chore(deploy): adjust local user permissions and Caddy routing blocks

This commit is contained in:
2026-08-17 13:02:35 +07:00
parent 261440c694
commit e2a9a4336b
5 changed files with 67 additions and 46 deletions

View File

@@ -1,8 +1,9 @@
# Production deployment
This stack exposes only Caddy on ports 80 and 443. PostgreSQL and the FastAPI backend
are isolated in the private Docker network. Caddy serves the Vite SPA and proxies public
`/api/*` requests to the backend after removing the `/api` prefix.
share an internal Docker network. The backend additionally uses a non-published egress
network for DNS and outbound requests to Pally and Remnawave. Caddy serves the Vite SPA and
proxies public `/api/*` requests to the backend after removing the `/api` prefix.
## First deployment
@@ -55,7 +56,9 @@ serves HTTP on `http://localhost:8080`. It does not need a domain, TLS certifica
1. Create a local `.env` from `.env.example` and fill the required backend integration
settings. `POSTGRES_HOST=postgres`, `PRIVATE_KEY_FP=/run/secrets/keys/private.pem`, and
`PUBLIC_KEY_FP=/run/secrets/keys/public.pem` must remain unchanged. The local `keys/`
directory must contain both PEM files.
directory must contain both PEM files. The local Compose override runs backend commands as
root only to read host-owned PEM files with mode `0600`; this override must not be used in
production.
2. Start PostgreSQL and apply migrations:
```bash