Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

docs: missing deployment security (firewall), Puma concurrency (WEB_CONCURRENCY), and sidekiq_alive host configuration

Aperta
#582 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
68/100
Tipo di issue
Documentazione
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
postgresql, ruby

Direzione di ricerca

Read the Linux VM deployment guide and Environment Variables reference linked in the issue, then inspect the configuration navigation where Performance and Monitoring are currently static. Document firewall guidance, WEB_CONCURRENCY, SIDEKIQ_ALIVE_HOST, and SIDEKIQ_ALIVE_PORT, and add the proposed performance guidance; done means all three references cover the named deployment and configuration gaps and the navigation links to the new content.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Description

Reviewing the current self-hosted deployment documentation (specifically /docs/self-hosted/deployment/linux-vm and /docs/self-hosted/configuration/environment-variables), there are critical gaps regarding network security, server concurrency, and health check ports that leave readers running unhardened and underperforming production instances.

Key Documentation Gaps
1. No Firewall (UFW) or Host Port Security Guidance
  • The Linux VM deployment guide suggests accessing http://{your_ip_address}:3000 before domain setup, but never instructs administrators to configure a host firewall (ufw or cloud security groups).
  • Because Puma binds to 0.0.0.0:3000 and SidekiqAlive binds to 0.0.0.0:7433, unfirewalled VM installations expose internal application and health check ports directly to public internet scans.
  • Suggested Addition: Add a dedicated "Security & Firewall" section to the Linux VM deployment guide recommending:
    sudo ufw default deny incoming
    sudo ufw default allow outgoing
    sudo ufw allow 22/tcp
    sudo ufw allow 80/tcp
    sudo ufw allow 443/tcp
    sudo ufw enable
    
2. Missing Documentation for sidekiq_alive (SIDEKIQ_ALIVE_HOST, SIDEKIQ_ALIVE_PORT)
  • With the introduction of sidekiq_alive for Sidekiq health checks (PR #12008), Sidekiq opens port 7433.
  • The Environment Variables reference has zero mention of SIDEKIQ_ALIVE_HOST or SIDEKIQ_ALIVE_PORT.
  • Readers have no way of knowing what port 7433 is, why it is listening, or how to bind it safely to 127.0.0.1 (SIDEKIQ_ALIVE_HOST=127.0.0.1) for non-Kubernetes environments.
3. Missing WEB_CONCURRENCY and Puma Clustered Mode Sizing
  • The environment variables page documents RAILS_MAX_THREADS but completely omits WEB_CONCURRENCY.
  • Without this, self-hosted administrators run Puma with workers = 0 (single process, 5 threads). Under Ruby GVL, production servers with 4–16 vCPUs experience severe request queueing and timeouts under moderate load because readers are never told how to enable Puma clustered mode.
4. Placeholder "Performance" and "Monitoring" sections in sidebar
  • In the documentation navigation under "Configuration", Performance and Monitoring exist merely as static text without pages or links.
  • Guidance on basic PostgreSQL sizing (shared_buffers beyond the default 128MB for larger message volumes) and Sidekiq concurrency is missing.
Proposed Improvement
  1. Update the Linux VM deployment guide with host firewall hardening instructions.
  2. Update the Environment Variables guide to document WEB_CONCURRENCY, SIDEKIQ_ALIVE_HOST, and SIDEKIQ_ALIVE_PORT.
  3. Add a basic Performance Tuning guide covering Puma worker sizing and PostgreSQL recommendations for growing self-hosted instances.
Lingua principale
MDX
Stelle
91
Fork
180
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di chatwoot/docs

Tutte le issue di chatwoot/docs

Issue simili

Altre issue su Databases

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.