50e4fb42df
gates / gates (push) Successful in 2s
household-switchable trustProxy reads the leftmost XFF into its logs. Once traefik trusts the tunnel's fixed address (controller v0.286.0), the leftmost entry is what a stranger writes; with the chain removed the app reads traefik's X-Real-Ip or its peer, as before — never forgeable. Measured on 9202: a router with this middleware receives no X-Forwarded-For (felhom.eu audits/visitors-2026-10-01/A/P1). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
57 lines
2.4 KiB
YAML
57 lines
2.4 KiB
YAML
# Uptime Kuma - Szolgáltatás és weboldal monitoring
|
|
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
|
# Database: None (file-based)
|
|
# RAM: ~50M (mem_limit: 256M) | Pi-compatible: Yes
|
|
#
|
|
# Environment variables:
|
|
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
|
|
|
services:
|
|
uptime-kuma:
|
|
image: louislam/uptime-kuma:2.5.5
|
|
container_name: uptime-kuma
|
|
restart: unless-stopped
|
|
environment:
|
|
- TZ=Europe/Budapest
|
|
# R-613 (measured 2026-09-23): without this, 2.x parks at its SETUP-DATABASE wizard on first boot
|
|
# — the main server never starts, and the probe's any-answer check calls it healthy. With it the
|
|
# database choice is made (SQLite in /app/data) and the real server starts: /api/entry-page
|
|
# answers entryPage, /metrics 401. An install that already chose keeps its data/db-config.json.
|
|
- UPTIME_KUMA_DB_TYPE=sqlite
|
|
volumes:
|
|
- uptime_kuma_data:/app/data
|
|
networks:
|
|
- traefik-public
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 256M
|
|
# uptime-kuma:2 ships its healthcheck as a compiled binary at /app/extra/healthcheck (WORKDIR /app);
|
|
# the old override pointed at a v1-era /app/extra/healthcheck.mjs that does NOT exist in v2, so the
|
|
# container stayed permanently "unhealthy" → Traefik withheld the route → the URL 404'd although the
|
|
# app was running (F5). Use the correct binary and the image's own timing (180s first-boot window).
|
|
healthcheck:
|
|
test: ["CMD", "extra/healthcheck"]
|
|
interval: 30s
|
|
timeout: 30s
|
|
retries: 5
|
|
start_period: 180s
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.uptime-kuma.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
|
# R-753: this app reads the LEFTMOST X-Forwarded-For entry, which a stranger writes once traefik keeps the
|
|
# tunnel's chain — so its chain is removed here (it then reads traefik's X-Real-Ip or peer; never forgeable).
|
|
- "traefik.http.middlewares.uptime-kuma-xff.headers.customrequestheaders.X-Forwarded-For="
|
|
- "traefik.http.routers.uptime-kuma.middlewares=uptime-kuma-xff"
|
|
- "traefik.http.routers.uptime-kuma.entrypoints=websecure"
|
|
- "traefik.http.routers.uptime-kuma.tls=true"
|
|
- "traefik.http.routers.uptime-kuma.tls.certresolver=letsencrypt"
|
|
- "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001"
|
|
|
|
volumes:
|
|
uptime_kuma_data:
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|