Only expose 8080 so Traefik routes to WS, not NATS TCP
This commit is contained in:
@@ -89,10 +89,10 @@ asyncio.run(main())
|
||||
|
||||
## What's inside the server
|
||||
|
||||
- **Listeners**
|
||||
- `4222` — native NATS protocol, `expose`d only inside the compose network. Not reachable from outside.
|
||||
- `8080` — WebSocket listener, `no_tls: true`. Traefik terminates TLS and forwards `ws://nats:8080` from the public `wss://nats.tes.gd`.
|
||||
- `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), internal only. Used by the compose healthcheck.
|
||||
- **Listeners** (NATS binds all three inside the container; only 8080 is declared in `expose:` so Traefik picks it as the routing target)
|
||||
- `4222` — native NATS protocol, reachable only from other containers on the compose network. Not routed publicly.
|
||||
- `8080` — WebSocket listener, `no_tls: true`. The only port in `expose:`. Traefik terminates TLS and forwards `ws://nats:8080` from `wss://nats.tes.gd`.
|
||||
- `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), used by the compose healthcheck; not routed publicly.
|
||||
- **JetStream**: enabled, persisted to the named volume `nats-data` mounted at `/data`. Limits: 256MB memory / 4GB file. Bump `max_file_store` in `nats-server.conf` if you need more.
|
||||
- **Auth**: a single user, whose name and password come from the `NATS_USER` / `NATS_PASSWORD` env vars. Substitution happens at Docker Compose parse time (the config lives inline in `docker-compose.yml` under `configs.nats-conf.content`), so NATS itself sees a static config. No accounts, no operator/JWT mode.
|
||||
|
||||
|
||||
@@ -11,9 +11,7 @@ services:
|
||||
volumes:
|
||||
- nats-data:/data
|
||||
expose:
|
||||
- "4222"
|
||||
- "8080"
|
||||
- "8222"
|
||||
healthcheck:
|
||||
test: ["CMD", "wget", "-qO-", "http://localhost:8222/healthz"]
|
||||
interval: 30s
|
||||
|
||||
Reference in New Issue
Block a user