04e951697c
Fastify trustProxy true — leftmost XFF; its login limit (10/min) is keyed by IP only. Once traefik trusts the tunnel's fixed address (controller v0.286.0), the leftmost entry is what a stranger writes; with the chain removed the app reads traefik's X-Real-Ip or its peer, as before — never forgeable. Measured on 9202: a router with this middleware receives no X-Forwarded-For (felhom.eu audits/visitors-2026-10-01/A/P1). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
115 lines
3.6 KiB
YAML
115 lines
3.6 KiB
YAML
# Docmost - Modern Wiki / Documentation (Notion-like)
|
|
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
|
# Database: PostgreSQL + Redis
|
|
# RAM: ~200MB (mem_limit: 896M total — docmost 512M + postgres 256M + redis 128M) | Pi-compatible: No (heavy)
|
|
# docmost 384M -> 512M (2026-09-25, `09` §3 decision 39): its own memory reached 91% of 384M under the harness's
|
|
# light load; Node sizes its heap from the limit (431 MB at 512M), 0 kills / 0 restarts in both 10-minute watches.
|
|
#
|
|
# Environment variables:
|
|
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
|
# APP_SECRET - Random secret for session signing (auto-generated)
|
|
# DB_PASSWORD - PostgreSQL password (auto-generated)
|
|
#
|
|
# First-time setup:
|
|
# First registered user becomes admin.
|
|
|
|
services:
|
|
docmost:
|
|
image: docmost/docmost:0.96.0
|
|
container_name: docmost
|
|
restart: unless-stopped
|
|
depends_on:
|
|
docmost-postgres:
|
|
condition: service_healthy
|
|
docmost-redis:
|
|
condition: service_healthy
|
|
environment:
|
|
- APP_SECRET=${APP_SECRET}
|
|
- DATABASE_URL=postgresql://docmost:${DB_PASSWORD}@docmost-postgres:5432/docmost
|
|
- REDIS_URL=redis://docmost-redis:6379
|
|
- APP_URL=https://${SUBDOMAIN}.${DOMAIN}
|
|
- STORAGE_DRIVER=local
|
|
- FILE_UPLOAD_SIZE_LIMIT=50mb
|
|
- TZ=Europe/Budapest
|
|
volumes:
|
|
- docmost_storage:/app/data/storage
|
|
networks:
|
|
- traefik-public
|
|
- docmost-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 512M
|
|
healthcheck:
|
|
test: ["CMD", "node", "-e", "const http = require('http'); http.get('http://127.0.0.1:3000/', (r) => { process.exit(r.statusCode === 200 ? 0 : 1) }).on('error', () => process.exit(1))"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 30s
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.docmost.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
|
# R-753: this app reads the LEFTMOST X-Forwarded-For entry, which a stranger writes once traefik keeps the
|
|
# tunnel's chain — so its chain is removed here (it then reads traefik's X-Real-Ip or peer; never forgeable).
|
|
- "traefik.http.middlewares.docmost-xff.headers.customrequestheaders.X-Forwarded-For="
|
|
- "traefik.http.routers.docmost.middlewares=docmost-xff"
|
|
- "traefik.http.routers.docmost.entrypoints=websecure"
|
|
- "traefik.http.routers.docmost.tls=true"
|
|
- "traefik.http.routers.docmost.tls.certresolver=letsencrypt"
|
|
- "traefik.http.services.docmost.loadbalancer.server.port=3000"
|
|
|
|
docmost-postgres:
|
|
image: postgres:18-alpine
|
|
container_name: docmost-postgres
|
|
restart: unless-stopped
|
|
environment:
|
|
- POSTGRES_USER=docmost
|
|
- POSTGRES_PASSWORD=${DB_PASSWORD}
|
|
- POSTGRES_DB=docmost
|
|
- TZ=Europe/Budapest
|
|
volumes:
|
|
- docmost_postgres_data:/var/lib/postgresql
|
|
networks:
|
|
- docmost-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 256M
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U docmost -d docmost"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
start_period: 20s
|
|
|
|
docmost-redis:
|
|
image: redis:7-alpine
|
|
container_name: docmost-redis
|
|
restart: unless-stopped
|
|
command: redis-server --appendonly yes
|
|
environment:
|
|
- TZ=Europe/Budapest
|
|
volumes:
|
|
- docmost_redis_data:/data
|
|
networks:
|
|
- docmost-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 128M
|
|
healthcheck:
|
|
test: ["CMD", "redis-cli", "ping"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 3
|
|
|
|
volumes:
|
|
docmost_storage:
|
|
docmost_postgres_data:
|
|
docmost_redis_data:
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|
|
docmost-internal:
|