change local

This commit is contained in:
2026-08-06 14:34:27 +00:00
parent 5078f6f3b1
commit 69f0fedc20
2 changed files with 46 additions and 13 deletions
+6 -3
View File
@@ -1,10 +1,13 @@
IMAGE_BIND_ADDRESS=0.0.0.0 # Same-host native reverse proxies should use the loopback-only published port.
IMAGE_BIND_ADDRESS=127.0.0.1
IMAGE_PORT=8191 IMAGE_PORT=8191
IMAGE_REPOSITORY_PATH=/home/letrhee/sam_rebuild/image IMAGE_REPOSITORY_PATH=/home/letrhee/sam_rebuild/image
IMAGE_UID=1000 IMAGE_UID=1000
IMAGE_GID=1000 IMAGE_GID=1000
# Comma- or space-separated source CIDRs of hosts that reverse-proxy to port 8191. # Source CIDRs observed inside image-web. A host-native proxy normally appears
TRUSTED_PROXY_CIDRS=172.30.1.75/32 # as this Compose network's Docker bridge gateway, not as 127.0.0.1.
# Confirm after startup with: docker compose logs image-web
TRUSTED_PROXY_CIDRS=172.24.0.1/32
IMAGE_REMOTE_URL=https://gitea.hided.net/devsam/image.git IMAGE_REMOTE_URL=https://gitea.hided.net/devsam/image.git
IMAGE_REPOSITORY_FULL_NAME=devsam/image IMAGE_REPOSITORY_FULL_NAME=devsam/image
+40 -10
View File
@@ -39,14 +39,31 @@ remote branch tip, rejects dirty or non-fast-forward updates, and serializes all
Git changes. The initial and only allowed branch is `master` unless Git changes. The initial and only allowed branch is `master` unless
`IMAGE_ALLOWED_BRANCHES` is explicitly expanded. `IMAGE_ALLOWED_BRANCHES` is explicitly expanded.
The service is reverse-proxy agnostic. Its current reverse proxy happens to The service is reverse-proxy agnostic. Caddy, Nginx, HAProxy, or another proxy
reach this server from `172.30.1.75`, but Caddy, Nginx, HAProxy, or another can use the same port and path contract.
proxy can be used. Keep every observed proxy source CIDR in the untracked
`TRUSTED_PROXY_CIDRS` value, separated by commas or spaces, and re-check the For a native reverse proxy running on the same host as Docker, publish port
value whenever proxy networking changes. The published port binds all server 8191 on loopback only and proxy to `127.0.0.1:8191`:
interfaces, so production also needs a host `DOCKER-USER` (or equivalent)
firewall rule allowing those source CIDRs to TCP 8191 and rejecting other ```dotenv
sources. The static Nginx edge applies the same source allowlist. IMAGE_BIND_ADDRESS=127.0.0.1
IMAGE_PORT=8191
TRUSTED_PROXY_CIDRS=172.24.0.1/32
```
These two addresses intentionally describe different hops. The native proxy
connects to the host loopback address, while the Nginx process inside
`image-web` normally observes the connection as coming from that Compose
network's Docker bridge gateway (`172.24.0.1` in the example). Use the source
shown in the `image-web` access/error log, then recreate `image-web` whenever
`TRUSTED_PROXY_CIDRS` changes. Do not replace it with a Cloudflare CIDR: the
direct peer of `image-web` remains the host-native reverse proxy path.
If the reverse proxy is on another host, bind an explicit private interface
instead of loopback and apply the host `DOCKER-USER` (or equivalent) firewall
rule. Keep every source CIDR observed by `image-web` in the untracked
`TRUSTED_PROXY_CIDRS` value, separated by commas or spaces. Avoid `0.0.0.0`
unless the firewall has already been verified.
### Prepare ### Prepare
@@ -57,10 +74,11 @@ docker compose config --quiet
docker compose build docker compose build
``` ```
Apply and inspect the dedicated Docker ingress chain with root privileges: Only for a proxy on another host, apply and inspect the dedicated Docker
ingress chain with root privileges:
```sh ```sh
sudo env TRUSTED_PROXY_CIDRS=172.30.1.75/32 IMAGE_PORT=8191 \ sudo env TRUSTED_PROXY_CIDRS=192.0.2.10/32 IMAGE_PORT=8191 \
./deploy/scripts/firewall-8191.sh apply ./deploy/scripts/firewall-8191.sh apply
sudo ./deploy/scripts/firewall-8191.sh check sudo ./deploy/scripts/firewall-8191.sh check
``` ```
@@ -68,6 +86,18 @@ sudo ./deploy/scripts/firewall-8191.sh check
The script only owns the `SAM_IMAGE_INGRESS` chain and its port-8191 jump from The script only owns the `SAM_IMAGE_INGRESS` chain and its port-8191 jump from
`DOCKER-USER`; it does not flush shared firewall chains. `DOCKER-USER`; it does not flush shared firewall chains.
For the same-host native-proxy case, point the proxy upstream at loopback. A
minimal Caddy site is:
```caddyfile
sam-image.hided.net {
reverse_proxy 127.0.0.1:8191
}
```
The equivalent Nginx/HAProxy configuration should use the same upstream. The
application does not depend on Caddy-specific request behavior.
Secret values are generated under ignored `secrets/` files with mode 0600 and Secret values are generated under ignored `secrets/` files with mode 0600 and
are never printed. Put the contents of `secrets/gitea_webhook_secret` into the are never printed. Put the contents of `secrets/gitea_webhook_secret` into the
Gitea webhook configuration. Configure a JSON push webhook targeting: Gitea webhook configuration. Configure a JSON push webhook targeting: