Add Docker setup and fix proxy config for containerized deployment
- Program.cs: remove UseHsts/UseHttpsRedirection (NPM terminates TLS, would loop behind the proxy, plan.md AE-4), add UseForwardedHeaders with emptied known networks/proxies. Uses KnownIPNetworks (net10). - Dockerfile: SDK build stage, chiseled aspnet runtime on port 8080. - .dockerignore: keep build output, git and docs out of the image. - compose.yaml: temporary test setup (builds from source, exposes 5000:8080) for the first run on Unraid without NPM or registry. - .gitignore: exclude .idea/ (Rider project files). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
2298051bf4
commit
95946a4349
5 files changed
+87
-5
No files matched your search
@@ -1,4 +1,5 @@
|
||||
using Elternbeirat.Web.Components;
|
||||
using Microsoft.AspNetCore.HttpOverrides;
|
||||
|
||||
var builder = WebApplication.CreateBuilder(args);
|
||||
|
||||
@@ -7,20 +8,32 @@ builder.Services.AddRazorComponents();
|
||||
|
||||
var app = builder.Build();
|
||||
|
||||
// NPM terminiert TLS und ist der einzige Weg zum Container (kein Port-Mapping
|
||||
// im Produktivbetrieb, siehe plan.md AE-4). Ohne UseForwardedHeaders sieht die
|
||||
// App jede Anfrage als HTTP und mit der Proxy-IP statt der Client-IP.
|
||||
// KnownNetworks/KnownProxies bewusst geleert, weil ausschliesslich NPM den
|
||||
// Container erreicht.
|
||||
app.UseForwardedHeaders(new ForwardedHeadersOptions
|
||||
{
|
||||
ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto,
|
||||
KnownIPNetworks = { },
|
||||
KnownProxies = { }
|
||||
});
|
||||
|
||||
// Configure the HTTP request pipeline.
|
||||
if (!app.Environment.IsDevelopment())
|
||||
{
|
||||
app.UseExceptionHandler("/Error", createScopeForErrors: true);
|
||||
// The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts.
|
||||
app.UseHsts();
|
||||
// Kein UseHsts() und kein UseHttpsRedirection(): NPM setzt HSTS und
|
||||
// terminiert TLS. Beides hier wuerde hinter dem Proxy eine
|
||||
// Redirect-Schleife erzeugen (plan.md AE-4).
|
||||
}
|
||||
|
||||
app.UseStatusCodePagesWithReExecute("/not-found", createScopeForStatusCodePages: true);
|
||||
app.UseHttpsRedirection();
|
||||
|
||||
app.UseAntiforgery();
|
||||
|
||||
app.MapStaticAssets();
|
||||
app.MapRazorComponents<App>();
|
||||
|
||||
app.Run();
|
||||
app.Run();
|
||||
Reference in new issue
Block a user