From 8406f0673810409eafc562fa62fed2953b8b3c25 Mon Sep 17 00:00:00 2001 From: Frank Date: Sun, 6 Sep 2026 21:32:10 +0200 Subject: [PATCH] docker: NPM joins dmtools_default, not a shared proxy network NPM (nginx_app_1) is connected to each stack's own default network by hand, not to a shared docker_default. Drop the unused external `proxy` network from the compose file; nginx just lives on dmtools_default. setup.sh now connects NPM to it (no-op if already connected) and prints the proxy-host settings. Co-Authored-By: Claude Sonnet 5 --- docker-compose.yml | 26 ++++++++++++-------------- docker/setup.sh | 13 +++++++++++++ 2 files changed, 25 insertions(+), 14 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index abaf696..6529738 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,9 +1,17 @@ # dmtools stack - servers only (testing + live). Not used locally. # -# Reached only through the shared Nginx Proxy Manager, which terminates TLS for -# dmtools.fvandenberg.nl and forwards to the `nginx` container by name over the -# external `docker_default` network. Published host ports are bound to loopback -# for local curl / DB-client access on the server itself. +# Reached through Nginx Proxy Manager, which terminates TLS for +# dmtools.fvandenberg.nl and forwards to the `nginx` container by name. +# NPM is not on a shared proxy network here - it is connected to each +# stack's own default network by hand. After the first `up`, run once: +# +# docker network connect dmtools_default nginx_app_1 +# +# (NPM keeps that connection across restarts; only needed again after a +# `docker compose down` removes the network.) +# +# Published host ports are bound to loopback for local curl / DB-client +# access on the server itself. # # Bring up with docker/setup.sh (pins the compose project name to `dmtools`). @@ -35,9 +43,6 @@ services: - ./docker/nginx/default.conf:/etc/nginx/conf.d/default.conf:ro depends_on: - php - networks: - - default - - proxy restart: unless-stopped database: @@ -66,10 +71,3 @@ services: volumes: database_data: php_var: - -networks: - # Pre-existing network the server's Nginx Proxy Manager uses to reach backend - # containers. Created outside this stack - must already exist on the host. - proxy: - name: docker_default - external: true diff --git a/docker/setup.sh b/docker/setup.sh index a93aa5d..25e938d 100755 --- a/docker/setup.sh +++ b/docker/setup.sh @@ -114,6 +114,15 @@ pexec php bin/console asset-map:compile # php-fpm runs as www-data and must be able to write there at runtime. pexec chown -R www-data:www-data var +# Make sure Nginx Proxy Manager can reach this stack's nginx by name. +# Harmless (and a no-op) if already connected; NPM keeps it across restarts. +NPM_CONTAINER="${NPM_CONTAINER:-nginx_app_1}" +if docker inspect "$NPM_CONTAINER" >/dev/null 2>&1; then + docker network connect "${PROJECT}_default" "$NPM_CONTAINER" 2>/dev/null \ + && echo "Connected $NPM_CONTAINER to ${PROJECT}_default." \ + || true +fi + APP_URL="http://localhost:${NGINX_PORT:-8085}" cat <