docker: NPM joins dmtools_default, not a shared proxy network

NPM (nginx_app_1) is connected to each stack's own default network by
hand, not to a shared docker_default. Drop the unused external `proxy`
network from the compose file; nginx just lives on dmtools_default.
setup.sh now connects NPM to it (no-op if already connected) and prints
the proxy-host settings.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Frank
2026-09-06 21:32:10 +02:00
co-authored by Claude Sonnet 5
parent 25b68cb1df
commit 8406f06738
2 changed files with 25 additions and 14 deletions
+12 -14
View File
@@ -1,9 +1,17 @@
# dmtools stack - servers only (testing + live). Not used locally. # dmtools stack - servers only (testing + live). Not used locally.
# #
# Reached only through the shared Nginx Proxy Manager, which terminates TLS for # Reached through Nginx Proxy Manager, which terminates TLS for
# dmtools.fvandenberg.nl and forwards to the `nginx` container by name over the # dmtools.fvandenberg.nl and forwards to the `nginx` container by name.
# external `docker_default` network. Published host ports are bound to loopback # NPM is not on a shared proxy network here - it is connected to each
# for local curl / DB-client access on the server itself. # stack's own default network by hand. After the first `up`, run once:
#
# docker network connect dmtools_default nginx_app_1
#
# (NPM keeps that connection across restarts; only needed again after a
# `docker compose down` removes the network.)
#
# Published host ports are bound to loopback for local curl / DB-client
# access on the server itself.
# #
# Bring up with docker/setup.sh (pins the compose project name to `dmtools`). # Bring up with docker/setup.sh (pins the compose project name to `dmtools`).
@@ -35,9 +43,6 @@ services:
- ./docker/nginx/default.conf:/etc/nginx/conf.d/default.conf:ro - ./docker/nginx/default.conf:/etc/nginx/conf.d/default.conf:ro
depends_on: depends_on:
- php - php
networks:
- default
- proxy
restart: unless-stopped restart: unless-stopped
database: database:
@@ -66,10 +71,3 @@ services:
volumes: volumes:
database_data: database_data:
php_var: php_var:
networks:
# Pre-existing network the server's Nginx Proxy Manager uses to reach backend
# containers. Created outside this stack - must already exist on the host.
proxy:
name: docker_default
external: true
+13
View File
@@ -114,6 +114,15 @@ pexec php bin/console asset-map:compile
# php-fpm runs as www-data and must be able to write there at runtime. # php-fpm runs as www-data and must be able to write there at runtime.
pexec chown -R www-data:www-data var pexec chown -R www-data:www-data var
# Make sure Nginx Proxy Manager can reach this stack's nginx by name.
# Harmless (and a no-op) if already connected; NPM keeps it across restarts.
NPM_CONTAINER="${NPM_CONTAINER:-nginx_app_1}"
if docker inspect "$NPM_CONTAINER" >/dev/null 2>&1; then
docker network connect "${PROJECT}_default" "$NPM_CONTAINER" 2>/dev/null \
&& echo "Connected $NPM_CONTAINER to ${PROJECT}_default." \
|| true
fi
APP_URL="http://localhost:${NGINX_PORT:-8085}" APP_URL="http://localhost:${NGINX_PORT:-8085}"
cat <<EOT cat <<EOT
@@ -121,6 +130,10 @@ Setup complete!
Open the app: $APP_URL (real access is via https://dmtools.fvandenberg.nl through NPM) Open the app: $APP_URL (real access is via https://dmtools.fvandenberg.nl through NPM)
NPM proxy host: scheme http, forward "dmtools-nginx" port 80.
If NPM ($NPM_CONTAINER) can't reach it, run:
docker network connect ${PROJECT}_default $NPM_CONTAINER
Create the first user: Create the first user:
$DOCKER_COMPOSE -p $PROJECT exec php php bin/console app:user:create you@example.com --admin $DOCKER_COMPOSE -p $PROJECT exec php php bin/console app:user:create you@example.com --admin