From 894a421a9d02a0449dcfb3863ee33ee5977609aa Mon Sep 17 00:00:00 2001 From: claude Date: Fri, 24 Jul 2026 17:04:31 +0700 Subject: [PATCH] feat: Traefik router labels for prod deploy Add traefik.enable + Host/entrypoints/tls/certresolver/service labels to the prod override, driven by MANGA_API_HOST / PROXY_NETWORK / TRAEFIK_ENTRYPOINT / TRAEFIK_CERTRESOLVER env vars (documented in .env.example). Co-Authored-By: Claude Opus 4.8 --- .env.example | 8 +++++++- docker-compose.prod.yml | 26 +++++++++++++++++++------- 2 files changed, 26 insertions(+), 8 deletions(-) diff --git a/.env.example b/.env.example index 515dd63..48ab922 100644 --- a/.env.example +++ b/.env.example @@ -8,5 +8,11 @@ API_TOKEN=changeme-generate-a-long-random-token # plus Demonic. Add/remove as the sites' hostnames change. ALLOWED_ORIGINS=https://asuracomic.net,https://asurascans.com,https://demonicscans.org -# Only needed for the prod override, if your proxy network isn't named "proxy". +# --- Prod override (Traefik) only --- +# Subdomain Traefik routes to this service (required by the prod override). +# MANGA_API_HOST=manga-api.example.com +# Traefik's docker network name, if not "proxy". # PROXY_NETWORK=proxy +# Traefik HTTPS entrypoint + cert resolver names, if yours differ from these. +# TRAEFIK_ENTRYPOINT=websecure +# TRAEFIK_CERTRESOLVER=le diff --git a/docker-compose.prod.yml b/docker-compose.prod.yml index 2ea4ae5..968c2ef 100644 --- a/docker-compose.prod.yml +++ b/docker-compose.prod.yml @@ -1,19 +1,31 @@ -# Production override: attach to an existing external reverse-proxy Docker -# network instead of publishing a host port. The proxy routes -# manga-api. -> manga-api:8080 over the shared network. +# Production override: join an existing Traefik network and let Traefik route +# manga-api. -> this service with TLS. No host port published. # -# docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d +# docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d --build # -# The network must already exist (created by your proxy stack): +# Set in .env: +# MANGA_API_HOST=manga-api.example.com # your subdomain (required) +# PROXY_NETWORK=proxy # Traefik's network name, if not "proxy" +# TRAEFIK_ENTRYPOINT=websecure # your HTTPS entrypoint name +# TRAEFIK_CERTRESOLVER=le # your ACME/cert resolver name +# +# The network must already exist and Traefik must watch it: # docker network create proxy # if it doesn't yet -# Override the name with PROXY_NETWORK in .env if yours differs. services: manga-api: - # Drop the loopback port publish; traffic comes over the proxy network. + # Traffic arrives over the Traefik network, not a published port. ports: !reset [] networks: - proxy + labels: + - "traefik.enable=true" + - "traefik.docker.network=${PROXY_NETWORK:-proxy}" + - "traefik.http.routers.mangabm.rule=Host(`${MANGA_API_HOST:?set MANGA_API_HOST in .env}`)" + - "traefik.http.routers.mangabm.entrypoints=${TRAEFIK_ENTRYPOINT:-websecure}" + - "traefik.http.routers.mangabm.tls=true" + - "traefik.http.routers.mangabm.tls.certresolver=${TRAEFIK_CERTRESOLVER:-le}" + - "traefik.http.services.mangabm.loadbalancer.server.port=8080" networks: proxy: