remake architecture.
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
services:
|
||||
shagram:
|
||||
image: ${APP_IMAGE}
|
||||
container_name: shagram-app
|
||||
environment:
|
||||
- DATABASE_PATH=/app/data/shagram.db
|
||||
volumes:
|
||||
- shagram_data:/app/data
|
||||
expose:
|
||||
- "8080"
|
||||
|
||||
nginx:
|
||||
image: nginx:alpine
|
||||
container_name: shagram-nginx
|
||||
ports:
|
||||
- "80:80"
|
||||
- "443:443"
|
||||
volumes:
|
||||
- ./nginx/conf.d:/etc/nginx/conf.d:ro
|
||||
- ./nginx/certs:/etc/nginx/certs:ro
|
||||
depends_on:
|
||||
- shagram
|
||||
volumes:
|
||||
shagram_data:
|
||||
@@ -0,0 +1,34 @@
|
||||
# TLS Certificates for Nginx (Development / Self-Signed)
|
||||
|
||||
In production, TLS certificates are typically issued by a trusted Certificate Authority (for example, via Let’s Encrypt).
|
||||
For local development and demo environments, a self-signed certificate can be used.
|
||||
|
||||
## Generate a self-signed certificate (Linux/macOS)
|
||||
From the repository root:
|
||||
|
||||
```bash
|
||||
mkdir -p deploy/shagram/nginx/certs
|
||||
|
||||
openssl req -x509 -newkey rsa:4096 \
|
||||
-keyout deploy/shagram/nginx/certs/key.pem \
|
||||
-out deploy/shagram/nginx/certs/cert.pem \
|
||||
-sha256 -days 365 -nodes \
|
||||
-subj "/C=RU/ST=Moscow/L=Korolyov/O=Shagram/CN=localhost"
|
||||
```
|
||||
|
||||
## Verify
|
||||
```bash
|
||||
openssl x509 -in deploy/shagram/nginx/certs/cert.pem -noout -text | head
|
||||
```
|
||||
|
||||
## Usage
|
||||
The Nginx configuration expects:
|
||||
- `deploy/shagram/nginx/certs/cert.pem`
|
||||
- `deploy/shagram/nginx/certs/key.pem`
|
||||
|
||||
Start the deployment:
|
||||
|
||||
```bash
|
||||
cd deploy/shagram
|
||||
docker compose up -d
|
||||
```
|
||||
@@ -0,0 +1,38 @@
|
||||
upstream shagram_app {
|
||||
server shagram:8080;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 80;
|
||||
server_name localhost;
|
||||
|
||||
location / {
|
||||
proxy_pass http://shagram_app;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
}
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
server_name localhost;
|
||||
|
||||
ssl_certificate /etc/nginx/certs/cert.pem;
|
||||
ssl_certificate_key /etc/nginx/certs/key.pem;
|
||||
|
||||
location / {
|
||||
proxy_pass http://shagram_app;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user