Showstopper. Adding, editing or deleting a dish redirected to /ruoat, which stopped existing when the tab was renamed to Ruuat — every one of those actions ended on a 404. Live in v20260905-4. The tests missed it because they asserted only a 303; a redirect to a dead URL is still a 303. They now assert the target. The page no longer jumps. Deleting a dish partway down the catalog, or opening a day in Kirjaa, sent the browser to the top. Both now patch in place via Datastar — bin, pencil, day rows, dish pills, save, delete, cancel and Näytä lisää. Links stay links and forms stay forms, so it works without JavaScript. Non-production tabs are labelled. ENV=dev gives dev · Foodster. Contributing guide added, and commits now take Conventional Commit types. ⚠️ Breaking: rewrite the server's .env in this deploy. Environment variables lost the FOODSTER_ prefix; the app refuses to start on an unset PASSWORD. REPO=… TAG=latest PASSWORD=… HOST=foodster.kessinen.com ENV=prod PUID=1000 PGID=1000 TZ=Europe/Helsinki PUID/PGID rather than UID/GID — UID is read-only in bash and would be silently overwritten. Co-authored-by: Esa Kataja <[email protected]> Reviewed-on: #3
39 lines
1.3 KiB
YAML
39 lines
1.3 KiB
YAML
services:
|
|
app:
|
|
image: ${REPO:?set REPO in .env}:${TAG:-latest}
|
|
restart: unless-stopped
|
|
|
|
# A bind mount rather than a named volume: the database sits in ./data on
|
|
# the host, where it can be listed, copied and backed up without going
|
|
# through the container engine. The image runs as UID 65534, so the
|
|
# container has to be told which host user owns that directory.
|
|
#
|
|
# PUID/PGID rather than UID/GID: UID is a read-only variable in bash, so a
|
|
# value set here would be silently replaced by the invoking shell's own.
|
|
user: "${PUID:-1000}:${PGID:-1000}"
|
|
volumes:
|
|
- ./data:/data
|
|
|
|
environment:
|
|
PASSWORD: ${PASSWORD:?set PASSWORD in .env}
|
|
DB: /data/foodster.db
|
|
ENV: ${ENV:-prod}
|
|
TZ: ${TZ:-Europe/Helsinki}
|
|
|
|
# No published ports: Traefik reaches the container over the shared
|
|
# network. Publishing 8080 as well would put an unencrypted copy of the
|
|
# app on the host, bypassing TLS.
|
|
labels:
|
|
- traefik.enable=true
|
|
- traefik.http.routers.foodster.entrypoints=websecure
|
|
- traefik.http.routers.foodster.rule=Host(`${HOST:?set HOST in .env}`)
|
|
- traefik.http.routers.foodster.tls=true
|
|
- traefik.http.services.foodster.loadbalancer.server.port=8080
|
|
- traefik.docker.network=traefik
|
|
networks:
|
|
- traefik
|
|
|
|
networks:
|
|
traefik:
|
|
external: true
|