1panel + docker-openresty + discourse + cloudflare: Show Real User IPs Using a Socket Connection
This post was translated from Chinese by AI. If anything reads oddly, the Chinese original is authoritative. 中文原文
Original post: https://www.sunai.net/t/754
Using nginx to proxy Discourse through a socket rather than a port has these advantages:
- Better security and performance, bypassing the TCP stack
- Officially recommended by Discourse
- No unnecessary ports exposed
- UNIX sockets are more efficient than local network communication (such as localhost:3000), bypassing the network protocol stack
Discourse
If you're modifying an existing deployment, rebuild the app with /var/discourse/launcher rebuild app
app.yml
templates:
- "templates/postgres.template.yml"
- "templates/redis.template.yml"
- "templates/web.template.yml"
## Uncomment the next line to enable the IPv6 listener
#- "templates/web.ipv6.template.yml"
- "templates/web.ratelimited.template.yml"
- "templates/cloudflare.template.yml"
- "templates/web.socketed.template.yml"
## Uncomment these two lines if you wish to add Lets Encrypt (https)
#- "templates/web.ssl.template.yml"
#- "templates/web.letsencrypt.ssl.template.yml"
## Which TCP/IP ports should this container expose?
## If you want Discourse to share ports with another web server (such as Apache or nginx),
## see https://meta.discourse.org/t/17247 for details
expose:
#- "2080:80" # http
#- "2443:443" # https
~~~~~~
1panel
Modify the compose.yml for openresty
- /var/discourse:/var/discourse

openresty
unix:/var/discourse/shared/standalone/nginx.http.sock:

Results
The IP address shown is no longer cloudflare's
However, I may have noticed an issue with user avatars loading. I'm not sure yet; I'll keep an eye on it

Last updated 2025-06-24
Comments 0