diff --git a/ui/Dockerfile b/ui/Dockerfile index 0d184b74493..a0abb031390 100644 --- a/ui/Dockerfile +++ b/ui/Dockerfile @@ -27,7 +27,10 @@ RUN npm run build FROM nginx:${NGINX_VERSION} AS runtime # Drop the upstream default :80 server; we own the config. -RUN rm -f /etc/nginx/conf.d/default.conf +RUN rm -f /etc/nginx/conf.d/default.conf && mkdir /etc/nginx/listen-ipv6 + +# Opt-in IPv6 listen (NGINX_LISTEN_IPV6=true|auto) — see the script header. +COPY --chmod=755 ui/docker-entrypoint.d/15-listen-on-ipv6.sh /docker-entrypoint.d/ # Static export → web root. COPY --from=builder /app/out /usr/share/nginx/html diff --git a/ui/docker-entrypoint.d/15-listen-on-ipv6.sh b/ui/docker-entrypoint.d/15-listen-on-ipv6.sh new file mode 100755 index 00000000000..ecdb00f38d8 --- /dev/null +++ b/ui/docker-entrypoint.d/15-listen-on-ipv6.sh @@ -0,0 +1,38 @@ +#!/bin/sh +# Renders the UI server's IPv6 listen directive, opt-in via NGINX_LISTEN_IPV6: +# "true" forces it on, "auto" enables it only when the container has an IPv6 +# stack (same /proc/net/if_inet6 gate as the stock +# 10-listen-on-ipv6-by-default.sh), anything else keeps today's IPv4-only bind. + +set -eu + +ME=$(basename "$0") +SNIPPET="/etc/nginx/listen-ipv6/enabled.conf" + +entrypoint_log() { + if [ -z "${NGINX_ENTRYPOINT_QUIET_LOGS:-}" ]; then + echo "$ME: $*" + fi +} + +case "${NGINX_LISTEN_IPV6:-}" in + true|on|1) + ;; + auto) + if [ ! -f /proc/net/if_inet6 ]; then + entrypoint_log "info: NGINX_LISTEN_IPV6=auto and ipv6 not available, keeping IPv4 only" + exit 0 + fi + ;; + *) + exit 0 + ;; +esac + +if ! touch "$SNIPPET" 2>/dev/null; then + entrypoint_log "info: can not write $SNIPPET (read-only file system?), keeping IPv4 only" + exit 0 +fi + +echo "listen [::]:3000 default_server;" > "$SNIPPET" +entrypoint_log "info: enabled listen on [::]:3000" diff --git a/ui/nginx.conf b/ui/nginx.conf index a41ee5bd5b4..f5583140b69 100644 --- a/ui/nginx.conf +++ b/ui/nginx.conf @@ -23,6 +23,9 @@ http { server { listen 3000 default_server; + # Populated by docker-entrypoint.d/15-listen-on-ipv6.sh when + # NGINX_LISTEN_IPV6 opts in; empty by default (IPv4 only). + include /etc/nginx/listen-ipv6/*.conf; server_name _; root /usr/share/nginx/html;