Files
app-catalog-felhom.eu/templates/ghost/docker-compose.yml
T
admin 8975984b6e ghost: remove the client-written X-Forwarded-For chain on its router (R-753)
Express trust proxy true — leftmost XFF; its brute-force buckets are keyed by IP (+username). Once traefik trusts the tunnel's fixed address (controller v0.286.0), the leftmost entry is what a
stranger writes; with the chain removed the app reads traefik's X-Real-Ip or its peer, as before — never forgeable.
Measured on 9202: a router with this middleware receives no X-Forwarded-For (felhom.eu audits/visitors-2026-10-01/A/P1).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-01 21:02:53 +02:00

52 lines
1.8 KiB
YAML

# Ghost - Professzionális blog és hírlevél platform
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: None (file-based)
# RAM: ~150M (mem_limit: 512M) | Pi-compatible: No
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
services:
ghost:
image: ghost:6.67.0-alpine
container_name: ghost
restart: unless-stopped
environment:
- TZ=Europe/Budapest
- NODE_ENV=production
- url=https://${SUBDOMAIN}.${DOMAIN}
- database__client=sqlite3
- database__connection__filename=content/data/ghost.db
volumes:
- ghost_content:/var/lib/ghost/content
networks:
- traefik-public
deploy:
resources:
limits:
memory: 512M
healthcheck:
test: ["CMD", "node", "-e", "require('http').get('http://127.0.0.1:2368/',r=>{process.exit(r.statusCode<400?0:1)}).on('error',()=>process.exit(1))"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
labels:
- "traefik.enable=true"
- "traefik.http.routers.ghost.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
# R-753: this app reads the LEFTMOST X-Forwarded-For entry, which a stranger writes once traefik keeps the
# tunnel's chain — so its chain is removed here (it then reads traefik's X-Real-Ip or peer; never forgeable).
- "traefik.http.middlewares.ghost-xff.headers.customrequestheaders.X-Forwarded-For="
- "traefik.http.routers.ghost.middlewares=ghost-xff"
- "traefik.http.routers.ghost.entrypoints=websecure"
- "traefik.http.routers.ghost.tls=true"
- "traefik.http.routers.ghost.tls.certresolver=letsencrypt"
- "traefik.http.services.ghost.loadbalancer.server.port=2368"
volumes:
ghost_content:
networks:
traefik-public:
external: true