From de6fb9d13ea604cc2f3197f170c136caaa1cc30e Mon Sep 17 00:00:00 2001 From: Andrey Antukh Date: Wed, 23 Sep 2026 12:44:37 +0000 Subject: [PATCH] :wrench: Drop loopback bind on the stub_status endpoint A compose port mapping delivers traffic to the container address, never to loopback, so `listen 127.0.0.1:8082` made `ports: :8082` fail from the host. Both configs (image template and devenv) now use `listen 8082`, which binds every interface and matches the implicit bind of the public `listen 8080 default_server`. Rewrite both block comments to state the new bind and who decides access from outside the host. The scrape URI stays on 127.0.0.1:8082: it still reaches the socket. AI-assisted-by: mimo-v2.6-flash-free --- docker/devenv/files/nginx.conf | 12 +++++++----- docker/images/files/nginx.conf.template | 10 ++++++---- 2 files changed, 13 insertions(+), 9 deletions(-) diff --git a/docker/devenv/files/nginx.conf b/docker/devenv/files/nginx.conf index b4d8829567..46246e5153 100644 --- a/docker/devenv/files/nginx.conf +++ b/docker/devenv/files/nginx.conf @@ -308,12 +308,14 @@ http { } # Dedicated health endpoint for the optional nginx-prometheus-exporter - # sidecar (scraping http://127.0.0.1:8082/stub_status). Bound to - # localhost only and out of the public server, so it can not be - # reached from outside the host. Counts client-side connections only; - # it says nothing about the upstream pools. + # sidecar (scraping http://127.0.0.1:8082/stub_status). `listen 8082` + # binds every interface and sits out of the public server: a compose + # port mapping delivers traffic to the container address, never to + # loopback, so only the published port decides who gets in from outside + # the host. Counts client-side connections only; it says nothing about + # the upstream pools. server { - listen 127.0.0.1:8082; + listen 8082; server_name _; access_log off; diff --git a/docker/images/files/nginx.conf.template b/docker/images/files/nginx.conf.template index 7c4d92dbb8..8e3b21d7e1 100644 --- a/docker/images/files/nginx.conf.template +++ b/docker/images/files/nginx.conf.template @@ -199,11 +199,13 @@ http { # Dedicated health endpoint consumed by the nginx-prometheus-exporter # sidecar (deployed by ops, scraping http://127.0.0.1:8082/stub_status). - # Bound to localhost only and out of the public server, so it can not - # be reached from outside the host. Counts client-side connections - # only; it says nothing about the upstream pools. + # `listen 8082` binds every interface and sits out of the public server: + # a compose port mapping delivers traffic to the container address, never + # to loopback, so only the published port decides who gets in from + # outside the host. Counts client-side connections only; it says nothing + # about the upstream pools. server { - listen 127.0.0.1:8082; + listen 8082; server_name _; access_log off;