diff --git a/docker-compose.yml b/docker-compose.yml index ce932ac..d9f4cf1 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -18,6 +18,12 @@ services: # Loopback only: reachable from the host machine (psql, backups), # never from the network. Remove this mapping to close it entirely. - "127.0.0.1:${DB_PORT:-58412}:5432" + networks: + default: + aliases: + # Unique hostname: "db" alone is ambiguous when other stacks on a + # shared network (nginx_default) also expose a "db" service. + - sbc-db healthcheck: test: ["CMD-SHELL", "pg_isready -U postgres -d sbc"] interval: 5s @@ -33,7 +39,7 @@ services: db: condition: service_healthy environment: - PGHOST: db + PGHOST: sbc-db PGUSER: postgres PGDATABASE: sbc PGPASSWORD: ${POSTGRES_PASSWORD:-sbc-pg-c7f3a91d284e6b05} @@ -48,7 +54,13 @@ services: environment: NODE_ENV: production PORT: "8321" - DATABASE_URL: postgres://sbc_app:${APP_DB_PASSWORD:-sbc-app-9e12d47ab8c3f605}@db:5432/sbc + # Discrete variables (no URL): immune to special characters in the + # password and to hostname ambiguity on shared networks + PGHOST: sbc-db + PGPORT: "5432" + PGDATABASE: sbc + PGUSER: sbc_app + PGPASSWORD: ${APP_DB_PASSWORD:-sbc-app-9e12d47ab8c3f605} # Empty by default: the app then generates a random ephemeral secret at # startup. Set a fixed value to keep sessions across restarts. JWT_SECRET: ${JWT_SECRET:-} diff --git a/server/src/config.js b/server/src/config.js index 787ef9e..69fdc15 100644 --- a/server/src/config.js +++ b/server/src/config.js @@ -23,7 +23,13 @@ if (jwtSecret.length < 32) { export const config = { port: Number(process.env.PORT || 8321), - databaseUrl: required('DATABASE_URL'), + db: { + host: process.env.PGHOST || 'localhost', + port: Number(process.env.PGPORT || 5432), + database: process.env.PGDATABASE || 'sbc', + user: process.env.PGUSER || 'sbc_app', + password: required('PGPASSWORD'), + }, jwtSecret, cookieSecure: process.env.COOKIE_SECURE === 'true', // set to "true" only when running behind a reverse proxy (TLS termination) diff --git a/server/src/db.js b/server/src/db.js index bfae3cc..0e0cd97 100644 --- a/server/src/db.js +++ b/server/src/db.js @@ -2,7 +2,7 @@ import pg from 'pg'; import { config } from './config.js'; export const pool = new pg.Pool({ - connectionString: config.databaseUrl, + ...config.db, max: 10, idleTimeoutMillis: 30_000, connectionTimeoutMillis: 5_000,