a4fb62c86c
Add a migrator Dockerfile target (drizzle-kit migrate + tier-definitions seed, both idempotent) and wire it as a one-shot compose service that web waits on via service_completed_successfully. No more manual exec step after first deploy — runs safely on every redeploy. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
50 lines
2.1 KiB
Markdown
50 lines
2.1 KiB
Markdown
# Deploy: Portainer (git stack) + external Traefik LXC
|
|
|
|
## Portainer
|
|
|
|
1. Stacks → Add stack → **Repository**
|
|
2. Repository URL: this repo. Reference: branch to track (e.g. `main`)
|
|
3. Compose path: `docker/compose.prod.yml`
|
|
4. Environment variables (Portainer stack env, not committed):
|
|
|
|
```
|
|
POSTGRES_DB=epicure
|
|
POSTGRES_USER=epicure
|
|
POSTGRES_PASSWORD=<generate>
|
|
REDIS_PASSWORD=<generate>
|
|
MINIO_ROOT_USER=<generate>
|
|
MINIO_ROOT_PASSWORD=<generate>
|
|
BETTER_AUTH_SECRET=<openssl rand -base64 32>
|
|
BETTER_AUTH_URL=https://HOST_DOMAIN
|
|
ENCRYPTION_SECRET=<openssl rand -base64 32>
|
|
NEXT_PUBLIC_VAPID_PUBLIC_KEY=<npx web-push generate-vapid-keys>
|
|
VAPID_PRIVATE_KEY=<from same command>
|
|
WEB_PORT=3000
|
|
# optional
|
|
GOOGLE_CLIENT_ID=
|
|
GOOGLE_CLIENT_SECRET=
|
|
OPENROUTER_API_KEY=
|
|
```
|
|
|
|
5. Deploy the stack. Portainer builds `web` from the repo's root `Dockerfile` (see `build:` in compose.prod.yml) — no separate image push needed.
|
|
6. Enable GitOps updates (webhook or polling) on the stack if you want redeploy-on-push.
|
|
|
|
## Migrations + seed
|
|
|
|
Handled automatically. The `migrate` service builds from the `migrator` Dockerfile target,
|
|
runs `drizzle-kit migrate` then the tier-definitions seed, and exits; `web` waits for it to
|
|
complete successfully before starting (`depends_on: migrate: condition: service_completed_successfully`).
|
|
Both are idempotent — safe to re-run on every stack redeploy, not just the first one.
|
|
|
|
## Traefik (separate LXC, file provider)
|
|
|
|
1. Copy `docker/traefik/epicure.yml` into the traefik LXC's dynamic config directory.
|
|
2. Replace `HOST_DOMAIN` with the public hostname and `PORTAINER_LXC_IP` with the portainer LXC's network IP (must match `WEB_PORT` published in compose.prod.yml).
|
|
3. Confirm `certResolver` name matches what's set in traefik's static config.
|
|
4. Traefik picks it up automatically (file provider watches for changes) — no restart needed.
|
|
|
|
## Notes
|
|
|
|
- `web` connects to `postgres`/`redis`/`minio` over the compose-internal network; only `web`'s port is published to the LXC host for traefik to reach.
|
|
- `apps/web/next.config.ts` has `output: "standalone"` — required for the Dockerfile's slim runtime stage.
|