Repository navigation
SOCFortress WAF: new service - #321
ChillBill77 wants to merge 10 commits into
Conversation
Removed the Include
|
Hi @ChillBill77, thanks for the SOCFortress WAF stack and for documenting why it deviates from the template. Here is a concrete list of what's needed before we can merge. Please use CONTRIBUTING.md and the service template as the reference. I did not run this stack locally: it binds host ports 80/443 and needs a MaxMind GeoIP file, and the branch has to be split first (point 1). 1. Split the PR This branch contains all Homebridge commits from #319, because both PRs come from your fork's 2. Make the README match the files The README describes a different setup than the PR contains:
The PR's
3. Working default configuration
4. Template conventions The network design (Tailscale as a peer on
5. Verification After the update, please add to the PR description what you checked: container status, the admin UI login through Thanks! Happy to review again once the branch is split. |
SOCFortress WAF: new service (Tailscale-served admin UI)
Description
Adds the SOCFortress WAF Management Platform
as a new service. Unlike the single-app template, this is a multi-container stack
(Caddy+Coraza WAF engine, FastAPI admin API, React/Nginx admin UI, PostgreSQL,
Redis, demo upstream). A Tailscale sidecar serves the admin UI privately over
the Tailnet via Tailscale Serve (Funnel disabled); the WAF data plane
(
caddy-waf) stays published on host80/443so per-site Let's Encrypt and realclient IPs keep working.
Because it is a multi-service stack,
network_mode: service:tailscaleis notusable (it collapses the namespace and breaks Docker DNS between the services).
Instead the Tailscale container runs as a normal peer on the stack's internal
network and reverse-proxies to
admin-ui:8080by container name using thehttps+insecure://scheme (the UI serves self-signed HTTPS internally; thepublic
*.ts.netcert is valid).Related Issues
Verification
docker compose config --quiet→ exit 0 (schema, interpolation, and merge valid; Compose v2).docker compose up -d: stack starts and the admin UI is reachableChecklist
Additional Context
Intentional deviations from
templates/service-template, with rationale:network_mode: service:tailscale— multi-service stack; Tailscale is apeer on the internal network proxying to
admin-ui:8080by DNS name.TS_USERSPACE=true(no/dev/net/tun, nocap_add: net_admin) — only theadmin UI is served, so kernel networking isn't needed; least privilege.
https+insecure://backend — admin UI is self-signed HTTPS internally.80/443— required; the WAF must receive realpublic traffic. Only the admin UI is Tailnet-only.
*.ts.nethostname, break per-site ACME, and hide real client IPs (degrading GeoIP).
User gotchas:
ALLOWED_ORIGINS=https://<host>.<tailnet>.ts.net(CORS, no wildcard) or login fails.GeoLite2-City.mmdb(MaxMind licensing).