Skip to content

Commit b84f51d

Browse files
Merge pull request #11193 from mruiserrmendix/patch-21
Enhance Docker deployment documentation with proxy setups
2 parents eb4f869 + f1fd2d9 commit b84f51d

1 file changed

Lines changed: 174 additions & 0 deletions

File tree

content/en/docs/deployment/docker-deploy/docker-pad.md

Lines changed: 174 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -235,3 +235,177 @@ The Mendix Runtime exposes health check endpoints that can be used to monitor th
235235
| `/health/ready` | Returns the readiness status — indicates if the app is ready to serve traffic |
236236

237237
These endpoints are especially useful when integrating with orchestration platforms such as Kubernetes, which rely on liveness and readiness probes to manage container lifecycle.
238+
239+
## Reverse Proxy
240+
241+
This section serves as a reference guide and starting point for configuring a reverse proxy on Docker. The configurations provided are intended for illustrative purposes only, as the required settings vary depending on your specific network environment and infrastructure setup.
242+
243+
{{% alert color="info" %}}
244+
This example implementation is provided as-is, and is not covered under official support. Support requests related to this specific configuration cannot be addressed.
245+
{{% /alert %}}
246+
247+
### Configuring Nginx
248+
249+
To configure Nginx, perform the following steps:
250+
251+
1. Define services for the app and Nginx reverse proxy:
252+
253+
```text
254+
services:
255+
app:
256+
build: .
257+
ports:
258+
- "127.0.0.1:8080:8080" # Bind only localhost
259+
environment:
260+
- SPRING_PROFILES_ACTIVE=docker
261+
nginx:
262+
image: nginx:alpine
263+
ports:
264+
- "80:80"
265+
volumes:
266+
- ./nginx.conf:/etc/nginx/nginx.conf:ro
267+
depends_on:
268+
- app
269+
```
270+
271+
2. Run the following command: `docker-compose up --build`.​
272+
3. Create the following `nginx.conf` file to proxy requests to the app:
273+
274+
```text
275+
events {}
276+
http {
277+
server {
278+
listen 80;
279+
location / {
280+
proxy_pass http://app:8080;
281+
proxy_set_header Host $host;
282+
proxy_set_header X-Real-IP $remote_addr;
283+
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
284+
proxy_set_header X-Forwarded-Proto $scheme;
285+
}
286+
}
287+
}
288+
```
289+
290+
This configuration exposes only port 80 publicly while acting as a proxy to your app on the internal port 8080.
291+
292+
### Configuring Traefik
293+
294+
To simplify setting up Traefik as a reverse proxy for your app running in a Docker container, use Docker Compose. This configuration exposes Traefik on ports `80/8080`, automatically discovers your app container through labels, and routes traffic to it.
295+
296+
Traefik uses two networks: *frontend* (public) and *backend* (internal).
297+
298+
1. Add Traefik labels to the app service:
299+
300+
```text
301+
services:
302+
traefik:
303+
image: traefik:v3.0
304+
ports:
305+
- "80:80"
306+
- "8080:8080" # Traefik dashboard
307+
volumes:
308+
- /var/run/docker.sock:/var/run/docker.sock:ro
309+
command:
310+
- --api.dashboard=true
311+
- --providers.docker=true
312+
- --providers.docker.exposedbydefault=false
313+
- --entrypoints.web.address=:80
314+
networks:
315+
- frontend
316+
- backend
317+
restart: unless-stopped
318+
app:
319+
build: .
320+
networks:
321+
- backend
322+
labels:
323+
- traefik.enable=true
324+
- traefik.docker.network=backend
325+
- traefik.http.routers.app.rule=Host(`localhost`) || PathPrefix(`/api`)
326+
- traefik.http.routers.app.entrypoints=web
327+
- traefik.http.services.app.loadbalancer.server.port=8080
328+
restart: unless-stopped
329+
networks:
330+
frontend:
331+
external: false
332+
backend:
333+
external: false
334+
```
335+
336+
2. Run the following command: `docker compose up -d --build`.
337+
338+
You can now access your app at `http://localhost`. Traefik proxies to `app:8080` internally.
339+
340+
#### Key Traefik Labels Explained
341+
342+
This section explains the main labels used by Traefik.
343+
344+
* `traefik.enable=true` - Enables Traefik for this container.
345+
* `traefik.http.routers.java-app.rule=Host(yourapp.example.com)` - Routes requests matching the host to this service.
346+
* `traefik.http.services.java-app.loadbalancer.server.port=8080` - Forwards to your app's internal port.
347+
348+
Traefik automatically detects changes through a Docker socket. You do not need to restart it to update the labels.
349+
350+
#### Main Differences between Traefik and Nginx
351+
352+
This section explains how Traefik proxies differ from Nginx.
353+
354+
* Traefik does not use static config files. Instead, the configuration is automatic through the use of labels.
355+
* A dashboard available at `http://localhost:8080` shows the routes.
356+
* You can easily scale by duplicating the `app service` with unique router rules (for example, `Host(app2.local)`).​
357+
358+
## Example High Availability Implementation
359+
360+
High availability (HA) requires redundancy, health checks, and restarts to handle failures. Scale for HA with Docker Compose (for local or development environments) or Kubernetes.
361+
362+
This section serves as a reference guide and starting point for configuring high availability on Docker. The configurations provided are intended for illustrative purposes only, as the settings will vary depending on your specific network environment and infrastructure setup.
363+
364+
{{% alert color="info" %}}
365+
This example implementation is provided as-is, and is not covered under official support. Support requests related to this specific configuration cannot be addressed.
366+
{{% /alert %}}
367+
368+
1. Configure the *docker-compose.yml* as in the following example:
369+
370+
```text
371+
services:
372+
myapp:
373+
image: myapp
374+
ports:
375+
- "8080:8080"
376+
deploy:
377+
replicas: 3 # Run 3 instances
378+
healthcheck:
379+
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:8080/actuator/health"]
380+
interval: 30s
381+
timeout: 10s
382+
retries: 3
383+
```
384+
385+
2. Start the process by running the following command: `docker-compose up --scale myapp=3`.
386+
3. Add a load balancer like Traefik or an NGINX reverse proxy in the front:
387+
388+
``` text
389+
services:
390+
traefik:
391+
image: traefik:v3.0
392+
command: --providers.docker --entrypoints.web.address=:80
393+
ports: ["80:80"]
394+
myapp:
395+
# No ports exposed; Traefik load balances
396+
```
397+
398+
This creates a redundancy—kill container, and traffic shifts automatically.
399+
400+
4. Build and run manually by running the following script:
401+
402+
``` text
403+
# Build image
404+
docker build -t myapp:latest .
405+
# Test single instance
406+
docker run -p 8080:8080 myapp:latest
407+
# For HA: Run 3 replicas (use docker-compose.yml for production)
408+
docker run -d -p 8081:8080 --name app1 myapp:latest
409+
docker run -d -p 8082:8080 --name app2 myapp:latest
410+
docker run -d -p 8083:8080 --name app3 myapp:latest
411+
```

0 commit comments

Comments
 (0)