PegaProx_project-pegaprox/docker-compose.yml
mkellermann97 28e43b360b fix: persist SSL certs + login background across docker compose pull
Two paint-points conflated into one fix (Nico reported, #454 anyblabla
asked for the persistent login-bg as a feature):

  * Customer-uploaded SSL certs vanished after `docker compose pull`.
    Root cause: Dockerfile only mounts /app/config and /app/logs as
    volumes (line 41). SSL_CERT_FILE was 'ssl/cert.pem' which sits
    inside the image layer — container recreate wipes it.

  * Custom login background (login_bg.<ext>) had the same shape:
    written under IMAGES_DIR='images/' which is also image-layer-only.
    The feature looked supported in the UI but didn't survive an
    update cycle.

Fix:
  - SSL_CERT_FILE / SSL_KEY_FILE / SSL_DIR now point under
    config/ssl/ (in the persistent volume).
  - New BRANDING_DIR = config/branding/ for login backgrounds.
  - /images/<path> route serves login_bg.* from BRANDING_DIR first,
    falls back to IMAGES_DIR for the bundled assets (logo / sponsors).
  - One-time startup migration in constants.py copies
    ssl/cert.pem + ssl/key.pem + images/login_bg.* into config/
    if the legacy file exists and the persistent location is empty.
    Legacy files left in place as read-only fallback.
  - docker-compose.yml comment refreshed — the ssl/ bind mount line
    isn't needed for persistence anymore.

Smoke-verified locally (cannot exercise full container recreate from
here):
  - constants.py imports clean, paths resolve to config/ssl + config/branding
  - settings.py / app.py / full app module import clean
  - In a tempdir with legacy ssl/*.pem + images/login_bg.png seeded
    and config/ empty, migration runs at import and copies all three
    into config/ with content preserved
  - Legacy locations stay readable as fallback after migration
  - /images/login_bg.png route correctly prefers BRANDING_DIR

@MrMasterbay — needs a real `docker compose pull && docker compose up -d`
cycle against a container that uploaded a cert pre-fix, to confirm
the migration shim fires on the first boot of the patched image.
2026-06-01 17:03:39 +02:00

30 lines
1.1 KiB
YAML

# PegaProx Docker Compose
# NS: just run: docker compose up -d
services:
pegaprox:
image: ghcr.io/pegaprox/pegaprox:latest
# build: . # uncomment to build locally
container_name: pegaprox
ports:
- "5000:5000" # web UI + API
- "5001:5001" # VNC websocket (noVNC console)
- "5002:5002" # SSH websocket (xterm.js)
volumes:
- pegaprox-config:/app/config
- pegaprox-logs:/app/logs
# MK 2026-06-01: SSL certs + login-background uploads now live under
# config/ssl and config/branding (auto-migrated from legacy ssl/ +
# images/login_bg.* on first boot). The separate ssl/ bind-mount is
# no longer needed for persistence — left here as a reference only.
# - ./ssl:/app/ssl # legacy path; only mount if you've got an external cert lifecycle
restart: unless-stopped
# environment:
# PEGAPROX_BEHIND_PROXY: "true" # behind nginx/haproxy
# PEGAPROX_TRUSTED_PROXIES: "172.16.0.0/12"
# PEGAPROX_ALLOWED_ORIGINS: "https://pegaprox.example.com"
volumes:
pegaprox-config:
pegaprox-logs: