Fix MEDIUM findings from 2026-09-24 maintenance review

- Backend retries DB connection at startup (up to 180s) so host reboots
  no longer crash-loop it; add backend and frontend healthchecks
- Docker log rotation (json-file 10m x 3) on all services
- ntfy alerts use X-Real-IP (set by nginx after real_ip resolution)
  instead of the client-controlled first X-Forwarded-For entry
- Frontend build on Node 24 LTS with package-lock.json + npm ci;
  axios 1.20.0, vite 5.4.21
- README: backup/restore/rollback runbook, real-IP proxy trust notes
- Release-Notes/v1.1.md; version 1.1.0

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
derekcandClaude Opus 5.5 committed 2026-09-24 23:44:25 -07:00
1 parent 3170c7f4eb
commit 4130467b22
11 files changed
+1851 -20

No files matched your search

+20
View File
@@ -1,3 +1,9 @@
x-logging: &default-logging
driver: json-file
options:
max-size: "10m"
max-file: "3"
services:
db:
image: mysql:8.4.11
@@ -20,6 +26,7 @@ services:
start_period: 180s
mem_limit: 512m
cpus: 1.0
logging: *default-logging
backend:
build: ./backend
@@ -41,8 +48,15 @@ services:
condition: service_healthy
networks:
- homeschool_net
healthcheck:
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://localhost:8000/api/health', timeout=3)"]
interval: 30s
timeout: 5s
retries: 3
start_period: 180s
mem_limit: 512m
cpus: 1.0
logging: *default-logging
frontend:
build: ./frontend
@@ -54,8 +68,14 @@ services:
- backend
networks:
- homeschool_net
healthcheck:
test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1/"]
interval: 30s
timeout: 5s
retries: 3
mem_limit: 128m
cpus: 0.5
logging: *default-logging
networks:
homeschool_net: