Compare commits

...
2 Commits
Author SHA1 Message Date
rmancinas 3b02c6944f chore(release): v1.0.17
Build and Push Images / Build jorgecuadros-api (push) Successful in 3m16s
Build and Push Images / Build jorgecuadros-web (push) Successful in 2m31s
Deploy on tag / Deploy to galactus (push) Successful in 5m33s
2026-08-11 12:56:52 -07:00
rmancinasandClaude Opus 5 683fd37b08 docs(deploy): stop documenting API_ORIGIN as required
The swarm stack still hard-failed on an unset API_ORIGIN, and both the env
template and the README told the reader to pin it — the exact habit the derived
origin was meant to end. Make it an optional override everywhere, and say that
WEB_ORIGIN is now a list.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 12:56:50 -07:00
7 changed files with 33 additions and 11 deletions
+8 -1
View File
@@ -96,7 +96,14 @@ NEXT_PUBLIC_API_ORIGIN=http://localhost:3001
```
The API loads `DATABASE_URL`, `SESSION_SECRET`, `WEB_ORIGIN`, and optional
`PORT` (default `3001`). The web app only needs `NEXT_PUBLIC_API_ORIGIN`.
`PORT` (default `3001`). `WEB_ORIGIN` is comma-separated — list every origin the
app is reached under, or credentialed fetches from the missing ones fail CORS.
The web app needs no API URL of its own: the browser derives it from the page it
loaded (same host on port `3001` over plain HTTP, or the same-origin `/api` path
behind a TLS proxy). Set `NEXT_PUBLIC_API_ORIGIN` (dev) or `API_ORIGIN` (deploy,
read at request time) only to override that — for instance when running the API
on a non-default port.
### 3. Start MySQL
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@jorgecuadros/api",
"version": "1.0.16",
"version": "1.0.17",
"private": true,
"scripts": {
"build": "nest build",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@jorgecuadros/web",
"version": "1.0.16",
"version": "1.0.17",
"private": true,
"scripts": {
"dev": "next dev -p 4500",
+15 -4
View File
@@ -8,10 +8,21 @@
APP_TAG=latest
# --- Public URLs (what the end user's BROWSER hits) ---------------------------
# API_ORIGIN is injected into the web app at runtime and used for browser fetches
# + document download links, so it must be browser-reachable (not swarm-internal).
# WEB_ORIGIN is the web app's own public origin; the API allows it via CORS.
API_ORIGIN=http://192.168.4.212:3001
# API_ORIGIN is OPTIONAL and normally left unset. The browser derives the API
# origin from the page it loaded (apps/web/src/lib/api.ts): same host on port
# 3001 over plain HTTP, or the same-origin /api path when the page is served
# over https by a TLS-terminating proxy that maps /api to the API. That is what
# lets the same deployment move — tailnet, office LAN, demo domain — untouched.
# Set it only when the API genuinely lives on a different host than the web app;
# it is used for browser fetches AND document download links, so it must be
# browser-reachable (never a swarm-internal name).
#API_ORIGIN=http://192.168.4.212:3001
#
# WEB_ORIGIN is the list of public origins the web app is reached under; the API
# allows them via CORS. COMMA-SEPARATED — one deployment is reachable under
# several origins (LAN IP, tailnet name, demo domain) and a credentialed fetch
# from an origin missing here gets no CORS headers and fails. A same-origin
# setup (web + API behind one proxy) never hits CORS at all.
WEB_ORIGIN=http://192.168.4.212:3000
# Published ports on the swarm host.
+6 -2
View File
@@ -92,8 +92,12 @@ services:
labels:
io.jorgecuadros.role: "web"
environment:
# Public API URL the browser calls (injected at runtime, see layout.tsx).
API_ORIGIN: ${API_ORIGIN:?API_ORIGIN must be set}
# OPTIONAL override of the API URL the browser calls (injected at runtime,
# see layout.tsx). Leave it unset: the browser then derives the origin
# from the page it loaded — same host on port 3001 over plain HTTP, or
# /api behind a TLS-terminating proxy. Set it only when the API really
# lives on a different host than the web app.
API_ORIGIN: ${API_ORIGIN:-}
ports:
- target: 3000
published: ${WEB_PORT:-3000}
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "jorgecuadros-platform",
"version": "1.0.16",
"version": "1.0.17",
"private": true,
"workspaces": [
"apps/*",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@jorgecuadros/database",
"version": "1.0.16",
"version": "1.0.17",
"private": true,
"main": "generated/client/index.js",
"types": "generated/client/index.d.ts",