Skip to content

feat: opt-in basic auth, noindex and PHP memory limit for FrankenPHP - #49

Merged
hussainweb merged 1 commit into
mainfrom
feat/frankenphp-opt-in-env
Sep 30, 2026
Merged

hussainweb merged 1 commit into
mainfrom
feat/frankenphp-opt-in-env

Conversation

@hussainweb

Copy link
Copy Markdown
Owner

Closes #43

Adds three opt-in, environment-driven features to the frankenphp-trixie variant (all off or unchanged by default):

  • Basic auth on every path except /robots.txt, from BASIC_AUTH_USER plus BASIC_AUTH_PASSWORD or BASIC_AUTH_HASH. A new docker-drupal-entrypoint hashes the password with frankenphp hash-password (stdin), fails closed when basic auth is requested without credentials, unsets the plaintext, then execs docker-php-entrypoint.
  • Noindex via NOINDEX_SNIPPET: X-Robots-Tag on every response (401 included) and a disallow-all robots.txt.
  • PHP_MEMORY_LIMIT for the web server (default 128M, PHP's built-in default; CLI stays -1).

The optional NOINDEX=true switch is intentionally not implemented; the snippet variable is enough.

Tests: new CI steps for the FrankenPHP variant on both arches (defaults unchanged, opt-in run, fail-closed) via tests/verify-frankenphp-optin.sh. README documents the variables, the fail-closed rule and the note for downstream entrypoints.

Add environment-driven, off-by-default features to the frankenphp-trixie
variant: basic auth (password hashed by a new docker-drupal-entrypoint,
failing closed when credentials are missing), noindex headers and
robots.txt via snippets, and PHP_MEMORY_LIMIT for the web server.
Includes README docs and CI tests on both architectures.
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 16 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 62fe6754-ebe9-4ecb-9bda-c1ddecb66626

📥 Commits

Reviewing files that changed from the base of the PR and between 008c8aa and 54078c3.

📒 Files selected for processing (11)
  • .github/workflows/docker-buildx.yml
  • README.md
  • php8/frankenphp-trixie/Caddyfile
  • php8/frankenphp-trixie/Dockerfile
  • php8/frankenphp-trixie/basic-auth/disabled.caddy
  • php8/frankenphp-trixie/basic-auth/enabled.caddy
  • php8/frankenphp-trixie/docker-drupal-entrypoint
  • php8/frankenphp-trixie/noindex/disabled.caddy
  • php8/frankenphp-trixie/noindex/enabled.caddy
  • tests/docker-compose.frankenphp-optin.yml
  • tests/verify-frankenphp-optin.sh

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hussainweb
hussainweb merged commit 5ee158a into main Sep 30, 2026
20 checks passed
@hussainweb
hussainweb deleted the feat/frankenphp-opt-in-env branch September 30, 2026 04:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

FrankenPHP: opt-in basic auth, noindex and PHP memory limit from environment variables

1 participant