docs: missing deployment security (firewall), Puma concurrency (WEB_CONCURRENCY), and sidekiq_alive host configuration
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 68/100
- Tipo di issue
- Documentazione
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- postgresql, ruby
- Ambito
- databases, devops, documentation, performance, security
Direzione di ricerca
Read the Linux VM deployment guide and Environment Variables reference linked in the issue, then inspect the configuration navigation where Performance and Monitoring are currently static. Document firewall guidance, WEB_CONCURRENCY, SIDEKIQ_ALIVE_HOST, and SIDEKIQ_ALIVE_PORT, and add the proposed performance guidance; done means all three references cover the named deployment and configuration gaps and the navigation links to the new content.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
Reviewing the current self-hosted deployment documentation (specifically /docs/self-hosted/deployment/linux-vm and /docs/self-hosted/configuration/environment-variables), there are critical gaps regarding network security, server concurrency, and health check ports that leave readers running unhardened and underperforming production instances.
Key Documentation Gaps
1. No Firewall (UFW) or Host Port Security Guidance
- The Linux VM deployment guide suggests accessing
http://{your_ip_address}:3000before domain setup, but never instructs administrators to configure a host firewall (ufwor cloud security groups). - Because Puma binds to
0.0.0.0:3000and SidekiqAlive binds to0.0.0.0:7433, unfirewalled VM installations expose internal application and health check ports directly to public internet scans. - Suggested Addition: Add a dedicated "Security & Firewall" section to the Linux VM deployment guide recommending:
sudo ufw default deny incoming sudo ufw default allow outgoing sudo ufw allow 22/tcp sudo ufw allow 80/tcp sudo ufw allow 443/tcp sudo ufw enable
2. Missing Documentation for sidekiq_alive (SIDEKIQ_ALIVE_HOST, SIDEKIQ_ALIVE_PORT)
- With the introduction of
sidekiq_alivefor Sidekiq health checks (PR #12008), Sidekiq opens port7433. - The Environment Variables reference has zero mention of
SIDEKIQ_ALIVE_HOSTorSIDEKIQ_ALIVE_PORT. - Readers have no way of knowing what port 7433 is, why it is listening, or how to bind it safely to
127.0.0.1(SIDEKIQ_ALIVE_HOST=127.0.0.1) for non-Kubernetes environments.
3. Missing WEB_CONCURRENCY and Puma Clustered Mode Sizing
- The environment variables page documents
RAILS_MAX_THREADSbut completely omitsWEB_CONCURRENCY. - Without this, self-hosted administrators run Puma with
workers = 0(single process, 5 threads). Under Ruby GVL, production servers with 4–16 vCPUs experience severe request queueing and timeouts under moderate load because readers are never told how to enable Puma clustered mode.
4. Placeholder "Performance" and "Monitoring" sections in sidebar
- In the documentation navigation under "Configuration", Performance and Monitoring exist merely as static text without pages or links.
- Guidance on basic PostgreSQL sizing (
shared_buffersbeyond the default 128MB for larger message volumes) and Sidekiq concurrency is missing.
Proposed Improvement
- Update the Linux VM deployment guide with host firewall hardening instructions.
- Update the Environment Variables guide to document
WEB_CONCURRENCY,SIDEKIQ_ALIVE_HOST, andSIDEKIQ_ALIVE_PORT. - Add a basic Performance Tuning guide covering Puma worker sizing and PostgreSQL recommendations for growing self-hosted instances.
- Lingua principale
- MDX
- Stelle
- 91
- Fork
- 180
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di chatwoot/docs
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 35/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 42/100
-
Contributing Guide - DockerForse di nuovo libera @vishnu-narayanan l’ha presa 1113 giorni fa e non c’è nessuna pull request aperta. Aperta
-
Expected version ">=16.14". Got "14.21.3"Forse di nuovo libera @vishnu-narayanan l’ha presa 1158 giorni fa e non c’è nessuna pull request aperta. Apertadocumentation
Tutte le issue di chatwoot/docs
Issue simili
-
Idle compaction monitors LIST the replica every tick when the newest destination file spans more than one TXIDForse già presa @pishuv l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
benbjohnson/litestream#1563 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
signalapp/Signal-Android#15056 ·
I maintainer di solito rispondono entro 7 giorni
-
[BUG] Qdrant RAG client applies score_threshold to raw cosine similarity, not the 0-1 score it returnsForse già presa @roydonsequeira l’ha presa oggi. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
NVIDIA/cuCollections#858 ·
I maintainer di solito rispondono entro 2 giorni