diff --git a/README.md b/README.md index c2fdcc2..3e02047 100644 --- a/README.md +++ b/README.md @@ -86,8 +86,9 @@ Set `abbr` to a short identifier for the VTC. The Docker frontend deployment derives the API base URL from its `VITE_CONFIG_URL`, so `abbr` does not have to match `prefix`. Create an hCaptcha site for the public frontend domain. Set its secret in the -`captcha.secret` value. Set the related public site key as -`VITE_HCAPTCHA_SITEKEY` in the frontend deployment. +`captcha.secret` value. The frontend deployment provides the related +`VITE_HCAPTCHA_SITEKEY` setting in its `.env.example`; set it to the public site +key. The upstream sample uses plural names for some built-in plugins, but the backend expects the singular names shown above. This deployment configuration @@ -261,6 +262,8 @@ backend source, compiler environment, or Docker build cache changed. By default, the API is available at `http://localhost:17777/api`. Swagger UI is available at `http://localhost:17777/api/doc`. The default bind address is suitable for a reverse proxy on the Docker host. +The reverse proxy examples in the frontend deployment already use this address +and the `/api` prefix. Update both deployments only if you change these defaults. The backend reads its active Docker network gateway when it starts. Uvicorn trusts forwarded headers only from this gateway and the loopback interface. This works with multiple Docker Compose networks and lets audit and security