<feed xmlns='http://www.w3.org/2005/Atom'>
<title>skunky-art.git/compose.vpn_example.yml, branch v1.3.3</title>
<subtitle>alternative deviantart frontend, no javascript. go.
</subtitle>
<id>http://git.krz.sh/krz/skunky-art.git/atom?h=v1.3.3</id>
<link rel='self' href='http://git.krz.sh/krz/skunky-art.git/atom?h=v1.3.3'/>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/'/>
<updated>2026-07-15T01:22:33+00:00</updated>
<entry>
<title>docs: add optional VPN egress compose example</title>
<updated>2026-07-15T01:22:33+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-15T01:22:33+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=369fd17e696699b9b1aa1ac8293e0122c7e3a41e'/>
<id>urn:sha1:369fd17e696699b9b1aa1ac8293e0122c7e3a41e</id>
<content type='text'>
CloudFront/WAF blocks some egress IPs on the /_puppy path, making every
DA-backed page fail while Go tries to unmarshal an HTML 403 page.
Routing outbound through a non-blocked exit fixes it with no code change,
since devianter's client honors HTTPS_PROXY.

Adds a compose stack with an optional gluetun sidecar behind the "vpn"
profile (off by default, so the stock direct setup is unchanged) and a
matching .env.example. Ignore .env so real credentials stay out of git.
</content>
</entry>
</feed>
