diff --git a/infrastructure/docker-compose.staging.yml b/infrastructure/docker-compose.staging.yml index fe71e9b..0d4da27 100644 --- a/infrastructure/docker-compose.staging.yml +++ b/infrastructure/docker-compose.staging.yml @@ -109,6 +109,9 @@ services: memory: 256M networks: + # Staging/preview services attach only to trails-shared — created (and + # IPv6-enabled) by the production compose project. There is no per-project + # default network here, so v6 egress comes from trails-shared itself. trails-shared: external: true name: trails-shared diff --git a/infrastructure/docker-compose.yml b/infrastructure/docker-compose.yml index 1390257..ac25be8 100644 --- a/infrastructure/docker-compose.yml +++ b/infrastructure/docker-compose.yml @@ -250,13 +250,23 @@ services: networks: # Default project network — kept implicit for production services. + # IPv6 is enabled so the journal can federate with v6-only instances + # (e.g. social.ullrich.is). Docker ≥27 auto-allocates a ULA subnet and + # NAT66-masquerades egress via the host's public v6 address. + # NOTE: flipping this on an existing deployment requires recreating the + # network: `docker compose down && docker compose --env-file .env up -d`. default: + enable_ipv6: true # Created by this compose project with a fixed (un-namespaced) name so the # staging compose project can attach to it via `external: true`. Only # postgres is joined here on the production side; staging containers join # to reach postgres by hostname. + # IPv6-enabled so staging/preview journals — whose only network this is — + # get v6 federation egress like production. Recreating it on a live host + # requires detaching staging, previews, and postgres first. trails-shared: name: trails-shared + enable_ipv6: true volumes: caddy_data: