- Debian-based api image (bookworm-slim), docker/debian mirrors, prisma binaryTargets for openssl 3.0 - nginx: admin SPA under /admin, TLS via acme.sh (ZeroSSL) + auto-renewal cron, http->https redirect - prisma: add origin_goods.delisted migration, sync missing schema (good_image/tag_font_color/good_tags), fix users.createdAt Timestamptz - api: CORS wildcard reflection, helmet CORP cross-origin, price backfill in persistProductDetail, categoryIcon ancestor fallback, mediaByColor per-color gallery in public goods detail - admin: /admin base path (vite + router) - import-data.mjs: udt_name casting, serial sequence advance fix
57 lines
1.3 KiB
YAML
57 lines
1.3 KiB
YAML
services:
|
|
postgres:
|
|
image: postgres:16-alpine
|
|
restart: unless-stopped
|
|
environment:
|
|
POSTGRES_USER: inkreach
|
|
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
|
POSTGRES_DB: inkreach
|
|
volumes:
|
|
- pgdata:/var/lib/postgresql/data
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U inkreach -d inkreach"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 10
|
|
# No ports exposed: only reachable from the compose network
|
|
|
|
api:
|
|
build:
|
|
context: ..
|
|
dockerfile: deploy/api.Dockerfile
|
|
restart: unless-stopped
|
|
depends_on:
|
|
postgres:
|
|
condition: service_healthy
|
|
environment:
|
|
NODE_ENV: production
|
|
PORT: 3001
|
|
DATABASE_URL: postgresql://inkreach:${POSTGRES_PASSWORD}@postgres:5432/inkreach
|
|
JWT_SECRET: ${JWT_SECRET}
|
|
CORS_ORIGINS: "*"
|
|
volumes:
|
|
- uploads:/app/uploads
|
|
|
|
admin:
|
|
build:
|
|
context: ..
|
|
dockerfile: deploy/admin.Dockerfile
|
|
args:
|
|
VITE_API_BASE: /api
|
|
restart: unless-stopped
|
|
depends_on:
|
|
- api
|
|
ports:
|
|
- "80:80"
|
|
- "443:443"
|
|
volumes:
|
|
- ./nginx/admin.conf:/etc/nginx/conf.d/default.conf:ro
|
|
- ./certbot/www:/var/www/certbot:ro
|
|
- ./certbot/acme:/etc/nginx/certs:ro
|
|
extra_hosts:
|
|
- "host.docker.internal:host-gateway"
|
|
|
|
volumes:
|
|
pgdata:
|
|
uploads:
|