From 5159d8a51847d9da765db62c2d0284bda5c1f39d Mon Sep 17 00:00:00 2001 From: Kibi Kelburton Date: Thu, 1 Oct 2026 21:41:42 +0200 Subject: [PATCH] Add a Docker image and compose file for the web proxy Co-Authored-By: Claude Opus 5.5 --- .dockerignore | 10 ++++++++++ .gitignore | 1 + Dockerfile | 18 ++++++++++++++++++ README.md | 9 +++++++++ docker-compose.yml | 16 ++++++++++++++++ 5 files changed, 54 insertions(+) create mode 100644 .dockerignore create mode 100644 Dockerfile create mode 100644 docker-compose.yml diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..86f871c --- /dev/null +++ b/.dockerignore @@ -0,0 +1,10 @@ +node_modules +dist +dist-web +dist-proxy +dist-electron +release +.git +docs +*.log +.env diff --git a/.gitignore b/.gitignore index 95533f8..f853b22 100644 --- a/.gitignore +++ b/.gitignore @@ -5,3 +5,4 @@ dist-proxy/ dist-electron/ release/ *.log +.env diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..7da8a72 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,18 @@ +# The browser version: web app and proxy in one image. +# docker compose up -d --build +FROM node:22-slim AS build +WORKDIR /src +COPY package.json package-lock.json ./ +# No install scripts: the Electron download they would trigger is only needed for the desktop app +RUN npm ci --ignore-scripts +COPY . . +RUN npm run build:web + +FROM node:22-slim +WORKDIR /app +COPY --from=build /src/dist-web ./dist-web +COPY --from=build /src/dist-proxy ./dist-proxy +USER node +ENV MUMH5_PORT=8080 +EXPOSE 8080/tcp 3478/udp +CMD ["node", "dist-proxy/proxy.mjs"] diff --git a/README.md b/README.md index d827394..2886218 100644 --- a/README.md +++ b/README.md @@ -168,6 +168,15 @@ MUMH5_SERVERS="mumble.example.com=My server" node dist-proxy/proxy.mjs Then open `http://127.0.0.1:8080`. For development, `npm run dev:web` starts the proxy and a hot-reloading page together, with any server allowed. To deploy, copy `dist-web/` and `dist-proxy/` next to each other on the server (Node 22 or newer, no `node_modules` needed) and put a reverse proxy with HTTPS in front that forwards WebSocket upgrades. Browsers only allow the microphone on HTTPS pages (or on localhost). +With Docker, the same thing is one command; settings go in a `.env` file next to `docker-compose.yml`: + +```bash +echo 'MUMH5_SERVERS=mumble.example.com=My server' > .env +docker compose up -d --build +``` + +The container uses the host's network: the proxy listens on `127.0.0.1:8080` for your reverse proxy and on UDP 3478 for STUN, and a Mumble server on the same machine is reachable as `localhost`. + | Variable | Default | Meaning | | --- | --- | --- | | `MUMH5_SERVERS` | none | Mumble servers people may connect to: `host[:port][=Label]`, comma-separated. Required unless `MUMH5_ALLOW_ANY=1` | diff --git a/docker-compose.yml b/docker-compose.yml new file mode 100644 index 0000000..461363c --- /dev/null +++ b/docker-compose.yml @@ -0,0 +1,16 @@ +# The mumh5 web proxy. Settings come from a .env file next to this one, for example: +# MUMH5_SERVERS=mumble.example.com=My server +# MUMH5_TRUST_PROXY=1 +services: + mumh5: + build: . + restart: unless-stopped + # Host networking, so STUN sees each visitor's real address (through Docker's port + # forwarding it would often see Docker's own) and a Mumble server on this machine is + # reachable as localhost. The proxy listens on 127.0.0.1:8080 for nginx and on UDP 3478. + network_mode: host + env_file: + - path: .env + required: false + environment: + MUMH5_BIND: ${MUMH5_BIND:-127.0.0.1}