fix: bake VITE_POCKETBASE_URL into image, guard against empty value

This commit is contained in:
Dikshantpatil2077 2026-09-07 16:41:21 +05:30
parent 24b0c5889f
commit e29ad75c55
3 changed files with 58 additions and 12 deletions

View File

@ -1,6 +1,19 @@
import PocketBase from 'pocketbase';
const rawUrl = import.meta.env.VITE_POCKETBASE_URL ?? '';
// VITE_ vars are inlined at BUILD time, not runtime. If the image is built
// without --build-arg VITE_POCKETBASE_URL, this is empty and the SDK silently
// resolves requests against `https://` — producing `https://api/collections/...`
// which fails as a DNS error that looks like CORS. Fail loudly instead.
const rawUrl = import.meta.env.VITE_POCKETBASE_URL;
if (!rawUrl) {
throw new Error(
'VITE_POCKETBASE_URL is not set. It must be passed as a --build-arg when ' +
'building the Docker image — setting it at runtime has no effect, because ' +
'Vite inlines VITE_ variables into the bundle at build time.',
);
}
// Ensure URL always has a protocol so PocketBase SDK treats it as absolute
const pbUrl = rawUrl.startsWith('http') ? rawUrl : `https://${rawUrl}`;

View File

@ -1,11 +1,28 @@
#!/bin/bash
set -e
set -euo pipefail
REGISTRY="registry.digitalocean.com/thob-blr1"
SHA=$(git rev-parse --short=10 HEAD)
# Load .env if present, so VITE_* don't have to be exported by hand.
if [ -f .env ]; then
echo "Loading build vars from .env"
set -a
# shellcheck disable=SC1091
. ./.env
set +a
fi
# VITE_ vars are inlined into the client bundle at BUILD time. If they are empty
# here, the app ships with a broken PocketBase URL (https://api/...) that fails
# in the browser as a DNS error resembling CORS. Refuse to build.
: "${VITE_POCKETBASE_URL:?VITE_POCKETBASE_URL is not set — export it or add it to .env}"
: "${VITE_FRONTEND_URL:?VITE_FRONTEND_URL is not set — export it or add it to .env}"
echo "Building commit: $SHA"
echo " VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL"
echo " VITE_FRONTEND_URL=$VITE_FRONTEND_URL"
# Login
doctl registry login
@ -14,13 +31,25 @@ doctl registry login
echo "Building AR App..."
docker buildx build \
--platform linux/amd64 \
--build-arg VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL \
--build-arg VITE_FRONTEND_URL=$VITE_FRONTEND_URL \
--build-arg "VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL" \
--build-arg "VITE_FRONTEND_URL=$VITE_FRONTEND_URL" \
-f Dockerfile \
--load \
-t $REGISTRY/ar:$SHA \
-t $REGISTRY/ar:latest .
docker push $REGISTRY/ar:$SHA
docker push $REGISTRY/ar:latest
-t "$REGISTRY/ar:$SHA" \
-t "$REGISTRY/ar:latest" .
echo "✅ All images built and pushed successfully"
# Verify the URL actually made it into the client bundle before pushing.
echo "Verifying baked-in PocketBase URL..."
PB_HOST=$(echo "$VITE_POCKETBASE_URL" | sed -e 's#^https\?://##' -e 's#/.*$##')
if ! docker run --rm --entrypoint sh "$REGISTRY/ar:$SHA" \
-c "grep -rq '$PB_HOST' /app/build/client"; then
echo "❌ Build verification failed: '$PB_HOST' not found in the client bundle."
echo " The image was NOT pushed."
exit 1
fi
echo "✅ Verified: $PB_HOST is baked into the client bundle"
docker push "$REGISTRY/ar:$SHA"
docker push "$REGISTRY/ar:latest"
echo "✅ All images built and pushed successfully (tag: $SHA)"

View File

@ -79,9 +79,10 @@ services:
- VITE_POCKETBASE_URL=${VITE_POCKETBASE_URL:-https://pb.ar.thob.studio}
expose:
- "3000"
# NOTE: VITE_* vars are inlined into the client bundle at BUILD time by Vite.
# Setting them here has NO effect on the pulled image — they must be passed
# as --build-arg in build-and-push.sh. Only server-side vars belong below.
environment:
- VITE_POCKETBASE_URL=${VITE_POCKETBASE_URL:-https://pb.ar.thob.studio}
- VITE_FRONTEND_URL=${VITE_FRONTEND_URL:-https://ar.thob.studio}
- INTERNAL_POCKETBASE_URL=http://ar-pb:8090
depends_on:
- pocketbase
@ -89,6 +90,9 @@ services:
- traefik
labels:
- "wud.watch=true"
# Required: the :latest tag doesn't change, so wud must compare digests
# to notice a new image was pushed to the same tag.
- "wud.watch.digest=true"
- "traefik.enable=true"
- "traefik.docker.network=traefik"
- "traefik.http.routers.ar-app.rule=Host(`ar.thob.studio`)"
@ -121,4 +125,4 @@ services:
- "traefik.http.routers.ar-pb.tls=true"
- "traefik.http.routers.ar-pb.tls.certresolver=letsencrypt"
- "traefik.http.routers.ar-pb.service=ar-pb"
- "traefik.http.services.ar-pb.loadbalancer.server.port=8090"
- "traefik.http.services.ar-pb.loadbalancer.server.port=8090"