Fix staging port binding + diagnostic ps env file
Two bugs in the staging-environments rollout: 1. Staging containers published on 127.0.0.1 are unreachable from the production Caddy container, which connects via the Docker bridge IP (host.docker.internal:host-gateway resolves to the bridge, not loopback). Bind to 0.0.0.0 instead — Hetzner Cloud firewall blocks ports 3000+ from the public internet, so it stays internal-only. 2. The trailing 'docker compose ps' diagnostic in deploy-staging / deploy-preview was missing --env-file staging.env, so compose failed env interpolation and the job exited non-zero even when the actual deploy succeeded. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
parent
7615ecb6e7
commit
25d21161c5
2 changed files with 10 additions and 4 deletions
4
.github/workflows/cd-staging.yml
vendored
4
.github/workflows/cd-staging.yml
vendored
|
|
@ -165,7 +165,7 @@ jobs:
|
|||
# via cd-infra) are live. Idempotent.
|
||||
docker compose exec -T caddy caddy reload --config /etc/caddy/Caddyfile || true
|
||||
|
||||
docker compose -f docker-compose.staging.yml -p trails-staging ps
|
||||
docker compose -f docker-compose.staging.yml -p trails-staging --env-file staging.env --profile persistent ps
|
||||
|
||||
# ── PR preview deploy ────────────────────────────────────────────────
|
||||
deploy-preview:
|
||||
|
|
@ -303,7 +303,7 @@ jobs:
|
|||
# Reload Caddy to pick up the per-PR snippet (writes/replaces it from the SCP step)
|
||||
docker compose exec -T caddy caddy reload --config /etc/caddy/Caddyfile
|
||||
|
||||
docker compose -f docker-compose.staging.yml -p "$PROJECT" ps
|
||||
docker compose -f docker-compose.staging.yml -p "$PROJECT" --env-file staging.env ps
|
||||
|
||||
- name: Comment preview URL on PR
|
||||
uses: peter-evans/create-or-update-comment@v4
|
||||
|
|
|
|||
|
|
@ -31,8 +31,13 @@ services:
|
|||
journal:
|
||||
image: ghcr.io/trails-cool/journal:${JOURNAL_IMAGE_TAG:-latest}
|
||||
restart: unless-stopped
|
||||
# Published on 0.0.0.0 (not 127.0.0.1) so the production Caddy container
|
||||
# can reach it via host.docker.internal — Docker's host-gateway resolves
|
||||
# to the bridge IP, not loopback. The Hetzner Cloud firewall blocks all
|
||||
# inbound on ports 3000+ from the public internet, so this is effectively
|
||||
# internal-only despite the bind address.
|
||||
ports:
|
||||
- "127.0.0.1:${JOURNAL_HOST_PORT:?JOURNAL_HOST_PORT must be set}:3000"
|
||||
- "${JOURNAL_HOST_PORT:?JOURNAL_HOST_PORT must be set}:3000"
|
||||
networks:
|
||||
- trails-shared
|
||||
environment:
|
||||
|
|
@ -72,8 +77,9 @@ services:
|
|||
# planner.staging.trails.cool. Saves ~256MB per active preview.
|
||||
profiles: ["persistent"]
|
||||
restart: unless-stopped
|
||||
# Same rationale as the journal port — see the comment there.
|
||||
ports:
|
||||
- "127.0.0.1:${PLANNER_HOST_PORT:-3101}:3001"
|
||||
- "${PLANNER_HOST_PORT:-3101}:3001"
|
||||
networks:
|
||||
- trails-shared
|
||||
environment:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue