feature/testing #3
@@ -1,4 +1,4 @@
|
|||||||
name: Build Production Images
|
name: Build Production Image
|
||||||
|
|
||||||
on:
|
on:
|
||||||
pull_request_review:
|
pull_request_review:
|
||||||
@@ -6,7 +6,7 @@ on:
|
|||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build Production Images
|
name: Build Production Image
|
||||||
if: github.event.review.state == 'approved' && github.event.pull_request.base.ref == 'main'
|
if: github.event.review.state == 'approved' && github.event.pull_request.base.ref == 'main'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
@@ -18,8 +18,5 @@ jobs:
|
|||||||
- name: Verify Docker CLI
|
- name: Verify Docker CLI
|
||||||
run: docker version
|
run: docker version
|
||||||
|
|
||||||
- name: Build backend image
|
- name: Build all-in-one image
|
||||||
run: docker build -t condado-newsletter-backend:latest -f backend/Dockerfile ./backend
|
run: docker build -t condado-newsletter:latest -f Dockerfile.allinone .
|
||||||
|
|
||||||
- name: Build frontend image
|
|
||||||
run: docker build -t condado-newsletter-frontend:latest -f frontend/Dockerfile ./frontend
|
|
||||||
10
.github/agents/infra.agent.md
vendored
10
.github/agents/infra.agent.md
vendored
@@ -15,14 +15,14 @@ You are a senior DevOps / infrastructure engineer and software architect for the
|
|||||||
| `backend/Dockerfile` | Backend-only multi-stage build image |
|
| `backend/Dockerfile` | Backend-only multi-stage build image |
|
||||||
| `frontend/Dockerfile` | Frontend build + Nginx image |
|
| `frontend/Dockerfile` | Frontend build + Nginx image |
|
||||||
| `docker-compose.yml` | Dev stack (postgres + backend + nginx + mailhog) |
|
| `docker-compose.yml` | Dev stack (postgres + backend + nginx + mailhog) |
|
||||||
| `docker-compose.prod.yml` | Prod stack (postgres + backend + nginx, no mailhog) |
|
| `docker-compose.prod.yml` | Prod stack (single all-in-one image) |
|
||||||
| `nginx/nginx.conf` | Nginx config for multi-container compose flavours |
|
| `nginx/nginx.conf` | Nginx config for multi-container compose flavours |
|
||||||
| `nginx/nginx.allinone.conf` | Nginx config for the all-in-one image (localhost backend) |
|
| `nginx/nginx.allinone.conf` | Nginx config for the all-in-one image (localhost backend) |
|
||||||
| `frontend/nginx.docker.conf` | Nginx config embedded in frontend image |
|
| `frontend/nginx.docker.conf` | Nginx config embedded in frontend image |
|
||||||
| `docker/supervisord.conf` | Supervisor config (manages postgres + java + nginx inside allinone) |
|
| `docker/supervisord.conf` | Supervisor config (manages postgres + java + nginx inside allinone) |
|
||||||
| `docker/entrypoint.sh` | Allinone container entrypoint (DB init, env wiring, supervisord start) |
|
| `docker/entrypoint.sh` | Allinone container entrypoint (DB init, env wiring, supervisord start) |
|
||||||
| `.gitea/workflows/ci.yml` | CI: backend tests + frontend tests on pull requests to `develop` |
|
| `.gitea/workflows/ci.yml` | CI: backend tests + frontend tests on pull requests to `develop` |
|
||||||
| `.gitea/workflows/build.yml` | Build: create local backend/frontend images on approved PRs to `main` |
|
| `.gitea/workflows/build.yml` | Build: create the local all-in-one image on approved PRs to `main` |
|
||||||
| `.env.example` | Template for all environment variables |
|
| `.env.example` | Template for all environment variables |
|
||||||
|
|
||||||
## System Topology
|
## System Topology
|
||||||
@@ -54,7 +54,7 @@ Docker volume → /var/lib/postgresql/data
|
|||||||
| Flavour | Command | Notes |
|
| Flavour | Command | Notes |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| Dev | `docker compose up --build` | Includes Mailhog on :1025/:8025 |
|
| Dev | `docker compose up --build` | Includes Mailhog on :1025/:8025 |
|
||||||
| Prod (compose) | `docker compose -f docker-compose.prod.yml up -d` | External DB/SMTP using prebuilt local images |
|
| Prod (compose) | `docker compose -f docker-compose.prod.yml up -d` | Prebuilt all-in-one image with internal PostgreSQL |
|
||||||
| All-in-one | `docker run -p 80:80 -e APP_PASSWORD=... <image>` | Everything in one container |
|
| All-in-one | `docker run -p 80:80 -e APP_PASSWORD=... <image>` | Everything in one container |
|
||||||
|
|
||||||
## Key Environment Variables
|
## Key Environment Variables
|
||||||
@@ -81,9 +81,9 @@ All injected at runtime — never hardcoded in images.
|
|||||||
| Workflow | Trigger | What it does |
|
| Workflow | Trigger | What it does |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| `ci.yml` | Pull request to `develop` | Backend `./gradlew test` + Frontend `npm run test` |
|
| `ci.yml` | Pull request to `develop` | Backend `./gradlew test` + Frontend `npm run test` |
|
||||||
| `build.yml` | Approved PR review to `main` | Builds `condado-newsletter-backend` and `condado-newsletter-frontend` on the target Docker host |
|
| `build.yml` | Approved PR review to `main` | Builds `condado-newsletter` on the target Docker host |
|
||||||
|
|
||||||
The runner shares the target Docker host, so this workflow produces local images directly on that host. `docker-compose.prod.yml` must reference images and not local build directives.
|
The runner shares the target Docker host, so this workflow produces the local `condado-newsletter` image directly on that host. `docker-compose.prod.yml` must reference that image and not local build directives.
|
||||||
|
|
||||||
## Implementation Rules
|
## Implementation Rules
|
||||||
|
|
||||||
|
|||||||
10
CLAUDE.md
10
CLAUDE.md
@@ -83,7 +83,7 @@ The cycle for every step is:
|
|||||||
| Reverse Proxy | Nginx (serves frontend + proxies `/api` to backend) |
|
| Reverse Proxy | Nginx (serves frontend + proxies `/api` to backend) |
|
||||||
| Dev Mail | Mailhog (SMTP trap + web UI) |
|
| Dev Mail | Mailhog (SMTP trap + web UI) |
|
||||||
| All-in-one image | Single Docker image: Nginx + Spring Boot + PostgreSQL + Supervisor |
|
| All-in-one image | Single Docker image: Nginx + Spring Boot + PostgreSQL + Supervisor |
|
||||||
| Image registry | Local Docker images on the deployment host (`condado-newsletter-backend`, `condado-newsletter-frontend`) |
|
| Image registry | Local Docker image on the deployment host (`condado-newsletter`) |
|
||||||
| CI/CD | Gitea Actions — test PRs to `develop`, deploy approved PRs targeting `main` |
|
| CI/CD | Gitea Actions — test PRs to `develop`, deploy approved PRs targeting `main` |
|
||||||
|
|
||||||
## Deployment Flavours
|
## Deployment Flavours
|
||||||
@@ -93,7 +93,7 @@ There are **three ways to run the project**:
|
|||||||
| Flavour | Command | When to use |
|
| Flavour | Command | When to use |
|
||||||
|---------------------|---------------------------------|------------------------------------------------|
|
|---------------------|---------------------------------|------------------------------------------------|
|
||||||
| **Dev** | `docker compose up` | Local development — includes Mailhog |
|
| **Dev** | `docker compose up` | Local development — includes Mailhog |
|
||||||
| **Prod (compose)** | `docker compose -f docker-compose.prod.yml up -d` | Production with prebuilt backend/frontend images |
|
| **Prod (compose)** | `docker compose -f docker-compose.prod.yml up -d` | Production with the prebuilt all-in-one image |
|
||||||
| **All-in-one** | `docker run ...` | Simplest deploy — everything in one container |
|
| **All-in-one** | `docker run ...` | Simplest deploy — everything in one container |
|
||||||
|
|
||||||
### All-in-one Image
|
### All-in-one Image
|
||||||
@@ -213,7 +213,7 @@ condado-news-letter/ ← repo root
|
|||||||
├── .env.example ← template for all env vars
|
├── .env.example ← template for all env vars
|
||||||
├── .gitignore
|
├── .gitignore
|
||||||
├── docker-compose.yml ← dev stack (Nginx + Backend + PostgreSQL + Mailhog)
|
├── docker-compose.yml ← dev stack (Nginx + Backend + PostgreSQL + Mailhog)
|
||||||
├── docker-compose.prod.yml ← prod stack (Nginx + Backend + PostgreSQL)
|
├── docker-compose.prod.yml ← prod stack (single all-in-one image)
|
||||||
├── Dockerfile.allinone ← all-in-one image (Nginx + Backend + PostgreSQL + Supervisor)
|
├── Dockerfile.allinone ← all-in-one image (Nginx + Backend + PostgreSQL + Supervisor)
|
||||||
│
|
│
|
||||||
├── .github/
|
├── .github/
|
||||||
@@ -575,9 +575,9 @@ Good examples:
|
|||||||
| Workflow file | Trigger | What it does |
|
| Workflow file | Trigger | What it does |
|
||||||
|----------------------------|----------------------------|-----------------------------------------------------------|
|
|----------------------------|----------------------------|-----------------------------------------------------------|
|
||||||
| `.gitea/workflows/ci.yml` | PR to `develop` | Backend tests (`./gradlew test`) + Frontend tests (`npm run test`) |
|
| `.gitea/workflows/ci.yml` | PR to `develop` | Backend tests (`./gradlew test`) + Frontend tests (`npm run test`) |
|
||||||
| `.gitea/workflows/build.yml` | Approved PR review on `main` | Build `condado-newsletter-backend` and `condado-newsletter-frontend` locally on the runner host |
|
| `.gitea/workflows/build.yml` | Approved PR review on `main` | Build `condado-newsletter` locally on the runner host |
|
||||||
|
|
||||||
Build policy: the runner shares the target Docker host, so the build workflow produces local Docker images directly on that host. `docker-compose.prod.yml` is image-based and can be started separately without build directives.
|
Build policy: the runner shares the target Docker host, so the build workflow produces the local `condado-newsletter` image directly on that host. `docker-compose.prod.yml` is image-based and can be started separately without build directives.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ FROM gradle:8-jdk21-alpine AS backend-build
|
|||||||
WORKDIR /app/backend
|
WORKDIR /app/backend
|
||||||
|
|
||||||
COPY backend/build.gradle.kts backend/settings.gradle.kts ./
|
COPY backend/build.gradle.kts backend/settings.gradle.kts ./
|
||||||
|
COPY backend/gradle.properties ./
|
||||||
COPY backend/gradle ./gradle
|
COPY backend/gradle ./gradle
|
||||||
RUN gradle dependencies --no-daemon --quiet || true
|
RUN gradle dependencies --no-daemon --quiet || true
|
||||||
|
|
||||||
|
|||||||
@@ -1,33 +1,10 @@
|
|||||||
services:
|
services:
|
||||||
|
condado-newsletter:
|
||||||
# ── PostgreSQL ───────────────────────────────────────────────────────────────
|
image: condado-newsletter:latest
|
||||||
postgres:
|
container_name: condado-newsletter
|
||||||
image: postgres:16-alpine
|
restart: unless-stopped
|
||||||
restart: always
|
|
||||||
environment:
|
|
||||||
POSTGRES_DB: condado
|
|
||||||
POSTGRES_USER: ${SPRING_DATASOURCE_USERNAME}
|
|
||||||
POSTGRES_PASSWORD: ${SPRING_DATASOURCE_PASSWORD}
|
|
||||||
volumes:
|
|
||||||
- postgres-data:/var/lib/postgresql/data
|
|
||||||
networks:
|
|
||||||
- condado-net
|
|
||||||
healthcheck:
|
|
||||||
test: ["CMD-SHELL", "pg_isready -U ${SPRING_DATASOURCE_USERNAME} -d condado"]
|
|
||||||
interval: 10s
|
|
||||||
timeout: 5s
|
|
||||||
retries: 5
|
|
||||||
|
|
||||||
# ── Backend (Spring Boot) ────────────────────────────────────────────────────
|
|
||||||
backend:
|
|
||||||
image: condado-newsletter-backend:latest
|
|
||||||
restart: always
|
|
||||||
depends_on:
|
|
||||||
postgres:
|
|
||||||
condition: service_healthy
|
|
||||||
environment:
|
environment:
|
||||||
SPRING_PROFILES_ACTIVE: prod
|
SPRING_PROFILES_ACTIVE: prod
|
||||||
SPRING_DATASOURCE_URL: ${SPRING_DATASOURCE_URL}
|
|
||||||
SPRING_DATASOURCE_USERNAME: ${SPRING_DATASOURCE_USERNAME}
|
SPRING_DATASOURCE_USERNAME: ${SPRING_DATASOURCE_USERNAME}
|
||||||
SPRING_DATASOURCE_PASSWORD: ${SPRING_DATASOURCE_PASSWORD}
|
SPRING_DATASOURCE_PASSWORD: ${SPRING_DATASOURCE_PASSWORD}
|
||||||
APP_PASSWORD: ${APP_PASSWORD}
|
APP_PASSWORD: ${APP_PASSWORD}
|
||||||
@@ -48,23 +25,22 @@ services:
|
|||||||
extra_hosts:
|
extra_hosts:
|
||||||
- "celtinha.desktop:host-gateway"
|
- "celtinha.desktop:host-gateway"
|
||||||
- "host.docker.internal:host-gateway"
|
- "host.docker.internal:host-gateway"
|
||||||
networks:
|
volumes:
|
||||||
- condado-net
|
- postgres-data:/var/lib/postgresql/data
|
||||||
|
labels:
|
||||||
# ── Frontend + Nginx ─────────────────────────────────────────────────────────
|
- "traefik.enable=true"
|
||||||
nginx:
|
- "traefik.http.routers.condado.rule=Host(`condado-newsletter.lab`)"
|
||||||
image: condado-newsletter-frontend:latest
|
- "traefik.http.services.condado.loadbalancer.server.port=80"
|
||||||
restart: always
|
- "homepage.group=Hyperlink"
|
||||||
ports:
|
- "homepage.name=Condado Newsletter"
|
||||||
- "80:80"
|
- "homepage.description=Automated newsletter generator using AI"
|
||||||
depends_on:
|
- "homepage.logo=https://raw.githubusercontent.com/celtinha/condado-newsletter/main/docs/logo.png"
|
||||||
- backend
|
- "homepage.url=http://condado-newsletter.lab"
|
||||||
networks:
|
|
||||||
- condado-net
|
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
postgres-data:
|
postgres-data:
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
condado-net:
|
default:
|
||||||
driver: bridge
|
name: traefik
|
||||||
|
external: true
|
||||||
|
|||||||
@@ -1,6 +1,10 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
|
APP_DB_NAME=${APP_DB_NAME:-condado}
|
||||||
|
APP_DB_USER=${SPRING_DATASOURCE_USERNAME:-condado}
|
||||||
|
APP_DB_PASSWORD=${SPRING_DATASOURCE_PASSWORD:-condado}
|
||||||
|
|
||||||
# ── Initialise PostgreSQL data directory on first run ─────────────────────────
|
# ── Initialise PostgreSQL data directory on first run ─────────────────────────
|
||||||
if [ ! -f /var/lib/postgresql/data/PG_VERSION ]; then
|
if [ ! -f /var/lib/postgresql/data/PG_VERSION ]; then
|
||||||
echo "Initialising PostgreSQL data directory..."
|
echo "Initialising PostgreSQL data directory..."
|
||||||
@@ -9,8 +13,8 @@ if [ ! -f /var/lib/postgresql/data/PG_VERSION ]; then
|
|||||||
# Start postgres temporarily to create the app database and user
|
# Start postgres temporarily to create the app database and user
|
||||||
su -c "/usr/lib/postgresql/16/bin/pg_ctl -D /var/lib/postgresql/data -w start" postgres
|
su -c "/usr/lib/postgresql/16/bin/pg_ctl -D /var/lib/postgresql/data -w start" postgres
|
||||||
|
|
||||||
su -c "psql -c \"CREATE USER condado WITH PASSWORD 'condado';\"" postgres
|
su -c "psql -v ON_ERROR_STOP=1 -c \"CREATE USER ${APP_DB_USER} WITH PASSWORD '${APP_DB_PASSWORD}';\"" postgres
|
||||||
su -c "psql -c \"CREATE DATABASE condado OWNER condado;\"" postgres
|
su -c "psql -v ON_ERROR_STOP=1 -c \"CREATE DATABASE ${APP_DB_NAME} OWNER ${APP_DB_USER};\"" postgres
|
||||||
|
|
||||||
su -c "/usr/lib/postgresql/16/bin/pg_ctl -D /var/lib/postgresql/data -w stop" postgres
|
su -c "/usr/lib/postgresql/16/bin/pg_ctl -D /var/lib/postgresql/data -w stop" postgres
|
||||||
echo "PostgreSQL initialised."
|
echo "PostgreSQL initialised."
|
||||||
@@ -20,9 +24,9 @@ fi
|
|||||||
mkdir -p /var/log/supervisor
|
mkdir -p /var/log/supervisor
|
||||||
|
|
||||||
# ── Defaults for all-in-one local PostgreSQL ─────────────────────────────────
|
# ── Defaults for all-in-one local PostgreSQL ─────────────────────────────────
|
||||||
export SPRING_DATASOURCE_URL=${SPRING_DATASOURCE_URL:-jdbc:postgresql://localhost:5432/condado}
|
export SPRING_DATASOURCE_URL=${SPRING_DATASOURCE_URL:-jdbc:postgresql://localhost:5432/${APP_DB_NAME}}
|
||||||
export SPRING_DATASOURCE_USERNAME=${SPRING_DATASOURCE_USERNAME:-condado}
|
export SPRING_DATASOURCE_USERNAME=${SPRING_DATASOURCE_USERNAME:-${APP_DB_USER}}
|
||||||
export SPRING_DATASOURCE_PASSWORD=${SPRING_DATASOURCE_PASSWORD:-condado}
|
export SPRING_DATASOURCE_PASSWORD=${SPRING_DATASOURCE_PASSWORD:-${APP_DB_PASSWORD}}
|
||||||
|
|
||||||
# ── Start all services via supervisord ───────────────────────────────────────
|
# ── Start all services via supervisord ───────────────────────────────────────
|
||||||
exec /usr/bin/supervisord -c /etc/supervisor/conf.d/supervisord.conf
|
exec /usr/bin/supervisord -c /etc/supervisor/conf.d/supervisord.conf
|
||||||
|
|||||||
Reference in New Issue
Block a user