refactor: route traefik straight to node and drop nginx - #23
Merged
Merged
Conversation
This was referenced Sep 22, 2026
Merged
turegjorup
force-pushed
the
feature/8293-drop-nginx
branch
from
September 23, 2026 07:17
37ee54a to
f98f326
Compare
rimi-itk
approved these changes
Sep 24, 2026
turegjorup
added this pull request to stack #32
September 24, 2026 11:12
turegjorup
force-pushed
the
feature/8293-drop-nginx
branch
6 times, most recently
from
September 24, 2026 11:29
a425be7 to
3c01132
Compare
nginx was a pure proxy - no static files, no cache, no auth - and it resolved node's IP once at startup, so a node container returning on a new IP meant a permanent 502 while nginx itself stayed healthy (F1). The traefik labels move to node, including the basic auth middleware on staging and the www redirect, so the routers keep their middlewares. The node image has no EXPOSE, so the port is stated explicitly. Claude-Session: https://claude.ai/code/session_012qXhBodStu75USEqkDEHKH
The hand-written vhost overwrote X-Forwarded-For with traefik's own IP and never set X-Forwarded-Proto, which is why the index page emitted http:// links over TLS (F12). With nginx gone traefik sets both correctly; express only needs to be told to believe the one hop. Claude-Session: https://claude.ai/code/session_012qXhBodStu75USEqkDEHKH
Also asserts that the index honours X-Forwarded-Proto, which is the observable half of the trust proxy change - it fails on http:// links without it. Claude-Session: https://claude.ai/code/session_012qXhBodStu75USEqkDEHKH
turegjorup
force-pushed
the
feature/8293-drop-nginx
branch
from
September 24, 2026 11:30
3c01132 to
18fbfd4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
nginx resolved
nodeonce at startup and cached the address for the life of the process. If node returned on a different IP, nginx served 502 permanently while staying healthy itself, so the restart policy never acted. It also overwroteX-Forwarded-Forwith Traefik's own address and never setX-Forwarded-Proto.https://leantime.itkdev.dk/#/tickets/showTicket/8293
It proxied and nothing else: no static files, no caching, no auth.
Changes
docker-compose.ymlanddocker-compose.server.yml: nginx service removed, Traefik labels moved tonode, which joins thefrontendnetwork.loadbalancer.server.port=3000label — the node image has noEXPOSE, so Traefik cannot detect the port.docker-compose.dev.yml:ITKBasicAuth@filemoved to the node router, so staging keeps its password.docker-compose.redirect.yml: www redirect labels moved likewise..docker/vhost.confdeleted.app.js:trust proxyset, so Express believes the headers Traefik sets.test.jsandREADME.md: reach the app onnode:3000instead of through nginx.Verify
Expected:
11/11 passed, and onlynodeandmssqlrunning.Deploy
Deploy this one with
--remove-orphans. Without itup --detachleaves the old nginx container running, with Traefik labels for the same router names and a stale upstream IP once node is recreated:Before deploying:
nodenow joins the sharedfrontendnetwork, where the service namenodebecomes a DNS alias. Rundocker network inspect frontendon the server and check that no other project has anodeservice there. If one does, the service needs a unique name.docker-compose.dev.ymlanddocker-compose.redirect.ymlare shared ITK templates (# itk-version:). The label move needs coordinating with the team so the next template update does not put nginx back.scripts/teston the server curls/through nginx. If it addresses nginx by name it breaks with this PR, until build: add taskfile #28 replaces it.On the server, confirm after deploy that
https://<host>/answers and lists both routes, that/posidryeartsl.csvreturns 200, and thatdocker compose psshows no nginx container.Stacked on #22.