82fff329a4
gates / gates (push) Successful in 2s
django-axes keyed on ip_address, and behind the tunnel every visitor has the tunnel container's address (R-753). Measured on 9202 (felhom.eu/documentation/audits/lockouts-2026-10-01/B/): live template — 10 wrong tries on admin locked the second member too; with AXES_LOCKOUT_PARAMETERS=username, AXES_COOLOFF_TIME=5 and the database handler — the second member unaffected, admin in again at 7.5 min after one retry during the lock, a wrong password still refused. Settings only: no image moves, no ladder entry (gates OK). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
92 lines
4.2 KiB
YAML
92 lines
4.2 KiB
YAML
# wger - Edzésnapló és fitnesz tervező
|
|
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
|
# Database: None (file-based)
|
|
# RAM: ~100M (mem_limit: 384M) | Pi-compatible: Yes
|
|
#
|
|
# Environment variables:
|
|
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
|
# SECRET_KEY - Titkosítási kulcs (auto-generated)
|
|
|
|
services:
|
|
wger:
|
|
image: wger/server:2.7
|
|
container_name: wger
|
|
# R-737 (2026-09-30): wger's app login API (the mobile app's) signs JWTs with JWT_PRIVATE_KEY / JWT_PUBLIC_KEY — an
|
|
# RSA pair the deploy's generators cannot make, and without it a CORRECT password answered 500. So the pair is made
|
|
# ONCE by wger's own `manage.py generate-jwt-keys`, kept 0600 on wger's own data volume (a restore brings the same
|
|
# key back), and loaded before the image's own entrypoint. Never printed.
|
|
entrypoint:
|
|
- /bin/sh
|
|
- -c
|
|
- |
|
|
K=/home/wger/db/.felhom-jwt.env
|
|
if [ ! -s "$$K" ]; then
|
|
(cd /home/wger/src && python3 manage.py generate-jwt-keys 2>/dev/null) | grep -E '^JWT_(PRIVATE|PUBLIC)_KEY=' > "$$K.tmp"
|
|
if [ "$$(grep -c . "$$K.tmp")" = 2 ]; then mv "$$K.tmp" "$$K" && chmod 600 "$$K"; else rm -f "$$K.tmp"; echo "felhom: JWT keys could not be made" >&2; fi
|
|
fi
|
|
if [ -s "$$K" ]; then set -a; . "$$K"; set +a; fi
|
|
exec /home/wger/entrypoint.sh
|
|
restart: unless-stopped
|
|
environment:
|
|
- TZ=Europe/Budapest
|
|
- SECRET_KEY=${SECRET_KEY}
|
|
# A wger 2.4+ a TELJES DJANGO_DB_* halmazt beolvassa, akkor is, ha az
|
|
# engine sqlite -- enélkül indulás nélkül kilép ("Set the DJANGO_DB_USER
|
|
# environment variable"). Az USER/PASSWORD/HOST/PORT értékeket az sqlite
|
|
# backend figyelmen kívül hagyja, de jelen kell lenniük.
|
|
# A DATABASE a wger_data kötetre mutat (/home/wger/db), oda, ahol a wger
|
|
# saját alapértelmezett sqlite fájlja is volt -- így meglévő telepítés
|
|
# adatai nem "tűnnek el" egy másik útvonalra.
|
|
# R-712 (measured 2026-09-29 on 9202): behind traefik wger saw the request as http and refused a browser's
|
|
# https Origin with "CSRF verification failed" — nobody could sign in from a browser.
|
|
- CSRF_TRUSTED_ORIGINS=https://${SUBDOMAIN}.${DOMAIN}
|
|
- X_FORWARDED_PROTO_HEADER_SET=True
|
|
# R-738: the image runs `manage.py migrate` at start ONLY with this switch (entrypoint.sh). Without it an update
|
|
# that brings migrations leaves wger serving its front page over an unmigrated database (login 500).
|
|
- DJANGO_PERFORM_MIGRATIONS=True
|
|
# R-752 (decided by CC unattended 2026-10-01, `09` §3 decision 58 — operator may reverse): django-axes locked by
|
|
# ip_address, and behind the tunnel every visitor has the tunnel's address (R-753) — a stranger's 10 wrong tries
|
|
# locked out EVERY household member for 30 min. Now only the targeted name, for 5 min (each try during a lock
|
|
# restarts it — wger 2.7 hard-codes that — so short is kinder), counted in the database (the default cache
|
|
# handler warns axes.W001). Measured on 9202: the other member unaffected; the targeted one in again at 7.5 min.
|
|
- AXES_LOCKOUT_PARAMETERS=username
|
|
- AXES_COOLOFF_TIME=5
|
|
- AXES_HANDLER=axes.handlers.database.AxesDatabaseHandler
|
|
- DJANGO_DB_ENGINE=django.db.backends.sqlite3
|
|
- DJANGO_DB_DATABASE=/home/wger/db/database.sqlite
|
|
- DJANGO_DB_USER=wger
|
|
- DJANGO_DB_PASSWORD=wger
|
|
- DJANGO_DB_HOST=localhost
|
|
- DJANGO_DB_PORT=5432
|
|
- SITE_URL=https://${SUBDOMAIN}.${DOMAIN}
|
|
volumes:
|
|
- wger_data:/home/wger/db
|
|
- wger_media:/home/wger/media
|
|
networks:
|
|
- traefik-public
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 384M
|
|
healthcheck:
|
|
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:8000"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 30s
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.wger.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
|
- "traefik.http.routers.wger.entrypoints=websecure"
|
|
- "traefik.http.routers.wger.tls=true"
|
|
- "traefik.http.routers.wger.tls.certresolver=letsencrypt"
|
|
- "traefik.http.services.wger.loadbalancer.server.port=8000"
|
|
|
|
volumes:
|
|
wger_data:
|
|
wger_media:
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|