Files
xenia-pos-local/docker-compose.yml
T
bonaminandClaude Opus 5.5 9fcb4df30e feat(proxy): plain-HTTP LAN entry for waiter (:80) and manager (:8081), no certs required
Phones can now open the waiter app at http://<LAN IP> with no domain, DNS
record or certificate (works around DNS-rebinding failures, KI-001). The
manager gets http://<LAN IP>:8081, with http://<LAN IP>/manager redirecting
there. waiter.*/manager.* hostnames on :80 still redirect to https, so
legacy domain sites behave as before.

- Both plain-HTTP servers are LAN-only (allow RFC1918/loopback/ULA/link-local,
  deny all -> 403), so a router port-forward can't expose an unencrypted POS
- nginx-proxy/nginx.conf and the install.sh heredoc are now byte-identical
  (one canonical config, routing map in its header)
- install.sh generates a 10-year self-signed cert when certs/ is empty (nginx
  won't start its TLS listeners without one), detects HOST_IP via
  'ip route get', prompts for it on fresh installs and backfills it into an
  existing .env, always starts the stack, prints the LAN URLs
- docker-compose publishes 8081; .env.example documents HOST_IP
- pack README: ports/request path updated, CS-5 byte-identical check

Verified: nginx -t; install.sh in Debian (fresh / upgrade without HOST_IP /
re-run - no duplicate HOST_IP, cert SAN includes HOST_IP, key 600); full
stack from freshly built images: every entry point returns the expected
200/301/302, and removing the gateway's range from the allow list yields 403
on :80 and :8081.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 11:50:29 +03:00

47 lines
1.2 KiB
YAML

services:
backend:
image: ${REGISTRY}/pos-backend:${VERSION:-latest}
restart: unless-stopped
environment:
- SITE_ID=${SITE_ID}
- SITE_KEY=${SITE_KEY}
- CLOUD_URL=${CLOUD_URL}
- SECRET_KEY=${SECRET_KEY}
- LICENSE_GRACE_HOURS=${LICENSE_GRACE_HOURS:-24}
- DATABASE_URL=sqlite:////app/data/pos.db
- VERSION=${VERSION:-0.0.0}
- HOST_IP=${HOST_IP:-}
- MASTER_USERNAME=${MASTER_USERNAME:-}
- MASTER_PASSWORD=${MASTER_PASSWORD:-}
volumes:
- ${DATA_PATH}:/app/data
- ${LOGO_PATH}:/app/logo.png:ro
- ${FISCAL_PATH}:/mnt/fiscal
waiter_pwa:
image: ${REGISTRY}/pos-waiter:${VERSION:-latest}
restart: unless-stopped
depends_on:
- backend
manager_dashboard:
image: ${REGISTRY}/pos-manager:${VERSION:-latest}
restart: unless-stopped
depends_on:
- backend
proxy:
image: nginx:alpine
ports:
- "80:80"
- "443:443"
- "4443:4443"
- "8081:8081" # manager over plain HTTP (LAN only)
volumes:
- ./nginx-proxy/nginx.conf:/etc/nginx/conf.d/default.conf:ro
- ./certs:/etc/nginx/certs:ro
depends_on:
- waiter_pwa
- manager_dashboard
restart: unless-stopped