Point production at the LAN MongoDB (192.168.1.7:27017)
All checks were successful
Build and Deploy Nuxt / build (push) Successful in 8s

Production uses the network's database server instead of a mongo service
inside the stack (the compose-managed one never served the API). Dev is
unchanged: backend/.env keeps localhost:27017.

- docker-compose.yml: MONGO_URI=mongodb://192.168.1.7:27017/mathew; drop
  the in-stack mongo service, its volume and the healthcheck gate
- deploy.yml: up -d --remove-orphans so yesterday's mongo container is
  retired when the new compose lands
This commit is contained in:
2026-10-02 00:07:03 +02:00
parent 5a7537f449
commit 325394150d
3 changed files with 8 additions and 25 deletions

View File

@@ -50,6 +50,6 @@ jobs:
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login git.aranroig.com -u "${{ secrets.REGISTRY_USER }}" --password-stdin
cd /var/www/app/
docker compose pull
docker compose up -d
docker compose up -d --remove-orphans
EOF

View File

@@ -29,8 +29,9 @@ Seed sample articles: `npm run seed` in `backend/`.
Environment: `backend/.env` (`PORT=5000`, `MONGO_URI=mongodb://127.0.0.1:27017/mathew`,
`JWT_SECRET` — signs session tokens, `AUTH_TOKEN_TTL` — how long one lasts, default `7d`;
see `.env.example`). Without `JWT_SECRET` the API warns and uses an insecure dev key.
Production (`docker-compose.yml`) runs MongoDB as its own `mongo` service (volume `mongo-data`)
and passes the backend a `MONGO_URI` by service name; `JWT_SECRET` interpolates from
Production (`docker-compose.yml`) points the backend at the LAN MongoDB server
(`MONGO_URI=mongodb://192.168.1.7:27017/mathew`; development keeps `localhost:27017` via
`backend/.env`); `JWT_SECRET` interpolates from
`/var/www/app/.env` on the deploy host (create it once — the public site must not sign sessions
with the dev key). The stack's nginx resolves `backend`/`frontend` through Docker's DNS per
request, so container recreates cannot leave it on a stale IP.

View File

@@ -19,32 +19,14 @@ services:
backend:
image: git.aranroig.com/syndria98/mathew-backend:latest
environment:
# The image carries no .env (it is gitignored), and a container's
# 127.0.0.1 is itself — with the default URI the API crashed on connect
# and nginx answered 502. Mongo is a service of this stack now.
MONGO_URI: mongodb://mongo:27017/mathew
# Production MongoDB — the LAN database server, not a container of this
# stack and not the container's own 127.0.0.1 (where nothing listens).
# Development keeps localhost:27017 via backend/.env.
MONGO_URI: mongodb://192.168.1.7:27017/mathew
# Interpolated from /var/www/app/.env on the deploy host (never
# committed, never overwritten by the pipeline's scp). Create it once:
# echo "JWT_SECRET=$(openssl rand -hex 32)" >> /var/www/app/.env
# Left unset, the backend falls back to the dev key in the repo —
# anyone could then forge sessions against the public site.
JWT_SECRET: ${JWT_SECRET:-}
depends_on:
mongo:
condition: service_healthy
restart: always
mongo:
image: mongo:7
volumes:
- mongo-data:/data/db
healthcheck:
test: ["CMD", "mongosh", "--quiet", "--eval", "db.adminCommand('ping')"]
interval: 10s
timeout: 5s
retries: 5
start_period: 20s
restart: always
volumes:
mongo-data: