accounts-service returned avatar_url built from the internal S3_ENDPOINT (http://minio:9000/<bucket>), which browsers cannot resolve, so avatars never rendered and the re-crop fetch failed. MinIO is intentionally not exposed. Add a public GET /media/{key} read route in accounts-service (behind the gateway internal-key guard, no identity required so anonymous profile pages work) that streams the object out of private MinIO. Introduce AVATAR_PUBLIC_BASE_URL so the browser-facing prefix is decoupled from the internal endpoint; prod sets it to the same-origin /api/media, gateway routes the media segment to accounts.
26 lines
989 B
Text
26 lines
989 B
Text
DATABASE_URL=postgres://lovisual:lovisual@localhost:5432/accounts_db
|
|
# at least 32 random bytes, e.g. `openssl rand -hex 32`
|
|
JWT_SECRET=
|
|
PORT=8081
|
|
GRPC_PORT=50051
|
|
S3_ENDPOINT=http://localhost:9000
|
|
S3_BUCKET=lovisual-avatars
|
|
S3_ACCESS_KEY=minioadmin
|
|
S3_SECRET_KEY=minioadmin
|
|
# Optional browser-facing avatar prefix (e.g. https://visual.loki-code.dev/api/media).
|
|
# Leave empty for local dev: avatars then resolve to <S3_ENDPOINT>/<S3_BUCKET> directly.
|
|
AVATAR_PUBLIC_BASE_URL=
|
|
# Shared secret between gateway and internal services (openssl rand -hex 32)
|
|
INTERNAL_KEY=
|
|
# Secure cookie flag: leave unset (or true) in production (HTTPS); false for local HTTP dev
|
|
COOKIE_SECURE=false
|
|
# gateway
|
|
GATEWAY_PORT=8080
|
|
ACCOUNTS_HTTP_URL=http://127.0.0.1:8081
|
|
ACCOUNTS_GRPC_URL=http://127.0.0.1:50051
|
|
CONFIGS_HTTP_URL=http://127.0.0.1:8082
|
|
SITE_ORIGIN=http://localhost:5173
|
|
TRUST_PROXY=false
|
|
# configs-service
|
|
CONFIGS_DATABASE_URL=postgres://lovisual:lovisual@localhost:5432/configs_db
|
|
CONFIGS_PORT=8082
|