Only expose 8080 so Traefik routes to WS, not NATS TCP

This commit is contained in:
2026-08-25 10:08:45 +00:00
parent acd37942e9
commit 8d25c22fc6
2 changed files with 4 additions and 6 deletions
+4 -4
View File
@@ -89,10 +89,10 @@ asyncio.run(main())
## What's inside the server
- **Listeners**
- `4222` — native NATS protocol, `expose`d only inside the compose network. Not reachable from outside.
- `8080` — WebSocket listener, `no_tls: true`. Traefik terminates TLS and forwards `ws://nats:8080` from the public `wss://nats.tes.gd`.
- `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), internal only. Used by the compose healthcheck.
- **Listeners** (NATS binds all three inside the container; only 8080 is declared in `expose:` so Traefik picks it as the routing target)
- `4222` — native NATS protocol, reachable only from other containers on the compose network. Not routed publicly.
- `8080` — WebSocket listener, `no_tls: true`. The only port in `expose:`. Traefik terminates TLS and forwards `ws://nats:8080` from `wss://nats.tes.gd`.
- `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), used by the compose healthcheck; not routed publicly.
- **JetStream**: enabled, persisted to the named volume `nats-data` mounted at `/data`. Limits: 256MB memory / 4GB file. Bump `max_file_store` in `nats-server.conf` if you need more.
- **Auth**: a single user, whose name and password come from the `NATS_USER` / `NATS_PASSWORD` env vars. Substitution happens at Docker Compose parse time (the config lives inline in `docker-compose.yml` under `configs.nats-conf.content`), so NATS itself sees a static config. No accounts, no operator/JWT mode.
-2
View File
@@ -11,9 +11,7 @@ services:
volumes:
- nats-data:/data
expose:
- "4222"
- "8080"
- "8222"
healthcheck:
test: ["CMD", "wget", "-qO-", "http://localhost:8222/healthz"]
interval: 30s