51 lines
1.4 KiB
YAML
51 lines
1.4 KiB
YAML
version: "3.9"
|
|
|
|
services:
|
|
nginx:
|
|
image: nginx:latest
|
|
ports:
|
|
- "3000:80"
|
|
volumes:
|
|
- ./nginx.conf:/etc/nginx/nginx.conf:ro
|
|
depends_on:
|
|
- frontend
|
|
- backend
|
|
restart: always
|
|
|
|
frontend:
|
|
image: git.aranroig.com/syndria98/mathew-frontend:latest
|
|
restart: always
|
|
|
|
backend:
|
|
image: git.aranroig.com/syndria98/mathew-backend:latest
|
|
environment:
|
|
# The image carries no .env (it is gitignored), and a container's
|
|
# 127.0.0.1 is itself — with the default URI the API crashed on connect
|
|
# and nginx answered 502. Mongo is a service of this stack now.
|
|
MONGO_URI: mongodb://mongo:27017/mathew
|
|
# Interpolated from /var/www/app/.env on the deploy host (never
|
|
# committed, never overwritten by the pipeline's scp). Create it once:
|
|
# echo "JWT_SECRET=$(openssl rand -hex 32)" >> /var/www/app/.env
|
|
# Left unset, the backend falls back to the dev key in the repo —
|
|
# anyone could then forge sessions against the public site.
|
|
JWT_SECRET: ${JWT_SECRET:-}
|
|
depends_on:
|
|
mongo:
|
|
condition: service_healthy
|
|
restart: always
|
|
|
|
mongo:
|
|
image: mongo:7
|
|
volumes:
|
|
- mongo-data:/data/db
|
|
healthcheck:
|
|
test: ["CMD", "mongosh", "--quiet", "--eval", "db.adminCommand('ping')"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
start_period: 20s
|
|
restart: always
|
|
|
|
volumes:
|
|
mongo-data:
|