Vince fixed

This commit is contained in:
2026-09-06 16:34:23 +00:00
parent 605b4b16cc
commit 3929d3f0b2
6 changed files with 54 additions and 14 deletions
+12 -4
View File
@@ -8,10 +8,11 @@
reverse_proxy {{ docker_container }}:{{ cms_port }}
}
# First-party analytics (Vince) — script (/stats/js/script.js) and event
# endpoint (/stats/api/event) proxied same-origin so they survive ad
# blockers and never touch a third-party domain.
handle /stats/* {
# First-party analytics (Vince) — the tracker script and event endpoint
# are proxied same-origin with the /stats prefix stripped (vince serves
# /js/script.js and /api/event), so they survive ad blockers and never
# touch a third-party domain.
handle_path /stats/* {
reverse_proxy {{ vince_container }}:{{ vince_port }}
}
@@ -25,3 +26,10 @@
redir / /_/
reverse_proxy {{ docker_container }}:{{ cms_port }}
}
# Vince analytics dashboard (login-protected). DNS for this host must point
# at this server; the tracker script itself stays on the www host at
# /stats/* — this is only for humans reading the dashboard.
{{ stats_host }} {
reverse_proxy {{ vince_container }}:{{ vince_port }}
}
+3 -2
View File
@@ -1,4 +1,5 @@
---
# vince_container / vince_port live in ansible/vars/default.yml (the Caddy
# template needs them at play level).
# vince_container / vince_port / vince_admin_* / vince_site_domain /
# stats_host live in ansible/vars/default.yml (the Caddy template needs them
# at play level).
vince_image: ghcr.io/vinceanalytics/vince:latest
+18 -2
View File
@@ -1,7 +1,12 @@
---
# Self-hosted first-party analytics (Vince — Plausible-protocol, single
# binary). Only reachable on the docker network: Caddy proxies /stats/*
# on the www host to this container, so browser requests stay first-party.
# binary). Only reachable on the docker network:
# - Caddy proxies /stats/* on the www host here (prefix stripped), serving
# the tracker script and event API first-party;
# - Caddy publishes the dashboard on {{ stats_host }}.
#
# The image's ENTRYPOINT is the bare /vince binary (prints help and exits
# with no args), so the container MUST be given the `serve` command.
- name: Pull Vince image
docker_image:
name: "{{ vince_image }}"
@@ -20,8 +25,19 @@
docker_container:
name: "{{ vince_container }}"
image: "{{ vince_image }}"
command: serve
state: started
restart_policy: "unless-stopped"
env:
VINCE_DATA: /data
VINCE_LISTEN: "0.0.0.0:{{ vince_port }}"
# serve (re)creates the admin account from these on every boot —
# the env file is the source of truth, like the PocketBase superuser.
VINCE_ADMIN_NAME: "{{ vince_admin_name }}"
VINCE_ADMIN_PASSWORD: "{{ vince_admin_password }}"
# create the tracked site on startup (CSV list)
VINCE_DOMAINS: "{{ vince_site_domain }}"
VINCE_URL: "https://{{ stats_host }}"
volumes:
- "{{ host_directory }}/vince_data:/data"
networks:
+7 -1
View File
@@ -20,9 +20,15 @@ docker_network: "{{ title }}_net"
docker_image: "{{ registry }}/{{ title }}:{{ image_tag | default(tag) }}"
docker_container: "{{ title }}-staging"
# self-hosted first-party analytics (Vince) — proxied at /stats/* on www host
# self-hosted first-party analytics (Vince) — script/events proxied at
# /stats/* on the www host, dashboard published on stats_host
vince_container: vince
vince_port: 8000
vince_admin_name: admin
# change this before first deploy — it (re)sets the dashboard login
vince_admin_password: "ChangeMe-Vince-2025!"
vince_site_domain: mozimo.in
stats_host: stats.mozimo.in
# caddy publishes www (SSR + /api/* + /_/* -> pocketbase) and cms (admin)