# Installed Discourse in Docker, Cannot Connect

**URL:** https://meta.discourse.org/t/installed-discourse-in-docker-cannot-connect/199386
**Category:** Self-hosting
**Created:** [August 6, 2021, 1:08am UTC](https://meta.discourse.org/t/installed-discourse-in-docker-cannot-connect/199386 "2021-08-06T01:08:56Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Seal](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Seal](https://meta.discourse.org/u/Seal)
#### Post date: [August 6, 2021, 1:08am UTC](https://meta.discourse.org/t/installed-discourse-in-docker-cannot-connect/199386/1 "2021-08-06T01:08:56Z")

</div>

So I used the [standard install doc](https://github.com/discourse/discourse/blob/main/docs/INSTALL-cloud.md#install-discourse) and everything seemed to go fine. I then edited the app.yml to change ports used, commented out LetsEncrypt and rebuilt. Looks like it all went fine.

But when I try to connect via the most direct method:

$lynx [https://127.0.0.1:44443](https://127.0.0.1:44443)

I get the following error:

Alert!: Unable to make secure connection to remote host.

I cannot even ping the port.

This make any kind of sense? Are there logs inside the container?

—edit to add----

```plaintext
$ sudo ./launcher logs app
run-parts: executing /etc/runit/1.d/00-ensure-links
run-parts: executing /etc/runit/1.d/00-fix-var-logs
run-parts: executing /etc/runit/1.d/01-cleanup-web-pids
run-parts: executing /etc/runit/1.d/anacron
run-parts: executing /etc/runit/1.d/cleanup-pids
Cleaning stale PID files
run-parts: executing /etc/runit/1.d/copy-env
Started runsvdir, PID is 43
ok: run: redis: (pid 56) 0s
**chgrp: invalid group: ‘syslog’**
ok: run: postgres: (pid 55) 0s
supervisor pid: 57 unicorn pid: 85
(57) Reopening logs

```

----edit to add more----

```plaintext
root@hestia-app:/shared/log/rails# tail -f *.log
==> production_errors.log <==

==> production.log <==

==> sidekiq.log <==

==> unicorn.stderr.log <==
I, [2021-08-06T00:56:35.859967 #85] INFO -- : master done reopening logs
I, [2021-08-06T00:56:50.911700 #142] INFO -- : worker=0 done reopening logs
I, [2021-08-06T00:56:50.911698 #152] INFO -- : worker=1 done reopening logs
I, [2021-08-06T00:56:50.935834 #162] INFO -- : worker=2 done reopening logs
I, [2021-08-06T00:56:50.941733 #233] INFO -- : worker=7 done reopening logs
I, [2021-08-06T00:56:50.945447 #203] INFO -- : worker=5 done reopening logs
I, [2021-08-06T00:56:50.947354 #172] INFO -- : worker=3 done reopening logs
I, [2021-08-06T00:56:50.949949 #187] INFO -- : worker=4 done reopening logs
I, [2021-08-06T00:56:50.953453 #213] INFO -- : worker=6 done reopening logs

==> unicorn.stdout.log <==
Sidekiq PID 131 done reopening logs...

```

```plaintext
root@hestia-app:/var/log/nginx# tail *.log
==> access.letsencrypt.log <==

==> access.log <==

==> error.letsencrypt.log <==

==> error.log <==

```

---

<div class="post-metadata">

### Author: ![Seal](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Seal](https://meta.discourse.org/u/Seal)
#### Post date: [August 6, 2021, 2:24am UTC](https://meta.discourse.org/t/installed-discourse-in-docker-cannot-connect/199386/2 "2021-08-06T02:24:37Z")

</div>

~~Must be a docker error, cuz… everything else looks fine.~~

I just installed a bare apache container mapped to 8088, and it works fine from lynx

---

<div class="post-metadata">

### Author: ![Seal](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Seal](https://meta.discourse.org/u/Seal)
#### Post date: [August 6, 2021, 3:05am UTC](https://meta.discourse.org/t/installed-discourse-in-docker-cannot-connect/199386/3 "2021-08-06T03:05:25Z")

</div>

I entered the app again, and ran ps ax, and it appears that everything is working. It just seems that the container is not accepting connections.

```plaintext
root@hestia-app:/var/www/discourse# ps ax
    PID TTY STAT TIME COMMAND
      1 pts/0 Ss+ 0:00 /bin/bash /sbin/boot
     43 pts/0 S+ 0:00 /usr/bin/runsvdir -P /etc/service
     44 ? Ss 0:00 runsv cron
     45 ? Ss 0:00 runsv rsyslog
     46 ? Ss 0:00 runsv redis
     47 ? Ss 0:00 runsv postgres
     48 ? Ss 0:00 runsv unicorn
     49 ? Ss 0:00 runsv nginx
     50 ? S 0:00 cron -f
     51 ? Sl 0:00 rsyslogd -n
     52 ? S 0:00 nginx: master process /usr/sbin/nginx
     53 ? S 0:00 svlogd /var/log/redis
     54 ? S 0:00 svlogd /var/log/postgres
     55 ? S 0:00 /usr/lib/postgresql/13/bin/postmaster -D /etc/postgresql/13/main
     56 ? Sl 0:33 /usr/bin/redis-server *:6379
     57 ? S 0:04 /bin/bash config/unicorn_launcher -E production -c config/unicorn.conf.rb
     64 ? S 0:00 nginx: worker process
     65 ? S 0:00 nginx: worker process
     66 ? S 0:00 nginx: worker process
     67 ? S 0:00 nginx: worker process
     68 ? S 0:00 nginx: cache manager process
     79 ? Ss 0:00 postgres: 13/main: checkpointer 
     80 ? Ss 0:00 postgres: 13/main: background writer 
     81 ? Ss 0:03 postgres: 13/main: walwriter 
     82 ? Ss 0:00 postgres: 13/main: autovacuum launcher 
     83 ? Ss 0:00 postgres: 13/main: stats collector 
     84 ? Ss 0:00 postgres: 13/main: logical replication launcher 
     85 ? Sl 0:13 unicorn master -E production -c config/unicorn.conf.rb
    113 ? Ss 0:01 postgres: 13/main: discourse discourse [local] idle
    131 ? SNl 0:48 sidekiq 6.2.1 discourse [0 of 5 busy]
    142 ? Sl 0:06 unicorn worker[0] -E production -c config/unicorn.conf.rb
    152 ? Sl 0:06 unicorn worker[1] -E production -c config/unicorn.conf.rb
    162 ? Sl 0:07 unicorn worker[2] -E production -c config/unicorn.conf.rb
    172 ? Sl 0:06 unicorn worker[3] -E production -c config/unicorn.conf.rb
    180 ? Ss 0:00 postgres: 13/main: discourse discourse [local] idle
    187 ? Sl 0:07 unicorn worker[4] -E production -c config/unicorn.conf.rb
    203 ? Sl 0:07 unicorn worker[5] -E production -c config/unicorn.conf.rb
    213 ? Sl 0:07 unicorn worker[6] -E production -c config/unicorn.conf.rb
    233 ? Sl 0:07 unicorn worker[7] -E production -c config/unicorn.conf.rb
  11733 pts/1 Ss 0:00 /bin/bash --login
  11748 ? S 0:00 sleep 1
  11749 pts/1 R+ 0:00 ps ax

```

---

<div class="post-metadata">

### Author: ![Seal](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Seal](https://meta.discourse.org/u/Seal)
#### Post date: [August 6, 2021, 4:12am UTC](https://meta.discourse.org/t/installed-discourse-in-docker-cannot-connect/199386/4 "2021-08-06T04:12:23Z")

</div>

Okay, so I entered the app and installed lynx inside the discord docker, and I _can_ get the welcome page there! So the install is working, the network mapping from in the docker out to the server is the issue.

Here is the #docker ps output:

```plaintext
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
c6d0209e4e72 local_discourse/app "/sbin/boot" 51 minutes ago Up 51 minutes 127.0.0.1:8880->80/tcp, 127.0.0.1:4443->443/tcp app

```

…and here is the app.yml info:

```plaintext
templates:
  - "templates/postgres.template.yml"
  - "templates/redis.template.yml"
  - "templates/web.template.yml"
  - "templates/web.ratelimited.template.yml"

expose:
  - "127.0.0.1:8880:80" # http
  - "127.0.0.1:4443:443" # https

params:
  db_default_text_search_config: "pg_catalog.english"
  db_shared_buffers: "2048MB"

env:
  LC_ALL: en_US.UTF-8
  LANG: en_US.UTF-8
  LANGUAGE: en_US.UTF-8

  UNICORN_WORKERS: 8

  DISCOURSE_HOSTNAME: [redacted]

  DISCOURSE_SMTP_ADDRESS: [redacted]
  DISCOURSE_SMTP_PORT: 587
  DISCOURSE_SMTP_USER_NAME: [redacted]
  DISCOURSE_SMTP_PASSWORD: "[redacted]"
  #DISCOURSE_SMTP_ENABLE_START_TLS: true # (optional, default true)
  DISCOURSE_SMTP_DOMAIN: [redacted]
  DISCOURSE_NOTIFICATION_EMAIL: [redacted]

## The Docker container is stateless; all data is stored in /shared
volumes:
  - volume:
      host: /var/discourse/shared/standalone
      guest: /shared
  - volume:
      host: /var/discourse/shared/standalone/log/var-log
      guest: /var/log

## Plugins go here
## see https://meta.discourse.org/t/19157 for details
hooks:
  after_code:
    - exec:
        cd: $home/plugins
        cmd:
          - git clone https://github.com/discourse/docker_manager.git

## Any custom commands to run after building
run:
  - exec: echo "Beginning of custom commands"
  - exec: echo "End of custom commands"

```

---

<div class="post-metadata">

### Author: ![Seal](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Seal](https://meta.discourse.org/u/Seal)
#### Post date: [August 6, 2021, 4:23am UTC](https://meta.discourse.org/t/installed-discourse-in-docker-cannot-connect/199386/5 "2021-08-06T04:23:41Z")

</div>

Ah, I see what I did. The 8880:80 works fine, I was only testing the 4443:443 side. It did not work as there is a certificate error. I am intending to install and manage the certificate at the webserver level in the virtual host. I will post a final solution for those interested once I get it all working.

---

<div class="post-metadata">

### Author: ![Seal](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Seal](https://meta.discourse.org/u/Seal)
#### Post date: [August 6, 2021, 11:39pm UTC](https://meta.discourse.org/t/installed-discourse-in-docker-cannot-connect/199386/6 "2021-08-06T23:39:03Z")

</div>

**Install environment**  
Hestia Control Panel (For Server Management)  
Apache2 (Webserver)  
Discourse in Docker reverse proxied to Apache2  
Let’sEncrypt not reverse proxied, but managed by Hestia in the www\_root

1. Setup unix sockets in app.yml (and rebuild):

```plaintext
  - "templates/web.socketed.template.yml"

```

1. Remove port mapping and Let’sEncrypt from app.yml (and rebuild)

```plaintext
# - "templates/web.ssl.template.yml"
# - "templates/web.letsencrypt.ssl.template.yml"
# - "80:80" # http
# - "443:443" # https
# LETSENCRYPT_ACCOUNT_EMAIL: {your email, probably}

```

1. Create Alternative apache2.conf templates for HestiaCP as follows (for those of you not using hestiacp, just realize that the %{replace tags}% are pretty standard and obvious if you look at any other apache2.conf file. The most important parts do not use many %{replace tags}%. Also note that the text _standalone_ could be _socket-only_ depending on your setup. Look to see what is in the /var/discourse/shared/ dir if you don’t remember.

{Custom Template}.stpl

```plaintext
<VirtualHost %ip%:%web_ssl_port%>

    ServerName %domain_idn%

    ProxyPreserveHost On
    ProxyRequests Off
    ProxyPass / unix:/var/discourse/shared/standalone/nginx.http.sock|http://localhost/
    ProxyPassReverse / unix:/var/discourse/shared/standalone/nginx.http.sock|http://localhost/

    ServerAdmin %email%

    Alias /vstats/ %home%/%user%/web/%domain%/stats/
    Alias /error/ %home%/%user%/web/%domain%/document_errors/

    CustomLog /var/log/%web_system%/domains/%domain%.bytes bytes
    CustomLog /var/log/%web_system%/domains/%domain%.log combined
    ErrorLog /var/log/%web_system%/domains/%domain%.error.log
    <Directory %home%/%user%/web/%domain%/stats>
        AllowOverride All
    </Directory>
    <Directory %sdocroot%>
        AllowOverride All
        SSLRequireSSL
        Options +Includes -Indexes +ExecCGI
    </Directory>
    SSLEngine on
    SSLVerifyClient none
    SSLCertificateFile %ssl_crt%
    SSLCertificateKeyFile %ssl_key%
    %ssl_ca_str%SSLCertificateChainFile %ssl_ca%

    IncludeOptional %home%/%user%/conf/web/%domain%/%web_system%.ssl.conf_*

</VirtualHost>

```

{Custom Template}.tpl

```plaintext
<VirtualHost %ip%:%web_port%>

    ServerName %domain_idn%
    %alias_string%

    ProxyPreserveHost On
    ProxyRequests Off
    ProxyPass / unix:/var/discourse/shared/standalone/nginx.http.sock|http://localhost/
    ProxyPassReverse / unix:/var/discourse/shared/standalone/nginx.http.sock|http://localhost/

    RewriteEngine On
    RewriteCond %{REQUEST_URI} !^.well-known/acme-challenge
    RewriteRule ^(.*) https://%domain_idn%/$1 [R=301,L]

    Alias /vstats/ %home%/%user%/web/%domain%/stats/
    Alias /error/ %home%/%user%/web/%domain%/document_errors/

    CustomLog /var/log/%web_system%/domains/%domain%.bytes bytes
    CustomLog /var/log/%web_system%/domains/%domain%.log combined
    ErrorLog /var/log/%web_system%/domains/%domain%.error.log

    <Directory %home%/%user%/web/%domain%/stats>
        AllowOverride All
    </Directory>
    <Directory %sdocroot%>
        AllowOverride All
        Options +Includes -Indexes +ExecCGI
    </Directory>

    IncludeOptional %home%/%user%/conf/web/%domain%/%web_system%.conf_*

</VirtualHost>

```

---

<div class="post-metadata">

### Author: ![Seal](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Seal](https://meta.discourse.org/u/Seal)
#### Post date: [August 8, 2021, 3:08am UTC](https://meta.discourse.org/t/installed-discourse-in-docker-cannot-connect/199386/7 "2021-08-08T03:08:56Z")

</div>

Ah, I missed something above, you will also need this in each file:

```plaintext
RequestHeader set X-Forwarded-Proto https

```
