diff --git a/docker-compose.yml b/docker-compose.yml index 898a00d..a1fcb82 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -18,4 +18,25 @@ services: backend: image: git.aranroig.com/syndria98/mathew-backend:latest + environment: + PORT: 5000 + # The image carries no .env, so without this the backend would try + # 127.0.0.1 inside its own container and crash-loop — nginx then + # answers every /api/ request with 502. + MONGO_URI: mongodb://mongo:27017/mathew + # Put JWT_SECRET (and AUTH_TOKEN_TTL if you like) in a .env file next + # to this compose file on the server; compose reads it from there. + JWT_SECRET: ${JWT_SECRET:-} + AUTH_TOKEN_TTL: ${AUTH_TOKEN_TTL:-7d} + depends_on: + - mongo restart: always + + mongo: + image: mongo:7 + volumes: + - mongo-data:/data/db + restart: always + +volumes: + mongo-data: diff --git a/nginx.conf b/nginx.conf index 507bd5c..825bde7 100644 --- a/nginx.conf +++ b/nginx.conf @@ -1,35 +1,49 @@ events {} http { + # Docker's built-in DNS. With the upstreams below held in variables, + # nginx re-resolves the service names at request time instead of caching + # the address from startup — so a recreated container (new IP) does not + # leave nginx proxying to a stale address (502). + resolver 127.0.0.11 valid=10s ipv6=off; + + # "Connection: upgrade" only for real upgrade requests, not every one. + map $http_upgrade $connection_upgrade { + default upgrade; + '' close; + } + server { listen 80; server_name _; # Api Requests location /api/ { - proxy_pass http://backend:5000; - + set $api_upstream http://backend:5000; + proxy_pass $api_upstream; + proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; + proxy_set_header Connection $connection_upgrade; } # Normal requests location / { - proxy_pass http://frontend:3000; - + set $frontend_upstream http://frontend:3000; + proxy_pass $frontend_upstream; + proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; + proxy_set_header Connection $connection_upgrade; } - + } }