# wger - Edzésnapló és fitnesz tervező # Domain: ${SUBDOMAIN}.${DOMAIN} # Database: None (file-based) # RAM: ~100M (mem_limit: 384M) | Pi-compatible: Yes # # Environment variables: # DOMAIN - Your domain (e.g., demo-felhom.eu) # SECRET_KEY - Titkosítási kulcs (auto-generated) services: wger: image: wger/server:2.7 container_name: wger # R-737 (2026-09-30): wger's app login API (the mobile app's) signs JWTs with JWT_PRIVATE_KEY / JWT_PUBLIC_KEY — an # RSA pair the deploy's generators cannot make, and without it a CORRECT password answered 500. So the pair is made # ONCE by wger's own `manage.py generate-jwt-keys`, kept 0600 on wger's own data volume (a restore brings the same # key back), and loaded before the image's own entrypoint. Never printed. entrypoint: - /bin/sh - -c - | K=/home/wger/db/.felhom-jwt.env if [ ! -s "$$K" ]; then (cd /home/wger/src && python3 manage.py generate-jwt-keys 2>/dev/null) | grep -E '^JWT_(PRIVATE|PUBLIC)_KEY=' > "$$K.tmp" if [ "$$(grep -c . "$$K.tmp")" = 2 ]; then mv "$$K.tmp" "$$K" && chmod 600 "$$K"; else rm -f "$$K.tmp"; echo "felhom: JWT keys could not be made" >&2; fi fi if [ -s "$$K" ]; then set -a; . "$$K"; set +a; fi exec /home/wger/entrypoint.sh restart: unless-stopped environment: - TZ=Europe/Budapest - SECRET_KEY=${SECRET_KEY} # A wger 2.4+ a TELJES DJANGO_DB_* halmazt beolvassa, akkor is, ha az # engine sqlite -- enélkül indulás nélkül kilép ("Set the DJANGO_DB_USER # environment variable"). Az USER/PASSWORD/HOST/PORT értékeket az sqlite # backend figyelmen kívül hagyja, de jelen kell lenniük. # A DATABASE a wger_data kötetre mutat (/home/wger/db), oda, ahol a wger # saját alapértelmezett sqlite fájlja is volt -- így meglévő telepítés # adatai nem "tűnnek el" egy másik útvonalra. # R-712 (measured 2026-09-29 on 9202): behind traefik wger saw the request as http and refused a browser's # https Origin with "CSRF verification failed" — nobody could sign in from a browser. - CSRF_TRUSTED_ORIGINS=https://${SUBDOMAIN}.${DOMAIN} - X_FORWARDED_PROTO_HEADER_SET=True # R-738: the image runs `manage.py migrate` at start ONLY with this switch (entrypoint.sh). Without it an update # that brings migrations leaves wger serving its front page over an unmigrated database (login 500). - DJANGO_PERFORM_MIGRATIONS=True # R-752 (decided by CC unattended 2026-10-01, `09` §3 decision 58 — operator may reverse): django-axes locked by # ip_address, and behind the tunnel every visitor has the tunnel's address (R-753) — a stranger's 10 wrong tries # locked out EVERY household member for 30 min. Now only the targeted name, for 5 min (each try during a lock # restarts it — wger 2.7 hard-codes that — so short is kinder), counted in the database (the default cache # handler warns axes.W001). Measured on 9202: the other member unaffected; the targeted one in again at 7.5 min. - AXES_LOCKOUT_PARAMETERS=username - AXES_COOLOFF_TIME=5 - AXES_HANDLER=axes.handlers.database.AxesDatabaseHandler - DJANGO_DB_ENGINE=django.db.backends.sqlite3 - DJANGO_DB_DATABASE=/home/wger/db/database.sqlite - DJANGO_DB_USER=wger - DJANGO_DB_PASSWORD=wger - DJANGO_DB_HOST=localhost - DJANGO_DB_PORT=5432 - SITE_URL=https://${SUBDOMAIN}.${DOMAIN} volumes: - wger_data:/home/wger/db - wger_media:/home/wger/media networks: - traefik-public deploy: resources: limits: memory: 384M healthcheck: test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:8000"] interval: 30s timeout: 5s retries: 3 start_period: 30s labels: - "traefik.enable=true" - "traefik.http.routers.wger.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)" - "traefik.http.routers.wger.entrypoints=websecure" - "traefik.http.routers.wger.tls=true" - "traefik.http.routers.wger.tls.certresolver=letsencrypt" - "traefik.http.services.wger.loadbalancer.server.port=8000" volumes: wger_data: wger_media: networks: traefik-public: external: true