2.9 KiB
2.9 KiB
Portainer deployment
Use docker-compose.yml as a Portainer Stack from this repository. It deploys the frontend, API, and PostgreSQL as one internal Docker network. Only the web container exposes a port; it proxies /api to the API container.
This is a Docker Swarm stack: Portainer pulls prebuilt API and web images from the Gitea Container Registry. It never builds Dockerfiles itself.
Gitea Actions registry secrets
Create these repository-level Action secrets in Gitea before pushing to main:
REGISTRY_USERNAME: the Gitea username that owns a package-write token.REGISTRY_TOKEN: a Gitea personal access token for that user with package read/write permission.
The built-in Actions job token can be disabled or lack registry scope on self-hosted Gitea instances, so the image publishing job intentionally uses these explicit secrets.
Required Portainer environment variables
POSTGRES_PASSWORD: a long, unique database password. Avoid characters that are not URL-safe because it is used inDATABASE_URL.JWT_SECRET: a unique random string of at least 32 characters.FRONTEND_ORIGIN: the exact public application URL, for examplehttps://hub.example.com.SUPERADMIN_EMAIL: email address for the initial platform administrator.SUPERADMIN_PASSWORD: password for that administrator (at least 12 characters).AUTH_RATE_LIMIT_MAXandAUTH_RATE_LIMIT_WINDOW_SECONDSare optional login and public-auth throttling controls (defaults: 10 attempts per 900 seconds per source IP).
Optional variables:
POSTGRES_DB(defaultcompor_hub)POSTGRES_USER(defaultcompor)WEB_PORT(default8080)IMAGE_TAG(defaultlatest; set a specific release tag when available)API_IMAGEandWEB_IMAGEonly if the Gitea registry namespace differs from the defaults.
Before publishing
- Push to
mainand wait for Gitea Actions to publishgitea.blyzer.com.br/blyzer/compor-academy-api:latestandgitea.blyzer.com.br/blyzer/compor-academy-web:latest. - Ensure the Portainer endpoint can pull from the Gitea Container Registry. If the images are private, add Gitea registry credentials to the endpoint/stack deployment configuration.
- Deploy the stack with a temporary
WEB_PORTand verify/api/v1/healththrough the public domain. A healthy response is{"status":"ok","database":"connected"}; Portainer also runs this check automatically for the API service. - Set
SUPERADMIN_EMAIL,SUPERADMIN_PASSWORD, and optionallySUPERADMIN_NAME. The API creates or updates this superadmin automatically when it starts. Keep these values in Portainer only; changing the password and redeploying resets that account's password. - Place the web service behind HTTPS, normally through your existing reverse proxy (Traefik, Nginx Proxy Manager, or Cloudflare Tunnel), and set
FRONTEND_ORIGINto that HTTPS address. - Back up the
compor_postgres_datavolume before updates.
Do not expose port 5432 or port 3001 publicly.