diff --git a/.env.example b/.env.example index 63b7162..bfc3cd8 100644 --- a/.env.example +++ b/.env.example @@ -14,3 +14,8 @@ JWT_SECRET=replace-this-with-a-long-random-secret-before-deploying BOOTSTRAP_ADMIN_EMAIL=admin@example.com BOOTSTRAP_ADMIN_PASSWORD=change-this-password BOOTSTRAP_ADMIN_NAME=Compor HUB Admin + +# Docker Swarm / Portainer image tags. The defaults are the Gitea Container Registry images. +API_IMAGE=gitea.blyzer.com.br/blyzer/compor-academy-api +WEB_IMAGE=gitea.blyzer.com.br/blyzer/compor-academy-web +IMAGE_TAG=latest diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8615fc4..c37730f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -7,6 +7,7 @@ on: permissions: contents: read + packages: write jobs: validate: @@ -20,3 +21,21 @@ jobs: - run: npm ci --include=dev - run: npm run typecheck - run: npm run build + + publish-images: + name: Build and publish Docker images + needs: validate + if: gitea.event_name == 'push' && gitea.ref == 'refs/heads/main' + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - name: Sign in to the Gitea Container Registry + run: echo "${{ secrets.GITEA_TOKEN }}" | docker login gitea.blyzer.com.br -u "${{ gitea.actor }}" --password-stdin + - name: Build and publish API + run: | + docker build --pull -f Dockerfile.api -t gitea.blyzer.com.br/blyzer/compor-academy-api:latest . + docker push gitea.blyzer.com.br/blyzer/compor-academy-api:latest + - name: Build and publish web + run: | + docker build --pull -f Dockerfile.web -t gitea.blyzer.com.br/blyzer/compor-academy-web:latest . + docker push gitea.blyzer.com.br/blyzer/compor-academy-web:latest diff --git a/PORTAINER.md b/PORTAINER.md index 15bdd8f..8152fa9 100644 --- a/PORTAINER.md +++ b/PORTAINER.md @@ -2,6 +2,8 @@ Use `docker-compose.yml` as a Portainer Stack from this repository. It deploys the frontend, API, and PostgreSQL as one internal Docker network. Only the web container exposes a port; it proxies `/api` to the API container. +This is a Docker Swarm stack: Portainer pulls prebuilt API and web images from the Gitea Container Registry. It never builds Dockerfiles itself. + ## Required Portainer environment variables - `POSTGRES_PASSWORD`: a long, unique database password. Avoid characters that are not URL-safe because it is used in `DATABASE_URL`. @@ -13,12 +15,16 @@ Optional variables: - `POSTGRES_DB` (default `compor_hub`) - `POSTGRES_USER` (default `compor`) - `WEB_PORT` (default `8080`) +- `IMAGE_TAG` (default `latest`; set a specific release tag when available) +- `API_IMAGE` and `WEB_IMAGE` only if the Gitea registry namespace differs from the defaults. ## Before publishing -1. Deploy the stack with a temporary `WEB_PORT` and verify `/api/v1/health` through the public domain. -2. Create the production administrator using the API container's console and `npm run db:bootstrap-admin`, with the `BOOTSTRAP_ADMIN_*` variables supplied only for that one command. -3. Place the web service behind HTTPS, normally through your existing reverse proxy (Traefik, Nginx Proxy Manager, or Cloudflare Tunnel), and set `FRONTEND_ORIGIN` to that HTTPS address. -4. Back up the `compor_postgres_data` volume before updates. +1. Push to `main` and wait for Gitea Actions to publish `gitea.blyzer.com.br/blyzer/compor-academy-api:latest` and `gitea.blyzer.com.br/blyzer/compor-academy-web:latest`. +2. Ensure the Portainer endpoint can pull from the Gitea Container Registry. If the images are private, add Gitea registry credentials to the endpoint/stack deployment configuration. +3. Deploy the stack with a temporary `WEB_PORT` and verify `/api/v1/health` through the public domain. +4. Create the production administrator using the API container's console and `npm run db:bootstrap-admin`, with the `BOOTSTRAP_ADMIN_*` variables supplied only for that one command. +5. Place the web service behind HTTPS, normally through your existing reverse proxy (Traefik, Nginx Proxy Manager, or Cloudflare Tunnel), and set `FRONTEND_ORIGIN` to that HTTPS address. +6. Back up the `compor_postgres_data` volume before updates. Do not expose port 5432 or port 3001 publicly. diff --git a/docker-compose.yml b/docker-compose.yml index 5ed6b07..98b2da7 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,7 +1,6 @@ services: postgres: image: postgres:16-alpine - restart: unless-stopped environment: POSTGRES_DB: ${POSTGRES_DB:-compor_hub} POSTGRES_USER: ${POSTGRES_USER:-compor} @@ -13,30 +12,32 @@ services: interval: 10s timeout: 5s retries: 10 + deploy: + replicas: 1 + restart_policy: + condition: any api: - build: - context: . - dockerfile: Dockerfile.api - restart: unless-stopped + image: ${API_IMAGE:-gitea.blyzer.com.br/blyzer/compor-academy-api}:${IMAGE_TAG:-latest} environment: APP_ENV: production API_PORT: 3001 FRONTEND_ORIGIN: ${FRONTEND_ORIGIN:?Set the public https URL in Portainer} DATABASE_URL: postgresql://${POSTGRES_USER:-compor}:${POSTGRES_PASSWORD}@postgres:5432/${POSTGRES_DB:-compor_hub} JWT_SECRET: ${JWT_SECRET:?Set a long random JWT_SECRET in Portainer} - depends_on: - - postgres + deploy: + replicas: 1 + restart_policy: + condition: any web: - build: - context: . - dockerfile: Dockerfile.web - restart: unless-stopped + image: ${WEB_IMAGE:-gitea.blyzer.com.br/blyzer/compor-academy-web}:${IMAGE_TAG:-latest} ports: - "${WEB_PORT:-8080}:80" - depends_on: - - api + deploy: + replicas: 1 + restart_policy: + condition: any volumes: compor_postgres_data: