feat(ui): opt-in IPv6 listen via NGINX_LISTEN_IPV6

Default behavior is unchanged: nginx binds IPv4 only. Setting
NGINX_LISTEN_IPV6=true renders listen [::]:3000 through an entrypoint
snippet; =auto does the same only when the container has an IPv6 stack,
using the /proc/net/if_inet6 gate the stock image's
10-listen-on-ipv6-by-default.sh already uses for default.conf (which this
image deletes). Read-only filesystems degrade to IPv4 with a log line
instead of failing the entrypoint
This commit is contained in:
namnt2307 2026-08-10 11:54:42 +07:00
parent f6b9518ddb
commit 80ab87d4bf
3 changed files with 45 additions and 1 deletions

View file

@ -27,7 +27,10 @@ RUN npm run build
FROM nginx:${NGINX_VERSION} AS runtime
# Drop the upstream default :80 server; we own the config.
RUN rm -f /etc/nginx/conf.d/default.conf
RUN rm -f /etc/nginx/conf.d/default.conf && mkdir /etc/nginx/listen-ipv6
# Opt-in IPv6 listen (NGINX_LISTEN_IPV6=true|auto) — see the script header.
COPY --chmod=755 ui/docker-entrypoint.d/15-listen-on-ipv6.sh /docker-entrypoint.d/
# Static export → web root.
COPY --from=builder /app/out /usr/share/nginx/html

View file

@ -0,0 +1,38 @@
#!/bin/sh
# Renders the UI server's IPv6 listen directive, opt-in via NGINX_LISTEN_IPV6:
# "true" forces it on, "auto" enables it only when the container has an IPv6
# stack (same /proc/net/if_inet6 gate as the stock
# 10-listen-on-ipv6-by-default.sh), anything else keeps today's IPv4-only bind.
set -eu
ME=$(basename "$0")
SNIPPET="/etc/nginx/listen-ipv6/enabled.conf"
entrypoint_log() {
if [ -z "${NGINX_ENTRYPOINT_QUIET_LOGS:-}" ]; then
echo "$ME: $*"
fi
}
case "${NGINX_LISTEN_IPV6:-}" in
true|on|1)
;;
auto)
if [ ! -f /proc/net/if_inet6 ]; then
entrypoint_log "info: NGINX_LISTEN_IPV6=auto and ipv6 not available, keeping IPv4 only"
exit 0
fi
;;
*)
exit 0
;;
esac
if ! touch "$SNIPPET" 2>/dev/null; then
entrypoint_log "info: can not write $SNIPPET (read-only file system?), keeping IPv4 only"
exit 0
fi
echo "listen [::]:3000 default_server;" > "$SNIPPET"
entrypoint_log "info: enabled listen on [::]:3000"

View file

@ -23,6 +23,9 @@ http {
server {
listen 3000 default_server;
# Populated by docker-entrypoint.d/15-listen-on-ipv6.sh when
# NGINX_LISTEN_IPV6 opts in; empty by default (IPv4 only).
include /etc/nginx/listen-ipv6/*.conf;
server_name _;
root /usr/share/nginx/html;