src/lib/dev-login-config.ts — startup assertion: throws if NODE_ENV=production + ENABLE_DEV_LOGIN=true, scoped to runtime (skipped during next build).
Container
scripts/migrate.mjs — runs Drizzle migrations against DATABASE_URL.
deploy/docker-entrypoint.sh — runs migrations then exec node server.js. Skip with RUN_MIGRATIONS=false.
Dockerfile — copies drizzle/, scripts/migrate.mjs, entrypoint into runner stage; ENTRYPOINT now points at the script.
Compose
deploy/compose.yaml — famapp now image: ${FAMAPP_IMAGE:-ghcr.io/ginnoir/famapp:latest} (build still works locally as fallback). Authentik pinned via AUTHENTIK_IMAGE_TAG (default 2024.12.3). New RUN_MIGRATIONS env passed through.
.env.production.example — documents FAMAPP_IMAGE, AUTHENTIK_IMAGE_TAG, RUN_MIGRATIONS.
CI/CD
.github/workflows/ci.yml — push/PR: typecheck + lint + format:check + build.
.github/workflows/release.yml — v* tag: build + push ghcr.io/ginnoir/famapp:vX.Y.Z, :X.Y, :latest to GHCR.
Docs
deploy/README.md — full deploy/rollback/release runbook.
CHANGELOG.md — release log seeded with an Unreleased entry.
docs/tasks/09-pre-deploy-checklist.md — task 09 reframed from one-shot removal to a recurring pre-deploy checklist.
STATUS.md — updated.
Verified: pnpm typecheck, pnpm format, pnpm build, and docker compose config all clean.
51 lines
2.1 KiB
Bash
51 lines
2.1 KiB
Bash
# ── famapp ────────────────────────────────────────────────────────────────────
|
|
|
|
# Image tag to deploy. Pin to a specific version after first deploy
|
|
# (e.g. ghcr.io/ginnoir/famapp:v0.1.0). `latest` is fine for staging/initial.
|
|
FAMAPP_IMAGE=ghcr.io/ginnoir/famapp:latest
|
|
# `always` pulls on every `up`; set `missing` if you want to skip pulls.
|
|
FAMAPP_PULL_POLICY=always
|
|
# Authentik image tag. Bump in lockstep with Authentik release notes.
|
|
AUTHENTIK_IMAGE_TAG=2024.12.3
|
|
# Run drizzle migrations on container start. Leave true.
|
|
RUN_MIGRATIONS=true
|
|
|
|
# Public URL for the app (used in share links, OIDC redirect URIs, etc.)
|
|
NEXT_PUBLIC_APP_URL=https://fam.ginnoir.com
|
|
|
|
# famapp Postgres credentials (used to build DATABASE_URL inside compose.yaml)
|
|
FAMAPP_DB_USER=famapp
|
|
FAMAPP_DB_PASSWORD=replace-with-strong-password
|
|
FAMAPP_DB_NAME=famapp
|
|
|
|
# Auth.js session secret — generate with: openssl rand -base64 32
|
|
AUTH_SECRET=replace-with-openssl-rand-base64-32
|
|
|
|
# OIDC provider (Authentik) — task 06 will fill these in after bootstrapping
|
|
AUTH_OIDC_ISSUER=https://auth.ginnoir.com/application/o/famapp/
|
|
AUTH_OIDC_CLIENT_ID=replace-me
|
|
AUTH_OIDC_CLIENT_SECRET=replace-me
|
|
|
|
# Web Push VAPID keys — generate with: pnpm vapid:generate
|
|
VAPID_PUBLIC_KEY=
|
|
VAPID_PRIVATE_KEY=
|
|
# Must be "mailto:<address>" or a URL
|
|
VAPID_SUBJECT=mailto:you@example.com
|
|
|
|
# ntfy (optional push fallback — leave blank to disable)
|
|
NTFY_URL=
|
|
NTFY_TOPIC=
|
|
|
|
# Log level: error | warn | info | debug
|
|
LOG_LEVEL=info
|
|
|
|
# ── Authentik ─────────────────────────────────────────────────────────────────
|
|
|
|
# Authentik Postgres credentials (separate DB per Matt's rule)
|
|
AUTHENTIK_DB_USER=authentik
|
|
AUTHENTIK_DB_PASSWORD=replace-with-strong-password
|
|
AUTHENTIK_DB_NAME=authentik
|
|
|
|
# Authentik secret key — generate with: openssl rand -base64 60
|
|
AUTHENTIK_SECRET_KEY=replace-with-openssl-rand-base64-60
|