Corrige la connexion BDD : alias unique sbc-db et variables PG discrètes
Sur le réseau partagé nginx_default, le nom « db » peut résoudre vers le PostgreSQL d'une autre stack : l'application se connectait au mauvais serveur (password authentication failed pour sbc_app alors que db-sync, lui, visait le bon). Reproduit et vérifié avec un conteneur leurre. - La base obtient l'alias réseau unique « sbc-db » ; l'app et db-sync s'y connectent via ce nom, jamais via « db » - DATABASE_URL remplacé par PGHOST/PGPORT/PGDATABASE/PGUSER/PGPASSWORD : insensible aux caractères spéciaux du mot de passe et aux ambiguïtés de résolution DNS Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Fkg15RCxNgUys4ru73He2o
This commit is contained in:
3 files changed
+22
-4
No files matched your search
+14
-2
@@ -18,6 +18,12 @@ services:
|
||||
# Loopback only: reachable from the host machine (psql, backups),
|
||||
# never from the network. Remove this mapping to close it entirely.
|
||||
- "127.0.0.1:${DB_PORT:-58412}:5432"
|
||||
networks:
|
||||
default:
|
||||
aliases:
|
||||
# Unique hostname: "db" alone is ambiguous when other stacks on a
|
||||
# shared network (nginx_default) also expose a "db" service.
|
||||
- sbc-db
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "pg_isready -U postgres -d sbc"]
|
||||
interval: 5s
|
||||
@@ -33,7 +39,7 @@ services:
|
||||
db:
|
||||
condition: service_healthy
|
||||
environment:
|
||||
PGHOST: db
|
||||
PGHOST: sbc-db
|
||||
PGUSER: postgres
|
||||
PGDATABASE: sbc
|
||||
PGPASSWORD: ${POSTGRES_PASSWORD:-sbc-pg-c7f3a91d284e6b05}
|
||||
@@ -48,7 +54,13 @@ services:
|
||||
environment:
|
||||
NODE_ENV: production
|
||||
PORT: "8321"
|
||||
DATABASE_URL: postgres://sbc_app:${APP_DB_PASSWORD:-sbc-app-9e12d47ab8c3f605}@db:5432/sbc
|
||||
# Discrete variables (no URL): immune to special characters in the
|
||||
# password and to hostname ambiguity on shared networks
|
||||
PGHOST: sbc-db
|
||||
PGPORT: "5432"
|
||||
PGDATABASE: sbc
|
||||
PGUSER: sbc_app
|
||||
PGPASSWORD: ${APP_DB_PASSWORD:-sbc-app-9e12d47ab8c3f605}
|
||||
# Empty by default: the app then generates a random ephemeral secret at
|
||||
# startup. Set a fixed value to keep sessions across restarts.
|
||||
JWT_SECRET: ${JWT_SECRET:-}
|
||||
|
||||
@@ -23,7 +23,13 @@ if (jwtSecret.length < 32) {
|
||||
|
||||
export const config = {
|
||||
port: Number(process.env.PORT || 8321),
|
||||
databaseUrl: required('DATABASE_URL'),
|
||||
db: {
|
||||
host: process.env.PGHOST || 'localhost',
|
||||
port: Number(process.env.PGPORT || 5432),
|
||||
database: process.env.PGDATABASE || 'sbc',
|
||||
user: process.env.PGUSER || 'sbc_app',
|
||||
password: required('PGPASSWORD'),
|
||||
},
|
||||
jwtSecret,
|
||||
cookieSecure: process.env.COOKIE_SECURE === 'true',
|
||||
// set to "true" only when running behind a reverse proxy (TLS termination)
|
||||
|
||||
+1
-1
@@ -2,7 +2,7 @@ import pg from 'pg';
|
||||
import { config } from './config.js';
|
||||
|
||||
export const pool = new pg.Pool({
|
||||
connectionString: config.databaseUrl,
|
||||
...config.db,
|
||||
max: 10,
|
||||
idleTimeoutMillis: 30_000,
|
||||
connectionTimeoutMillis: 5_000,
|
||||
|
||||
Reference in new issue
Block a user