security: require auth on MongoDB and Redis

Enable mongod --auth with root credentials from MONGO_USER/PASSWORD,
and redis-server --requirepass from REDIS_PASSWORD. App connection
strings now embed credentials. All secrets are required (no fallback)
so misconfiguration fails fast at compose time.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
This commit is contained in:
MichaelandClaude Haiku 4.5 committed 2026-04-18 07:25:38 +02:00
1 parent 5497c89a99
commit f620ec614c
3 files changed
+47 -36

No files matched your search

+15 -10
View File
@@ -1,24 +1,29 @@
# Backend Configuration
NODE_ENV=development
PORT=5000
API_URL=http://localhost:5000
# MongoDB Configuration
MONGODB_URI=mongodb://mongo:27017/podcastic
MONGODB_USER=podcastic
MONGODB_PASSWORD=podcastic_dev
# CORS — comma-separated list of allowed origins (e.g. https://podcastic.example.com,https://app.example.com)
# Leave empty in dev to allow all origins
CORS_ORIGIN=
# Redis Configuration
REDIS_URL=redis://redis:6379
# MongoDB Configuration (REQUIRED — no defaults)
MONGO_USER=podcastic
MONGO_PASSWORD=replace_with_strong_password
# Used by the app — credentials must match MONGO_USER/MONGO_PASSWORD above
MONGODB_URI=mongodb://podcastic:replace_with_strong_password@mongodb:27017/podcastic?authSource=admin
# JWT Configuration
JWT_SECRET=your_super_secret_jwt_key_change_in_production
# Redis Configuration (REQUIRED — no defaults)
REDIS_PASSWORD=replace_with_strong_password
REDIS_URL=redis://:replace_with_strong_password@redis:6379
# JWT Configuration (REQUIRED — min 32 chars, no defaults accepted)
# Generate: openssl rand -base64 32
JWT_SECRET=
JWT_EXPIRES_IN=7d
JWT_REFRESH_EXPIRES_IN=30d
# Podcast API (PodcastIndex) - OPTIONAL but recommended for search feature
# Get free API keys at: https://podcastindex-api.com/
# These enable podcast discovery and search functionality
PODCAST_INDEX_API_KEY=
PODCAST_INDEX_API_SECRET=
+20 -21
View File
@@ -1,26 +1,35 @@
# ==========================================
# Podcastic - Unraid Configuration
# ==========================================
# All services in single container on port 3579
# Application Environment
NODE_ENV=production
# ==========================================
# DATABASE & CACHE (Internal - Don't change)
# DATABASE & CACHE — REQUIRED, set strong passwords
# ==========================================
MONGODB_URI=mongodb://127.0.0.1:27017/podcastic
REDIS_URL=redis://127.0.0.1:6379
# Generate strong passwords: openssl rand -base64 24
MONGO_USER=podcastic
MONGO_PASSWORD=CHANGE_ME_strong_random_password
REDIS_PASSWORD=CHANGE_ME_strong_random_password
# These are derived from the credentials above (do not edit unless you know what you're doing)
MONGODB_URI=mongodb://podcastic:CHANGE_ME_strong_random_password@mongodb:27017/podcastic?authSource=admin
REDIS_URL=redis://:CHANGE_ME_strong_random_password@redis:6379
# ==========================================
# SECURITY - CHANGE THESE!
# SECURITY — REQUIRED
# ==========================================
# JWT Secret - Use strong random string
# JWT Secret — minimum 32 chars, must be a strong random string
# Generate: openssl rand -base64 32
JWT_SECRET=change-this-to-random-secret-key-in-production
JWT_SECRET=
JWT_EXPIRES_IN=7d
JWT_REFRESH_EXPIRES_IN=30d
# CORS — comma-separated list of frontend origins (e.g. https://podcastic.your-domain.com)
# Leave empty only if frontend and backend share the same origin
CORS_ORIGIN=
# ==========================================
# OPTIONAL: PodcastIndex API (Podcast Search)
# ==========================================
@@ -30,26 +39,16 @@ PODCAST_INDEX_API_KEY=
PODCAST_INDEX_API_SECRET=
# ==========================================
# PORTS (Single container)
# PORTS
# ==========================================
# Frontend: http://your-unraid-ip:3579
# API: http://your-unraid-ip:3579/api
# Health: http://your-unraid-ip:3579/health
PORT=5000 # Internal backend port (don't change)
# ==========================================
# Frontend Configuration
# ==========================================
VITE_API_URL=http://your-unraid-ip:3579/api
# Or use relative path:
# VITE_API_URL=/api
PORT=3579
# ==========================================
# NOTES FOR UNRAID
# ==========================================
# 1. Change JWT_SECRET to a random string
# 2. If accessing from WAN, update VITE_API_URL to your domain
# 1. Generate strong passwords with: openssl rand -base64 32
# 2. Set CORS_ORIGIN to your public frontend URL if accessing from WAN
# 3. Optionally add PodcastIndex API keys for search feature
# 4. All data stored in /mnt/user/appdata/podcastic/
# 5. Logs in /mnt/user/appdata/podcastic/logs/
+12 -5
View File
@@ -5,12 +5,17 @@ services:
image: mongo:8
container_name: podcastic-mongodb
restart: unless-stopped
command: ["--auth"]
environment:
MONGO_INITDB_ROOT_USERNAME: ${MONGO_USER:?MONGO_USER is required}
MONGO_INITDB_ROOT_PASSWORD: ${MONGO_PASSWORD:?MONGO_PASSWORD is required}
MONGO_INITDB_DATABASE: podcastic
volumes:
- mongodb_data:/data/db
networks:
- podcastic_net
healthcheck:
test: ["CMD", "mongosh", "--eval", "db.adminCommand('ping')"]
test: ["CMD", "mongosh", "--quiet", "-u", "${MONGO_USER}", "-p", "${MONGO_PASSWORD}", "--authenticationDatabase", "admin", "--eval", "db.adminCommand('ping')"]
interval: 10s
timeout: 5s
retries: 5
@@ -20,12 +25,13 @@ services:
image: redis:7-alpine
container_name: podcastic-redis
restart: unless-stopped
command: ["redis-server", "--requirepass", "${REDIS_PASSWORD:?REDIS_PASSWORD is required}"]
volumes:
- redis_data:/data
networks:
- podcastic_net
healthcheck:
test: ["CMD", "redis-cli", "ping"]
test: ["CMD", "redis-cli", "-a", "${REDIS_PASSWORD}", "ping"]
interval: 10s
timeout: 5s
retries: 5
@@ -41,11 +47,12 @@ services:
environment:
NODE_ENV: production
PORT: 3579
MONGODB_URI: mongodb://mongodb:27017/podcastic
REDIS_URL: redis://redis:6379
JWT_SECRET: ${JWT_SECRET:-change_me_in_production}
MONGODB_URI: mongodb://${MONGO_USER}:${MONGO_PASSWORD}@mongodb:27017/podcastic?authSource=admin
REDIS_URL: redis://:${REDIS_PASSWORD}@redis:6379
JWT_SECRET: ${JWT_SECRET:?JWT_SECRET is required (min 32 chars, generate with: openssl rand -base64 32)}
JWT_EXPIRES_IN: 7d
JWT_REFRESH_EXPIRES_IN: 30d
CORS_ORIGIN: ${CORS_ORIGIN:-}
PODCAST_INDEX_API_KEY: ${PODCAST_INDEX_API_KEY:-}
PODCAST_INDEX_API_SECRET: ${PODCAST_INDEX_API_SECRET:-}
depends_on: