# AdventureLog - Utazási napló és kalandtervező # Domain: ${SUBDOMAIN}.${DOMAIN} # Database: postgres # RAM: ~100M (mem_limit: 384M) | Pi-compatible: Yes # # Environment variables: # DOMAIN - Your domain (e.g., demo-felhom.eu) # SECRET_KEY - Titkosítási kulcs (auto-generated) # DB_PASSWORD - Adatbázis jelszó (auto-generated) services: adventurelog: image: ghcr.io/seanmorley15/adventurelog-backend:v0.13.0 container_name: adventurelog restart: unless-stopped depends_on: adventurelog-postgres: condition: service_healthy environment: # decision 47: the app's own sign-up switch — open until the box closes it after the first admin (after_setup) - DISABLE_REGISTRATION=${SIGNUP_CLOSED:-false} - DJANGO_SECRET_KEY=${SECRET_KEY} - SECRET_KEY=${SECRET_KEY} # R-482: the image defaults DEBUG to True (settings: getenv('DEBUG','True')), which serves full # Django debug pages — settings, paths, tracebacks — on the internet-facing origin. Measured # 2026-09-13 on demo-hp. Upstream's own compose sets it False; so do we. - DEBUG=False - PGHOST=adventurelog-postgres - PGDATABASE=adventurelog - PGUSER=adventurelog - PGPASSWORD=${DB_PASSWORD} - PUBLIC_URL=https://${SUBDOMAIN}.${DOMAIN} - CSRF_TRUSTED_ORIGINS=https://${SUBDOMAIN}.${DOMAIN} - FRONTEND_URL=https://${SUBDOMAIN}.${DOMAIN} # `09` §3 decision 41 (R-655): the world-data download stays. v0.13.0 runs `download-countries` at EVERY # start and fetches only when the file is ABSENT — a cut-off file from an interrupted download (v0.12.1 # ignored such failures) makes every start fail with `IncompleteJSONError`. Before the image's own # entrypoint, a file that does not parse to its end is SET ASIDE (renamed, never deleted), so the # command downloads it again. The same entrypoint and command as the image's (both versions, measured). entrypoint: - /bin/bash - -c - | for f in /code/media/countries+regions+states-*.json; do [ -s "$$f" ] || continue if ! python3 -c 'import ijson,sys; [0 for _ in ijson.items(open(sys.argv[1],"rb"),"item")]' "$$f" 2>/dev/null; then mv "$$f" "$$f.cutoff-$$(date +%Y%m%d%H%M%S)" echo "felhom: $$f did not parse to its end - set aside, it is downloaded again" >&2 fi done exec /code/entrypoint.sh "$$@" - -- command: ["supervisord", "-c", "/etc/supervisor/conf.d/supervisord.conf"] volumes: - adventurelog_media:/code/media networks: - traefik-public - adventurelog-internal # R-483: the backend serves the uploaded photos (/media), Django's static files, the admin and the # account pages ITSELF; the frontend does not proxy them. With every path routed to the frontend an # uploaded photo rendered as a broken "Uploaded content" (measured 2026-09-13 on demo-hp; the # operator's k3s install routes exactly these four prefixes to the backend and renders photos). # Higher priority than the frontend router, same host. labels: - "traefik.enable=true" - "traefik.http.routers.adventurelog-backend.rule=Host(`${SUBDOMAIN}.${DOMAIN}`) && (PathPrefix(`/media`) || PathPrefix(`/static`) || PathPrefix(`/admin`) || PathPrefix(`/accounts`))" # R-753: this app reads the LEFTMOST X-Forwarded-For entry, which a stranger writes once traefik keeps the # tunnel's chain — so its chain is removed here (it then reads traefik's X-Real-Ip or peer; never forgeable). - "traefik.http.middlewares.adventurelog-backend-xff.headers.customrequestheaders.X-Forwarded-For=" - "traefik.http.routers.adventurelog-backend.middlewares=adventurelog-backend-xff" - "traefik.http.routers.adventurelog-backend.priority=20" - "traefik.http.routers.adventurelog-backend.entrypoints=websecure" - "traefik.http.routers.adventurelog-backend.tls=true" - "traefik.http.routers.adventurelog-backend.tls.certresolver=letsencrypt" - "traefik.http.routers.adventurelog-backend.service=adventurelog-backend" # Port 80, not 8000: the backend image runs nginx in front of gunicorn, and Django answers a # /media request with an X-Accel-Redirect that ONLY that nginx can serve — straight to gunicorn # (8000) the photo comes back as a 200 with an empty body (measured 2026-09-13). The k3s # service targets port 80 for the same reason. - "traefik.http.services.adventurelog-backend.loadbalancer.server.port=80" deploy: resources: limits: memory: 384M healthcheck: test: ["CMD-SHELL", "python -c 'import urllib.request; urllib.request.urlopen(\"http://127.0.0.1:8000/api/\")'"] interval: 30s timeout: 10s retries: 3 start_period: 30s adventurelog-postgres: image: postgis/postgis:16-3.5-alpine container_name: adventurelog-postgres restart: unless-stopped environment: - POSTGRES_USER=adventurelog - POSTGRES_PASSWORD=${DB_PASSWORD} - POSTGRES_DB=adventurelog - TZ=Europe/Budapest volumes: - adventurelog_postgres_data:/var/lib/postgresql/data networks: - adventurelog-internal deploy: resources: limits: memory: 256M healthcheck: test: ["CMD-SHELL", "pg_isready -U adventurelog -d adventurelog"] interval: 10s timeout: 5s retries: 5 start_period: 20s adventurelog-frontend: image: ghcr.io/seanmorley15/adventurelog-frontend:v0.13.0 container_name: adventurelog-frontend restart: unless-stopped environment: - PUBLIC_SERVER_URL=http://adventurelog:8000 - BODY_SIZE_LIMIT=Infinity - ORIGIN=https://${SUBDOMAIN}.${DOMAIN} networks: - traefik-public - adventurelog-internal labels: - "traefik.enable=true" - "traefik.http.routers.adventurelog.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)" # R-753: this app reads the LEFTMOST X-Forwarded-For entry, which a stranger writes once traefik keeps the # tunnel's chain — so its chain is removed here (it then reads traefik's X-Real-Ip or peer; never forgeable). - "traefik.http.middlewares.adventurelog-xff.headers.customrequestheaders.X-Forwarded-For=" - "traefik.http.routers.adventurelog.middlewares=adventurelog-xff" - "traefik.http.routers.adventurelog.priority=10" - "traefik.http.routers.adventurelog.entrypoints=websecure" - "traefik.http.routers.adventurelog.tls=true" - "traefik.http.routers.adventurelog.tls.certresolver=letsencrypt" - "traefik.http.services.adventurelog.loadbalancer.server.port=3000" deploy: resources: limits: memory: 256M # No healthcheck override (R-655): v0.12.1's image has none and keeps node at /nodejs/bin/node only; # v0.13.0's image brings its own (`node` on the PATH, /usr/bin/node, fetching /health, which needs the # backend). No single exec path works on both versions (measured 2026-09-27), and the old override # (/nodejs/bin/node) left v0.13.0 unhealthy forever. volumes: adventurelog_media: adventurelog_postgres_data: networks: traefik-public: external: true adventurelog-internal: