# Discourse shows server IP/localhost as user's IP

**URL:** https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474
**Category:** Self-hosting
**Tags:** unsupported-install
**Created:** [July 11, 2022, 8:43am UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474 "2022-07-11T08:43:24Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 11, 2022, 8:43am UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/1 "2022-07-11T08:43:24Z")

</div>

Hello, I’ve deployed Discourse on my own server, everything works normally except detecting user’s IP address, I’ve even made a php script (outside docker container) to get all headers where IP can be:

```plaintext
REMOTE_ADDR: 212.58.xxx.xxx
SERVER_PORT: 80
SERVER_ADDR: 85.25.xxx.xxx
SERVER_SOFTWARE: Apache:
HTTP_CF_CONNECTING_IP: 212.58.xxx.xxx
HTTP_CDN_LOOP: cloudflare
HTTP_X_REAL_IP: 162.158.xxx.xxx

```

Details:  
Server has BrainyCP panel installed with Apache and Nginx (currently website uses Nginx, which reverse proxies the docker container)  
`HTTP_CF_CONNECTING_IP` gives `127.0.0.1` inside docker container, but outside they have normal values  
Without changing the header using custom commands, Discourse displays server’s IP.

(Soon will add more details as my Discourse instance is now rebuilding)

---

<div class="post-metadata">

### Author: ![MarcP](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/marcp/32/160184_2.png) [@MarcP](https://meta.discourse.org/u/MarcP)
#### Post date: [July 11, 2022, 8:53am UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/2 "2022-07-11T08:53:16Z")

</div>

I’m not really sure about your setup, but noticed cloudflare in your post. Did you add the CloudFlare template to your app.yml file?

```plaintext
  - "templates/cloudflare.template.yml"

```

 ![image](https://global.discourse-cdn.com/meta/original/4X/0/a/b/0ab052e03d980201a6ff3fe34bd6324d8b536c33.png)

EDIT: used the wrong " "

---

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 11, 2022, 8:58am UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/3 "2022-07-11T08:58:40Z")

</div>

No, I’ve added it to the templates list, now waiting for rebuild

---

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 11, 2022, 10:51am UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/4 "2022-07-11T10:51:39Z")

</div>

Rebuilded, but it still shows server IP (I’ve commented custom commands

```yaml
## Any custom commands to run after building
run:
  - exec: echo "Beginning of custom commands"
  ## If you want to set the 'From' email address for your first registration, uncomment and change:
  ## After getting the first signup email, re-comment the line. It only needs to run once.
  - exec: rails r "SiteSetting.notification_email='noreply@zeronet.space'"
  #- replace:
  # filename: /etc/nginx/conf.d/discourse.conf
  # from: "types {"
  # to: |
  # set_real_ip_from 85.25.134.45;
  # real_ip_header CF-Connection-IP;
  # real_ip_recursive on;
  # types {
  #- replace:
  # filename: /etc/nginx/conf.d/discourse.conf
  # from: $proxy_add_x_forwarded_for
  # to: $send_http_cf_connection_ip;
  # global: true
  - exec: echo "End of custom commands"

```

Do I need to uncomment them? (also want to notice that they not worked even before I’ve added cloudflare template to app.yml))

---

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 11, 2022, 1:45pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/5 "2022-07-11T13:45:16Z")

</div>

Uncommented, `$sent_http_cf_connection_ip` gives `127.0.0.1`  
 ![image](https://global.discourse-cdn.com/meta/original/4X/8/5/5/85534c502e45e4472769037e6b99446636574f0f.png)

---

<div class="post-metadata">

### Author: ![Fma965](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/fma965/32/259795_2.png) [@Fma965](https://meta.discourse.org/u/Fma965)
#### Post date: [July 11, 2022, 4:03pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/6 "2022-07-11T16:03:22Z")

</div>

Nginx is likely reporting 127.0.0.1 not Discourse it self, you will probably need to set up realip in nginx

---

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 11, 2022, 4:24pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/7 "2022-07-11T16:24:18Z")

</div>

I’ve already added `cloudflare.template.yml` which adds realip directives, but still not working.  
I’ve even removed custom commands which are changing to custom header and now Discourse reports server IP for all users instead of localhost.

---

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 11, 2022, 4:29pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/8 "2022-07-11T16:29:56Z")

</div>

Also this is the Nginx config for domain `zeronet.space` generated by the panel itself

```nginx
server {
	listen 85.25.xxx.xx:443 ssl http2;
	server_name zeronet.space www.zeronet.space;
	root /home/ay0ks/workspace/sites/zeronet.space;
	
	# ssl on;
	ssl_certificate /etc/certs/ay0ks/zeronet.space_1655753906.crt;
	ssl_certificate_key /etc/certs/ay0ks/zeronet.space_1655753906.key;
	#ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
	#ssl_ciphers "HIGH:!RC4:!aNULL:!MD5:!kEDH";
	ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
	ssl_ciphers TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-128-GCM-SHA256:TLS13-AES-256-GCM-SHA384:ECDHE:!COMPLEMENTOFDEFAULT;
	ssl_prefer_server_ciphers on;
	
	add_header Strict-Transport-Security 'max-age=604800';
	
	access_log /etc/nginx/vhost_logs/zeronet.space_access;
	error_log /etc/nginx/vhost_logs/zeronet.space_error;
	
	location ~ /.well-known {
		allow all;
	}
	
	location ~ /\.ht {
		deny all;
		access_log off;
		log_not_found off;
	}

	location / {
		root /home/ay0ks/workspace/sites/zeronet.space;
		proxy_pass http://85.25.xxx.xx:31080; # Discourse is deployed on ports 31080/31443
		proxy_redirect off;
		proxy_force_ranges on;
		proxy_set_header Host $host;
		proxy_set_header X-Real-IP $remote_addr;
		proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
		proxy_set_header X-Forwarded-Proto $scheme;
		proxy_set_header HTTPS $scheme;
		
		proxy_cache off;
		proxy_cache_key "$request_method|$http_if_modified_since|$http_if_none_match|$host|$request_uri";
		#access_log /etc/nginx/vhost_logs//home/ay0ks/workspace/sites/zeronet.space;
		
		proxy_cache_valid 3s;
		proxy_cache_min_uses 2;
		# proxy_cache_lock on;
		# proxy_cache_use_stale error timeout;
		# proxy_cache_use_stale updating http_502 http_504;
		limit_conn lone 100;
		# limit_req zone=ltwo burst=10;
		
		client_body_buffer_size 128k;
		client_max_body_size 1024m;
		proxy_connect_timeout 180;
		proxy_send_timeout 180;
		proxy_read_timeout 180;
		send_timeout 180;
		
		proxy_buffer_size 4k;
		proxy_buffers 8 32k;
		proxy_busy_buffers_size 68k;
		proxy_temp_file_write_size 10m;
	}

	# error_page 404 /404.html;
	# error_page 500 502 503 504 /50x.html;
}

```

Also I want to note the “path” of request:  
`User -> Cloudflare -> Server(Nginx -> Docker -> Discourse)`  
And note that user’s IP is visible outside docker in cloudflare’s header `CF-Connecting-IP`

---

<div class="post-metadata">

### Author: ![Simon\_Manning](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/simon_manning/32/198596_2.png) [@Simon\_Manning](https://meta.discourse.org/u/Simon_Manning)
#### Post date: [July 11, 2022, 4:52pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/9 "2022-07-11T16:52:27Z")

</div>

I don’t know a lot about how the Cloudflare real IP stuff works but my suspicion is that your Discourse nginx will need `set_real_ip_from` to be the IP address that it sees your proxy nginx as. 127.0.0.1? Some other internal address? The public address? Not sure which it would see.

Once you know what address that is, I think what I would do is leave the cloudflare template in there, then add a new `replace` just for `set_real_ip_from`.

In addition to that, your proxy nginx will need to be configured to pass along the `CF-Connecting-IP` header if it isn’t already configured to do so or doesn’t already do so by default. I can’t really help with this bit.

---

<div class="post-metadata">

### Author: ![Fma965](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/fma965/32/259795_2.png) [@Fma965](https://meta.discourse.org/u/Fma965)
#### Post date: [July 11, 2022, 4:53pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/10 "2022-07-11T16:53:06Z")

</div>

Same path as me, my issue was nginx wasn’t configured to take the docker IP as a range to set the realip on.

```plaintext
set_real_ip_from 172.18.0.0/16;
real_ip_header X-Forwarded-For;
real_ip_recursive on;
set_real_ip_from 172.18.0.0/16;

```

So i go User \> Cloudflare \> Server Nginx (SWAG Docker) \> Discourse

```plaintext
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Proto https;
proxy_set_header X-Forwarded-Ssl on;
proxy_set_header X-Real-IP $remote_addr;

```

```plaintext
templates:
  - "templates/postgres.template.yml"
  - "templates/redis.template.yml"
  - "templates/web.template.yml"
  - "templates/web.ratelimited.template.yml"
## Uncomment these two lines if you wish to add Lets Encrypt (https)
# - "templates/web.ssl.template.yml"
# - "templates/web.letsencrypt.ssl.template.yml"
# - "templates/web.socketed.template.yml"
  - "templates/cloudflare.template.yml"

```

---

<div class="post-metadata">

### Author: ![itsbhanusharma](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/itsbhanusharma/32/180717_2.png) [@itsbhanusharma](https://meta.discourse.org/u/itsbhanusharma)
#### Post date: [July 11, 2022, 5:14pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/11 "2022-07-11T17:14:14Z")

</div>

> [@ay0ks](#):
>
> BrainyCP panel installed with Apache and Nginx

This could be the cause of your problems. Try setting up discourse on a server without any panels or reverse proxies installed and report if you experience the same problem.

As a first step, start by ammending the location block for discourse to match up with the details provided here: [Run other websites on the same machine as Discourse](https://meta.discourse.org/t/running-other-websites-on-the-same-machine-as-discourse/17247)

---

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 11, 2022, 5:32pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/12 "2022-07-11T17:32:08Z")

</div>

That’s not a solution of a problem, basically buying a new 30€/mo dedicated server can solve anything lol (this thread won’t exist then).

---

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 11, 2022, 5:34pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/13 "2022-07-11T17:34:52Z")

</div>

Will try and post results here

---

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 11, 2022, 8:07pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/14 "2022-07-11T20:07:25Z")

</div>

Do I need to add headers also in Discourse Nginx config? (inside docker) Because it’s still showing me server’s address instead of users

---

<div class="post-metadata">

### Author: ![Fma965](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/fma965/32/259795_2.png) [@Fma965](https://meta.discourse.org/u/Fma965)
#### Post date: [July 11, 2022, 8:55pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/15 "2022-07-11T20:55:57Z")

</div>

Based on your path that doesn’t make sense to me.

Your nginx goes to discourse to docker, why would your discourse be using it’s own nginx also?

---

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 12, 2022, 7:15am UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/16 "2022-07-12T07:15:55Z")

</div>

Don’t know, I’ve added your Nginx directives to mine though the panel (also checked from ssh), but it still shows server’s ip

---

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 12, 2022, 7:38am UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/17 "2022-07-12T07:38:00Z")

</div>

This is my app.yml:

```yaml
## this is the all-in-one, standalone Discourse Docker container template
##
## After making changes to this file, you MUST rebuild
## /var/discourse/launcher rebuild app
##
## BE *VERY* CAREFUL WHEN EDITING!
## YAML FILES ARE SUPER SUPER SENSITIVE TO MISTAKES IN WHITESPACE OR ALIGNMENT!
## visit http://www.yamllint.com/ to validate this file as needed

templates:
  - "templates/postgres.template.yml"
  - "templates/redis.template.yml"
  - "templates/web.template.yml"
  - "templates/web.ratelimited.template.yml"
  - "templates/cloudflare.template.yml"
## Uncomment these two lines if you wish to add Lets Encrypt (https)
  #- "templates/web.ssl.template.yml"
  #- "templates/web.letsencrypt.ssl.template.yml"

## which TCP/IP ports should this container expose?
## If you want Discourse to share a port with another webserver like Apache or nginx,
## see https://meta.discourse.org/t/17247 for details
expose:
  - "31080:80" # http
  - "31443:443" # https

params:
  db_default_text_search_config: "pg_catalog.russian"

  ## Set db_shared_buffers to a max of 25% of the total memory.
  ## will be set automatically by bootstrap based on detected RAM, or you can override
  db_shared_buffers: "4096MB"

  ## can improve sorting performance, but adds memory usage per-connection
  #db_work_mem: "40MB"

  ## Which Git revision should this container use? (default: tests-passed)
  #version: tests-passed

env:
  LC_ALL: ru_RU.UTF-8
  LANG: ru_RU.UTF-8
  LANGUAGE: ru_RU.UTF-8
  DISCOURSE_DEFAULT_LOCALE: ru

  ## How many concurrent web requests are supported? Depends on memory and CPU cores.
  ## will be set automatically by bootstrap based on detected CPUs, or you can override
  UNICORN_WORKERS: 8

  ## TODO: The domain name this Discourse instance will respond to
  ## Required. Discourse will not work with a bare IP number.
  DISCOURSE_HOSTNAME: 'zeronet.space'

  ## Uncomment if you want the container to be started with the same
  ## hostname (-h option) as specified above (default "$hostname-$config")
  #DOCKER_USE_HOSTNAME: true

  ## TODO: List of comma delimited emails that will be made admin and developer
  ## on initial signup example 'user1@example.com,user2@example.com'
  DISCOURSE_DEVELOPER_EMAILS: 'contact@zeronet.space'

  ## TODO: The SMTP mail server used to validate new accounts and send notifications
  # SMTP ADDRESS, username, and password are required
  # WARNING the char '#' in SMTP password can cause problems!
  DISCOURSE_SMTP_ADDRESS: smtp.zeronet.space
  DISCOURSE_SMTP_PORT: 587
  DISCOURSE_SMTP_USER_NAME: noreply@zeronet.space
  DISCOURSE_SMTP_PASSWORD: "xxxxxxx"
  DISCOURSE_SMTP_ENABLE_START_TLS: true
  DISCOURSE_SMTP_AUTHENTICATION: login
  DISCOURSE_SMTP_OPENSSL_VERIFY_MODE: none
  DISCOURSE_NOTIFICATION_EMAIL: "noreply@zeronet.space"
  #DISCOURSE_SMTP_DOMAIN: "zeronet.space"

  ## If you added the Lets Encrypt template, uncomment below to get a free SSL certificate
  #LETSENCRYPT_ACCOUNT_EMAIL: me@example.com

  ## The http or https CDN address for this Discourse instance (configured to pull)
  ## see https://meta.discourse.org/t/14857 for details
  #DISCOURSE_CDN_URL: https://discourse-cdn.example.com

  ## The maxmind geolocation IP address key for IP address lookup
  ## see https://meta.discourse.org/t/-/137387/23 for details
  #DISCOURSE_MAXMIND_LICENSE_KEY: 1234567890123456

## The Docker container is stateless; all data is stored in /shared
volumes:
  - volume:
      host: /var/discourse/shared/standalone
      guest: /shared
  - volume:
      host: /var/discourse/shared/standalone/log/var-log
      guest: /var/log

## Plugins go here
## see https://meta.discourse.org/t/19157 for details
hooks:
  after_code:
    - exec:
        cd: $home/plugins
        cmd:
          - git clone https://github.com/discourse/docker_manager.git

## Any custom commands to run after building
run:
  - exec: echo "Beginning of custom commands"
  ## If you want to set the 'From' email address for your first registration, uncomment and change:
  ## After getting the first signup email, re-comment the line. It only needs to run once.
  - exec: rails r "SiteSetting.notification_email='noreply@zeronet.space'"
  - exec: echo "End of custom commands"

```

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [July 12, 2022, 9:12am UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/18 "2022-07-12T09:12:18Z")

</div>

The answer was linked above. You need something like this.

> [@Run other websites on the same machine as Discourse](https://meta.discourse.org/t/run-other-websites-on-the-same-machine-as-discourse/17247/1):
>
> and editing the `server_name` and `location` stanza like this:
> 
> ```plaintext
> server_name discourse.example.com; # <-- change this
> 
> location / {
> proxy_pass http://unix:/var/discourse/shared/standalone/nginx.http.sock:;
> proxy_set_header Host $http_host;
> proxy_http_version 1.1;
> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
> proxy_set_header X-Forwarded-Proto $scheme;
> proxy_set_header X-Real-IP $remote_addr;
> 
> }
> 
> ```

---

<div class="post-metadata">

### Author: ![ay0ks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ay0ks/32/266371_2.png) [@ay0ks](https://meta.discourse.org/u/ay0ks)
#### Post date: [July 12, 2022, 2:18pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/19 "2022-07-12T14:18:21Z")

</div>

This fixed issues with ip detection (now everything works normal) but now some of images are not loading

EDIT: this was a cache issue, now everything works! Thank you all!

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [August 11, 2022, 2:18pm UTC](https://meta.discourse.org/t/discourse-shows-server-ip-localhost-as-users-ip/232474/20 "2022-08-11T14:18:43Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
