Files
app-catalog-felhom.eu/templates/outline/docker-compose.yml
T
admin ba06d488db outline: remove the client-written X-Forwarded-For chain on its router (R-753)
Koa proxy — leftmost XFF for its per-IP limits and the sign-in link's IP binding. Once traefik trusts the tunnel's fixed address (controller v0.286.0), the leftmost entry is what a
stranger writes; with the chain removed the app reads traefik's X-Real-Ip or its peer, as before — never forgeable.
Measured on 9202: a router with this middleware receives no X-Forwarded-For (felhom.eu audits/visitors-2026-10-01/A/P1).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-01 21:03:00 +02:00

117 lines
3.7 KiB
YAML

# Outline - Modern csapat tudásbázis Markdown támogatással
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: postgres
# RAM: ~200M (mem_limit: 768M) | Pi-compatible: No
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
# SECRET_KEY - Titkosítási kulcs (auto-generated)
# UTILS_SECRET - Segédprogram kulcs (auto-generated)
# DB_PASSWORD - Adatbázis jelszó (auto-generated)
services:
outline:
image: outlinewiki/outline:1.10.1
container_name: outline
restart: unless-stopped
depends_on:
outline-postgres:
condition: service_healthy
outline-redis:
condition: service_healthy
environment:
- NODE_ENV=production
- SECRET_KEY=${SECRET_KEY}
- UTILS_SECRET=${UTILS_SECRET}
- DATABASE_URL=postgres://outline:${DB_PASSWORD}@outline-postgres:5432/outline
# Az Outline 1.x alapértelmezésben SSL-t vár a Postgrestől. A stackben futó
# sidecar Postgres nem beszél SSL-t (belső hálózat), ezért enélkül az app
# indulási hurokba kerül: "The server does not support SSL connections".
- PGSSLMODE=disable
- REDIS_URL=redis://outline-redis:6379
- URL=https://${SUBDOMAIN}.${DOMAIN}
- PORT=3000
- FILE_STORAGE=local
- FILE_STORAGE_LOCAL_ROOT_DIR=/var/lib/outline/data
volumes:
- outline_data:/var/lib/outline/data
networks:
- traefik-public
- outline-internal
deploy:
resources:
limits:
memory: 768M
healthcheck:
test: ["CMD", "node", "-e", "const http = require('http'); http.get('http://127.0.0.1:3000/_health', (r) => { process.exit(r.statusCode === 200 ? 0 : 1) }).on('error', () => process.exit(1))"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
labels:
- "traefik.enable=true"
- "traefik.http.routers.outline.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
# R-753: this app reads the LEFTMOST X-Forwarded-For entry, which a stranger writes once traefik keeps the
# tunnel's chain — so its chain is removed here (it then reads traefik's X-Real-Ip or peer; never forgeable).
- "traefik.http.middlewares.outline-xff.headers.customrequestheaders.X-Forwarded-For="
- "traefik.http.routers.outline.middlewares=outline-xff"
- "traefik.http.routers.outline.entrypoints=websecure"
- "traefik.http.routers.outline.tls=true"
- "traefik.http.routers.outline.tls.certresolver=letsencrypt"
- "traefik.http.services.outline.loadbalancer.server.port=3000"
outline-postgres:
image: postgres:18-alpine
container_name: outline-postgres
restart: unless-stopped
environment:
- POSTGRES_USER=outline
- POSTGRES_PASSWORD=${DB_PASSWORD}
- POSTGRES_DB=outline
- TZ=Europe/Budapest
volumes:
- outline_postgres_data:/var/lib/postgresql
networks:
- outline-internal
deploy:
resources:
limits:
memory: 256M
healthcheck:
test: ["CMD-SHELL", "pg_isready -U outline -d outline"]
interval: 10s
timeout: 5s
retries: 5
start_period: 20s
outline-redis:
image: redis:7-alpine
container_name: outline-redis
restart: unless-stopped
environment:
- TZ=Europe/Budapest
volumes:
- outline_redis_data:/data
networks:
- outline-internal
deploy:
resources:
limits:
memory: 128M
healthcheck:
test: ["CMD", "redis-cli", "ping"]
interval: 10s
timeout: 5s
retries: 5
start_period: 20s
volumes:
outline_data:
outline_postgres_data:
outline_redis_data:
networks:
traefik-public:
external: true
outline-internal: