fix: bake VITE_POCKETBASE_URL into image, guard against empty value
This commit is contained in:
parent
24b0c5889f
commit
e29ad75c55
@ -1,6 +1,19 @@
|
|||||||
import PocketBase from 'pocketbase';
|
import PocketBase from 'pocketbase';
|
||||||
|
|
||||||
const rawUrl = import.meta.env.VITE_POCKETBASE_URL ?? '';
|
// VITE_ vars are inlined at BUILD time, not runtime. If the image is built
|
||||||
|
// without --build-arg VITE_POCKETBASE_URL, this is empty and the SDK silently
|
||||||
|
// resolves requests against `https://` — producing `https://api/collections/...`
|
||||||
|
// which fails as a DNS error that looks like CORS. Fail loudly instead.
|
||||||
|
const rawUrl = import.meta.env.VITE_POCKETBASE_URL;
|
||||||
|
|
||||||
|
if (!rawUrl) {
|
||||||
|
throw new Error(
|
||||||
|
'VITE_POCKETBASE_URL is not set. It must be passed as a --build-arg when ' +
|
||||||
|
'building the Docker image — setting it at runtime has no effect, because ' +
|
||||||
|
'Vite inlines VITE_ variables into the bundle at build time.',
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
// Ensure URL always has a protocol so PocketBase SDK treats it as absolute
|
// Ensure URL always has a protocol so PocketBase SDK treats it as absolute
|
||||||
const pbUrl = rawUrl.startsWith('http') ? rawUrl : `https://${rawUrl}`;
|
const pbUrl = rawUrl.startsWith('http') ? rawUrl : `https://${rawUrl}`;
|
||||||
|
|
||||||
|
|||||||
@ -1,11 +1,28 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
set -e
|
set -euo pipefail
|
||||||
|
|
||||||
REGISTRY="registry.digitalocean.com/thob-blr1"
|
REGISTRY="registry.digitalocean.com/thob-blr1"
|
||||||
SHA=$(git rev-parse --short=10 HEAD)
|
SHA=$(git rev-parse --short=10 HEAD)
|
||||||
|
|
||||||
|
# Load .env if present, so VITE_* don't have to be exported by hand.
|
||||||
|
if [ -f .env ]; then
|
||||||
|
echo "Loading build vars from .env"
|
||||||
|
set -a
|
||||||
|
# shellcheck disable=SC1091
|
||||||
|
. ./.env
|
||||||
|
set +a
|
||||||
|
fi
|
||||||
|
|
||||||
|
# VITE_ vars are inlined into the client bundle at BUILD time. If they are empty
|
||||||
|
# here, the app ships with a broken PocketBase URL (https://api/...) that fails
|
||||||
|
# in the browser as a DNS error resembling CORS. Refuse to build.
|
||||||
|
: "${VITE_POCKETBASE_URL:?VITE_POCKETBASE_URL is not set — export it or add it to .env}"
|
||||||
|
: "${VITE_FRONTEND_URL:?VITE_FRONTEND_URL is not set — export it or add it to .env}"
|
||||||
|
|
||||||
echo "Building commit: $SHA"
|
echo "Building commit: $SHA"
|
||||||
|
echo " VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL"
|
||||||
|
echo " VITE_FRONTEND_URL=$VITE_FRONTEND_URL"
|
||||||
|
|
||||||
# Login
|
# Login
|
||||||
doctl registry login
|
doctl registry login
|
||||||
@ -14,13 +31,25 @@ doctl registry login
|
|||||||
echo "Building AR App..."
|
echo "Building AR App..."
|
||||||
docker buildx build \
|
docker buildx build \
|
||||||
--platform linux/amd64 \
|
--platform linux/amd64 \
|
||||||
--build-arg VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL \
|
--build-arg "VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL" \
|
||||||
--build-arg VITE_FRONTEND_URL=$VITE_FRONTEND_URL \
|
--build-arg "VITE_FRONTEND_URL=$VITE_FRONTEND_URL" \
|
||||||
-f Dockerfile \
|
-f Dockerfile \
|
||||||
--load \
|
--load \
|
||||||
-t $REGISTRY/ar:$SHA \
|
-t "$REGISTRY/ar:$SHA" \
|
||||||
-t $REGISTRY/ar:latest .
|
-t "$REGISTRY/ar:latest" .
|
||||||
docker push $REGISTRY/ar:$SHA
|
|
||||||
docker push $REGISTRY/ar:latest
|
|
||||||
|
|
||||||
echo "✅ All images built and pushed successfully"
|
# Verify the URL actually made it into the client bundle before pushing.
|
||||||
|
echo "Verifying baked-in PocketBase URL..."
|
||||||
|
PB_HOST=$(echo "$VITE_POCKETBASE_URL" | sed -e 's#^https\?://##' -e 's#/.*$##')
|
||||||
|
if ! docker run --rm --entrypoint sh "$REGISTRY/ar:$SHA" \
|
||||||
|
-c "grep -rq '$PB_HOST' /app/build/client"; then
|
||||||
|
echo "❌ Build verification failed: '$PB_HOST' not found in the client bundle."
|
||||||
|
echo " The image was NOT pushed."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "✅ Verified: $PB_HOST is baked into the client bundle"
|
||||||
|
|
||||||
|
docker push "$REGISTRY/ar:$SHA"
|
||||||
|
docker push "$REGISTRY/ar:latest"
|
||||||
|
|
||||||
|
echo "✅ All images built and pushed successfully (tag: $SHA)"
|
||||||
|
|||||||
@ -79,9 +79,10 @@ services:
|
|||||||
- VITE_POCKETBASE_URL=${VITE_POCKETBASE_URL:-https://pb.ar.thob.studio}
|
- VITE_POCKETBASE_URL=${VITE_POCKETBASE_URL:-https://pb.ar.thob.studio}
|
||||||
expose:
|
expose:
|
||||||
- "3000"
|
- "3000"
|
||||||
|
# NOTE: VITE_* vars are inlined into the client bundle at BUILD time by Vite.
|
||||||
|
# Setting them here has NO effect on the pulled image — they must be passed
|
||||||
|
# as --build-arg in build-and-push.sh. Only server-side vars belong below.
|
||||||
environment:
|
environment:
|
||||||
- VITE_POCKETBASE_URL=${VITE_POCKETBASE_URL:-https://pb.ar.thob.studio}
|
|
||||||
- VITE_FRONTEND_URL=${VITE_FRONTEND_URL:-https://ar.thob.studio}
|
|
||||||
- INTERNAL_POCKETBASE_URL=http://ar-pb:8090
|
- INTERNAL_POCKETBASE_URL=http://ar-pb:8090
|
||||||
depends_on:
|
depends_on:
|
||||||
- pocketbase
|
- pocketbase
|
||||||
@ -89,6 +90,9 @@ services:
|
|||||||
- traefik
|
- traefik
|
||||||
labels:
|
labels:
|
||||||
- "wud.watch=true"
|
- "wud.watch=true"
|
||||||
|
# Required: the :latest tag doesn't change, so wud must compare digests
|
||||||
|
# to notice a new image was pushed to the same tag.
|
||||||
|
- "wud.watch.digest=true"
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=traefik"
|
- "traefik.docker.network=traefik"
|
||||||
- "traefik.http.routers.ar-app.rule=Host(`ar.thob.studio`)"
|
- "traefik.http.routers.ar-app.rule=Host(`ar.thob.studio`)"
|
||||||
@ -121,4 +125,4 @@ services:
|
|||||||
- "traefik.http.routers.ar-pb.tls=true"
|
- "traefik.http.routers.ar-pb.tls=true"
|
||||||
- "traefik.http.routers.ar-pb.tls.certresolver=letsencrypt"
|
- "traefik.http.routers.ar-pb.tls.certresolver=letsencrypt"
|
||||||
- "traefik.http.routers.ar-pb.service=ar-pb"
|
- "traefik.http.routers.ar-pb.service=ar-pb"
|
||||||
- "traefik.http.services.ar-pb.loadbalancer.server.port=8090"
|
- "traefik.http.services.ar-pb.loadbalancer.server.port=8090"
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user