Auto-répare le mot de passe du rôle BDD et change le port PostgreSQL

- Nouveau service one-shot db-sync : à chaque démarrage de la stack, il
  réaligne le mot de passe du rôle sbc_app sur APP_DB_PASSWORD (corrige
  « password authentication failed » quand le volume a été initialisé
  avec une ancienne valeur) ; l'app démarre après sa réussite
- Port hôte PostgreSQL : 56432 → 58412 (conflit avec un service existant),
  toujours en loopback uniquement
- Note de dépannage dans le README

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fkg15RCxNgUys4ru73He2o
This commit is contained in:
Claude committed 2026-07-10 20:09:39 +00:00
1 parent 3f35ea584f
commit 2df7d37b72
4 files changed
+58 -4

No files matched your search

+21 -1
View File
@@ -17,13 +17,31 @@ services:
ports:
# Loopback only: reachable from the host machine (psql, backups),
# never from the network. Remove this mapping to close it entirely.
- "127.0.0.1:${DB_PORT:-56432}:5432"
- "127.0.0.1:${DB_PORT:-58412}:5432"
healthcheck:
test: ["CMD-SHELL", "pg_isready -U postgres -d sbc"]
interval: 5s
timeout: 3s
retries: 12
# One-shot at every stack start: realigns the sbc_app role password with
# APP_DB_PASSWORD, healing volumes initialized with an older value.
db-sync:
image: postgres:16-alpine
restart: "no"
depends_on:
db:
condition: service_healthy
environment:
PGHOST: db
PGUSER: postgres
PGDATABASE: sbc
PGPASSWORD: ${POSTGRES_PASSWORD:-sbc-pg-c7f3a91d284e6b05}
APP_DB_PASSWORD: ${APP_DB_PASSWORD:-sbc-app-9e12d47ab8c3f605}
volumes:
- ./db/sync-app-role.sh:/sync-app-role.sh:ro
entrypoint: ["/bin/sh", "/sync-app-role.sh"]
app:
build: .
restart: unless-stopped
@@ -46,6 +64,8 @@ services:
depends_on:
db:
condition: service_healthy
db-sync:
condition: service_completed_successfully
read_only: true
tmpfs:
- /tmp