harden(docker): non-root, dedicated healthcheck, opcache split, graceful shutdown
Coolify-doc-driven production hardening of the deploy stack: - run the whole stack as non-root www-data; nginx on 8080 (non-privileged), pid in /tmp, user directive dropped (Coolify routes to any port) - docker/healthcheck.sh: hit real /health route via PHP (not just port probe) - split OPcache config into docker/php/opcache.ini - graceful shutdown: supervisord stopsignal/stopwaitsecs + worker stop_grace_period - APCu intentionally not added (Symfony cache uses redis) - DEPLOY.md: 8080 port, non-root, resource-limit guidance Verified on linux/amd64: non-root uid=82, /health 200, migrations run, worker process healthcheck OK. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,8 @@
|
||||
server {
|
||||
listen 80 default_server;
|
||||
# Non-privileged port so the whole stack can run as www-data (non-root).
|
||||
# Coolify/Traefik routes to whatever port the service exposes — assign 8080
|
||||
# as the service port in Coolify.
|
||||
listen 8080 default_server;
|
||||
server_name _;
|
||||
root /app/public;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user