From cf23b184d25cdcb6073c6816855b8e9affc13d29 Mon Sep 17 00:00:00 2001 From: onysd Date: Fri, 7 Aug 2026 13:50:38 +0300 Subject: [PATCH] fix --- deploy/docker-compose.yml | 16 +++++----------- 1 file changed, 5 insertions(+), 11 deletions(-) diff --git a/deploy/docker-compose.yml b/deploy/docker-compose.yml index f253228c..9dfa32c7 100644 --- a/deploy/docker-compose.yml +++ b/deploy/docker-compose.yml @@ -41,7 +41,7 @@ services: POSTGRES_PASSWORD: owpengram TZ: UTC ports: - - "5432:5432" + - "127.0.0.1:5432:5432" # <-- ЗАХИЩЕНО (доступ тільки з 127.0.0.1) volumes: - pgdata:/var/lib/postgresql/data healthcheck: @@ -56,7 +56,7 @@ services: container_name: ${TELESRV_DOCKER_PREFIX:-owpengram}-redis command: ["redis-server", "--appendonly", "yes"] ports: - - "6399:6379" # 宿主 6379 常被其他项目占用,telesrv 对外用 6399(容器内仍 6379) + - "127.0.0.1:6399:6379" # <-- ЗАХИЩЕНО (доступ тільки з 127.0.0.1) volumes: - redisdata:/data healthcheck: @@ -73,18 +73,12 @@ services: image: minio/minio:latest container_name: ${TELESRV_DOCKER_PREFIX:-owpengram}-minio command: ["server", "/data", "--console-address", ":9001"] - # Reuses the same TELESRV_S3_* vars the app itself reads (single source - # of truth), with the documented local-dev defaults as a fallback so a - # fresh clone still works with no .env at all. Run docker compose with - # --env-file pointed at your real .env (or export the vars into the - # shell) so a production deployment gets real credentials here instead - # of silently falling back to the checked-in defaults. environment: MINIO_ROOT_USER: ${TELESRV_S3_ACCESS_KEY_ID:-owpengram} MINIO_ROOT_PASSWORD: ${TELESRV_S3_SECRET_ACCESS_KEY:-owpengram123} ports: - - "9000:9000" # S3 API(对应 .env.example 的 TELESRV_S3_ENDPOINT=localhost:9000) - - "9001:9001" # Web 控制台,浏览器打开 http://localhost:9001 查看存储内容 + - "127.0.0.1:9000:9000" # <-- якщо S3 використовує тільки локальний бекенд + - "127.0.0.1:9001:9001" # <-- Web UI Minio (можна залишити без 127.0.0.1, якщо потрібен адмін-веб ззовні) volumes: - miniodata:/data healthcheck: @@ -100,4 +94,4 @@ volumes: redisdata: name: ${TELESRV_DOCKER_PREFIX:-owpengram}_redisdata miniodata: - name: ${TELESRV_DOCKER_PREFIX:-owpengram}_miniodata + name: ${TELESRV_DOCKER_PREFIX:-owpengram}_miniodata \ No newline at end of file