# Production override: join an existing Traefik network and let Traefik route # manga-api. -> this service with TLS. No host port published. # # docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d --build # # Set in .env: # MANGA_API_HOST=manga-api.example.com # your subdomain (required) # MANGA_WEB_HOST=manga.example.com # browser UI subdomain, same container (required) # PROXY_NETWORK=proxy # Traefik's network name, if not "proxy" # TRAEFIK_ENTRYPOINT=websecure # your HTTPS entrypoint name # TRAEFIK_CERTRESOLVER=le # your ACME/cert resolver name # # The network must already exist and Traefik must watch it: # docker network create proxy # if it doesn't yet services: manga-api: # Traffic arrives over the Traefik network, not a published port. ports: !reset [] environment: # Must be an IP, not the DNS name — see the base file's comment on this # same key: Chrome's DevTools HTTP handler 500s any Host header that # isn't an IP or "localhost". BROWSER_WS_URL: ${BROWSER_WS_URL:-ws://172.28.0.10:9222} depends_on: - headless-shell # `networks:` here replaces the base file's list entirely, so both must be # named: `proxy` for Traefik routing, `browser` (defined in the base file) # to keep reaching headless-shell without putting it on `proxy` too. networks: - proxy - browser labels: - "traefik.enable=true" - "traefik.docker.network=${PROXY_NETWORK:-proxy}" - "traefik.http.routers.mangabm.rule=Host(`${MANGA_API_HOST:?set MANGA_API_HOST in .env}`)" - "traefik.http.routers.mangabm.entrypoints=${TRAEFIK_ENTRYPOINT:-websecure}" - "traefik.http.routers.mangabm.tls=true" - "traefik.http.routers.mangabm.tls.certresolver=${TRAEFIK_CERTRESOLVER:-le}" - "traefik.http.services.mangabm.loadbalancer.server.port=8080" # Second hostname for the browser UI, same container. Traefik needs the # service named explicitly once more than one router targets it. - "traefik.http.routers.mangabm.service=mangabm" - "traefik.http.routers.mangaweb.rule=Host(`${MANGA_WEB_HOST:?set MANGA_WEB_HOST in .env}`)" - "traefik.http.routers.mangaweb.entrypoints=${TRAEFIK_ENTRYPOINT:-websecure}" - "traefik.http.routers.mangaweb.tls=true" - "traefik.http.routers.mangaweb.tls.certresolver=${TRAEFIK_CERTRESOLVER:-le}" - "traefik.http.routers.mangaweb.service=mangabm" # headless-shell is untouched here: it keeps its `browser` network membership # from the base file and must never join `proxy` — that network is shared # with whatever else sits behind Traefik on this host, and an exposed # CDP endpoint on it would be remote code execution for any of them. networks: proxy: external: true name: ${PROXY_NETWORK:-proxy}