Publish on host loopback for NPMplus with host networking
NPMplus runs with network_mode: host, so it cannot reach the container by name on a shared Docker network. Publish the app on 127.0.0.1:4181 instead and drop the NPM_NETWORK setting. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
5b7b73225f
commit
a51d5825ce
3 files changed
+14
-16
No files matched your search
+4
-2
@@ -1,8 +1,10 @@
|
|||||||
# Stack settings. In Portainer, enter these under the stack's "Environment variables".
|
# Stack settings. In Portainer, enter these under the stack's "Environment variables".
|
||||||
# For the docker compose CLI, copy this file to .env next to compose.yaml. Never commit the completed file.
|
# For the docker compose CLI, copy this file to .env next to compose.yaml. Never commit the completed file.
|
||||||
|
|
||||||
# Docker network Nginx Proxy Manager is attached to (Portainer > Networks shows the name).
|
# Host port the app listens on, bound to loopback so only NPMplus (host networking) can reach it.
|
||||||
NPM_NETWORK=npm_default
|
# Change PROPOSAL_BOT_PORT if 4181 is already taken on the host.
|
||||||
|
PROPOSAL_BOT_BIND=127.0.0.1
|
||||||
|
PROPOSAL_BOT_PORT=4181
|
||||||
|
|
||||||
# Absolute host folders. The data folder must be writable by UID 1000.
|
# Absolute host folders. The data folder must be writable by UID 1000.
|
||||||
PROPOSAL_BOT_DATA_HOST_PATH=/opt/proposal-bot/data
|
PROPOSAL_BOT_DATA_HOST_PATH=/opt/proposal-bot/data
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ The image contains only the app code and Chromium (used by the InDesign export).
|
|||||||
|
|
||||||
## Deploy with Portainer
|
## Deploy with Portainer
|
||||||
|
|
||||||
The stack has no published port. Nginx Proxy Manager (NPM) handles HTTPS and reaches the container by name over NPM's Docker network.
|
NPMplus handles HTTPS. It runs with host networking, so the container publishes its port on the host's loopback address only (`127.0.0.1:4181`). NPMplus can reach that port; other machines cannot.
|
||||||
|
|
||||||
### 1. Put the project and photo folders on the Docker host
|
### 1. Put the project and photo folders on the Docker host
|
||||||
|
|
||||||
@@ -29,7 +29,7 @@ sudo chown -R 1000:1000 /opt/proposal-bot/data # the container runs as UID 10
|
|||||||
### 2. Create the Microsoft Entra app registration
|
### 2. Create the Microsoft Entra app registration
|
||||||
|
|
||||||
1. Create a web app registration for Proposal Bot with a client secret.
|
1. Create a web app registration for Proposal Bot with a client secret.
|
||||||
2. Register the callback `https://<proposal-bot-hostname>/auth/microsoft/callback`, using the hostname NPM will serve.
|
2. Register the callback `https://<proposal-bot-hostname>/auth/microsoft/callback`, using the hostname NPMplus will serve.
|
||||||
|
|
||||||
### 3. Create the stack
|
### 3. Create the stack
|
||||||
|
|
||||||
@@ -38,16 +38,16 @@ In Portainer, go to **Stacks > Add stack > Repository**:
|
|||||||
- **Repository URL:** this repo's Gitea URL. Turn on **Authentication** and use a Gitea access token if the repo is private.
|
- **Repository URL:** this repo's Gitea URL. Turn on **Authentication** and use a Gitea access token if the repo is private.
|
||||||
- **Compose path:** `compose.yaml`
|
- **Compose path:** `compose.yaml`
|
||||||
- **Environment variables:** add every entry from `.env.example`. **Advanced mode** accepts the whole file pasted in.
|
- **Environment variables:** add every entry from `.env.example`. **Advanced mode** accepts the whole file pasted in.
|
||||||
- `NPM_NETWORK`: the network NPM's container is attached to. To find it, open NPM's container in Portainer and look at its network section, usually something like `npm_default`.
|
- `PROPOSAL_BOT_PORT`: leave at `4181` unless that port is already in use on the host.
|
||||||
- `PROPOSAL_BOT_DATA_HOST_PATH` and `PROPOSAL_BOT_PROJECT_IMAGES_HOST_PATH`: the folders from step 1. Use absolute paths. A relative path would end up inside Portainer's copy of the repo and be lost on redeploy.
|
- `PROPOSAL_BOT_DATA_HOST_PATH` and `PROPOSAL_BOT_PROJECT_IMAGES_HOST_PATH`: the folders from step 1. Use absolute paths. A relative path would end up inside Portainer's copy of the repo and be lost on redeploy.
|
||||||
- `MICROSOFT_REDIRECT_URI`: exactly the callback from step 2.
|
- `MICROSOFT_REDIRECT_URI`: exactly the callback from step 2.
|
||||||
|
|
||||||
Deploy the stack. Portainer builds the image on the host, which takes a few minutes the first time because it installs Chromium. The container should show **healthy**. Its logs show startup warnings, such as missing sign-in settings or a `data` folder the container cannot write to.
|
Deploy the stack. Portainer builds the image on the host, which takes a few minutes the first time because it installs Chromium. The container should show **healthy**. Its logs show startup warnings, such as missing sign-in settings or a `data` folder the container cannot write to.
|
||||||
|
|
||||||
### 4. Add the NPM proxy host
|
### 4. Add the NPMplus proxy host
|
||||||
|
|
||||||
- **Domain:** the Proposal Bot hostname
|
- **Domain:** the Proposal Bot hostname
|
||||||
- **Forward:** scheme `http`, hostname `proposal-bot`, port `4181`
|
- **Forward:** scheme `http`, hostname `127.0.0.1`, port `4181` (or your `PROPOSAL_BOT_PORT`)
|
||||||
- **SSL tab:** request or choose a certificate, and turn on **Force SSL**
|
- **SSL tab:** request or choose a certificate, and turn on **Force SSL**
|
||||||
- **Advanced tab:** paste the lines below so long InDesign exports are not cut off after 60 seconds:
|
- **Advanced tab:** paste the lines below so long InDesign exports are not cut off after 60 seconds:
|
||||||
|
|
||||||
@@ -68,7 +68,7 @@ Copy `.env.example` to `.env`, fill it in, and run `docker compose up -d --build
|
|||||||
|
|
||||||
## Sign-in
|
## Sign-in
|
||||||
|
|
||||||
Sign-in uses Microsoft Entra and the email allowlist in `PROPOSAL_BOT_ALLOWED_EMAILS` (comma-separated). Microsoft only accepts HTTPS callbacks, which NPM provides.
|
Sign-in uses Microsoft Entra and the email allowlist in `PROPOSAL_BOT_ALLOWED_EMAILS` (comma-separated). Microsoft only accepts HTTPS callbacks, which NPMplus provides.
|
||||||
|
|
||||||
Sessions are kept in memory, so restarting or redeploying the container signs everyone out.
|
Sessions are kept in memory, so restarting or redeploying the container signs everyone out.
|
||||||
|
|
||||||
|
|||||||
+4
-8
@@ -9,9 +9,10 @@ services:
|
|||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
# Reaps the headless Chromium processes the InDesign export starts.
|
# Reaps the headless Chromium processes the InDesign export starts.
|
||||||
init: true
|
init: true
|
||||||
# No published port: Nginx Proxy Manager reaches http://proposal-bot:4181 over its Docker network.
|
# Published on the host's loopback only. NPMplus (host networking) forwards to http://127.0.0.1:4181;
|
||||||
networks:
|
# other machines cannot reach the port directly.
|
||||||
- proxy
|
ports:
|
||||||
|
- "${PROPOSAL_BOT_BIND:-127.0.0.1}:${PROPOSAL_BOT_PORT:-4181}:4181"
|
||||||
environment:
|
environment:
|
||||||
HOST: 0.0.0.0
|
HOST: 0.0.0.0
|
||||||
PORT: 4181
|
PORT: 4181
|
||||||
@@ -33,8 +34,3 @@ services:
|
|||||||
source: ${PROPOSAL_BOT_PROJECT_IMAGES_HOST_PATH:?Set PROPOSAL_BOT_PROJECT_IMAGES_HOST_PATH to an absolute host folder for the photo library}
|
source: ${PROPOSAL_BOT_PROJECT_IMAGES_HOST_PATH:?Set PROPOSAL_BOT_PROJECT_IMAGES_HOST_PATH to an absolute host folder for the photo library}
|
||||||
target: /app/Project Images
|
target: /app/Project Images
|
||||||
read_only: true
|
read_only: true
|
||||||
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
|
||||||
name: ${NPM_NETWORK:?Set NPM_NETWORK to the Docker network Nginx Proxy Manager is attached to}
|
|
||||||
Reference in new issue
Block a user