Dockerize the proxy (all-in-one image) + Docker docs

All-in-one Dockerfile bundling OpenResty + the Node mgmt app + Redis in one
container, mirroring the bare-metal ops/install.sh layout:
- Dockerfile (openresty/openresty:1.31.1.1-2-bookworm-fat base; dumb-init PID 1;
  luarocks install lua-resty-auto-ssl/luasocket/lua-resty-ipmatcher; node 22.x;
  npm ci --omit=dev; OpenResty confs + lua copied into place).
- docker-entrypoint.sh: fallback cert, sed-parameterize RESOLVER/REAL_IP_FROM,
  start bundled redis + node app, exec openresty foreground.
- docker-compose.yml (standalone), .dockerignore, DEPLOYMENT.md.
- nodejs/routes/render.js: /health endpoint for healthchecks.
- nodejs/models/user_ldap.js: tlsOptions forwarded to ldapts Client so the
  proxy can bind ldaps:// with a self-signed cert (app_ldap__tlsOptions__*).
- nodejs/package.json: bump @simpleworkjs/conf to ^1.1.0 (app_* env overrides).
- docs/docker.md + index.md: Docker deployment guide + fronting an SSO Manager.
- ops/proxy.service: add WorkingDirectory=/var/www/proxy/nodejs (bare-metal
  cwd fix so relative conf/ paths resolve).

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2026-07-11 17:02:52 -04:00
parent c19cd2243e
commit 94ad6143cc
13 changed files with 663 additions and 9 deletions
+32
View File
@@ -0,0 +1,32 @@
# Exclude everything not needed in the all-in-one image. The build context is
# the repo root; the Dockerfile COPYs nodejs/* (app) + ops/nginx_conf/* (OpenResty
# config). Keep those, drop the rest.
# Node deps are rebuilt in the image from the lockfile (clean tree).
nodejs/node_modules/
nodejs/test/
nodejs/npm-debug.log*
# Bare-metal installer + chef/vagrant ops not needed in the image.
ops/install.sh
ops/cert.sh
ops/cookbooks/
ops/roles/
ops/proxy.service
Vagrantfile
# Docs site (served via GitHub Pages, not from the image).
docs/
.github/
# Git + editor + secrets.
.git/
.gitignore
*.md
!README.md
secrets.js
secrets.json
*.env
.env
.DS_Store
*.swp