docs: stats.hoelee.com is live via DNS+DSM reverse proxy (not CF) — record the exposure path, the client-IP header fix, and the open default-credential item
Deploy / build (push) Successful in 34s
Deploy / build (push) Successful in 34s
This commit is contained in:
@@ -69,10 +69,13 @@ unanswerable, and the job-hunt thesis can't be verified. Decisions (2026-09-29):
|
||||
| Stack | DSM Portainer **stack 284 `umami`** (endpoint 2), container `umami`, host port **5410 → 3000**, network `bridge_hoelee` |
|
||||
| Image | `ghcr.io/umami-software/umami:postgresql-latest` → resolved **v3.4.0** (Node 22.23.2). ⚠ v3 publishes versioned tags on `docker.umami.is`, but ghcr only carries rolling tags (`postgresql-v*` stops at 2.16) — record the running version before any upgrade or there is no tag to roll back to |
|
||||
| Database | **Reused the shared instance**: stack 139 `postgres` → `postgres-server` (PG 17.10, `Etc/UTC`). New role + DB `umami` (login only, **not** superuser). `CREATE EXTENSION pgcrypto` works because PG 13+ treats it as trusted. ⚠ Data lives in `/volume1/docker/postgres-server/data` next to authentik / n8n / tubesync / crowdsec — same fate if that volume is restored |
|
||||
| Env | `DATABASE_URL`, `APP_SECRET`, `TWO_FACTOR_ENCRYPTION_KEY`, `CLIENT_IP_HEADER=cf-connecting-ip`, `DISABLE_TELEMETRY=1`, `DISABLE_UPDATES=1`, `MCP_ENABLED=1`, `TZ=Asia/Kuala_Lumpur`. No `cpus:` (DSM has no CFS quota) |
|
||||
| Env | `DATABASE_URL`, `APP_SECRET`, `TWO_FACTOR_ENCRYPTION_KEY`, `CLIENT_IP_HEADER=x-forwarded-for`, `DISABLE_TELEMETRY=1`, `DISABLE_UPDATES=1`, `MCP_ENABLED=1`, `TZ=Asia/Kuala_Lumpur`. No `cpus:` (DSM has no CFS quota) |
|
||||
| Verified on LAN | `/api/heartbeat` → `{"ok":true}` (first hit 6.1 s cold, then 66 ms), `/login` 200, container `healthy`, prisma migrations created **16 tables** |
|
||||
| Ops notes | `/volume1/docker/umami/README.md` |
|
||||
| Still open | (a) `stats.hoelee.com` DNS + Cloudflare tunnel public-hostname → `http://192.168.1.1:5410` — the tunnel is **remotely managed** (`cloudflared --token`), and the existing `.cf-token` is Pages-only, so this needs a token with `Zone:DNS:Edit` + `Account:Cloudflare Tunnel:Edit` or a manual dashboard edit; `.hoelee.com` has **no wildcard DNS**. (b) CF Web Analytics still not enabled. (c) GSC sitemap submission still unconfirmed. (d) The blog's tracker snippet is **not** wired yet — nothing is being recorded until (a) exists. |
|
||||
| **Public URL** | **https://stats.hoelee.com** live 2026-09-29 — DNS **A → 180.73.9.11** (the user's usual path, **not** through Cloudflare) → router 443 → DSM nginx reverse proxy (`ReverseProxy.json` key `8df2ab4d-ff73-47a0-b5ad-5a09957e6402`, frontend `stats.hoelee.com:443` → `localhost:5410`) → container. Cert = Let's Encrypt `CN=stats.hoelee.com`, 2026-09-28 → 2026-12-27; `http://` → 308. Public checks: `/api/heartbeat` 200 `{"ok":true}`, `/login` 200, `/script.js` 200, `/api/send` with a bogus id → 400 `Website not found` |
|
||||
| **Client IP fix** | ⚠ Because traffic does **not** pass Cloudflare, `CLIENT_IP_HEADER` was changed `cf-connecting-ip` → **`x-forwarded-for`** (what DSM nginx sets) on 2026-09-29, stack re-PUT and verified in the running container. Without it every visit would be attributed to the proxy. Consequence of no CF: no WAF/rate-limit/bot protection on this hostname |
|
||||
| ⚠ **Open security item** | The Umami dashboard is **publicly reachable with the default `admin` / `umami` credentials** — verified 2026-09-29 (`POST /api/auth/login` → 200 + token). New subdomains appear in Certificate Transparency logs within minutes, so this needs closing now: (a) change the password, and/or (b) gate it — public router for `/script.js` + `/api/send` + `/api/heartbeat`, everything else behind basicAuth/authentik (recipe in the stack README) |
|
||||
| Still open | (a) CF Web Analytics still not enabled (independent of Umami). (b) GSC sitemap submission still unconfirmed. (c) The blog's tracker snippet is **not** wired yet — no data is collected until a website record exists and the snippet is in the base layout. |
|
||||
| Dashboard login | default `admin` / `umami` — change on first login (agent does not hold this password) |
|
||||
|
||||
**Step E2 — Wire the two sites together (www.hoelee.com → blog).** ⏸ Deferred by user 2026-09-29
|
||||
|
||||
Reference in New Issue
Block a user