From 325394150d5583bc2deb58099a9f2c266138eeb4 Mon Sep 17 00:00:00 2001 From: Aran Roig Date: Fri, 2 Oct 2026 00:07:03 +0200 Subject: [PATCH] Point production at the LAN MongoDB (192.168.1.7:27017) Production uses the network's database server instead of a mongo service inside the stack (the compose-managed one never served the API). Dev is unchanged: backend/.env keeps localhost:27017. - docker-compose.yml: MONGO_URI=mongodb://192.168.1.7:27017/mathew; drop the in-stack mongo service, its volume and the healthcheck gate - deploy.yml: up -d --remove-orphans so yesterday's mongo container is retired when the new compose lands --- .gitea/workflows/deploy.yml | 2 +- AGENTS.md | 5 +++-- docker-compose.yml | 26 ++++---------------------- 3 files changed, 8 insertions(+), 25 deletions(-) diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index 0458afd..7d0ef16 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -50,6 +50,6 @@ jobs: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login git.aranroig.com -u "${{ secrets.REGISTRY_USER }}" --password-stdin cd /var/www/app/ docker compose pull - docker compose up -d + docker compose up -d --remove-orphans EOF diff --git a/AGENTS.md b/AGENTS.md index 2c7905c..9bd3095 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -29,8 +29,9 @@ Seed sample articles: `npm run seed` in `backend/`. Environment: `backend/.env` (`PORT=5000`, `MONGO_URI=mongodb://127.0.0.1:27017/mathew`, `JWT_SECRET` — signs session tokens, `AUTH_TOKEN_TTL` — how long one lasts, default `7d`; see `.env.example`). Without `JWT_SECRET` the API warns and uses an insecure dev key. -Production (`docker-compose.yml`) runs MongoDB as its own `mongo` service (volume `mongo-data`) -and passes the backend a `MONGO_URI` by service name; `JWT_SECRET` interpolates from +Production (`docker-compose.yml`) points the backend at the LAN MongoDB server +(`MONGO_URI=mongodb://192.168.1.7:27017/mathew`; development keeps `localhost:27017` via +`backend/.env`); `JWT_SECRET` interpolates from `/var/www/app/.env` on the deploy host (create it once — the public site must not sign sessions with the dev key). The stack's nginx resolves `backend`/`frontend` through Docker's DNS per request, so container recreates cannot leave it on a stale IP. diff --git a/docker-compose.yml b/docker-compose.yml index ded6632..2776ab6 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -19,32 +19,14 @@ services: backend: image: git.aranroig.com/syndria98/mathew-backend:latest environment: - # The image carries no .env (it is gitignored), and a container's - # 127.0.0.1 is itself — with the default URI the API crashed on connect - # and nginx answered 502. Mongo is a service of this stack now. - MONGO_URI: mongodb://mongo:27017/mathew + # Production MongoDB — the LAN database server, not a container of this + # stack and not the container's own 127.0.0.1 (where nothing listens). + # Development keeps localhost:27017 via backend/.env. + MONGO_URI: mongodb://192.168.1.7:27017/mathew # Interpolated from /var/www/app/.env on the deploy host (never # committed, never overwritten by the pipeline's scp). Create it once: # echo "JWT_SECRET=$(openssl rand -hex 32)" >> /var/www/app/.env # Left unset, the backend falls back to the dev key in the repo — # anyone could then forge sessions against the public site. JWT_SECRET: ${JWT_SECRET:-} - depends_on: - mongo: - condition: service_healthy restart: always - - mongo: - image: mongo:7 - volumes: - - mongo-data:/data/db - healthcheck: - test: ["CMD", "mongosh", "--quiet", "--eval", "db.adminCommand('ping')"] - interval: 10s - timeout: 5s - retries: 5 - start_period: 20s - restart: always - -volumes: - mongo-data: