Files
WhatIDo/docker-compose.yml
T
dev 6844d659fc harden security and add public TLS scaffold
- require ADMIN_PASSWORD (no default), remove CORS
- close public DB port, move DB credentials to .env (DB_PASSWORD)
- fix HTML escaping, add helmet + sec headers (no CSP due to inline scripts)
- rate limit public routes by IP (express-rate-limit)
- validate restore data and confine file unlinking to uploads/
- block dangerous upload extensions, 30MB per-entry limit, SVG not served inline
- return 400 on unknown group_id in POST /api/entries
- add commented Caddy/Let's Encrypt reverse-proxy scaffold + Caddyfile.example
- update README
2026-09-07 11:27:04 +03:00

69 lines
1.9 KiB
YAML

name: whatido
services:
db:
image: postgres:16-alpine
environment:
POSTGRES_DB: whereldo
POSTGRES_USER: app
POSTGRES_PASSWORD: ${DB_PASSWORD}
TZ: Europe/Moscow
volumes:
- pgdata:/var/lib/postgresql/data
- ./db/init.sql:/docker-entrypoint-initdb.d/init.sql
healthcheck:
test: ["CMD-SHELL", "pg_isready -U app -d whereldo"]
interval: 2s
timeout: 3s
retries: 10
app:
build: .
# --- Публикация портов через reverse-proxy (Caddy), см. сервис caddy ниже ---
ports:
- "3000:3000"
- "3443:3443"
environment:
DATABASE_URL: postgres://app:${DB_PASSWORD}@db:5432/whereldo
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
TZ: Europe/Moscow
depends_on:
db:
condition: service_healthy
volumes:
- ./uploads:/app/uploads
# --- Настоящий TLS (Let's Encrypt) перед публичным запуском ---
#
# Расскомментируйте сервис caddy, скопируйте Caddyfile.example в Caddyfile,
# замените yourdomain.example на реальный домен и в app замените блок ports:
#
# expose:
# - "3000"
# - "3443"
# ports:
# - "127.0.0.1:3000:3000"
# - "127.0.0.1:3443:3443" (и удалить внешние "3000:3000" / "3443:3443")
#
# Затем: docker compose up -d --build
#
# caddy:
# image: caddy:2-alpine
# restart: unless-stopped
# ports:
# - "80:80"
# - "443:443"
# environment:
# DOMAIN: yourdomain.example # ЗАМЕНИТЕ на реальный домен
# volumes:
# - ./Caddyfile:/etc/caddy/Caddyfile:ro
# - caddy_data:/data
# - caddy_config:/config
# depends_on:
# - app
volumes:
pgdata:
# caddy_data:
# caddy_config: