TL;DR: A 502 Bad Gateway from Pangolin means the proxy can reach the network boundary, but nothing is successfully answering on the target IP and port. Hugo is either crashing on startup, failing to bind properly due to permissions or missing files, or Pangolin is pointed at the wrong internal port (e.g., expecting 80 instead of 1313). Here is how you dig into this crawl and squash the bug: * Check the Container Runtime Status & Logs: * Run docker ps -a --filter name=blog to verify the container is actually Up and not stuck in a restart loop. * Inspect the container logs: docker logs blog --tail 50 * Watch out for: Hugo building errors, missing themes, or permissions errors (especially since you forced user: "1000:1000" over the bind-mounted /src). * Verify Pangolin's Target Port: * Hugo is serving on port 1313, but most reverse proxy site definitions default to 80. * Check your Pangolin resource config or dashboard for word.ptrwd.com. * Ensure the upstream destination is explicitly set to http://blog:1313 (or the container's IP on port 1313), not http://blog:80. * Test Network Reachability from Inside the Network: * Spawn a temporary curl container on the pangolin network to see if the webserver actually responds to HTTP requests: docker run --rm --network pangolin curlimages/curl -Iv http://blog:1313 * If curl returns Connection refused, Hugo is not listening on 0.0.0.0:1313. * If it resolves and returns HTTP/2 200 or HTTP/1.1 200, the issue lies strictly inside Pangolin's upstream routing or SSL offloading rules. * Check Pangolin Reverse Proxy Logs: * Check the logs of your Pangolin container to see what IP and port it is attempting to hit when throwing the 502: docker logs --tail 50 * Look for connection timeouts, DNS resolution failures for blog, or connection resets.