feat(demo): whole-origin IndeeHub proxy on :2101 with sign-in seeding

- nginx-demo.conf: new :2101 server block reverse-proxying the live
  indee.tx1138.com site with no path prefix (fixes the old sub_filter
  path-rewrite breakage), X-Frame-Options/CSP stripped, WS upgrade
  passthrough, and a demo sign-in script injected into <head>
- indee-demo-signin.js: PUBLIC-DEMO-ONLY seeder that writes a labelled
  throwaway "nsec" account (freshly generated keypair, not a secret) into
  the :2101 origin's indeedhub-accounts/indeedhub-active-account
  localStorage keys, idempotently, so IndeeHub boots signed in
- Dockerfile.web: copy the seeder into the demo web image, EXPOSE 2101
- docker-compose.demo.yml + demo-deploy/docker-compose.yml: publish 2101
  (DEMO_INDEE_PORT override documented in the thin deploy stack)

Verified: nginx -t clean in nginx:alpine; live proxy smoke shows 200 with
no framing headers, injected tag, seed script served, assets proxied.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
archipelago
2026-07-29 12:23:18 -04:00
co-authored by Claude Fable 5
parent e2278ad518
commit 69bc3d3f27
5 changed files with 119 additions and 6 deletions
+2
View File
@@ -47,6 +47,8 @@ services:
container_name: archy-demo-web
ports:
- "2100:80"
# IndeeHub whole-origin demo proxy (nginx :2101 in nginx-demo.conf)
- "2101:2101"
depends_on:
- neode-backend
restart: unless-stopped