2.5 KiB
2.5 KiB
Portainer deployment
Use docker-compose.yml as a Portainer Stack from this repository. It deploys the frontend, API, and PostgreSQL as one internal Docker network. Only the web container exposes a port; it proxies /api to the API container.
This is a Docker Swarm stack: Portainer pulls prebuilt API and web images from the Gitea Container Registry. It never builds Dockerfiles itself.
Gitea Actions registry secrets
Create these repository-level Action secrets in Gitea before pushing to main:
REGISTRY_USERNAME: the Gitea username that owns a package-write token.REGISTRY_TOKEN: a Gitea personal access token for that user with package read/write permission.
The built-in Actions job token can be disabled or lack registry scope on self-hosted Gitea instances, so the image publishing job intentionally uses these explicit secrets.
Required Portainer environment variables
POSTGRES_PASSWORD: a long, unique database password. Avoid characters that are not URL-safe because it is used inDATABASE_URL.JWT_SECRET: a unique random string of at least 32 characters.FRONTEND_ORIGIN: the exact public application URL, for examplehttps://hub.example.com.
Optional variables:
POSTGRES_DB(defaultcompor_hub)POSTGRES_USER(defaultcompor)WEB_PORT(default8080)IMAGE_TAG(defaultlatest; set a specific release tag when available)API_IMAGEandWEB_IMAGEonly if the Gitea registry namespace differs from the defaults.
Before publishing
- Push to
mainand wait for Gitea Actions to publishgitea.blyzer.com.br/blyzer/compor-academy-api:latestandgitea.blyzer.com.br/blyzer/compor-academy-web:latest. - Ensure the Portainer endpoint can pull from the Gitea Container Registry. If the images are private, add Gitea registry credentials to the endpoint/stack deployment configuration.
- Deploy the stack with a temporary
WEB_PORTand verify/api/v1/healththrough the public domain. A healthy response is{"status":"ok","database":"connected"}; Portainer also runs this check automatically for the API service. - Create the production administrator using the API container's console and
npm run db:bootstrap-admin, with theBOOTSTRAP_ADMIN_*variables supplied only for that one command. - Place the web service behind HTTPS, normally through your existing reverse proxy (Traefik, Nginx Proxy Manager, or Cloudflare Tunnel), and set
FRONTEND_ORIGINto that HTTPS address. - Back up the
compor_postgres_datavolume before updates.
Do not expose port 5432 or port 3001 publicly.