From cf40cd22ef5cd44656b855396565ff6f394be802 Mon Sep 17 00:00:00 2001 From: Ricardo Mancinas Date: Tue, 11 Aug 2026 13:14:04 -0700 Subject: [PATCH] fix(deploy): stop pinning API_ORIGIN, and probe one origin not the list Two leftovers from making the browser derive the API origin. The stack env still injected API_ORIGIN from a repo secret, which pinned the origin again on every deploy and would have re-broken an https front door with mixed active content. Drop it from both env_data blocks; the secret stays, now purely as the URL the verify step probes. That verify step was also about to break on its own: WEB_ORIGIN is a comma-separated CORS list now, and `curl "$WEB_ORIGIN/version"` on a list retries thirty times and fails a deploy whose app is perfectly healthy. Probe the first entry, so keep the runner-reachable origin first in the secret. Co-Authored-By: Claude Opus 5 --- .gitea/workflows/deploy-galactus.yml | 15 ++++++++++++++- .gitea/workflows/deploy.yml | 14 +++++++++++++- 2 files changed, 27 insertions(+), 2 deletions(-) diff --git a/.gitea/workflows/deploy-galactus.yml b/.gitea/workflows/deploy-galactus.yml index 907e194..5178b20 100644 --- a/.gitea/workflows/deploy-galactus.yml +++ b/.gitea/workflows/deploy-galactus.yml @@ -281,13 +281,20 @@ jobs: standalone: true pull: true endpoint: ${{ secrets.PORTAINER_ENDPOINT_ID_GALACTUS }} + # NOTE: the block below is parsed as JSON — no comments inside it. + # + # API_ORIGIN is deliberately absent. The browser derives the API origin + # from the page it loaded (apps/web/src/lib/api.ts), so the deployment + # survives the box moving between the tailnet, the office LAN and a + # demo domain. Setting it here would pin it again and re-break an https + # front door with mixed active content. APP_API_ORIGIN_GALACTUS lives + # on only as the URL the verify step probes. env_data: | { "APP_TAG": "${{ github.event.inputs.tag }}", "API_PORT": "3001", "WEB_PORT": "3000", "S3_BUCKET": "jorgecuadros-documents", - "API_ORIGIN": "${{ secrets.APP_API_ORIGIN_GALACTUS }}", "WEB_ORIGIN": "${{ secrets.APP_WEB_ORIGIN_GALACTUS }}", "S3_ENDPOINT": "${{ secrets.APP_S3_ENDPOINT_GALACTUS }}", "DATABASE_URL": "${{ secrets.DATABASE_URL_GALACTUS }}", @@ -322,6 +329,12 @@ jobs: run: | set -e apk add --no-cache curl >/dev/null + # These secrets are CORS origin LISTS as far as the app is concerned + # (WEB_ORIGIN is comma-separated so one deployment can be reached by + # LAN IP, tailnet name and demo domain at once). A list is not a URL, + # so probe the FIRST entry — keep the runner-reachable origin first. + API_ORIGIN=${API_ORIGIN%%,*} + WEB_ORIGIN=${WEB_ORIGIN%%,*} fetch_version() { for i in $(seq 1 30); do if curl -fsS "$1/version" > "$2"; then return 0; fi diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index 4889a02..19f697a 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -253,13 +253,19 @@ jobs: type: file pull: true endpoint: ${{ secrets.PORTAINER_ENDPOINT_ID }} + # NOTE: the block below is parsed as JSON — no comments inside it. + # + # API_ORIGIN is deliberately absent. The browser derives the API origin + # from the page it loaded (apps/web/src/lib/api.ts), so the deployment + # survives the host moving. Setting it here would pin it again and + # re-break an https front door with mixed active content. APP_API_ORIGIN + # lives on only as the URL the verify step probes. env_data: | { "APP_TAG": "${{ github.event.inputs.tag }}", "API_PORT": "3001", "WEB_PORT": "3000", "S3_BUCKET": "jorgecuadros-documents", - "API_ORIGIN": "${{ secrets.APP_API_ORIGIN }}", "WEB_ORIGIN": "${{ secrets.APP_WEB_ORIGIN }}", "S3_ENDPOINT": "${{ secrets.APP_S3_ENDPOINT }}", "DATABASE_URL": "${{ secrets.DATABASE_URL }}", @@ -288,6 +294,12 @@ jobs: run: | set -e apk add --no-cache curl >/dev/null + # These secrets are CORS origin LISTS as far as the app is concerned + # (WEB_ORIGIN is comma-separated so one deployment can be reached under + # several origins at once). A list is not a URL, so probe the FIRST + # entry — keep the runner-reachable origin first. + API_ORIGIN=${API_ORIGIN%%,*} + WEB_ORIGIN=${WEB_ORIGIN%%,*} fetch_version() { for i in $(seq 1 30); do if curl -fsS "$1/version" > "$2"; then return 0; fi