9395d19333
leftmost XFF decides who is on the LAN (remote-access and IP-filter bypass). Once traefik trusts the tunnel's fixed address (controller v0.286.0), the leftmost entry is what a stranger writes; with the chain removed the app reads traefik's X-Real-Ip or its peer, as before — never forgeable. Measured on 9202: a router with this middleware receives no X-Forwarded-For (felhom.eu audits/visitors-2026-10-01/A/P1). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
58 lines
2.0 KiB
YAML
58 lines
2.0 KiB
YAML
# Emby - Személyes média szerver élő TV és DVR támogatással
|
|
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
|
# Database: None (file-based)
|
|
# RAM: ~512M (mem_limit: 2048M) | Pi-compatible: No
|
|
#
|
|
# Environment variables:
|
|
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
|
# USERDATA_PATH - Ügyfél-tartalom gyökér (<namespace>/userdata)
|
|
#
|
|
# Storage layout (felhom userdata convention):
|
|
# Médiatár → ${USERDATA_PATH}/media (csak olvasható)
|
|
|
|
services:
|
|
emby:
|
|
image: emby/embyserver:4.11.0.4
|
|
container_name: emby
|
|
restart: unless-stopped
|
|
environment:
|
|
- TZ=Europe/Budapest
|
|
- UID=1000
|
|
- GID=1000
|
|
volumes:
|
|
- emby_config:/config
|
|
- ${USERDATA_PATH}/media:/media:ro
|
|
networks:
|
|
- traefik-public
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 2048M
|
|
healthcheck:
|
|
# Az Emby képfájlban NINCS curl és nincs önálló wget — csak BusyBox van.
|
|
# A korábbi curl-próba ezért soha nem futott le, a konténer véglegesen
|
|
# unhealthy maradt, és a Traefik nem irányított rá forgalmat (404).
|
|
test: ["CMD", "/bin/busybox", "wget", "--spider", "-q", "http://127.0.0.1:8096/emby/system/ping"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 30s
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.emby.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
|
# R-753: this app reads the LEFTMOST X-Forwarded-For entry, which a stranger writes once traefik keeps the
|
|
# tunnel's chain — so its chain is removed here (it then reads traefik's X-Real-Ip or peer; never forgeable).
|
|
- "traefik.http.middlewares.emby-xff.headers.customrequestheaders.X-Forwarded-For="
|
|
- "traefik.http.routers.emby.middlewares=emby-xff"
|
|
- "traefik.http.routers.emby.entrypoints=websecure"
|
|
- "traefik.http.routers.emby.tls=true"
|
|
- "traefik.http.routers.emby.tls.certresolver=letsencrypt"
|
|
- "traefik.http.services.emby.loadbalancer.server.port=8096"
|
|
|
|
volumes:
|
|
emby_config:
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|