Files
redefined-designs/docker-compose.qa.yml
T
bermudalambandClaude Opus 5 c01e434747
SonarQube Analysis / sonarqube (pull_request) Successful in 3m48s
Tests / backend-unit (pull_request) Successful in 1m18s
Tests / backend-integration (pull_request) Failing after 4m12s
Tests / frontend-e2e (pull_request) Failing after 12m52s
fix(qa): build the QA image before deploying the stack (#25)
Deploying the stack first failed with "pull access denied for
redefined-designs, repository does not exist or may require docker
login". The README had the Portainer stack creation ahead of the build,
so no local redefined-designs:qa image existed and Compose fell back to
pulling from Docker Hub, where the repository does not exist.

The build step now comes first in the one-time setup, and the review
workflow says to rebuild before restarting the stack — the stack builds
nothing itself and would otherwise run whatever was last tagged :qa.

pull_policy: never makes the failure legible: a missing local image now
reports itself as missing rather than as a registry authentication
problem. Noted as safe to remove if the NAS's Compose ever rejects the
key, since it only affects the error message.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-17 12:29:14 -05:00

95 lines
4.1 KiB
YAML

# QA stack — a disposable copy of the app for reviewing merged-but-undeployed
# changes online. See issue #25.
#
# Deployed as its own Portainer stack, separate from production. Every value
# that could collide with production has been changed: container names, host
# port, volume paths, database name, and image tag. Do not copy a path or port
# back from the production stack — a shared Postgres data directory would mean
# QA writing into production's database files.
#
# Name the Portainer stack `redefined-designs-qa`, NOT `redefined-designs`.
# The stack name becomes the compose project name. Reusing production's name
# would make compose treat this as the same project and reconcile the two
# against each other — it would happily remove the production containers
# because they are not declared in this file.
#
# Required stack environment variable:
# QA_DB_PASSWORD — deliberately not named DB_PASSWORD, so pasting the
# production stack's variables here does nothing silently.
#
# BUILD THE IMAGE BEFORE DEPLOYING THIS STACK. redefined-designs:qa exists only
# on the NAS and is never pushed to a registry, so deploying first makes Compose
# fall back to pulling from Docker Hub and fail with a misleading
# "pull access denied ... repository does not exist or may require docker login".
#
# sudo docker build --no-cache -t redefined-designs:qa /volume1/docker/redefined-designs
#
# For the same reason, leave Portainer's "Pull latest image" toggle off.
# `pull_policy: never` below makes a missing image report itself as missing
# rather than as a registry authentication problem. If the Docker Compose
# version on the NAS ever rejects that key, it is safe to delete the line — it
# only improves the error message.
services:
redefined-designs-qa:
image: redefined-designs:qa
pull_policy: never
container_name: redefined-designs-qa-syn
environment:
- TZ=America/Chicago
- PORT=3000
- PGHOST=redefined-designs-qa-db-syn
- PGPORT=5432
- PGUSER=redefined_qa
- PGPASSWORD=${QA_DB_PASSWORD}
- PGDATABASE=redefined_qa
# No PayPal credentials at all. DEMO_MODE lets the full cart and checkout
# flow run without them, so QA can exercise the whole purchase path with
# no way to reach live PayPal. Never set PAYPAL_ENV=live here. To test a
# real PayPal integration change, add sandbox credentials and set
# PAYPAL_ENV=sandbox — never the live ones.
- DEMO_MODE=true
# No SMTP configuration either. The mailer degrades gracefully when
# unconfigured: it logs a warning and skips sending. That is the desired
# behaviour here — a QA run must not be able to email real customers if
# a fixture ever contains a real address.
- SITE_CURRENCY=USD
- RESERVATION_MINUTES=15
- PUBLIC_URL=https://qa-redefined-designs.bermudalamb.synology.me
volumes:
# Separate uploads directory. Sharing production's would let a QA run
# write into, and a QA teardown delete, real product images.
- /volume1/configs/redefined-designs-qa/uploads:/app/uploads
ports:
# 32751, not production's 32750.
- 32751:3000
depends_on:
redefined-designs-qa-db-syn:
condition: service_healthy
# Not `unless-stopped`: QA is meant to be up only while a review is
# happening. `unless-stopped` would silently bring it back after every NAS
# reboot and leave it running indefinitely.
restart: "no"
redefined-designs-qa-db-syn:
image: postgres:16
container_name: redefined-designs-qa-db-syn
environment:
- POSTGRES_USER=redefined_qa
- POSTGRES_PASSWORD=${QA_DB_PASSWORD}
- POSTGRES_DB=redefined_qa
- PGDATA=/var/lib/postgresql/data/pgdata
volumes:
# Distinct data directory from production's
# /volume1/configs/redefined-designs/postgres. This is the single most
# important difference in this file.
- /volume1/configs/redefined-designs-qa/postgres:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U redefined_qa -d redefined_qa"]
interval: 10s
timeout: 5s
retries: 10
restart: "no"