docker to be more inline with other projects and best practices
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
# PreAuth — Caddyfile / FrankenPHP app config.
|
||||
#
|
||||
# The container serves plain HTTP on :80; TLS is terminated by the upstream
|
||||
# proxy. SERVER_NAME=:80 is set in the Dockerfile.
|
||||
#
|
||||
# This is the config the image ships (/etc/frankenphp/Caddyfile). The
|
||||
# Caddyfile in the repository root is the example for host-side setups.
|
||||
{
|
||||
frankenphp {
|
||||
# Restart each PHP worker thread after this many requests, containing
|
||||
# slow memory growth across long uptime. Preserves the 7.4-era default
|
||||
# loop count of runtime/frankenphp-symfony (500) after the Symfony 8.1
|
||||
# upgrade. Set MAX_REQUESTS=0 to disable restarts. The Dockerfile bakes
|
||||
# in the default of 500 via build arg; override at runtime with:
|
||||
# docker run -e MAX_REQUESTS=5000 ...
|
||||
# For full control, the stock FRANKENPHP_CONFIG env var can inject any
|
||||
# directive under this block instead.
|
||||
max_requests {$MAX_REQUESTS}
|
||||
}
|
||||
|
||||
# The admin API is deliberately left at its default: bound to 127.0.0.1
|
||||
# inside the container, where it is the target of the image's
|
||||
# HEALTHCHECK. It is not reachable from outside the container. Do NOT set
|
||||
# `admin off` here without also changing that probe — the app has no 2xx
|
||||
# liveness route to fall back on, because every anonymous request is
|
||||
# answered with the login page and a 401.
|
||||
}
|
||||
|
||||
http:// {
|
||||
root public/
|
||||
rewrite index.php
|
||||
php {
|
||||
root /app/public
|
||||
worker index.php
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# PreAuth container entrypoint.
|
||||
#
|
||||
# Responsibilities:
|
||||
# 1. Warm the prod cache with the injected secrets.
|
||||
# 2. Hand off to CMD (FrankenPHP server, or a console override:
|
||||
# `docker exec -it preauth bin/console app:generate-backup-codes`).
|
||||
#
|
||||
# Secrets are env vars injected at runtime, never baked into images (§8.12).
|
||||
# The container has no shell to hand out otherwise — it runs as an unprivileged
|
||||
# user with a nologin shell — so the real boot validation is
|
||||
# `cache:warmup` failing here, which is also what makes it worth doing.
|
||||
|
||||
set -e
|
||||
|
||||
if [ "$APP_ENV" = "prod" ]; then
|
||||
echo "Warming cache..."
|
||||
php bin/console cache:warmup
|
||||
fi
|
||||
|
||||
exec "$@"
|
||||
@@ -0,0 +1,41 @@
|
||||
; PreAuth php.ini overrides — merged on top of the FrankenPHP base image
|
||||
; defaults.
|
||||
;
|
||||
; The base image ships no php.ini (only the php.ini-production template), so
|
||||
; the production switches that matter are stated explicitly here rather than
|
||||
; inherited — verified against a real boot: without them the response carries
|
||||
; `X-Powered-By: PHP/8.5.10` and errors would render into the body.
|
||||
;
|
||||
; PreAuth keeps its session state in APCu plus a filesystem cache pool, so the
|
||||
; settings that matter most are the cache ones.
|
||||
|
||||
; Never advertise the interpreter, never print errors to the client. This is
|
||||
; an authentication gateway: a stack trace in a 500 body is an information
|
||||
; leak. Errors go to stderr for the log collector.
|
||||
expose_php = Off
|
||||
display_errors = Off
|
||||
log_errors = On
|
||||
error_log = /proc/self/fd/2
|
||||
|
||||
memory_limit = 256M
|
||||
upload_max_filesize = 2M
|
||||
post_max_size = 8M
|
||||
|
||||
; OPcache for the FrankenPHP worker: the image is immutable, so timestamps
|
||||
; never need revalidating. The CLI console also runs the app, hence
|
||||
; enable_cli = 1.
|
||||
opcache.enable = 1
|
||||
opcache.enable_cli = 1
|
||||
opcache.validate_timestamps = 0
|
||||
opcache.memory_consumption = 128
|
||||
opcache.interned_strings_buffer = 16
|
||||
opcache.max_accelerated_files = 20000
|
||||
|
||||
; APCu — nonce cache, rate limiter and session cache all live in it, and the
|
||||
; console needs it too (`bin/console` commands manage cache state).
|
||||
apc.enabled = 1
|
||||
apc.enable_cli = 1
|
||||
apc.shm_size = 64M
|
||||
apc.ttl = 0
|
||||
|
||||
date.timezone = UTC
|
||||
Reference in New Issue
Block a user