Files
app-catalog-felhom.eu/templates/wger/docker-compose.yml
T
admin 45d84827ad
gates / gates (push) Successful in 2s
wger: its app login API gets its JWT key pair (R-737)
The template set no JWT_PRIVATE_KEY/JWT_PUBLIC_KEY, so the app login (the mobile app's route) answered 500
on a CORRECT password. The deploy's generators cannot make an RSA pair, so the start command makes it ONCE
with wger's own `manage.py generate-jwt-keys`, keeps it 0600 on wger's data volume (a restore brings it
back), and loads it before the image's own entrypoint. Measured on the bench (2.7): right password 200 with
an access token that reads the API (200); wrong password 400 (allauth's answer); the key survives a
restart. No image moves.

Evidence: felhom.eu/documentation/audits/night-rulings-2026-09-30/D/

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-30 22:27:13 +02:00

84 lines
3.5 KiB
YAML

# wger - Edzésnapló és fitnesz tervező
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: None (file-based)
# RAM: ~100M (mem_limit: 384M) | Pi-compatible: Yes
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
# SECRET_KEY - Titkosítási kulcs (auto-generated)
services:
wger:
image: wger/server:2.7
container_name: wger
# R-737 (2026-09-30): wger's app login API (the mobile app's) signs JWTs with JWT_PRIVATE_KEY / JWT_PUBLIC_KEY — an
# RSA pair the deploy's generators cannot make, and without it a CORRECT password answered 500. So the pair is made
# ONCE by wger's own `manage.py generate-jwt-keys`, kept 0600 on wger's own data volume (a restore brings the same
# key back), and loaded before the image's own entrypoint. Never printed.
entrypoint:
- /bin/sh
- -c
- |
K=/home/wger/db/.felhom-jwt.env
if [ ! -s "$$K" ]; then
(cd /home/wger/src && python3 manage.py generate-jwt-keys 2>/dev/null) | grep -E '^JWT_(PRIVATE|PUBLIC)_KEY=' > "$$K.tmp"
if [ "$$(grep -c . "$$K.tmp")" = 2 ]; then mv "$$K.tmp" "$$K" && chmod 600 "$$K"; else rm -f "$$K.tmp"; echo "felhom: JWT keys could not be made" >&2; fi
fi
if [ -s "$$K" ]; then set -a; . "$$K"; set +a; fi
exec /home/wger/entrypoint.sh
restart: unless-stopped
environment:
- TZ=Europe/Budapest
- SECRET_KEY=${SECRET_KEY}
# A wger 2.4+ a TELJES DJANGO_DB_* halmazt beolvassa, akkor is, ha az
# engine sqlite -- enélkül indulás nélkül kilép ("Set the DJANGO_DB_USER
# environment variable"). Az USER/PASSWORD/HOST/PORT értékeket az sqlite
# backend figyelmen kívül hagyja, de jelen kell lenniük.
# A DATABASE a wger_data kötetre mutat (/home/wger/db), oda, ahol a wger
# saját alapértelmezett sqlite fájlja is volt -- így meglévő telepítés
# adatai nem "tűnnek el" egy másik útvonalra.
# R-712 (measured 2026-09-29 on 9202): behind traefik wger saw the request as http and refused a browser's
# https Origin with "CSRF verification failed" — nobody could sign in from a browser.
- CSRF_TRUSTED_ORIGINS=https://${SUBDOMAIN}.${DOMAIN}
- X_FORWARDED_PROTO_HEADER_SET=True
# R-738: the image runs `manage.py migrate` at start ONLY with this switch (entrypoint.sh). Without it an update
# that brings migrations leaves wger serving its front page over an unmigrated database (login 500).
- DJANGO_PERFORM_MIGRATIONS=True
- DJANGO_DB_ENGINE=django.db.backends.sqlite3
- DJANGO_DB_DATABASE=/home/wger/db/database.sqlite
- DJANGO_DB_USER=wger
- DJANGO_DB_PASSWORD=wger
- DJANGO_DB_HOST=localhost
- DJANGO_DB_PORT=5432
- SITE_URL=https://${SUBDOMAIN}.${DOMAIN}
volumes:
- wger_data:/home/wger/db
- wger_media:/home/wger/media
networks:
- traefik-public
deploy:
resources:
limits:
memory: 384M
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:8000"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
labels:
- "traefik.enable=true"
- "traefik.http.routers.wger.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.wger.entrypoints=websecure"
- "traefik.http.routers.wger.tls=true"
- "traefik.http.routers.wger.tls.certresolver=letsencrypt"
- "traefik.http.services.wger.loadbalancer.server.port=8000"
volumes:
wger_data:
wger_media:
networks:
traefik-public:
external: true