targets port 80 for the same reason. + - "traefik.http.services.adventurelog-backend.loadbalancer.server.port=80" deploy: resources: limits: