diff --git a/CLAUDE.md b/CLAUDE.md index 5202da6..5dea7b5 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -89,10 +89,10 @@ asyncio.run(main()) ## What's inside the server -- **Listeners** - - `4222` — native NATS protocol, `expose`d only inside the compose network. Not reachable from outside. - - `8080` — WebSocket listener, `no_tls: true`. Traefik terminates TLS and forwards `ws://nats:8080` from the public `wss://nats.tes.gd`. - - `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), internal only. Used by the compose healthcheck. +- **Listeners** (NATS binds all three inside the container; only 8080 is declared in `expose:` so Traefik picks it as the routing target) + - `4222` — native NATS protocol, reachable only from other containers on the compose network. Not routed publicly. + - `8080` — WebSocket listener, `no_tls: true`. The only port in `expose:`. Traefik terminates TLS and forwards `ws://nats:8080` from `wss://nats.tes.gd`. + - `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), used by the compose healthcheck; not routed publicly. - **JetStream**: enabled, persisted to the named volume `nats-data` mounted at `/data`. Limits: 256MB memory / 4GB file. Bump `max_file_store` in `nats-server.conf` if you need more. - **Auth**: a single user, whose name and password come from the `NATS_USER` / `NATS_PASSWORD` env vars. Substitution happens at Docker Compose parse time (the config lives inline in `docker-compose.yml` under `configs.nats-conf.content`), so NATS itself sees a static config. No accounts, no operator/JWT mode. diff --git a/docker-compose.yml b/docker-compose.yml index 5f2180e..93bf622 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -11,9 +11,7 @@ services: volumes: - nats-data:/data expose: - - "4222" - "8080" - - "8222" healthcheck: test: ["CMD", "wget", "-qO-", "http://localhost:8222/healthz"] interval: 30s