13070a275d
Closes #2: bootstrap JWTs cannot mutate admin APIs except change-password, production requires ADMIN_PASSWORD on first boot, admin binds loopback.
33 lines
1.1 KiB
YAML
33 lines
1.1 KiB
YAML
services:
|
|
app:
|
|
build: .
|
|
image: helix-proxy:dev
|
|
restart: unless-stopped
|
|
ports:
|
|
- "80:80"
|
|
# Admin binds 127.0.0.1; do not publish :81 on untrusted networks.
|
|
# - "81:81"
|
|
- "443:443"
|
|
volumes:
|
|
- ./data:/app/data
|
|
# user: "0:0" # required when using PUID/PGID != built-in to allow binary to chown+drop
|
|
# working_dir: /app # binary uses CWD for relative data/ + data/www/
|
|
# environment:
|
|
# - JWT_SECRET= # optional; otherwise a random secret is stored in data/.jwt_secret
|
|
# - DATA_DIR=/app/data
|
|
# - WWW_DIR=/app/data/www
|
|
# - PUID=1000
|
|
# - PGID=1000
|
|
# - DISABLE_IPV6=1
|
|
# # PUID_NO_DROP=1 # if using low ports (80/443) + PUID: chown as root but skip drop (stay root for bind; default drop runs as PUID after, requires high ports or NET_BIND_SERVICE cap)
|
|
# To use optional SQL backend instead of default yaml:
|
|
# - DB_TYPE=postgres
|
|
# - DB_POSTGRES_HOST=db
|
|
# ... and add a db service
|
|
healthcheck:
|
|
test: ["CMD", "wget", "-qO-", "http://127.0.0.1:81/api"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 10s
|