Skip to content

refactor: route traefik straight to node and drop nginx - #23

Merged
turegjorup merged 3 commits into
mainfrom
feature/8293-drop-nginx
Sep 24, 2026
Merged

turegjorup merged 3 commits into
mainfrom
feature/8293-drop-nginx

Conversation

@turegjorup

@turegjorup turegjorup commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

nginx resolved node once at startup and cached the address for the life of the process. If node returned on a different IP, nginx served 502 permanently while staying healthy itself, so the restart policy never acted. It also overwrote X-Forwarded-For with Traefik's own address and never set X-Forwarded-Proto.

https://leantime.itkdev.dk/#/tickets/showTicket/8293

It proxied and nothing else: no static files, no caching, no auth.

Changes

  • docker-compose.yml and docker-compose.server.yml: nginx service removed, Traefik labels moved to node, which joins the frontend network.
  • An explicit loadbalancer.server.port=3000 label — the node image has no EXPOSE, so Traefik cannot detect the port.
  • docker-compose.dev.yml: ITKBasicAuth@file moved to the node router, so staging keeps its password.
  • docker-compose.redirect.yml: www redirect labels moved likewise.
  • .docker/vhost.conf deleted.
  • app.js: trust proxy set, so Express believes the headers Traefik sets.
  • test.js and README.md: reach the app on node:3000 instead of through nginx.

Verify

cp config.dev.js.dist config.js
docker compose run --rm node yarn install
docker compose --profile db up --detach
docker compose run --rm node node .docker/mssql/seed.js
docker compose run --rm node node test.js
docker compose ps

Expected: 11/11 passed, and only node and mssql running.

Deploy

Deploy this one with --remove-orphans. Without it up --detach leaves the old nginx container running, with Traefik labels for the same router names and a stale upstream IP once node is recreated:

docker compose --env-file .env.docker.local --file docker-compose.server.yml up --detach --remove-orphans

Before deploying:

  • node now joins the shared frontend network, where the service name node becomes a DNS alias. Run docker network inspect frontend on the server and check that no other project has a node service there. If one does, the service needs a unique name.
  • docker-compose.dev.yml and docker-compose.redirect.yml are shared ITK templates (# itk-version:). The label move needs coordinating with the team so the next template update does not put nginx back.
  • The unversioned scripts/test on the server curls / through nginx. If it addresses nginx by name it breaks with this PR, until build: add taskfile #28 replaces it.

On the server, confirm after deploy that https://<host>/ answers and lists both routes, that /posidryeartsl.csv returns 200, and that docker compose ps shows no nginx container.

Stacked on #22.

@turegjorup turegjorup self-assigned this Sep 22, 2026
turegjorup added a commit that referenced this pull request Sep 22, 2026
All fourteen branches are open and green. Notes the merge order constraint
between #24 and #23, which both edit docker-compose.server.yml.
@turegjorup
turegjorup force-pushed the feature/8293-drop-nginx branch from 37ee54a to f98f326 Compare September 23, 2026 07:17
@turegjorup
turegjorup requested a review from rimi-itk September 24, 2026 10:37
@turegjorup
turegjorup added this pull request to stack #32 September 24, 2026 11:12
@turegjorup
turegjorup force-pushed the feature/8293-drop-nginx branch 6 times, most recently from a425be7 to 3c01132 Compare September 24, 2026 11:29
Base automatically changed from feature/8293-connection-pools to main September 24, 2026 11:30
nginx was a pure proxy - no static files, no cache, no auth - and it
resolved node's IP once at startup, so a node container returning on a new
IP meant a permanent 502 while nginx itself stayed healthy (F1).

The traefik labels move to node, including the basic auth middleware on
staging and the www redirect, so the routers keep their middlewares. The
node image has no EXPOSE, so the port is stated explicitly.

Claude-Session: https://claude.ai/code/session_012qXhBodStu75USEqkDEHKH
The hand-written vhost overwrote X-Forwarded-For with traefik's own IP and
never set X-Forwarded-Proto, which is why the index page emitted http://
links over TLS (F12). With nginx gone traefik sets both correctly; express
only needs to be told to believe the one hop.

Claude-Session: https://claude.ai/code/session_012qXhBodStu75USEqkDEHKH
Also asserts that the index honours X-Forwarded-Proto, which is the
observable half of the trust proxy change - it fails on http:// links
without it.

Claude-Session: https://claude.ai/code/session_012qXhBodStu75USEqkDEHKH
@turegjorup
turegjorup force-pushed the feature/8293-drop-nginx branch from 3c01132 to 18fbfd4 Compare September 24, 2026 11:30
@turegjorup
turegjorup merged commit 2e19068 into main Sep 24, 2026
1 check passed
@turegjorup
turegjorup deleted the feature/8293-drop-nginx branch September 24, 2026 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants