chore(deploy): adjust local user permissions and Caddy routing blocks
This commit is contained in:
@@ -6,3 +6,11 @@ services:
|
|||||||
ports: !override
|
ports: !override
|
||||||
- "8080:80"
|
- "8080:80"
|
||||||
environment: !reset {}
|
environment: !reset {}
|
||||||
|
|
||||||
|
# Local PEM files are commonly mode 0600 and owned by the host user.
|
||||||
|
# Production keeps the backend non-root and uses keys owned by UID 10001.
|
||||||
|
backend:
|
||||||
|
user: "0:0"
|
||||||
|
|
||||||
|
migrate:
|
||||||
|
user: "0:0"
|
||||||
|
|||||||
@@ -42,6 +42,7 @@ services:
|
|||||||
start_period: 20s
|
start_period: 20s
|
||||||
networks:
|
networks:
|
||||||
- private
|
- private
|
||||||
|
- egress
|
||||||
|
|
||||||
migrate:
|
migrate:
|
||||||
build:
|
build:
|
||||||
@@ -85,3 +86,4 @@ networks:
|
|||||||
public:
|
public:
|
||||||
private:
|
private:
|
||||||
internal: true
|
internal: true
|
||||||
|
egress:
|
||||||
|
|||||||
@@ -1,8 +1,9 @@
|
|||||||
# Production deployment
|
# Production deployment
|
||||||
|
|
||||||
This stack exposes only Caddy on ports 80 and 443. PostgreSQL and the FastAPI backend
|
This stack exposes only Caddy on ports 80 and 443. PostgreSQL and the FastAPI backend
|
||||||
are isolated in the private Docker network. Caddy serves the Vite SPA and proxies public
|
share an internal Docker network. The backend additionally uses a non-published egress
|
||||||
`/api/*` requests to the backend after removing the `/api` prefix.
|
network for DNS and outbound requests to Pally and Remnawave. Caddy serves the Vite SPA and
|
||||||
|
proxies public `/api/*` requests to the backend after removing the `/api` prefix.
|
||||||
|
|
||||||
## First deployment
|
## First deployment
|
||||||
|
|
||||||
@@ -55,7 +56,9 @@ serves HTTP on `http://localhost:8080`. It does not need a domain, TLS certifica
|
|||||||
1. Create a local `.env` from `.env.example` and fill the required backend integration
|
1. Create a local `.env` from `.env.example` and fill the required backend integration
|
||||||
settings. `POSTGRES_HOST=postgres`, `PRIVATE_KEY_FP=/run/secrets/keys/private.pem`, and
|
settings. `POSTGRES_HOST=postgres`, `PRIVATE_KEY_FP=/run/secrets/keys/private.pem`, and
|
||||||
`PUBLIC_KEY_FP=/run/secrets/keys/public.pem` must remain unchanged. The local `keys/`
|
`PUBLIC_KEY_FP=/run/secrets/keys/public.pem` must remain unchanged. The local `keys/`
|
||||||
directory must contain both PEM files.
|
directory must contain both PEM files. The local Compose override runs backend commands as
|
||||||
|
root only to read host-owned PEM files with mode `0600`; this override must not be used in
|
||||||
|
production.
|
||||||
2. Start PostgreSQL and apply migrations:
|
2. Start PostgreSQL and apply migrations:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
|
|||||||
@@ -20,7 +20,8 @@ malenia.space {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@api path /api/*
|
@api path /api/*
|
||||||
route @api {
|
handle @api {
|
||||||
|
route {
|
||||||
rate_limit {
|
rate_limit {
|
||||||
zone auth {
|
zone auth {
|
||||||
match {
|
match {
|
||||||
@@ -63,8 +64,11 @@ malenia.space {
|
|||||||
uri strip_prefix /api
|
uri strip_prefix /api
|
||||||
reverse_proxy backend:8000
|
reverse_proxy backend:8000
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
handle {
|
||||||
root * /srv
|
root * /srv
|
||||||
try_files {path} /index.html
|
try_files {path} /index.html
|
||||||
file_server
|
file_server
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -11,7 +11,8 @@
|
|||||||
}
|
}
|
||||||
|
|
||||||
@api path /api/*
|
@api path /api/*
|
||||||
route @api {
|
handle @api {
|
||||||
|
route {
|
||||||
rate_limit {
|
rate_limit {
|
||||||
zone auth {
|
zone auth {
|
||||||
match {
|
match {
|
||||||
@@ -50,8 +51,11 @@
|
|||||||
uri strip_prefix /api
|
uri strip_prefix /api
|
||||||
reverse_proxy backend:8000
|
reverse_proxy backend:8000
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
handle {
|
||||||
root * /srv
|
root * /srv
|
||||||
try_files {path} /index.html
|
try_files {path} /index.html
|
||||||
file_server
|
file_server
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user