Point production at the LAN MongoDB (192.168.1.7:27017)
All checks were successful
Build and Deploy Nuxt / build (push) Successful in 8s
All checks were successful
Build and Deploy Nuxt / build (push) Successful in 8s
Production uses the network's database server instead of a mongo service inside the stack (the compose-managed one never served the API). Dev is unchanged: backend/.env keeps localhost:27017. - docker-compose.yml: MONGO_URI=mongodb://192.168.1.7:27017/mathew; drop the in-stack mongo service, its volume and the healthcheck gate - deploy.yml: up -d --remove-orphans so yesterday's mongo container is retired when the new compose lands
This commit is contained in:
@@ -50,6 +50,6 @@ jobs:
|
|||||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login git.aranroig.com -u "${{ secrets.REGISTRY_USER }}" --password-stdin
|
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login git.aranroig.com -u "${{ secrets.REGISTRY_USER }}" --password-stdin
|
||||||
cd /var/www/app/
|
cd /var/www/app/
|
||||||
docker compose pull
|
docker compose pull
|
||||||
docker compose up -d
|
docker compose up -d --remove-orphans
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
|
|||||||
@@ -29,8 +29,9 @@ Seed sample articles: `npm run seed` in `backend/`.
|
|||||||
Environment: `backend/.env` (`PORT=5000`, `MONGO_URI=mongodb://127.0.0.1:27017/mathew`,
|
Environment: `backend/.env` (`PORT=5000`, `MONGO_URI=mongodb://127.0.0.1:27017/mathew`,
|
||||||
`JWT_SECRET` — signs session tokens, `AUTH_TOKEN_TTL` — how long one lasts, default `7d`;
|
`JWT_SECRET` — signs session tokens, `AUTH_TOKEN_TTL` — how long one lasts, default `7d`;
|
||||||
see `.env.example`). Without `JWT_SECRET` the API warns and uses an insecure dev key.
|
see `.env.example`). Without `JWT_SECRET` the API warns and uses an insecure dev key.
|
||||||
Production (`docker-compose.yml`) runs MongoDB as its own `mongo` service (volume `mongo-data`)
|
Production (`docker-compose.yml`) points the backend at the LAN MongoDB server
|
||||||
and passes the backend a `MONGO_URI` by service name; `JWT_SECRET` interpolates from
|
(`MONGO_URI=mongodb://192.168.1.7:27017/mathew`; development keeps `localhost:27017` via
|
||||||
|
`backend/.env`); `JWT_SECRET` interpolates from
|
||||||
`/var/www/app/.env` on the deploy host (create it once — the public site must not sign sessions
|
`/var/www/app/.env` on the deploy host (create it once — the public site must not sign sessions
|
||||||
with the dev key). The stack's nginx resolves `backend`/`frontend` through Docker's DNS per
|
with the dev key). The stack's nginx resolves `backend`/`frontend` through Docker's DNS per
|
||||||
request, so container recreates cannot leave it on a stale IP.
|
request, so container recreates cannot leave it on a stale IP.
|
||||||
|
|||||||
@@ -19,32 +19,14 @@ services:
|
|||||||
backend:
|
backend:
|
||||||
image: git.aranroig.com/syndria98/mathew-backend:latest
|
image: git.aranroig.com/syndria98/mathew-backend:latest
|
||||||
environment:
|
environment:
|
||||||
# The image carries no .env (it is gitignored), and a container's
|
# Production MongoDB — the LAN database server, not a container of this
|
||||||
# 127.0.0.1 is itself — with the default URI the API crashed on connect
|
# stack and not the container's own 127.0.0.1 (where nothing listens).
|
||||||
# and nginx answered 502. Mongo is a service of this stack now.
|
# Development keeps localhost:27017 via backend/.env.
|
||||||
MONGO_URI: mongodb://mongo:27017/mathew
|
MONGO_URI: mongodb://192.168.1.7:27017/mathew
|
||||||
# Interpolated from /var/www/app/.env on the deploy host (never
|
# Interpolated from /var/www/app/.env on the deploy host (never
|
||||||
# committed, never overwritten by the pipeline's scp). Create it once:
|
# committed, never overwritten by the pipeline's scp). Create it once:
|
||||||
# echo "JWT_SECRET=$(openssl rand -hex 32)" >> /var/www/app/.env
|
# echo "JWT_SECRET=$(openssl rand -hex 32)" >> /var/www/app/.env
|
||||||
# Left unset, the backend falls back to the dev key in the repo —
|
# Left unset, the backend falls back to the dev key in the repo —
|
||||||
# anyone could then forge sessions against the public site.
|
# anyone could then forge sessions against the public site.
|
||||||
JWT_SECRET: ${JWT_SECRET:-}
|
JWT_SECRET: ${JWT_SECRET:-}
|
||||||
depends_on:
|
|
||||||
mongo:
|
|
||||||
condition: service_healthy
|
|
||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
mongo:
|
|
||||||
image: mongo:7
|
|
||||||
volumes:
|
|
||||||
- mongo-data:/data/db
|
|
||||||
healthcheck:
|
|
||||||
test: ["CMD", "mongosh", "--quiet", "--eval", "db.adminCommand('ping')"]
|
|
||||||
interval: 10s
|
|
||||||
timeout: 5s
|
|
||||||
retries: 5
|
|
||||||
start_period: 20s
|
|
||||||
restart: always
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
mongo-data:
|
|
||||||
|
|||||||
Reference in New Issue
Block a user