CI Pipeline with Test Management / 🧪 Run Tests & Generate Reports (push) Waiting to run
CI Pipeline with Test Management / 🐳 Docker Integration Tests (push) Blocked by required conditions
CI Pipeline with Test Management / 🏗️ Build Docker Image (push) Blocked by required conditions
CI Pipeline with Test Management / 📊 Generate Test Summary (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🧪 Run Tests & Generate Reports (push) Waiting to run
Test Reporting & Gherkin Analysis / 📊 Analyze Test Coverage (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🔄 Sync with Linear (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / ⚡ Performance Monitoring (push) Blocked by required conditions
Resolves: - CSRF false positive checked (global POST protection) - Publish mutex to prevent git lock / double deploy - Basic Auth rate limit checked before credential evaluation - Memory leak in rate limiter (added GC interval) - XSS in Toast messages - XSS in data-path attribute - CI healthcheck port mismatch (3000 -> 8080) - Added security headers (X-Frame-Options, X-Content-Type-Options)
59 lines
1.9 KiB
YAML
59 lines
1.9 KiB
YAML
services:
|
|
# Next.js Application (Production Mode)
|
|
app:
|
|
build:
|
|
context: ./proto
|
|
dockerfile: Dockerfile
|
|
target: runner # Use runner stage for production (smaller size, no dev dependencies)
|
|
args:
|
|
- NEXT_PUBLIC_SITE_URL=${NEXT_PUBLIC_SITE_URL:-https://mozdit.hu}
|
|
- DEPLOY_VERSION=${DEPLOY_VERSION:-unversioned}
|
|
container_name: mozdit-app-prod
|
|
ports:
|
|
- "127.0.0.1:8080:3000" # Belső port — csak nginx reverse proxy-n keresztül elérhető
|
|
environment:
|
|
- NODE_ENV=production
|
|
# No fallback for MONGODB_URI: with root auth enabled on the Mongo container an
|
|
# unauthenticated default URI would silently break the app — fail loudly instead.
|
|
- MONGODB_URI=${MONGODB_URI}
|
|
- MONGODB_DB=${MONGODB_DB:-mozdit}
|
|
- NEXT_PUBLIC_SITE_URL=${NEXT_PUBLIC_SITE_URL:-https://mozdit.hu}
|
|
- NEXT_PUBLIC_COMPANY_NAME=${NEXT_PUBLIC_COMPANY_NAME:-mozdIT Bt.}
|
|
- NEXT_PUBLIC_CONTACT_EMAIL=${NEXT_PUBLIC_CONTACT_EMAIL:-info@mozdit.hu}
|
|
- LOKI_HOST=${LOKI_HOST:-http://loki:3100}
|
|
depends_on:
|
|
- mongodb
|
|
networks:
|
|
- mozdit-network
|
|
restart: always
|
|
logging:
|
|
driver: "json-file"
|
|
options:
|
|
max-size: "10m"
|
|
max-file: "3"
|
|
|
|
# MongoDB Database
|
|
mongodb:
|
|
image: mongo:7.0
|
|
container_name: mozdit-mongodb-prod
|
|
ports:
|
|
- "127.0.0.1:27018:27017" # Belső port, nem publikus az internet felé
|
|
environment:
|
|
- MONGO_INITDB_ROOT_USERNAME=${MONGO_ROOT_USER:-admin}
|
|
# No weak default password: a missing value must fail the container loudly.
|
|
- MONGO_INITDB_ROOT_PASSWORD=${MONGO_ROOT_PASSWORD}
|
|
- MONGO_INITDB_DATABASE=mozdit
|
|
volumes:
|
|
- mongodb_data_prod:/data/db
|
|
networks:
|
|
- mozdit-network
|
|
restart: always
|
|
|
|
volumes:
|
|
mongodb_data_prod:
|
|
driver: local
|
|
|
|
networks:
|
|
mozdit-network:
|
|
driver: bridge
|