G1: Veron 1 host live behind Cloudflare Tunnel
app.windygit.com / api.windygit.com / models.windygit.com are serving over
HTTPS with ZERO inbound ports open on Grant's network.
- tunnel 4e856c5d, 4 registered edge connections, systemd-managed and bounded
- three proxied single-level CNAMEs (Free Universal SSL covers them; a
two-level name would need ACM and would die in the TLS handshake)
- services bound to 127.0.0.1 with configurable host ports — Veron 1 is
Grant's workstation and 3000/3300 belong to other projects
- docs/RUNBOOK-VERON.md
I-12 PROVEN IN PRODUCTION: /version reports source=baked with a sha equal to
the deployed HEAD.
Also fixed: the tunnel health probe targeted localhost from inside a container,
so it was permanently red. A check that is always red is as useless as one that
is always green — it is how a fleet canary goes 37 days dead unnoticed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -24,6 +24,9 @@ services:
|
||||
# nothing needs to be reachable from the LAN, let alone the internet (G1.6).
|
||||
ports: ["127.0.0.1:${API_PORT:-8600}:8600"]
|
||||
depends_on: {db: {condition: service_healthy}}
|
||||
# cloudflared runs on the host, not in this network. Without this the tunnel
|
||||
# probe is permanently red and stops meaning anything.
|
||||
extra_hosts: ["host.docker.internal:host-gateway"]
|
||||
restart: unless-stopped
|
||||
|
||||
gitea:
|
||||
|
||||
Reference in New Issue
Block a user