mirror of
https://github.com/R0m1k3/podcastic.git
synced 2026-10-11 17:26:20 +02:00
security: require auth on MongoDB and Redis
Enable mongod --auth with root credentials from MONGO_USER/PASSWORD, and redis-server --requirepass from REDIS_PASSWORD. App connection strings now embed credentials. All secrets are required (no fallback) so misconfiguration fails fast at compose time. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
5497c89a99
commit
f620ec614c
3 files changed
+47
-36
No files matched your search
+15
-10
@@ -1,24 +1,29 @@
|
||||
# Backend Configuration
|
||||
NODE_ENV=development
|
||||
PORT=5000
|
||||
API_URL=http://localhost:5000
|
||||
|
||||
# MongoDB Configuration
|
||||
MONGODB_URI=mongodb://mongo:27017/podcastic
|
||||
MONGODB_USER=podcastic
|
||||
MONGODB_PASSWORD=podcastic_dev
|
||||
# CORS — comma-separated list of allowed origins (e.g. https://podcastic.example.com,https://app.example.com)
|
||||
# Leave empty in dev to allow all origins
|
||||
CORS_ORIGIN=
|
||||
|
||||
# Redis Configuration
|
||||
REDIS_URL=redis://redis:6379
|
||||
# MongoDB Configuration (REQUIRED — no defaults)
|
||||
MONGO_USER=podcastic
|
||||
MONGO_PASSWORD=replace_with_strong_password
|
||||
# Used by the app — credentials must match MONGO_USER/MONGO_PASSWORD above
|
||||
MONGODB_URI=mongodb://podcastic:replace_with_strong_password@mongodb:27017/podcastic?authSource=admin
|
||||
|
||||
# JWT Configuration
|
||||
JWT_SECRET=your_super_secret_jwt_key_change_in_production
|
||||
# Redis Configuration (REQUIRED — no defaults)
|
||||
REDIS_PASSWORD=replace_with_strong_password
|
||||
REDIS_URL=redis://:replace_with_strong_password@redis:6379
|
||||
|
||||
# JWT Configuration (REQUIRED — min 32 chars, no defaults accepted)
|
||||
# Generate: openssl rand -base64 32
|
||||
JWT_SECRET=
|
||||
JWT_EXPIRES_IN=7d
|
||||
JWT_REFRESH_EXPIRES_IN=30d
|
||||
|
||||
# Podcast API (PodcastIndex) - OPTIONAL but recommended for search feature
|
||||
# Get free API keys at: https://podcastindex-api.com/
|
||||
# These enable podcast discovery and search functionality
|
||||
PODCAST_INDEX_API_KEY=
|
||||
PODCAST_INDEX_API_SECRET=
|
||||
|
||||
|
||||
+20
-21
@@ -1,26 +1,35 @@
|
||||
# ==========================================
|
||||
# Podcastic - Unraid Configuration
|
||||
# ==========================================
|
||||
# All services in single container on port 3579
|
||||
|
||||
# Application Environment
|
||||
NODE_ENV=production
|
||||
|
||||
# ==========================================
|
||||
# DATABASE & CACHE (Internal - Don't change)
|
||||
# DATABASE & CACHE — REQUIRED, set strong passwords
|
||||
# ==========================================
|
||||
MONGODB_URI=mongodb://127.0.0.1:27017/podcastic
|
||||
REDIS_URL=redis://127.0.0.1:6379
|
||||
# Generate strong passwords: openssl rand -base64 24
|
||||
MONGO_USER=podcastic
|
||||
MONGO_PASSWORD=CHANGE_ME_strong_random_password
|
||||
REDIS_PASSWORD=CHANGE_ME_strong_random_password
|
||||
|
||||
# These are derived from the credentials above (do not edit unless you know what you're doing)
|
||||
MONGODB_URI=mongodb://podcastic:CHANGE_ME_strong_random_password@mongodb:27017/podcastic?authSource=admin
|
||||
REDIS_URL=redis://:CHANGE_ME_strong_random_password@redis:6379
|
||||
|
||||
# ==========================================
|
||||
# SECURITY - CHANGE THESE!
|
||||
# SECURITY — REQUIRED
|
||||
# ==========================================
|
||||
# JWT Secret - Use strong random string
|
||||
# JWT Secret — minimum 32 chars, must be a strong random string
|
||||
# Generate: openssl rand -base64 32
|
||||
JWT_SECRET=change-this-to-random-secret-key-in-production
|
||||
JWT_SECRET=
|
||||
JWT_EXPIRES_IN=7d
|
||||
JWT_REFRESH_EXPIRES_IN=30d
|
||||
|
||||
# CORS — comma-separated list of frontend origins (e.g. https://podcastic.your-domain.com)
|
||||
# Leave empty only if frontend and backend share the same origin
|
||||
CORS_ORIGIN=
|
||||
|
||||
# ==========================================
|
||||
# OPTIONAL: PodcastIndex API (Podcast Search)
|
||||
# ==========================================
|
||||
@@ -30,26 +39,16 @@ PODCAST_INDEX_API_KEY=
|
||||
PODCAST_INDEX_API_SECRET=
|
||||
|
||||
# ==========================================
|
||||
# PORTS (Single container)
|
||||
# PORTS
|
||||
# ==========================================
|
||||
# Frontend: http://your-unraid-ip:3579
|
||||
# API: http://your-unraid-ip:3579/api
|
||||
# Health: http://your-unraid-ip:3579/health
|
||||
|
||||
PORT=5000 # Internal backend port (don't change)
|
||||
|
||||
# ==========================================
|
||||
# Frontend Configuration
|
||||
# ==========================================
|
||||
VITE_API_URL=http://your-unraid-ip:3579/api
|
||||
# Or use relative path:
|
||||
# VITE_API_URL=/api
|
||||
PORT=3579
|
||||
|
||||
# ==========================================
|
||||
# NOTES FOR UNRAID
|
||||
# ==========================================
|
||||
# 1. Change JWT_SECRET to a random string
|
||||
# 2. If accessing from WAN, update VITE_API_URL to your domain
|
||||
# 1. Generate strong passwords with: openssl rand -base64 32
|
||||
# 2. Set CORS_ORIGIN to your public frontend URL if accessing from WAN
|
||||
# 3. Optionally add PodcastIndex API keys for search feature
|
||||
# 4. All data stored in /mnt/user/appdata/podcastic/
|
||||
# 5. Logs in /mnt/user/appdata/podcastic/logs/
|
||||
+12
-5
@@ -5,12 +5,17 @@ services:
|
||||
image: mongo:8
|
||||
container_name: podcastic-mongodb
|
||||
restart: unless-stopped
|
||||
command: ["--auth"]
|
||||
environment:
|
||||
MONGO_INITDB_ROOT_USERNAME: ${MONGO_USER:?MONGO_USER is required}
|
||||
MONGO_INITDB_ROOT_PASSWORD: ${MONGO_PASSWORD:?MONGO_PASSWORD is required}
|
||||
MONGO_INITDB_DATABASE: podcastic
|
||||
volumes:
|
||||
- mongodb_data:/data/db
|
||||
networks:
|
||||
- podcastic_net
|
||||
healthcheck:
|
||||
test: ["CMD", "mongosh", "--eval", "db.adminCommand('ping')"]
|
||||
test: ["CMD", "mongosh", "--quiet", "-u", "${MONGO_USER}", "-p", "${MONGO_PASSWORD}", "--authenticationDatabase", "admin", "--eval", "db.adminCommand('ping')"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
@@ -20,12 +25,13 @@ services:
|
||||
image: redis:7-alpine
|
||||
container_name: podcastic-redis
|
||||
restart: unless-stopped
|
||||
command: ["redis-server", "--requirepass", "${REDIS_PASSWORD:?REDIS_PASSWORD is required}"]
|
||||
volumes:
|
||||
- redis_data:/data
|
||||
networks:
|
||||
- podcastic_net
|
||||
healthcheck:
|
||||
test: ["CMD", "redis-cli", "ping"]
|
||||
test: ["CMD", "redis-cli", "-a", "${REDIS_PASSWORD}", "ping"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
@@ -41,11 +47,12 @@ services:
|
||||
environment:
|
||||
NODE_ENV: production
|
||||
PORT: 3579
|
||||
MONGODB_URI: mongodb://mongodb:27017/podcastic
|
||||
REDIS_URL: redis://redis:6379
|
||||
JWT_SECRET: ${JWT_SECRET:-change_me_in_production}
|
||||
MONGODB_URI: mongodb://${MONGO_USER}:${MONGO_PASSWORD}@mongodb:27017/podcastic?authSource=admin
|
||||
REDIS_URL: redis://:${REDIS_PASSWORD}@redis:6379
|
||||
JWT_SECRET: ${JWT_SECRET:?JWT_SECRET is required (min 32 chars, generate with: openssl rand -base64 32)}
|
||||
JWT_EXPIRES_IN: 7d
|
||||
JWT_REFRESH_EXPIRES_IN: 30d
|
||||
CORS_ORIGIN: ${CORS_ORIGIN:-}
|
||||
PODCAST_INDEX_API_KEY: ${PODCAST_INDEX_API_KEY:-}
|
||||
PODCAST_INDEX_API_SECRET: ${PODCAST_INDEX_API_SECRET:-}
|
||||
depends_on:
|
||||
|
||||
Reference in new issue
Block a user