JB/docker-compose.yml
JobsBoard Deployer bb4c93b11c fix(db): derive DATABASE_URL from POSTGRES_PASSWORD and harden credential sync
Stop web/scraper containers from using a stray literal DATABASE_URL in the
root .env (which desynced the postgres role password and caused persistent
'password authentication failed' errors). DATABASE_URL is now always computed
from POSTGRES_USER/POSTGRES_PASSWORD.

Also harden postgres-entrypoint.sh: log to stderr, retry on failure, and run
ALTER ROLE unconditionally so the stored password always matches the env.
2026-09-07 13:06:42 -04:00

77 lines
2.2 KiB
YAML

version: "3.8"
services:
db:
image: postgres:16-alpine
container_name: jobsboard_db
restart: always
environment:
POSTGRES_USER: "${POSTGRES_USER:-postgres}"
POSTGRES_PASSWORD: "${POSTGRES_PASSWORD:-postgres}"
POSTGRES_DB: "${POSTGRES_DB:-jobsboard}"
ports:
- "${DB_PORT:-5432}:5432"
volumes:
- postgres_data:/var/lib/postgresql/data
- ./postgres-entrypoint.sh:/usr/local/bin/postgres-entrypoint.sh:ro
entrypoint: ["/usr/local/bin/postgres-entrypoint.sh"]
command: ["postgres"]
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-postgres} -d ${POSTGRES_DB:-jobsboard}"]
interval: 5s
timeout: 5s
retries: 5
networks:
- default
- mediaserver_default
web:
build:
context: ./web
dockerfile: Dockerfile
container_name: jobsboard_web
restart: always
ports:
- "${WEB_PORT:-3000}:3000"
environment:
DATABASE_URL: "postgresql://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@db:5432/${POSTGRES_DB:-jobsboard}?schema=public"
NEXTAUTH_SECRET: "${NEXTAUTH_SECRET:-jobsboard-secret-key-for-auth-sessions}"
NEXTAUTH_URL: "${NEXTAUTH_URL:-http://localhost:3000}"
NODE_ENV: "production"
OPENROUTER_API_KEY: "${OPENROUTER_API_KEY:-}"
OPENROUTER_MODEL: "${OPENROUTER_MODEL:-google/gemini-2.5-flash}"
depends_on:
db:
condition: service_healthy
networks:
- default
- mediaserver_default
scraper:
build:
context: ./scraper
dockerfile: Dockerfile
container_name: jobsboard_scraper
restart: always
environment:
DATABASE_URL: "postgresql://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@db:5432/${POSTGRES_DB:-jobsboard}?schema=public"
SCRAPE_INTERVAL_MINUTES: "30"
SOCKS5_PROXY: "${SOCKS5_PROXY:-}"
PROXY_URL: "${PROXY_URL:-}"
PRIVADO_USER: "${PRIVADO_USER:-}"
PRIVADO_PASS: "${PRIVADO_PASS:-}"
depends_on:
db:
condition: service_healthy
networks:
- default
- mediaserver_default
volumes:
postgres_data:
networks:
default:
mediaserver_default:
external: true