This commit is contained in:
@@ -29,6 +29,11 @@ Seed sample articles: `npm run seed` in `backend/`.
|
|||||||
Environment: `backend/.env` (`PORT=5000`, `MONGO_URI=mongodb://127.0.0.1:27017/mathew`,
|
Environment: `backend/.env` (`PORT=5000`, `MONGO_URI=mongodb://127.0.0.1:27017/mathew`,
|
||||||
`JWT_SECRET` — signs session tokens, `AUTH_TOKEN_TTL` — how long one lasts, default `7d`;
|
`JWT_SECRET` — signs session tokens, `AUTH_TOKEN_TTL` — how long one lasts, default `7d`;
|
||||||
see `.env.example`). Without `JWT_SECRET` the API warns and uses an insecure dev key.
|
see `.env.example`). Without `JWT_SECRET` the API warns and uses an insecure dev key.
|
||||||
|
Production (`docker-compose.yml`) runs MongoDB as its own `mongo` service (volume `mongo-data`)
|
||||||
|
and passes the backend a `MONGO_URI` by service name; `JWT_SECRET` interpolates from
|
||||||
|
`/var/www/app/.env` on the deploy host (create it once — the public site must not sign sessions
|
||||||
|
with the dev key). The stack's nginx resolves `backend`/`frontend` through Docker's DNS per
|
||||||
|
request, so container recreates cannot leave it on a stale IP.
|
||||||
Frontend API URL comes from `NUXT_PUBLIC_API_BASE`
|
Frontend API URL comes from `NUXT_PUBLIC_API_BASE`
|
||||||
(default `http://localhost:5000`, read via `runtimeConfig.public.apiBase`). The frontend image
|
(default `http://localhost:5000`, read via `runtimeConfig.public.apiBase`). The frontend image
|
||||||
builds it empty: the browser then calls `/api` on its own origin, which nginx routes to
|
builds it empty: the browser then calls `/api` on its own origin, which nginx routes to
|
||||||
|
|||||||
@@ -23,6 +23,12 @@ services:
|
|||||||
# 127.0.0.1 is itself — with the default URI the API crashed on connect
|
# 127.0.0.1 is itself — with the default URI the API crashed on connect
|
||||||
# and nginx answered 502. Mongo is a service of this stack now.
|
# and nginx answered 502. Mongo is a service of this stack now.
|
||||||
MONGO_URI: mongodb://mongo:27017/mathew
|
MONGO_URI: mongodb://mongo:27017/mathew
|
||||||
|
# Interpolated from /var/www/app/.env on the deploy host (never
|
||||||
|
# committed, never overwritten by the pipeline's scp). Create it once:
|
||||||
|
# echo "JWT_SECRET=$(openssl rand -hex 32)" >> /var/www/app/.env
|
||||||
|
# Left unset, the backend falls back to the dev key in the repo —
|
||||||
|
# anyone could then forge sessions against the public site.
|
||||||
|
JWT_SECRET: ${JWT_SECRET:-}
|
||||||
depends_on:
|
depends_on:
|
||||||
mongo:
|
mongo:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
|
|||||||
Reference in New Issue
Block a user