Files
app-catalog-felhom.eu/templates/wger/docker-compose.yml
T
admin eec9a0d5af
gates / gates (push) Successful in 6s
wger: gunicorn with 2 workers instead of the development server (R-762)
WGER_USE_GUNICORN=True + WEB_CONCURRENCY=2. Proven on bench 9401 (anon 44 %) and
scratch 9202 (anon 64.1 % of 384M, 0 oom_kill, 0 restarts; login, CSS and a photo
200). wger stays lifecycle: hidden. No ladder entry: no image moves.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-08 10:10:07 +02:00

161 lines
8.5 KiB
YAML

# wger - Edzésnapló és fitnesz tervező
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: None (file-based)
# RAM: ~250M with 2 gunicorn workers (measured 2026-10-08; mem_limit: 384M + wger-files 32M) | Pi-compatible: Yes
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
# SECRET_KEY - Titkosítási kulcs (auto-generated)
services:
wger:
image: wger/server:2.7
container_name: wger
# R-737 (2026-09-30): wger's app login API (the mobile app's) signs JWTs with JWT_PRIVATE_KEY / JWT_PUBLIC_KEY — an
# RSA pair the deploy's generators cannot make, and without it a CORRECT password answered 500. So the pair is made
# ONCE by wger's own `manage.py generate-jwt-keys`, kept 0600 on wger's own data volume (a restore brings the same
# key back), and loaded before the image's own entrypoint. Never printed.
entrypoint:
- /bin/sh
- -c
- |
K=/home/wger/db/.felhom-jwt.env
if [ ! -s "$$K" ]; then
(cd /home/wger/src && python3 manage.py generate-jwt-keys 2>/dev/null) | grep -E '^JWT_(PRIVATE|PUBLIC)_KEY=' > "$$K.tmp"
if [ "$$(grep -c . "$$K.tmp")" = 2 ]; then mv "$$K.tmp" "$$K" && chmod 600 "$$K"; else rm -f "$$K.tmp"; echo "felhom: JWT keys could not be made" >&2; fi
fi
if [ -s "$$K" ]; then set -a; . "$$K"; set +a; fi
exec /home/wger/entrypoint.sh
restart: unless-stopped
environment:
- TZ=Europe/Budapest
- SECRET_KEY=${SECRET_KEY}
# A wger 2.4+ a TELJES DJANGO_DB_* halmazt beolvassa, akkor is, ha az
# engine sqlite -- enélkül indulás nélkül kilép ("Set the DJANGO_DB_USER
# environment variable"). Az USER/PASSWORD/HOST/PORT értékeket az sqlite
# backend figyelmen kívül hagyja, de jelen kell lenniük.
# A DATABASE a wger_data kötetre mutat (/home/wger/db), oda, ahol a wger
# saját alapértelmezett sqlite fájlja is volt -- így meglévő telepítés
# adatai nem "tűnnek el" egy másik útvonalra.
# R-712 (measured 2026-09-29 on 9202): behind traefik wger saw the request as http and refused a browser's
# https Origin with "CSRF verification failed" — nobody could sign in from a browser.
- CSRF_TRUSTED_ORIGINS=https://${SUBDOMAIN}.${DOMAIN}
- X_FORWARDED_PROTO_HEADER_SET=True
# R-738: the image runs `manage.py migrate` at start ONLY with this switch (entrypoint.sh). Without it an update
# that brings migrations leaves wger serving its front page over an unmigrated database (login 500).
- DJANGO_PERFORM_MIGRATIONS=True
# R-752 (decided by CC unattended 2026-10-01, `09` §3 decision 58 — operator may reverse): django-axes locked by
# ip_address, and behind the tunnel every visitor has the tunnel's address (R-753) — a stranger's 10 wrong tries
# locked out EVERY household member for 30 min. Now only the targeted name, for 5 min (each try during a lock
# restarts it — wger 2.7 hard-codes that — so short is kinder), counted in the database (the default cache
# handler warns axes.W001). Measured on 9202: the other member unaffected; the targeted one in again at 7.5 min.
- AXES_LOCKOUT_PARAMETERS=username
- AXES_COOLOFF_TIME=5
- AXES_HANDLER=axes.handlers.database.AxesDatabaseHandler
# R-763 (2026-10-05): the image defaults both to True. After the install the admin exists (after_install sets its
# password), so nobody needs wger's own sign-up: a stranger could make an account through the front door, and every
# anonymous visit to the dashboard made a guest user row (wger's middleware create_temporary_user). Both read by
# settings/main.py as env.bool (wger 2.7 L179-180); the sign-up view then redirects to the features page.
- ALLOW_REGISTRATION=False
- ALLOW_GUEST_USERS=False
# R-764 (2026-10-05): mail through the box's relay (smtp_mapping in .felhom.yml, tls_mode plaintext -> :2526).
# wger 2.7 settings/main.py:162 reads the EMAIL_* group ONLY when ENABLE_EMAIL is true, and then env.str() with
# no default on EMAIL_HOST_USER / EMAIL_HOST_PASSWORD — so both stay defined-EMPTY here (the relay takes no
# login; an absent one would stop wger at start). ENABLE_EMAIL is the gate: False unless the mail toggle injects
# "True". EMAIL_USE_TLS False: Django's STARTTLS verifies the certificate and the relay's is self-signed.
- ENABLE_EMAIL=${ENABLE_EMAIL:-False}
- EMAIL_HOST=${EMAIL_HOST:-}
- EMAIL_PORT=${EMAIL_PORT:-2526}
- EMAIL_HOST_USER=
- EMAIL_HOST_PASSWORD=
- EMAIL_USE_TLS=False
- EMAIL_USE_SSL=False
- FROM_EMAIL=${FROM_EMAIL:-wger Workout Manager <wger@example.com>}
- DJANGO_DB_ENGINE=django.db.backends.sqlite3
- DJANGO_DB_DATABASE=/home/wger/db/database.sqlite
- DJANGO_DB_USER=wger
- DJANGO_DB_PASSWORD=wger
- DJANGO_DB_HOST=localhost
- DJANGO_DB_PORT=5432
- SITE_URL=https://${SUBDOMAIN}.${DOMAIN}
# R-762 (2026-10-06): production mode, as upstream's own prod.env (wger-project/docker config/prod.env). With
# DJANGO_DEBUG=False the image's entrypoint runs `collectstatic` at every start (entrypoint.sh:27) into
# /home/wger/static, and Django stops serving /static and /media itself (it never did in production — upstream
# puts nginx in front). wger-files below serves both from the shared volumes.
- DJANGO_DEBUG=False
# R-762 (2026-10-08): the real web server. The image's entrypoint.sh runs `gunicorn wger.wsgi:application --preload
# --bind 0.0.0.0:$PORT` when WGER_USE_GUNICORN is "True" (else Django's development server, `manage.py runserver`).
# It passes no -w and the image has no gunicorn.conf.py, so the worker count is gunicorn's own WEB_CONCURRENCY
# (unset = 1). Two workers: measured on the bench and on 9202 (2 x "Booting worker" in the log). anon peak under
# load: 170 MiB (44 %) on the bench, 246 MiB (64 %) on 9202 after a photo upload, flat for 1,200 more page loads;
# 0 oom_kill, 0 restarts. --preload: the workers share the app's pages with the master.
- WGER_USE_GUNICORN=True
- WEB_CONCURRENCY=2
volumes:
- wger_data:/home/wger/db
- wger_media:/home/wger/media
- wger_static:/home/wger/static
networks:
- traefik-public
deploy:
resources:
limits:
memory: 384M
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:8000"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
labels:
- "traefik.enable=true"
- "traefik.http.routers.wger.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.wger.entrypoints=websecure"
- "traefik.http.routers.wger.tls=true"
- "traefik.http.routers.wger.tls.certresolver=letsencrypt"
- "traefik.http.services.wger.loadbalancer.server.port=8000"
# R-762 (2026-10-06): the file server upstream's production compose puts in front of wger (its `nginx` service and
# config/nginx.conf: `location /static/ { alias /wger/static/; }`, `location /media/ { alias /wger/media/; }`).
# Here traefik is already the front door, so traefik sends ONLY /static/ and /media/ to this nginx and everything
# else to wger as before — no config file is needed: nginx's stock config serves /usr/share/nginx/html, and the two
# volumes are mounted there read-only. Every gate the box puts in front of the app wraps EVERY router of the stack
# (stacks/setup_gate.go, family_gate.go), so this router is gated exactly like wger's own.
wger-files:
image: nginx:1.30.5-alpine
container_name: wger-files
restart: unless-stopped
depends_on:
- wger
volumes:
- wger_static:/usr/share/nginx/html/static:ro
- wger_media:/usr/share/nginx/html/media:ro
networks:
- traefik-public
deploy:
resources:
limits:
memory: 32M
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 10s
labels:
- "traefik.enable=true"
- "traefik.http.routers.wger-files.rule=Host(`${SUBDOMAIN}.${DOMAIN}`) && (PathPrefix(`/static/`) || PathPrefix(`/media/`))"
- "traefik.http.routers.wger-files.entrypoints=websecure"
- "traefik.http.routers.wger-files.tls=true"
- "traefik.http.routers.wger-files.tls.certresolver=letsencrypt"
- "traefik.http.services.wger-files.loadbalancer.server.port=80"
volumes:
wger_data:
wger_media:
wger_static:
networks:
traefik-public:
external: true