From e29ad75c55e86374fe65b044a7cdb92a3077643d Mon Sep 17 00:00:00 2001 From: Dikshantpatil2077 Date: Mon, 7 Sep 2026 16:41:21 +0530 Subject: [PATCH] fix: bake VITE_POCKETBASE_URL into image, guard against empty value --- app/lib/pocketbase.ts | 15 ++++++++++++++- build-and-push.sh | 45 +++++++++++++++++++++++++++++++++++-------- docker-compose.yml | 10 +++++++--- 3 files changed, 58 insertions(+), 12 deletions(-) diff --git a/app/lib/pocketbase.ts b/app/lib/pocketbase.ts index de15a2c..01eb834 100644 --- a/app/lib/pocketbase.ts +++ b/app/lib/pocketbase.ts @@ -1,6 +1,19 @@ import PocketBase from 'pocketbase'; -const rawUrl = import.meta.env.VITE_POCKETBASE_URL ?? ''; +// VITE_ vars are inlined at BUILD time, not runtime. If the image is built +// without --build-arg VITE_POCKETBASE_URL, this is empty and the SDK silently +// resolves requests against `https://` — producing `https://api/collections/...` +// which fails as a DNS error that looks like CORS. Fail loudly instead. +const rawUrl = import.meta.env.VITE_POCKETBASE_URL; + +if (!rawUrl) { + throw new Error( + 'VITE_POCKETBASE_URL is not set. It must be passed as a --build-arg when ' + + 'building the Docker image — setting it at runtime has no effect, because ' + + 'Vite inlines VITE_ variables into the bundle at build time.', + ); +} + // Ensure URL always has a protocol so PocketBase SDK treats it as absolute const pbUrl = rawUrl.startsWith('http') ? rawUrl : `https://${rawUrl}`; diff --git a/build-and-push.sh b/build-and-push.sh index 585c5ef..05c11c6 100755 --- a/build-and-push.sh +++ b/build-and-push.sh @@ -1,11 +1,28 @@ #!/bin/bash -set -e +set -euo pipefail REGISTRY="registry.digitalocean.com/thob-blr1" SHA=$(git rev-parse --short=10 HEAD) +# Load .env if present, so VITE_* don't have to be exported by hand. +if [ -f .env ]; then + echo "Loading build vars from .env" + set -a + # shellcheck disable=SC1091 + . ./.env + set +a +fi + +# VITE_ vars are inlined into the client bundle at BUILD time. If they are empty +# here, the app ships with a broken PocketBase URL (https://api/...) that fails +# in the browser as a DNS error resembling CORS. Refuse to build. +: "${VITE_POCKETBASE_URL:?VITE_POCKETBASE_URL is not set — export it or add it to .env}" +: "${VITE_FRONTEND_URL:?VITE_FRONTEND_URL is not set — export it or add it to .env}" + echo "Building commit: $SHA" +echo " VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL" +echo " VITE_FRONTEND_URL=$VITE_FRONTEND_URL" # Login doctl registry login @@ -14,13 +31,25 @@ doctl registry login echo "Building AR App..." docker buildx build \ --platform linux/amd64 \ - --build-arg VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL \ - --build-arg VITE_FRONTEND_URL=$VITE_FRONTEND_URL \ + --build-arg "VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL" \ + --build-arg "VITE_FRONTEND_URL=$VITE_FRONTEND_URL" \ -f Dockerfile \ --load \ - -t $REGISTRY/ar:$SHA \ - -t $REGISTRY/ar:latest . -docker push $REGISTRY/ar:$SHA -docker push $REGISTRY/ar:latest + -t "$REGISTRY/ar:$SHA" \ + -t "$REGISTRY/ar:latest" . -echo "✅ All images built and pushed successfully" +# Verify the URL actually made it into the client bundle before pushing. +echo "Verifying baked-in PocketBase URL..." +PB_HOST=$(echo "$VITE_POCKETBASE_URL" | sed -e 's#^https\?://##' -e 's#/.*$##') +if ! docker run --rm --entrypoint sh "$REGISTRY/ar:$SHA" \ + -c "grep -rq '$PB_HOST' /app/build/client"; then + echo "❌ Build verification failed: '$PB_HOST' not found in the client bundle." + echo " The image was NOT pushed." + exit 1 +fi +echo "✅ Verified: $PB_HOST is baked into the client bundle" + +docker push "$REGISTRY/ar:$SHA" +docker push "$REGISTRY/ar:latest" + +echo "✅ All images built and pushed successfully (tag: $SHA)" diff --git a/docker-compose.yml b/docker-compose.yml index c83337b..bbaa0cc 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -79,9 +79,10 @@ services: - VITE_POCKETBASE_URL=${VITE_POCKETBASE_URL:-https://pb.ar.thob.studio} expose: - "3000" + # NOTE: VITE_* vars are inlined into the client bundle at BUILD time by Vite. + # Setting them here has NO effect on the pulled image — they must be passed + # as --build-arg in build-and-push.sh. Only server-side vars belong below. environment: - - VITE_POCKETBASE_URL=${VITE_POCKETBASE_URL:-https://pb.ar.thob.studio} - - VITE_FRONTEND_URL=${VITE_FRONTEND_URL:-https://ar.thob.studio} - INTERNAL_POCKETBASE_URL=http://ar-pb:8090 depends_on: - pocketbase @@ -89,6 +90,9 @@ services: - traefik labels: - "wud.watch=true" + # Required: the :latest tag doesn't change, so wud must compare digests + # to notice a new image was pushed to the same tag. + - "wud.watch.digest=true" - "traefik.enable=true" - "traefik.docker.network=traefik" - "traefik.http.routers.ar-app.rule=Host(`ar.thob.studio`)" @@ -121,4 +125,4 @@ services: - "traefik.http.routers.ar-pb.tls=true" - "traefik.http.routers.ar-pb.tls.certresolver=letsencrypt" - "traefik.http.routers.ar-pb.service=ar-pb" - - "traefik.http.services.ar-pb.loadbalancer.server.port=8090" \ No newline at end of file + - "traefik.http.services.ar-pb.loadbalancer.server.port=8090"