- setup.sh: interactive/non-interactive one-shot installer (build, DB healthcheck, migrate, seed, start), idempotent secret generation, NPM reverse-proxy network auto-detection and optional join, optional AUTO_UPDATE cron install. - update.sh: release-tag-gated updates only (never bare main), DB backup with retention before every update, lock file against concurrent runs, automatic code rollback on failed post-update healthcheck. - Dockerfile: multi-stage build, non-root user, built-in HEALTHCHECK against the new /api/health route, wholesale COPY so new source dirs (e.g. scripts/) never silently go missing at runtime. - docker-compose.yml: internal anouma-network (configurable), named volume for Postgres, app depends_on postgres healthy, no unnecessary published ports; docker-compose.override.yml.example documents joining an existing NPM network without ever touching NPM itself. - Fix host-detection: isHost was Boolean(user), wrongly granting host privileges to logged-in customers; now checks user.collection === "users". - Wire configurable STUN/TURN servers through to the WebRTC client (lib/meeting/iceServers.ts) so a TURN server can be added later via env vars only, no code changes. - DEPLOYMENT.md, updated README.md and .env.example documenting the whole flow: NPM integration, env vars, WebRTC, updates, backups, rollback. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
26 lines
933 B
Plaintext
26 lines
933 B
Plaintext
# Example override for running ANOUMA behind an existing reverse proxy (e.g.
|
|
# Nginx Proxy Manager) that has its own Docker network.
|
|
#
|
|
# setup.sh generates docker-compose.override.yml automatically when it
|
|
# detects such a network — this file is just the committed reference/manual
|
|
# fallback. Docker Compose picks up docker-compose.override.yml automatically
|
|
# alongside docker-compose.yml, no extra -f flags needed.
|
|
#
|
|
# To use manually: copy this to docker-compose.override.yml and set
|
|
# NPM_NETWORK in .env to your proxy's actual network name (find it with
|
|
# `docker network ls`).
|
|
|
|
networks:
|
|
npm-network:
|
|
name: ${NPM_NETWORK}
|
|
external: true
|
|
|
|
services:
|
|
app:
|
|
networks:
|
|
- anouma-network
|
|
- npm-network
|
|
# No need to publish the port to the host when a reverse proxy reaches
|
|
# the container directly over the shared network — remove/comment the
|
|
# "ports" mapping in docker-compose.yml if so.
|