Only expose 8080 so Traefik routes to WS, not NATS TCP
This commit is contained in:
@@ -89,10 +89,10 @@ asyncio.run(main())
|
|||||||
|
|
||||||
## What's inside the server
|
## What's inside the server
|
||||||
|
|
||||||
- **Listeners**
|
- **Listeners** (NATS binds all three inside the container; only 8080 is declared in `expose:` so Traefik picks it as the routing target)
|
||||||
- `4222` — native NATS protocol, `expose`d only inside the compose network. Not reachable from outside.
|
- `4222` — native NATS protocol, reachable only from other containers on the compose network. Not routed publicly.
|
||||||
- `8080` — WebSocket listener, `no_tls: true`. Traefik terminates TLS and forwards `ws://nats:8080` from the public `wss://nats.tes.gd`.
|
- `8080` — WebSocket listener, `no_tls: true`. The only port in `expose:`. Traefik terminates TLS and forwards `ws://nats:8080` from `wss://nats.tes.gd`.
|
||||||
- `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), internal only. Used by the compose healthcheck.
|
- `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), used by the compose healthcheck; not routed publicly.
|
||||||
- **JetStream**: enabled, persisted to the named volume `nats-data` mounted at `/data`. Limits: 256MB memory / 4GB file. Bump `max_file_store` in `nats-server.conf` if you need more.
|
- **JetStream**: enabled, persisted to the named volume `nats-data` mounted at `/data`. Limits: 256MB memory / 4GB file. Bump `max_file_store` in `nats-server.conf` if you need more.
|
||||||
- **Auth**: a single user, whose name and password come from the `NATS_USER` / `NATS_PASSWORD` env vars. Substitution happens at Docker Compose parse time (the config lives inline in `docker-compose.yml` under `configs.nats-conf.content`), so NATS itself sees a static config. No accounts, no operator/JWT mode.
|
- **Auth**: a single user, whose name and password come from the `NATS_USER` / `NATS_PASSWORD` env vars. Substitution happens at Docker Compose parse time (the config lives inline in `docker-compose.yml` under `configs.nats-conf.content`), so NATS itself sees a static config. No accounts, no operator/JWT mode.
|
||||||
|
|
||||||
|
|||||||
@@ -11,9 +11,7 @@ services:
|
|||||||
volumes:
|
volumes:
|
||||||
- nats-data:/data
|
- nats-data:/data
|
||||||
expose:
|
expose:
|
||||||
- "4222"
|
|
||||||
- "8080"
|
- "8080"
|
||||||
- "8222"
|
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD", "wget", "-qO-", "http://localhost:8222/healthz"]
|
test: ["CMD", "wget", "-qO-", "http://localhost:8222/healthz"]
|
||||||
interval: 30s
|
interval: 30s
|
||||||
|
|||||||
Reference in New Issue
Block a user