diff --git a/docker-compose.yml b/docker-compose.yml index a1fcb82..dc6d981 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -19,23 +19,25 @@ services: backend: image: git.aranroig.com/syndria98/mathew-backend:latest environment: - PORT: 5000 - # The image carries no .env, so without this the backend would try - # 127.0.0.1 inside its own container and crash-loop — nginx then - # answers every /api/ request with 502. + # The image carries no .env (it is gitignored), and a container's + # 127.0.0.1 is itself — with the default URI the API crashed on connect + # and nginx answered 502. Mongo is a service of this stack now. MONGO_URI: mongodb://mongo:27017/mathew - # Put JWT_SECRET (and AUTH_TOKEN_TTL if you like) in a .env file next - # to this compose file on the server; compose reads it from there. - JWT_SECRET: ${JWT_SECRET:-} - AUTH_TOKEN_TTL: ${AUTH_TOKEN_TTL:-7d} depends_on: - - mongo + mongo: + condition: service_healthy restart: always mongo: image: mongo:7 volumes: - mongo-data:/data/db + healthcheck: + test: ["CMD", "mongosh", "--quiet", "--eval", "db.adminCommand('ping')"] + interval: 10s + timeout: 5s + retries: 5 + start_period: 20s restart: always volumes: diff --git a/nginx.conf b/nginx.conf index 825bde7..969813c 100644 --- a/nginx.conf +++ b/nginx.conf @@ -1,26 +1,20 @@ events {} http { - # Docker's built-in DNS. With the upstreams below held in variables, - # nginx re-resolves the service names at request time instead of caching - # the address from startup — so a recreated container (new IP) does not - # leave nginx proxying to a stale address (502). + # Docker's embedded DNS: resolve service names per request (cached 10s). + # nginx would otherwise resolve them once at startup and keep proxying to + # a recreated container's old IP — a 502 until nginx itself is reloaded. resolver 127.0.0.11 valid=10s ipv6=off; - # "Connection: upgrade" only for real upgrade requests, not every one. - map $http_upgrade $connection_upgrade { - default upgrade; - '' close; - } - server { listen 80; server_name _; - # Api Requests - location /api/ { - set $api_upstream http://backend:5000; - proxy_pass $api_upstream; + # Api Requests ("/api" without a trailing slash must land here too, + # or it falls through to the frontend and loops through its SSR proxy) + location /api { + set $api_upstream backend:5000; + proxy_pass http://$api_upstream; proxy_http_version 1.1; proxy_set_header Host $host; @@ -28,13 +22,13 @@ http { proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection $connection_upgrade; + proxy_set_header Connection "upgrade"; } # Normal requests location / { - set $frontend_upstream http://frontend:3000; - proxy_pass $frontend_upstream; + set $frontend_upstream frontend:3000; + proxy_pass http://$frontend_upstream; proxy_http_version 1.1; proxy_set_header Host $host; @@ -42,7 +36,7 @@ http { proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection $connection_upgrade; + proxy_set_header Connection "upgrade"; } }