Wood Chen

1panel + docker-openresty + discourse + cloudflare: Show Real User IPs Using a Socket Connection

0 comments96 views129 words

This post was translated from Chinese by AI. If anything reads oddly, the Chinese original is authoritative. 中文原文

Original post: https://www.sunai.net/t/754

Using nginx to proxy Discourse through a socket rather than a port has these advantages:

  • Better security and performance, bypassing the TCP stack
  • Officially recommended by Discourse
  • No unnecessary ports exposed
  • UNIX sockets are more efficient than local network communication (such as localhost:3000), bypassing the network protocol stack

Discourse

If you're modifying an existing deployment, rebuild the app with /var/discourse/launcher rebuild app

app.yml

templates:
  - "templates/postgres.template.yml"
  - "templates/redis.template.yml"
  - "templates/web.template.yml"
  ## Uncomment the next line to enable the IPv6 listener
  #- "templates/web.ipv6.template.yml"
  - "templates/web.ratelimited.template.yml"
  - "templates/cloudflare.template.yml"
  - "templates/web.socketed.template.yml"
  ## Uncomment these two lines if you wish to add Lets Encrypt (https)
  #- "templates/web.ssl.template.yml"
  #- "templates/web.letsencrypt.ssl.template.yml"

## Which TCP/IP ports should this container expose?
## If you want Discourse to share ports with another web server (such as Apache or nginx),
## see https://meta.discourse.org/t/17247 for details
expose:
  #- "2080:80"   # http
  #- "2443:443" # https

~~~~~~

1panel

Modify the compose.yml for openresty

- /var/discourse:/var/discourse

Pasted image 20250620202924

openresty

unix:/var/discourse/shared/standalone/nginx.http.sock:

Pasted image 20250620203011

Results

The IP address shown is no longer cloudflare's

However, I may have noticed an issue with user avatars loading. I'm not sure yet; I'll keep an eye on it

Pasted image 20250620203436

Last updated 2025-06-24

Related posts

Comments 0