Commit graph

3 commits

Author SHA1 Message Date
b496bde701
feat(backend): serve avatars through accounts-service behind the gateway
accounts-service returned avatar_url built from the internal S3_ENDPOINT
(http://minio:9000/<bucket>), which browsers cannot resolve, so avatars never
rendered and the re-crop fetch failed. MinIO is intentionally not exposed.

Add a public GET /media/{key} read route in accounts-service (behind the
gateway internal-key guard, no identity required so anonymous profile pages
work) that streams the object out of private MinIO. Introduce
AVATAR_PUBLIC_BASE_URL so the browser-facing prefix is decoupled from the
internal endpoint; prod sets it to the same-origin /api/media, gateway routes
the media segment to accounts.
2026-09-29 10:14:18 +02:00
d5f3b68195
fix(deploy): use quay.io/minio images (Docker Hub minio/minio delisted)
minio/minio and minio/mc are no longer pullable from Docker Hub; use
quay.io/minio/minio for both the server and the one-shot bucket-init step
(mc ships bundled inside the minio image).

Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
2026-09-28 15:08:11 +02:00
2735a1c161
deploy(backend): add prod Dockerfiles, compose stack, nginx configs, deploy scripts
Multi-stage Dockerfiles for accounts-service/configs-service/gateway, a
docker-compose.prod.yml wiring fresh Postgres+MinIO+the three services on a
private network, nginx site templates for visual.loki-code.dev (static SPA +
/api proxy) and bekend.loki-code.dev (full gateway proxy for the mod), and
idempotent setup.sh/deploy.sh scripts for the VDS.

Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
2026-09-28 14:47:53 +02:00