The QA image is now built by Portainer from this repository rather than by Gitea Actions. Deployed as a Git repository stack, "Pull and redeploy" pulls the repo, builds from the Dockerfile, and recreates the containers in one action. This removes the runner from the loop entirely. Three dispatches failed without ever building: the runner refuses privileged containers, so the dind service was never created. Working around that needed either the host Docker socket mounted into the runner or privileged containers enabled runner-wide, and both hand every workflow on every branch root-equivalent control of the NAS, production included. Portainer already holds the socket — that is how it manages containers — so building there needs no new privilege at all. pull_policy: build is what keeps it honest. Without it the stack reuses whatever is tagged redefined-designs:qa, which is exactly how a redeploy appears to succeed while still serving old code — a failure this project has already hit twice. Deleting qa-build.yml also drops the registry, the REGISTRY_TOKEN and BREVO_API_KEY secrets, and the notification email. The email existed because CI worked asynchronously and had to tell you when it finished; redeploying from Portainer is synchronous, so the browser already does. Losing the per-commit image tags is a real cost — rollback becomes "rebuild from the ref you want" rather than retagging a specific build. README changes for this are deliberately not in this commit: that file also carries uncommitted work of Thom's. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
107 lines
4.6 KiB
YAML
107 lines
4.6 KiB
YAML
# QA stack — a disposable copy of the app for reviewing merged-but-undeployed
|
|
# changes online. See issue #25.
|
|
#
|
|
# Deployed as its own Portainer stack, separate from production. Every value
|
|
# that could collide with production has been changed: container names, host
|
|
# port, volume paths, database name, and image tag. Do not copy a path or port
|
|
# back from the production stack — a shared Postgres data directory would mean
|
|
# QA writing into production's database files.
|
|
#
|
|
# Name the Portainer stack `redefined-designs-qa`, NOT `redefined-designs`.
|
|
# The stack name becomes the compose project name. Reusing production's name
|
|
# would make compose treat this as the same project and reconcile the two
|
|
# against each other — it would happily remove the production containers
|
|
# because they are not declared in this file.
|
|
#
|
|
# DEPLOY THIS AS A GIT REPOSITORY STACK, not from the web editor.
|
|
#
|
|
# Repository: https://gitea.bermudalamb.synology.me/bermudalamb/redefined-designs
|
|
# Reference: refs/heads/main
|
|
# Compose path: docker-compose.qa.yml
|
|
#
|
|
# The repository is public, so no credentials are needed. Portainer then does
|
|
# the whole cycle from one button: it pulls the repo, builds the image from the
|
|
# Dockerfile below, and recreates the containers. Nothing is built by hand on
|
|
# the NAS, and no image has to be pushed anywhere first.
|
|
#
|
|
# `pull_policy: build` matters. Without it the stack reuses whatever is already
|
|
# tagged redefined-designs:qa, which is how a redeploy can appear to succeed
|
|
# while still running old code. Leave any Portainer option that re-pulls images
|
|
# turned OFF — there is no registry to pull this image from.
|
|
#
|
|
# Required stack environment variables:
|
|
# QA_DB_PASSWORD — deliberately not named DB_PASSWORD, so pasting the
|
|
# production stack's variables here does nothing silently.
|
|
# PUBLIC_URL — the QA hostname, e.g.
|
|
# https://qa-redefined-designs.bermudalamb.synology.me
|
|
|
|
services:
|
|
redefined-designs-qa:
|
|
# Built from this repository by Portainer rather than pulled. The context is
|
|
# the repo root, which is where the Dockerfile lives — the same Dockerfile
|
|
# production uses, so QA and production images differ only in configuration.
|
|
build:
|
|
context: .
|
|
dockerfile: Dockerfile
|
|
image: redefined-designs:qa
|
|
# Always build; never reuse the existing tag.
|
|
pull_policy: build
|
|
container_name: redefined-designs-qa-syn
|
|
environment:
|
|
- TZ=America/Chicago
|
|
- PORT=3000
|
|
- PGHOST=redefined-designs-qa-db-syn
|
|
- PGPORT=5432
|
|
- PGUSER=redefined_qa
|
|
- PGPASSWORD=${QA_DB_PASSWORD}
|
|
- PGDATABASE=redefined_qa
|
|
|
|
# No PayPal credentials at all. DEMO_MODE lets the full cart and checkout
|
|
# flow run without them, so QA can exercise the whole purchase path with
|
|
# no way to reach live PayPal. Never set PAYPAL_ENV=live here. To test a
|
|
# real PayPal integration change, add sandbox credentials and set
|
|
# PAYPAL_ENV=sandbox — never the live ones.
|
|
- DEMO_MODE=true
|
|
|
|
# No SMTP configuration either. The mailer degrades gracefully when
|
|
# unconfigured: it logs a warning and skips sending. That is the desired
|
|
# behaviour here — a QA run must not be able to email real customers if
|
|
# a fixture ever contains a real address.
|
|
- SITE_CURRENCY=USD
|
|
- RESERVATION_MINUTES=15
|
|
- PUBLIC_URL=${PUBLIC_URL}
|
|
volumes:
|
|
# Separate uploads directory. Sharing production's would let a QA run
|
|
# write into, and a QA teardown delete, real product images.
|
|
- /volume1/configs/redefined-designs-qa/uploads:/app/uploads
|
|
ports:
|
|
# 32751, not production's 32750.
|
|
- 32751:3000
|
|
depends_on:
|
|
redefined-designs-qa-db-syn:
|
|
condition: service_healthy
|
|
# Not `unless-stopped`: QA is meant to be up only while a review is
|
|
# happening. `unless-stopped` would silently bring it back after every NAS
|
|
# reboot and leave it running indefinitely.
|
|
restart: "no"
|
|
|
|
redefined-designs-qa-db-syn:
|
|
image: postgres:16
|
|
container_name: redefined-designs-qa-db-syn
|
|
environment:
|
|
- POSTGRES_USER=redefined_qa
|
|
- POSTGRES_PASSWORD=${QA_DB_PASSWORD}
|
|
- POSTGRES_DB=redefined_qa
|
|
- PGDATA=/var/lib/postgresql/data/pgdata
|
|
volumes:
|
|
# Distinct data directory from production's
|
|
# /volume1/configs/redefined-designs/postgres. This is the single most
|
|
# important difference in this file.
|
|
- /volume1/configs/redefined-designs-qa/postgres:/var/lib/postgresql/data
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U redefined_qa -d redefined_qa"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 10
|
|
restart: "no"
|