🔧 Drop loopback bind on the stub_status endpoint

A compose port mapping delivers traffic to the container address,
never to loopback, so `listen 127.0.0.1:8082` made
`ports: <host>:8082` fail from the host. Both configs (image
template and devenv) now use `listen 8082`, which binds every
interface and matches the implicit bind of the public
`listen 8080 default_server`.

Rewrite both block comments to state the new bind and who decides
access from outside the host. The scrape URI stays on
127.0.0.1:8082: it still reaches the socket.

AI-assisted-by: mimo-v2.6-flash-free
This commit is contained in:
Andrey Antukh 2026-09-23 12:44:37 +00:00
parent 5b3844c37a
commit de6fb9d13e
2 changed files with 13 additions and 9 deletions

View File

@ -308,12 +308,14 @@ http {
}
# Dedicated health endpoint for the optional nginx-prometheus-exporter
# sidecar (scraping http://127.0.0.1:8082/stub_status). Bound to
# localhost only and out of the public server, so it can not be
# reached from outside the host. Counts client-side connections only;
# it says nothing about the upstream pools.
# sidecar (scraping http://127.0.0.1:8082/stub_status). `listen 8082`
# binds every interface and sits out of the public server: a compose
# port mapping delivers traffic to the container address, never to
# loopback, so only the published port decides who gets in from outside
# the host. Counts client-side connections only; it says nothing about
# the upstream pools.
server {
listen 127.0.0.1:8082;
listen 8082;
server_name _;
access_log off;

View File

@ -199,11 +199,13 @@ http {
# Dedicated health endpoint consumed by the nginx-prometheus-exporter
# sidecar (deployed by ops, scraping http://127.0.0.1:8082/stub_status).
# Bound to localhost only and out of the public server, so it can not
# be reached from outside the host. Counts client-side connections
# only; it says nothing about the upstream pools.
# `listen 8082` binds every interface and sits out of the public server:
# a compose port mapping delivers traffic to the container address, never
# to loopback, so only the published port decides who gets in from
# outside the host. Counts client-side connections only; it says nothing
# about the upstream pools.
server {
listen 127.0.0.1:8082;
listen 8082;
server_name _;
access_log off;