accounts-service returned avatar_url built from the internal S3_ENDPOINT
(http://minio:9000/<bucket>), which browsers cannot resolve, so avatars never
rendered and the re-crop fetch failed. MinIO is intentionally not exposed.
Add a public GET /media/{key} read route in accounts-service (behind the
gateway internal-key guard, no identity required so anonymous profile pages
work) that streams the object out of private MinIO. Introduce
AVATAR_PUBLIC_BASE_URL so the browser-facing prefix is decoupled from the
internal endpoint; prod sets it to the same-origin /api/media, gateway routes
the media segment to accounts.
minio/minio and minio/mc are no longer pullable from Docker Hub; use
quay.io/minio/minio for both the server and the one-shot bucket-init step
(mc ships bundled inside the minio image).
Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
Multi-stage Dockerfiles for accounts-service/configs-service/gateway, a
docker-compose.prod.yml wiring fresh Postgres+MinIO+the three services on a
private network, nginx site templates for visual.loki-code.dev (static SPA +
/api proxy) and bekend.loki-code.dev (full gateway proxy for the mod), and
idempotent setup.sh/deploy.sh scripts for the VDS.
Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ