conf 1.2.0 adds CONF_SECRETS, an env var to point at the secrets file
directly -- use it in the Docker entrypoint instead of symlinking the
mounted file into /app/conf/secrets.js, so the app no longer needs
write access to its own conf/ directory to pick up mounted secrets.
jq-repeat 2.2.0 is a compatible feature release (sort(), replace(),
faster leading-edge update() timing); no call-site changes needed.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Lossless upgrades + config story for the all-in-one proxy image.
Redis persistence (Part A):
- Replace in-memory `--save "" --appendonly no` with AOF + RDB persisted to
/data. Host records, permissions, DNS creds, local users, AND the
lua-resty-auto-ssl Let's Encrypt certs now all survive container recreation
(persisting Redis persists the cert store — no LE re-issue / rate-limit on
rebuild).
- Add the `proxy-data` named volume -> /data in docker-compose.yml; fix the
stale "in-memory, lost on recreation" comment.
Config from ./config/proxy-secrets.js (Part B):
- docker-entrypoint.sh: when /config/proxy-secrets.js is mounted, symlink it to
/app/conf/secrets.js so @simpleworkjs/conf reads the oidc/ldap/auth config
from the file. No app_* env should then be passed (app_* beats secrets.js).
Falls back to app_* env when the file is absent (standalone still works).
- docker-compose.yml: drop all app_oidc__* / app_ldap__* / app_auth__* env and
add `./config:/config:ro`. Keep RESOLVER/REAL_IP_FROM/NODE_ENV/NODE_PORT
(OpenResty-runtime / process env, not app_* config). No env_file.
- New secrets.js.example (the proxy had none): oidc (enabled, endpoints,
clientId/clientSecret, redirectUri, scopes, claims), ldap (url, bindDN,
bindPassword, searchBase, userFilter, tlsOptions), auth (adminGroups,
adminUsers, groupRoleMap), plus an orchestrator-only `stack` key.
Backup/restore docs:
- Full "Backups and restore" runbook in DEPLOYMENT.md (what lives where, manual
backup, Redis restore with the AOF-vs-RDB note — AOF wins on startup so the
AOF must be deleted before an RDB load; restoring Redis restores cert state
at snapshot time; migrations note). Update the Setup + Auto-SSL sections.
- docs/docker.md: update Quick start + How configuration works + Auto-SSL for
the new ./config/ approach (app_* env now advanced/optional).
Co-authored-by: Claude <noreply@anthropic.com>