feat(proxy): https://<LAN IP>:8443 for the native app (backend-managed cert, LAN only)

- new :8443 server (both copies byte-identical): TLS with the backend's
  data/tls key+cert, LAN-only allow list, proxies the whole waiter
  origin incl. /api/ws/ upgrades
- compose: backend healthcheck; proxy waits for backend healthy (TLS files
  exist) and mounts ${DATA_PATH}/tls read-only; publishes 8443;
  TLS_PORT passed to the backend so it advertises the published port

Verified on an isolated stack: served key == advertised pin, identity and
WebSocket over TLS, proxy starts only after the backend is healthy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-28 17:41:25 +03:00
co-authored by Claude Opus 5.5
parent 8924a16747
commit 2b9f841bbd
3 changed files with 95 additions and 2 deletions
+17 -2
View File
@@ -11,6 +11,7 @@ services:
- DATABASE_URL=sqlite:////app/data/pos.db
- VERSION=${VERSION:-0.0.0}
- HOST_IP=${HOST_IP:-}
- TLS_PORT=${TLS_PORT:-8443} # published port of the proxy's TLS entry (advertised to the app)
- MASTER_USERNAME=${MASTER_USERNAME:-}
- MASTER_PASSWORD=${MASTER_PASSWORD:-}
volumes:
@@ -18,6 +19,14 @@ services:
- ${LOGO_PATH}:/app/logo.png:ro
- ${FISCAL_PATH}:/mnt/fiscal
- netinfo:/netinfo:ro
# "Healthy" = app started, which also means the TLS key/cert for the
# proxy's :8443 exist (created at startup by services/tls_identity.py)
healthcheck:
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8000/api/system/health', timeout=3)"]
interval: 5s
timeout: 5s
retries: 12
start_period: 20s
# Finds the server's LAN IP on the PHYSICAL network (never a VPN) every minute
# and shares it with the backend (pairing QR, manager, heartbeat). Needs the
@@ -50,12 +59,18 @@ services:
- "443:443"
- "4443:4443"
- "8081:8081" # manager over plain HTTP (LAN only)
- "8443:8443" # native app over TLS with a pinned key (LAN only)
volumes:
- ./nginx-proxy/nginx.conf:/etc/nginx/conf.d/default.conf:ro
- ./certs:/etc/nginx/certs:ro
- ${DATA_PATH}/tls:/etc/nginx/xenia-tls:ro
depends_on:
- waiter_pwa
- manager_dashboard
backend:
condition: service_healthy
waiter_pwa:
condition: service_started
manager_dashboard:
condition: service_started
restart: unless-stopped
volumes: