Files
oicd/docker-compose.prod.yml
stephan 1e8071b76a Add automatic database initialization on container startup
Previously, database migrations and seeding had to be run manually after
deployment, causing 500 errors on fresh deployments. This commit automates
the entire database setup process.

Changes to docker-entrypoint.sh:
- Wait for PostgreSQL to be ready before proceeding
- Run 'flask db upgrade' automatically on startup
- Check if database is already seeded (admin user exists)
- Run 'flask seed' only if needed (idempotent)
- Provides clear console output for each step

Changes to docker-compose.prod.yml:
- Bind to 0.0.0.0:5000 instead of 127.0.0.1:5000
- Allows access from reverse proxy on different machines
- Necessary for production deployments with external proxies

Benefits:
- Zero manual intervention required after 'docker-compose up'
- Idempotent: Safe to restart containers without data loss
- Works on fresh clones and existing deployments
- Clear logging for troubleshooting

Fixes:
- "relation users does not exist" error on login
- Manual migration/seeding requirement
- Network accessibility from external proxies

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 13:44:22 +01:00

55 lines
1.2 KiB
YAML

version: '3.8'
services:
# PostgreSQL Database
postgres:
image: postgres:15-alpine
container_name: oidc_postgres
env_file:
- .env
environment:
POSTGRES_DB: oidc_db
POSTGRES_USER: oidc_user
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
volumes:
- postgres_data:/var/lib/postgresql/data
- ./backups:/backups # Mount for database backups
# Only accessible internally - no port exposure
healthcheck:
test: ["CMD-SHELL", "pg_isready -U oidc_user -d oidc_db"]
interval: 10s
timeout: 5s
retries: 5
restart: unless-stopped
networks:
- oidc_network
# OIDC Identity Provider
oidc_server:
build: .
container_name: oidc_server
env_file:
- .env
# Expose only to host for your existing nginx to proxy to
ports:
- "0.0.0.0:5000:5000" # Only accessible from localhost
depends_on:
postgres:
condition: service_healthy
restart: unless-stopped
networks:
- oidc_network
logging:
driver: "json-file"
options:
max-size: "10m"
max-file: "3"
volumes:
postgres_data:
driver: local
networks:
oidc_network:
driver: bridge