828fafe7d7
django-allauth 0.63.3 — leftmost XFF for its per-IP login limits. Once traefik trusts the tunnel's fixed address (controller v0.286.0), the leftmost entry is what a stranger writes; with the chain removed the app reads traefik's X-Real-Ip or its peer, as before — never forgeable. Measured on 9202: a router with this middleware receives no X-Forwarded-For (felhom.eu audits/visitors-2026-10-01/A/P1). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
155 lines
7.2 KiB
YAML
155 lines
7.2 KiB
YAML
# AdventureLog - Utazási napló és kalandtervező
|
|
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
|
# Database: postgres
|
|
# RAM: ~100M (mem_limit: 384M) | Pi-compatible: Yes
|
|
#
|
|
# Environment variables:
|
|
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
|
# SECRET_KEY - Titkosítási kulcs (auto-generated)
|
|
# DB_PASSWORD - Adatbázis jelszó (auto-generated)
|
|
|
|
services:
|
|
adventurelog:
|
|
image: ghcr.io/seanmorley15/adventurelog-backend:v0.13.0
|
|
container_name: adventurelog
|
|
restart: unless-stopped
|
|
depends_on:
|
|
adventurelog-postgres:
|
|
condition: service_healthy
|
|
environment:
|
|
# decision 47: the app's own sign-up switch — open until the box closes it after the first admin (after_setup)
|
|
- DISABLE_REGISTRATION=${SIGNUP_CLOSED:-false}
|
|
- DJANGO_SECRET_KEY=${SECRET_KEY}
|
|
- SECRET_KEY=${SECRET_KEY}
|
|
# R-482: the image defaults DEBUG to True (settings: getenv('DEBUG','True')), which serves full
|
|
# Django debug pages — settings, paths, tracebacks — on the internet-facing origin. Measured
|
|
# 2026-09-13 on demo-hp. Upstream's own compose sets it False; so do we.
|
|
- DEBUG=False
|
|
- PGHOST=adventurelog-postgres
|
|
- PGDATABASE=adventurelog
|
|
- PGUSER=adventurelog
|
|
- PGPASSWORD=${DB_PASSWORD}
|
|
- PUBLIC_URL=https://${SUBDOMAIN}.${DOMAIN}
|
|
- CSRF_TRUSTED_ORIGINS=https://${SUBDOMAIN}.${DOMAIN}
|
|
- FRONTEND_URL=https://${SUBDOMAIN}.${DOMAIN}
|
|
# `09` §3 decision 41 (R-655): the world-data download stays. v0.13.0 runs `download-countries` at EVERY
|
|
# start and fetches only when the file is ABSENT — a cut-off file from an interrupted download (v0.12.1
|
|
# ignored such failures) makes every start fail with `IncompleteJSONError`. Before the image's own
|
|
# entrypoint, a file that does not parse to its end is SET ASIDE (renamed, never deleted), so the
|
|
# command downloads it again. The same entrypoint and command as the image's (both versions, measured).
|
|
entrypoint:
|
|
- /bin/bash
|
|
- -c
|
|
- |
|
|
for f in /code/media/countries+regions+states-*.json; do
|
|
[ -s "$$f" ] || continue
|
|
if ! python3 -c 'import ijson,sys; [0 for _ in ijson.items(open(sys.argv[1],"rb"),"item")]' "$$f" 2>/dev/null; then
|
|
mv "$$f" "$$f.cutoff-$$(date +%Y%m%d%H%M%S)"
|
|
echo "felhom: $$f did not parse to its end - set aside, it is downloaded again" >&2
|
|
fi
|
|
done
|
|
exec /code/entrypoint.sh "$$@"
|
|
- --
|
|
command: ["supervisord", "-c", "/etc/supervisor/conf.d/supervisord.conf"]
|
|
volumes:
|
|
- adventurelog_media:/code/media
|
|
networks:
|
|
- traefik-public
|
|
- adventurelog-internal
|
|
# R-483: the backend serves the uploaded photos (/media), Django's static files, the admin and the
|
|
# account pages ITSELF; the frontend does not proxy them. With every path routed to the frontend an
|
|
# uploaded photo rendered as a broken "Uploaded content" (measured 2026-09-13 on demo-hp; the
|
|
# operator's k3s install routes exactly these four prefixes to the backend and renders photos).
|
|
# Higher priority than the frontend router, same host.
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.adventurelog-backend.rule=Host(`${SUBDOMAIN}.${DOMAIN}`) && (PathPrefix(`/media`) || PathPrefix(`/static`) || PathPrefix(`/admin`) || PathPrefix(`/accounts`))"
|
|
# R-753: this app reads the LEFTMOST X-Forwarded-For entry, which a stranger writes once traefik keeps the
|
|
# tunnel's chain — so its chain is removed here (it then reads traefik's X-Real-Ip or peer; never forgeable).
|
|
- "traefik.http.middlewares.adventurelog-backend-xff.headers.customrequestheaders.X-Forwarded-For="
|
|
- "traefik.http.routers.adventurelog-backend.middlewares=adventurelog-backend-xff"
|
|
- "traefik.http.routers.adventurelog-backend.priority=20"
|
|
- "traefik.http.routers.adventurelog-backend.entrypoints=websecure"
|
|
- "traefik.http.routers.adventurelog-backend.tls=true"
|
|
- "traefik.http.routers.adventurelog-backend.tls.certresolver=letsencrypt"
|
|
- "traefik.http.routers.adventurelog-backend.service=adventurelog-backend"
|
|
# Port 80, not 8000: the backend image runs nginx in front of gunicorn, and Django answers a
|
|
# /media request with an X-Accel-Redirect that ONLY that nginx can serve — straight to gunicorn
|
|
# (8000) the photo comes back as a 200 with an empty body (measured 2026-09-13). The k3s
|
|
# service targets port 80 for the same reason.
|
|
- "traefik.http.services.adventurelog-backend.loadbalancer.server.port=80"
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 384M
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "python -c 'import urllib.request; urllib.request.urlopen(\"http://127.0.0.1:8000/api/\")'"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 3
|
|
start_period: 30s
|
|
adventurelog-postgres:
|
|
image: postgis/postgis:16-3.5-alpine
|
|
container_name: adventurelog-postgres
|
|
restart: unless-stopped
|
|
environment:
|
|
- POSTGRES_USER=adventurelog
|
|
- POSTGRES_PASSWORD=${DB_PASSWORD}
|
|
- POSTGRES_DB=adventurelog
|
|
- TZ=Europe/Budapest
|
|
volumes:
|
|
- adventurelog_postgres_data:/var/lib/postgresql/data
|
|
networks:
|
|
- adventurelog-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 256M
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U adventurelog -d adventurelog"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
start_period: 20s
|
|
|
|
adventurelog-frontend:
|
|
image: ghcr.io/seanmorley15/adventurelog-frontend:v0.13.0
|
|
container_name: adventurelog-frontend
|
|
restart: unless-stopped
|
|
environment:
|
|
- PUBLIC_SERVER_URL=http://adventurelog:8000
|
|
- BODY_SIZE_LIMIT=Infinity
|
|
- ORIGIN=https://${SUBDOMAIN}.${DOMAIN}
|
|
networks:
|
|
- traefik-public
|
|
- adventurelog-internal
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.adventurelog.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
|
# R-753: this app reads the LEFTMOST X-Forwarded-For entry, which a stranger writes once traefik keeps the
|
|
# tunnel's chain — so its chain is removed here (it then reads traefik's X-Real-Ip or peer; never forgeable).
|
|
- "traefik.http.middlewares.adventurelog-xff.headers.customrequestheaders.X-Forwarded-For="
|
|
- "traefik.http.routers.adventurelog.middlewares=adventurelog-xff"
|
|
- "traefik.http.routers.adventurelog.priority=10"
|
|
- "traefik.http.routers.adventurelog.entrypoints=websecure"
|
|
- "traefik.http.routers.adventurelog.tls=true"
|
|
- "traefik.http.routers.adventurelog.tls.certresolver=letsencrypt"
|
|
- "traefik.http.services.adventurelog.loadbalancer.server.port=3000"
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 256M
|
|
# No healthcheck override (R-655): v0.12.1's image has none and keeps node at /nodejs/bin/node only;
|
|
# v0.13.0's image brings its own (`node` on the PATH, /usr/bin/node, fetching /health, which needs the
|
|
# backend). No single exec path works on both versions (measured 2026-09-27), and the old override
|
|
# (/nodejs/bin/node) left v0.13.0 unhealthy forever.
|
|
|
|
volumes:
|
|
adventurelog_media:
|
|
adventurelog_postgres_data:
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|
|
adventurelog-internal:
|