feat(deploy): dockerize web app for portainer git-stack deploy behind external traefik

Add root Dockerfile (standalone Next output, multi-stage pnpm build), drop
in-stack caddy in favor of publishing web's port for an external traefik
LXC (file-provider dynamic config included), and document the portainer
deploy flow.

Also fixes issues that blocked any production build: a bad auth-client
type cast, the ai SDK's mimeType->mediaType rename, an implicit-any
callback param, and push.ts eagerly calling webpush.setVapidDetails at
module import time (which crashed page-data collection whenever VAPID
env vars weren't present at build) — now lazily configured on first send.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Arnaud
2026-07-01 16:20:34 +02:00
parent 8b57a3fd87
commit 4a90ad910c
12 changed files with 174 additions and 29 deletions
+51
View File
@@ -0,0 +1,51 @@
# Deploy: Portainer (git stack) + external Traefik LXC
## Portainer
1. Stacks → Add stack → **Repository**
2. Repository URL: this repo. Reference: branch to track (e.g. `main`)
3. Compose path: `docker/compose.prod.yml`
4. Environment variables (Portainer stack env, not committed):
```
POSTGRES_DB=epicure
POSTGRES_USER=epicure
POSTGRES_PASSWORD=<generate>
REDIS_PASSWORD=<generate>
MINIO_ROOT_USER=<generate>
MINIO_ROOT_PASSWORD=<generate>
BETTER_AUTH_SECRET=<openssl rand -base64 32>
BETTER_AUTH_URL=https://HOST_DOMAIN
ENCRYPTION_SECRET=<openssl rand -base64 32>
NEXT_PUBLIC_VAPID_PUBLIC_KEY=<npx web-push generate-vapid-keys>
VAPID_PRIVATE_KEY=<from same command>
WEB_PORT=3000
# optional
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
OPENROUTER_API_KEY=
```
5. Deploy the stack. Portainer builds `web` from the repo's root `Dockerfile` (see `build:` in compose.prod.yml) — no separate image push needed.
6. Enable GitOps updates (webhook or polling) on the stack if you want redeploy-on-push.
## First deploy: run migrations + seed
Compose does not auto-migrate. After the stack is up, exec into the `web` container once (or run a one-off container against the same network) with `DATABASE_URL` set, then:
```bash
pnpm db:migrate
pnpm db:seed # tier definitions — first deploy only
```
## Traefik (separate LXC, file provider)
1. Copy `docker/traefik/epicure.yml` into the traefik LXC's dynamic config directory.
2. Replace `HOST_DOMAIN` with the public hostname and `PORTAINER_LXC_IP` with the portainer LXC's network IP (must match `WEB_PORT` published in compose.prod.yml).
3. Confirm `certResolver` name matches what's set in traefik's static config.
4. Traefik picks it up automatically (file provider watches for changes) — no restart needed.
## Notes
- `web` connects to `postgres`/`redis`/`minio` over the compose-internal network; only `web`'s port is published to the LXC host for traefik to reach.
- `apps/web/next.config.ts` has `output: "standalone"` — required for the Dockerfile's slim runtime stage.