summaryrefslogtreecommitdiff
path: root/compose.vpn_example.yml
Commit message (Collapse)AuthorAgeFilesLines
* update org nameChristian Cleberg44 hours1-1/+1
|
* fix: refuse to start when the cache directory is not writableChristian Cleberg2026-07-151-1/+3
| | | | | | | | | | | An unwritable cache directory degraded silently: media still served, because the download succeeds before the cache write is attempted, so the only symptom was one "permission denied" line per request and a cache that never filled. Every request re-fetched from the CDN. Probe the directory at startup and exit with the uid and the chown that fixes it. The container image runs as uid 10000, which is the usual cause with a bind-mounted cache, so say so in the message and in both compose examples.
* ci: publish multi-arch image to GHCR on release tagsv1.3.4Christian Cleberg2026-07-151-1/+5
| | | | | | | | | | | Build and push linux/amd64 + linux/arm64 images to ghcr.io/zerolabsco/skunky-art on every v* tag, with a signed provenance attestation. The Dockerfile cross-compiles from $BUILDPLATFORM, so the arm64 image builds without QEMU emulation. Default both compose examples to the published image and keep `build: .` commented out for building from a checkout, and extend dependabot to the github-actions and docker ecosystems.
* docs: add optional VPN egress compose exampleChristian Cleberg2026-07-141-0/+95
CloudFront/WAF blocks some egress IPs on the /_puppy path, making every DA-backed page fail while Go tries to unmarshal an HTML 403 page. Routing outbound through a non-blocked exit fixes it with no code change, since devianter's client honors HTTPS_PROXY. Adds a compose stack with an optional gluetun sidecar behind the "vpn" profile (off by default, so the stock direct setup is unchanged) and a matching .env.example. Ignore .env so real credentials stay out of git.