diff --git a/services/kb-site/README.md b/services/kb-site/README.md index 3146c16..7051ec1 100644 --- a/services/kb-site/README.md +++ b/services/kb-site/README.md @@ -2,4 +2,20 @@ Public slice of the knowledge base (`kb.okit.pl`) — static HTML generated from `kb/**/*.md` by `scripts/kb/gen_pages.py`, served by nginx on PIHA. +## Sieć + +Stack nie tworzy własnej sieci — dołącza do istniejącego bridge'a `proxy` na PIHA +(`external: true`). Powód: Docker na PIHA wyczerpał domyślne pule adresowe +(`all predefined address pools have been fully subnetted`), więc kolejny +`kb-site_default` nie może powstać. + +Warunek wstępny deployu — sieć musi już istnieć na hoście: + +```bash +docker network ls | grep -w proxy # brak wyniku => docker network create proxy +``` + +Ruch publiczny i tak nie idzie przez tę sieć: npm@PIHA (vhost `kb.okit.pl`) trafia +do kontenera po opublikowanym porcie hosta `8250`. + Dokumentacja: [kb/services/kb-site.md](../../kb/services/kb-site.md) diff --git a/services/kb-site/docker-compose.yml b/services/kb-site/docker-compose.yml index d991ac6..a7cf8d3 100644 --- a/services/kb-site/docker-compose.yml +++ b/services/kb-site/docker-compose.yml @@ -15,6 +15,15 @@ services: # through the helper-container procedure in kb/runbooks/kb-site-deploy.md # (docker cp cannot write into a :ro mount). - kb-site_content:/usr/share/nginx/html:ro + # Docker on PIHA has exhausted its default address pools (~30 live stacks: + # "all predefined address pools have been fully subnetted"), so this stack + # must not ask for a subnet of its own. Declaring a network here suppresses + # the implicit kb-site_default; we join the pre-existing shared "proxy" + # bridge instead. This is only about subnet economy — npm@PIHA still reaches + # this container over the published 8250 host port (npm itself lives on + # nginxproxymanager_default), not over this network. + networks: + - proxy # busybox wget — nginx:alpine ships no curl. index.html is generated on # every run, so it is the one file that must always be there. healthcheck: @@ -24,5 +33,13 @@ services: retries: 5 start_period: 5s +networks: + # Created out-of-band on PIHA (docker network create proxy); never managed by + # this stack. `docker network ls | grep -w proxy` must return a row before + # deploy, otherwise compose fails with "network proxy declared as external, + # but could not be found". + proxy: + external: true + volumes: kb-site_content: