Compare commits
2
Commits
21bd070dc1
...
7432a9af05
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7432a9af05 | ||
|
|
3bb4d5aa65 |
@@ -0,0 +1,24 @@
|
|||||||
|
# dependencies
|
||||||
|
node_modules
|
||||||
|
|
||||||
|
# build outputs / caches
|
||||||
|
.next
|
||||||
|
dist
|
||||||
|
coverage
|
||||||
|
.vinext
|
||||||
|
.wrangler
|
||||||
|
|
||||||
|
# local data / misc
|
||||||
|
.data
|
||||||
|
.DS_Store
|
||||||
|
|
||||||
|
# secrets & env files
|
||||||
|
.env
|
||||||
|
.env.*
|
||||||
|
|
||||||
|
# logs
|
||||||
|
npm-debug.log*
|
||||||
|
|
||||||
|
# git / tooling
|
||||||
|
.git
|
||||||
|
.vercel
|
||||||
+5
-1
@@ -6,6 +6,10 @@ NEXT_PUBLIC_AUTH_MODE=demo
|
|||||||
|
|
||||||
# --- Storage (MinIO via docker compose) -------------------------------------
|
# --- Storage (MinIO via docker compose) -------------------------------------
|
||||||
# Leave DATABASE_URL empty to run with an in-memory store instead of Postgres.
|
# Leave DATABASE_URL empty to run with an in-memory store instead of Postgres.
|
||||||
|
# docker-compose.yml keeps MinIO internal-only (no published ports/domain) and
|
||||||
|
# all uploads flow through the API, so the API uses the internal endpoint.
|
||||||
|
# When running the API on the host instead of inside compose, re-add MinIO's
|
||||||
|
# host ports (9000/9001) to docker-compose.yml first.
|
||||||
DATABASE_URL=postgres://altdock:altdock@localhost:5432/altdock
|
DATABASE_URL=postgres://altdock:altdock@localhost:5432/altdock
|
||||||
STORAGE_MODE=s3
|
STORAGE_MODE=s3
|
||||||
S3_ENDPOINT=http://localhost:9000
|
S3_ENDPOINT=http://localhost:9000
|
||||||
@@ -17,7 +21,7 @@ S3_FORCE_PATH_STYLE=true
|
|||||||
# MinIO root credentials, consumed by docker-compose.yml. CHANGE in production.
|
# MinIO root credentials, consumed by docker-compose.yml. CHANGE in production.
|
||||||
MINIO_ROOT_USER=minioadmin
|
MINIO_ROOT_USER=minioadmin
|
||||||
MINIO_ROOT_PASSWORD=minioadmin123
|
MINIO_ROOT_PASSWORD=minioadmin123
|
||||||
# Only needed when MinIO is behind a reverse proxy / domain (e.g. on Coolify):
|
# Only needed when MinIO is exposed behind a reverse proxy / domain:
|
||||||
MINIO_SERVER_URL=
|
MINIO_SERVER_URL=
|
||||||
MINIO_BROWSER_REDIRECT_URL=
|
MINIO_BROWSER_REDIRECT_URL=
|
||||||
|
|
||||||
|
|||||||
+16
@@ -0,0 +1,16 @@
|
|||||||
|
FROM node:22-bookworm
|
||||||
|
|
||||||
|
WORKDIR /workspace
|
||||||
|
|
||||||
|
# package-lock.json is committed, so npm ci installs the exact dependency tree.
|
||||||
|
COPY package.json package-lock.json ./
|
||||||
|
|
||||||
|
RUN npm ci --no-audit --no-fund
|
||||||
|
|
||||||
|
COPY . .
|
||||||
|
|
||||||
|
# vinext/wrangler writes logs and registry state under .wrangler; the directory
|
||||||
|
# itself is git/dockerignored, so create it explicitly.
|
||||||
|
RUN mkdir -p /workspace/.wrangler
|
||||||
|
|
||||||
|
CMD ["npm", "run", "dev"]
|
||||||
@@ -180,7 +180,7 @@ export async function createServer() {
|
|||||||
const upload = await runtime.store.getUpload(uploadId);
|
const upload = await runtime.store.getUpload(uploadId);
|
||||||
if (!upload || upload.objectKey !== key) return reply.code(404).send({ error: "UPLOAD_NOT_FOUND" });
|
if (!upload || upload.objectKey !== key) return reply.code(404).send({ error: "UPLOAD_NOT_FOUND" });
|
||||||
const body = request.body as NodeJS.ReadableStream;
|
const body = request.body as NodeJS.ReadableStream;
|
||||||
const receivedSize = await runtime.storage.writeUploadFromStream(key, body);
|
const receivedSize = await runtime.storage.writeUploadFromStream(key, body, upload.expectedSize);
|
||||||
if (receivedSize !== upload.expectedSize) return reply.code(400).send({ error: "UPLOAD_SIZE_MISMATCH", expectedSize: upload.expectedSize, receivedSize });
|
if (receivedSize !== upload.expectedSize) return reply.code(400).send({ error: "UPLOAD_SIZE_MISMATCH", expectedSize: upload.expectedSize, receivedSize });
|
||||||
await runtime.store.updateUpload(upload.id, { receivedSize, status: "uploaded" });
|
await runtime.store.updateUpload(upload.id, { receivedSize, status: "uploaded" });
|
||||||
return { ok: true, receivedSize };
|
return { ok: true, receivedSize };
|
||||||
|
|||||||
@@ -27,7 +27,7 @@ export type UploadPlan =
|
|||||||
export interface StorageAdapter {
|
export interface StorageAdapter {
|
||||||
createUploadPlan(key: string, contentType: string, sizeBytes: number): Promise<UploadPlan>;
|
createUploadPlan(key: string, contentType: string, sizeBytes: number): Promise<UploadPlan>;
|
||||||
completeMultipartUpload(key: string, uploadId: string | undefined, parts: Array<{ partNumber: number; etag: string }> | undefined): Promise<void>;
|
completeMultipartUpload(key: string, uploadId: string | undefined, parts: Array<{ partNumber: number; etag: string }> | undefined): Promise<void>;
|
||||||
writeUploadFromStream(key: string, stream: NodeJS.ReadableStream): Promise<number>;
|
writeUploadFromStream(key: string, stream: NodeJS.ReadableStream, sizeBytes?: number): Promise<number>;
|
||||||
writeObject(key: string, body: Buffer, contentType: string): Promise<void>;
|
writeObject(key: string, body: Buffer, contentType: string): Promise<void>;
|
||||||
writeStream(key: string, transform: NodeJS.ReadWriteStream, contentType: string, sizeBytes: number, source: NodeJS.ReadableStream): Promise<void>;
|
writeStream(key: string, transform: NodeJS.ReadWriteStream, contentType: string, sizeBytes: number, source: NodeJS.ReadableStream): Promise<void>;
|
||||||
downloadToFile(key: string, filePath: string): Promise<void>;
|
downloadToFile(key: string, filePath: string): Promise<void>;
|
||||||
@@ -66,7 +66,8 @@ export class LocalStorage implements StorageAdapter {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
async writeUploadFromStream(key: string, stream: NodeJS.ReadableStream) {
|
// eslint-disable-next-line @typescript-eslint/no-unused-vars -- sizeBytes is only needed by S3.
|
||||||
|
async writeUploadFromStream(key: string, stream: NodeJS.ReadableStream, sizeBytes?: number) {
|
||||||
const filePath = this.pathFor(key);
|
const filePath = this.pathFor(key);
|
||||||
await mkdir(dirname(filePath), { recursive: true });
|
await mkdir(dirname(filePath), { recursive: true });
|
||||||
await pipeline(stream, createWriteStream(filePath, { flags: "w" }));
|
await pipeline(stream, createWriteStream(filePath, { flags: "w" }));
|
||||||
@@ -158,8 +159,11 @@ export class S3Storage implements StorageAdapter {
|
|||||||
await this.client.send(new CompleteMultipartUploadCommand({ Bucket: this.appConfig.S3_BUCKET, Key: key, UploadId: uploadId, MultipartUpload: { Parts: parts.sort((a, b) => a.partNumber - b.partNumber).map((part) => ({ PartNumber: part.partNumber, ETag: part.etag })) } }));
|
await this.client.send(new CompleteMultipartUploadCommand({ Bucket: this.appConfig.S3_BUCKET, Key: key, UploadId: uploadId, MultipartUpload: { Parts: parts.sort((a, b) => a.partNumber - b.partNumber).map((part) => ({ PartNumber: part.partNumber, ETag: part.etag })) } }));
|
||||||
}
|
}
|
||||||
|
|
||||||
async writeUploadFromStream(key: string, stream: NodeJS.ReadableStream) {
|
async writeUploadFromStream(key: string, stream: NodeJS.ReadableStream, sizeBytes?: number) {
|
||||||
await this.client.send(new PutObjectCommand({ Bucket: this.appConfig.S3_BUCKET, Key: key, Body: stream as any }));
|
// ContentLength must be provided for streaming bodies, otherwise the SDK's
|
||||||
|
// flexible-checksums middleware sends `x-amz-decoded-content-length:
|
||||||
|
// undefined` and the upload fails with ERR_HTTP_INVALID_HEADER_VALUE.
|
||||||
|
await this.client.send(new PutObjectCommand({ Bucket: this.appConfig.S3_BUCKET, Key: key, Body: stream as any, ContentLength: sizeBytes }));
|
||||||
const metadata = await this.headObject(key);
|
const metadata = await this.headObject(key);
|
||||||
return metadata?.sizeBytes || 0;
|
return metadata?.sizeBytes || 0;
|
||||||
}
|
}
|
||||||
@@ -169,7 +173,7 @@ export class S3Storage implements StorageAdapter {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async writeStream(key: string, transform: NodeJS.ReadWriteStream, contentType: string, sizeBytes: number, source: NodeJS.ReadableStream) {
|
async writeStream(key: string, transform: NodeJS.ReadWriteStream, contentType: string, sizeBytes: number, source: NodeJS.ReadableStream) {
|
||||||
const upload = this.client.send(new PutObjectCommand({ Bucket: this.appConfig.S3_BUCKET, Key: key, Body: transform as any, ContentType: contentType, ContentLength: sizeBytes || undefined }));
|
const upload = this.client.send(new PutObjectCommand({ Bucket: this.appConfig.S3_BUCKET, Key: key, Body: transform as any, ContentType: contentType, ContentLength: sizeBytes }));
|
||||||
await pipeline(source, transform);
|
await pipeline(source, transform);
|
||||||
await upload;
|
await upload;
|
||||||
}
|
}
|
||||||
|
|||||||
+38
-52
@@ -3,14 +3,24 @@
|
|||||||
# Environment Variables / secrets panel.
|
# Environment Variables / secrets panel.
|
||||||
#
|
#
|
||||||
# Coolify notes:
|
# Coolify notes:
|
||||||
# - All credentials are parameterized; set them in Coolify's env to avoid
|
# - web/api/worker are all built from the same root Dockerfile and run from
|
||||||
# the insecure local defaults.
|
# the image contents. There are no bind mounts, so nothing depends on
|
||||||
# - MinIO has a real healthcheck, so api/worker wait until it can serve.
|
# Coolify mounting the git repository at /workspace (relative paths are
|
||||||
# - The API also creates the S3 bucket itself on startup (ensureBucket),
|
# mounted as empty named volumes there).
|
||||||
# so the stack no longer depends on minio-init completing successfully.
|
# - node_modules is baked into the image once by `npm ci` at build time, so
|
||||||
# - If you expose MinIO through a domain, set MINIO_SERVER_URL (public S3 API
|
# the containers never race each other running npm install.
|
||||||
# origin) and MINIO_BROWSER_REDIRECT_URL (public console origin) so
|
# - MinIO is fully private: uploads always flow through the API (browser ->
|
||||||
# presigned upload URLs and console redirects work from the browser.
|
# API -> MinIO) and the API creates its bucket on startup, so no
|
||||||
|
# minio-init container and no published MinIO ports/domain are required.
|
||||||
|
# - postgres published port exists only for local development; on Coolify,
|
||||||
|
# public traffic goes through its reverse proxy and MinIO stays internal.
|
||||||
|
|
||||||
|
x-altdock-app: &altdock-app
|
||||||
|
build:
|
||||||
|
context: .
|
||||||
|
dockerfile: Dockerfile
|
||||||
|
working_dir: /workspace
|
||||||
|
restart: unless-stopped
|
||||||
|
|
||||||
services:
|
services:
|
||||||
postgres:
|
postgres:
|
||||||
@@ -35,12 +45,11 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
MINIO_ROOT_USER: ${MINIO_ROOT_USER:-minioadmin}
|
MINIO_ROOT_USER: ${MINIO_ROOT_USER:-minioadmin}
|
||||||
MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-minioadmin123}
|
MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-minioadmin123}
|
||||||
# Public origins, only needed when MinIO is behind a reverse proxy/domain.
|
# Internal-only: the API reaches MinIO over the compose network and uploads
|
||||||
MINIO_SERVER_URL: ${MINIO_SERVER_URL:-}
|
# are proxied through the API, so no host ports / public domain are needed.
|
||||||
MINIO_BROWSER_REDIRECT_URL: ${MINIO_BROWSER_REDIRECT_URL:-}
|
expose:
|
||||||
ports:
|
- "9000"
|
||||||
- "9000:9000"
|
- "9001"
|
||||||
- "9001:9001"
|
|
||||||
volumes:
|
volumes:
|
||||||
- minio-data:/data
|
- minio-data:/data
|
||||||
healthcheck:
|
healthcheck:
|
||||||
@@ -50,35 +59,16 @@ services:
|
|||||||
retries: 12
|
retries: 12
|
||||||
start_period: 10s
|
start_period: 10s
|
||||||
|
|
||||||
# Optional belt-and-suspenders: pre-creates the bucket. The API does the
|
|
||||||
# same on startup, so this can be removed without affecting functionality.
|
|
||||||
minio-init:
|
|
||||||
image: minio/mc:latest
|
|
||||||
depends_on:
|
|
||||||
minio:
|
|
||||||
condition: service_healthy
|
|
||||||
entrypoint: ["/bin/sh", "-c"]
|
|
||||||
command: >-
|
|
||||||
"until mc alias set local http://minio:9000 ${MINIO_ROOT_USER:-minioadmin} ${MINIO_ROOT_PASSWORD:-minioadmin123}; do sleep 1; done;
|
|
||||||
mc mb --ignore-existing local/${S3_BUCKET:-altdock}"
|
|
||||||
environment:
|
|
||||||
MINIO_ROOT_USER: ${MINIO_ROOT_USER:-minioadmin}
|
|
||||||
MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-minioadmin123}
|
|
||||||
|
|
||||||
api:
|
api:
|
||||||
image: node:22-bookworm
|
<<: *altdock-app
|
||||||
working_dir: /workspace
|
command: sh -c "npm run db:migrate && exec npm run dev:api"
|
||||||
command: sh -c "npm install --no-audit --no-fund && npm run dev:api"
|
|
||||||
environment:
|
environment:
|
||||||
NODE_ENV: development
|
|
||||||
PORT: 4000
|
PORT: 4000
|
||||||
PUBLIC_BASE_URL: ${PUBLIC_BASE_URL:-http://localhost:4000}
|
|
||||||
WEB_ORIGIN: ${WEB_ORIGIN:-http://localhost:3000}
|
|
||||||
DATABASE_URL: postgres://${POSTGRES_USER:-altdock}:${POSTGRES_PASSWORD:-altdock}@postgres:5432/${POSTGRES_DB:-altdock}
|
DATABASE_URL: postgres://${POSTGRES_USER:-altdock}:${POSTGRES_PASSWORD:-altdock}@postgres:5432/${POSTGRES_DB:-altdock}
|
||||||
STORAGE_MODE: s3
|
STORAGE_MODE: s3
|
||||||
# S3_ENDPOINT is the internal address; presigned URLs resolve via the
|
# Internal address only; uploads are proxied through the API, so MinIO
|
||||||
# public MINIO_SERVER_URL when set.
|
# never needs a public URL.
|
||||||
S3_ENDPOINT: ${S3_ENDPOINT:-http://minio:9000}
|
S3_ENDPOINT: http://minio:9000
|
||||||
S3_REGION: ${S3_REGION:-us-east-1}
|
S3_REGION: ${S3_REGION:-us-east-1}
|
||||||
S3_BUCKET: ${S3_BUCKET:-altdock}
|
S3_BUCKET: ${S3_BUCKET:-altdock}
|
||||||
S3_ACCESS_KEY_ID: ${MINIO_ROOT_USER:-minioadmin}
|
S3_ACCESS_KEY_ID: ${MINIO_ROOT_USER:-minioadmin}
|
||||||
@@ -86,10 +76,10 @@ services:
|
|||||||
S3_FORCE_PATH_STYLE: "true"
|
S3_FORCE_PATH_STYLE: "true"
|
||||||
AUTH_MODE: ${AUTH_MODE:-demo}
|
AUTH_MODE: ${AUTH_MODE:-demo}
|
||||||
PROCESS_INLINE: "false"
|
PROCESS_INLINE: "false"
|
||||||
|
PUBLIC_BASE_URL: ${PUBLIC_BASE_URL:-http://localhost:4000}
|
||||||
|
WEB_ORIGIN: ${WEB_ORIGIN:-http://localhost:3000}
|
||||||
ports:
|
ports:
|
||||||
- "4000:4000"
|
- "4000:4000"
|
||||||
volumes:
|
|
||||||
- .:/workspace
|
|
||||||
depends_on:
|
depends_on:
|
||||||
postgres:
|
postgres:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
@@ -97,14 +87,12 @@ services:
|
|||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
|
|
||||||
worker:
|
worker:
|
||||||
image: node:22-bookworm
|
<<: *altdock-app
|
||||||
working_dir: /workspace
|
command: npm run dev:worker
|
||||||
command: sh -c "npm install --no-audit --no-fund && npm run dev:worker"
|
|
||||||
environment:
|
environment:
|
||||||
NODE_ENV: development
|
|
||||||
DATABASE_URL: postgres://${POSTGRES_USER:-altdock}:${POSTGRES_PASSWORD:-altdock}@postgres:5432/${POSTGRES_DB:-altdock}
|
DATABASE_URL: postgres://${POSTGRES_USER:-altdock}:${POSTGRES_PASSWORD:-altdock}@postgres:5432/${POSTGRES_DB:-altdock}
|
||||||
STORAGE_MODE: s3
|
STORAGE_MODE: s3
|
||||||
S3_ENDPOINT: ${S3_ENDPOINT:-http://minio:9000}
|
S3_ENDPOINT: http://minio:9000
|
||||||
S3_REGION: ${S3_REGION:-us-east-1}
|
S3_REGION: ${S3_REGION:-us-east-1}
|
||||||
S3_BUCKET: ${S3_BUCKET:-altdock}
|
S3_BUCKET: ${S3_BUCKET:-altdock}
|
||||||
S3_ACCESS_KEY_ID: ${MINIO_ROOT_USER:-minioadmin}
|
S3_ACCESS_KEY_ID: ${MINIO_ROOT_USER:-minioadmin}
|
||||||
@@ -112,8 +100,6 @@ services:
|
|||||||
S3_FORCE_PATH_STYLE: "true"
|
S3_FORCE_PATH_STYLE: "true"
|
||||||
AUTH_MODE: ${AUTH_MODE:-demo}
|
AUTH_MODE: ${AUTH_MODE:-demo}
|
||||||
PROCESS_INLINE: "false"
|
PROCESS_INLINE: "false"
|
||||||
volumes:
|
|
||||||
- .:/workspace
|
|
||||||
depends_on:
|
depends_on:
|
||||||
postgres:
|
postgres:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
@@ -121,15 +107,15 @@ services:
|
|||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
|
|
||||||
web:
|
web:
|
||||||
image: node:22-bookworm
|
<<: *altdock-app
|
||||||
working_dir: /workspace
|
# vinext uses --hostname (not vite's --host) to bind the dev server.
|
||||||
command: sh -c "npm install --no-audit --no-fund && npm run dev -- --host 0.0.0.0"
|
command: npm run dev -- --hostname 0.0.0.0
|
||||||
environment:
|
environment:
|
||||||
|
HOST: 0.0.0.0
|
||||||
NEXT_PUBLIC_API_BASE_URL: ${NEXT_PUBLIC_API_BASE_URL:-http://localhost:4000}
|
NEXT_PUBLIC_API_BASE_URL: ${NEXT_PUBLIC_API_BASE_URL:-http://localhost:4000}
|
||||||
|
NEXT_PUBLIC_AUTH_MODE: ${AUTH_MODE:-demo}
|
||||||
ports:
|
ports:
|
||||||
- "3000:3000"
|
- "3000:3000"
|
||||||
volumes:
|
|
||||||
- .:/workspace
|
|
||||||
depends_on:
|
depends_on:
|
||||||
api:
|
api:
|
||||||
condition: service_started
|
condition: service_started
|
||||||
|
|||||||
Reference in New Issue
Block a user