Lossless upgrades + config story for the all-in-one proxy image.
Redis persistence (Part A):
- Replace in-memory `--save "" --appendonly no` with AOF + RDB persisted to
/data. Host records, permissions, DNS creds, local users, AND the
lua-resty-auto-ssl Let's Encrypt certs now all survive container recreation
(persisting Redis persists the cert store — no LE re-issue / rate-limit on
rebuild).
- Add the `proxy-data` named volume -> /data in docker-compose.yml; fix the
stale "in-memory, lost on recreation" comment.
Config from ./config/proxy-secrets.js (Part B):
- docker-entrypoint.sh: when /config/proxy-secrets.js is mounted, symlink it to
/app/conf/secrets.js so @simpleworkjs/conf reads the oidc/ldap/auth config
from the file. No app_* env should then be passed (app_* beats secrets.js).
Falls back to app_* env when the file is absent (standalone still works).
- docker-compose.yml: drop all app_oidc__* / app_ldap__* / app_auth__* env and
add `./config:/config:ro`. Keep RESOLVER/REAL_IP_FROM/NODE_ENV/NODE_PORT
(OpenResty-runtime / process env, not app_* config). No env_file.
- New secrets.js.example (the proxy had none): oidc (enabled, endpoints,
clientId/clientSecret, redirectUri, scopes, claims), ldap (url, bindDN,
bindPassword, searchBase, userFilter, tlsOptions), auth (adminGroups,
adminUsers, groupRoleMap), plus an orchestrator-only `stack` key.
Backup/restore docs:
- Full "Backups and restore" runbook in DEPLOYMENT.md (what lives where, manual
backup, Redis restore with the AOF-vs-RDB note — AOF wins on startup so the
AOF must be deleted before an RDB load; restoring Redis restores cert state
at snapshot time; migrations note). Update the Setup + Auto-SSL sections.
- docs/docker.md: update Quick start + How configuration works + Auto-SSL for
the new ./config/ approach (app_* env now advanced/optional).
Co-authored-by: Claude <noreply@anthropic.com>
Document how to get logs when running the all-in-one image: docker compose
logs for app + OpenResty (stdout/stderr), and the nginx access/error logs
which go to /var/log/nginx on the proxy-logs volume (not docker logs).
Co-Authored-By: Claude <noreply@anthropic.com>