From 67753497f8eedcfbdb78837d9ff80c591f8b3c94 Mon Sep 17 00:00:00 2001 From: Grant Whitmer Date: Tue, 11 Aug 2026 14:30:06 -0400 Subject: [PATCH] G1: bind services to loopback, make host ports configurable MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Veron 1 is Grant's workstation and already runs other projects on 3000 (node dev server) and 3300 (nginx). A deploy must never fight a resident process for a port, and nothing here needs to be reachable from the LAN — the Cloudflare Tunnel runs on the host and reaches us over 127.0.0.1 (G1.6). Co-Authored-By: Claude Opus 5 --- docker-compose.yml | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index 299cbe8..37b0697 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -20,7 +20,9 @@ services: environment: DATABASE_URL: postgresql+asyncpg://windygit:${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}@db:5432/windygit GITEA_BASE_URL: http://gitea:3000 - ports: ["8600:8600"] + # Loopback ONLY. cloudflared runs on the host and reaches us over 127.0.0.1; + # nothing needs to be reachable from the LAN, let alone the internet (G1.6). + ports: ["127.0.0.1:${API_PORT:-8600}:8600"] depends_on: {db: {condition: service_healthy}} restart: unless-stopped @@ -42,7 +44,10 @@ services: volumes: # I-3: git object databases on a POSIX filesystem. Never object storage. - ${GIT_DATA_ROOT:-./data/gitea}:/data - ports: ["3000:3000"] + # Loopback only, and the host port is configurable: Veron 1 is Grant's + # workstation and already has other projects on 3000 (a node dev server) and + # 3300 (nginx). A deploy must never fight a resident process for a port. + ports: ["127.0.0.1:${GITEA_PORT:-3080}:3000"] depends_on: {db: {condition: service_healthy}} restart: unless-stopped