version: "3.9" services: nginx: image: nginx:latest ports: - "3000:80" volumes: - ./nginx.conf:/etc/nginx/nginx.conf:ro depends_on: - frontend - backend restart: always frontend: image: git.aranroig.com/syndria98/mathew-frontend:latest restart: always backend: image: git.aranroig.com/syndria98/mathew-backend:latest environment: # Production MongoDB — the LAN database server, not a container of this # stack and not the container's own 127.0.0.1 (where nothing listens). # Development keeps localhost:27017 via backend/.env. MONGO_URI: mongodb://192.168.1.7:27017/mathew # Interpolated from /var/www/app/.env on the deploy host (never # committed, never overwritten by the pipeline's scp). Create it once: # echo "JWT_SECRET=$(openssl rand -hex 32)" >> /var/www/app/.env # Left unset, the backend falls back to the dev key in the repo — # anyone could then forge sessions against the public site. JWT_SECRET: ${JWT_SECRET:-} restart: always