Skip to content

Separate app services from the shared HTTPS proxy - #10

Merged
Eoic merged 2 commits into
masterfrom
fix/public-website-hosting
Oct 5, 2026
Merged

Eoic merged 2 commits into
masterfrom
fix/public-website-hosting

Conversation

@Eoic

@Eoic Eoic commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

App deployment currently owns the public HTTPS proxy, so restarting app services also restarts the shared entry point. Move public TLS and hostname routing to the independent papyrus-edge project. Keep the API, PowerSync and an internal Flutter web service in the app project, with explicit aliases on the external edge network and databases on the private app network. App deployments no longer require ACME contact settings or manage website files.

Validation: three focused deployment configuration tests, scoped Ruff/format/Mypy checks, ShellCheck, and the workspace Compose layout check passed. This layout is applied on Hetzner; website, app, API health, sync readiness, HTTPS and www redirects were verified. Existing database/media and certificate volumes were preserved. No migrations or full application test suite were run.

Merge this PR together with the independent website and workspace edge changes.

Copilot AI balanced review requested due to automatic review settings October 5, 2026 23:07

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T23:10:07.465022Z d6e56e8 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d6e56e8b29

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread deploy/compose.yml Outdated
- caddy-data:/data
- caddy-config:/config
- ./web:/srv/web:ro
- ./website:/srv/website:ro

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Create the website directory before mounting it

On a fresh VM that follows the documented first-deployment steps, website/ does not exist when deploy.sh starts this service. Docker Compose's short bind-mount syntax automatically creates a missing source directory; with a normal rootful Docker daemon that directory is root-owned, so the unprivileged account used by the separate website deployment cannot create release directories or update current. Explicitly create website/ with the other host directories before starting Compose (and preserve ownership for the deployment account).

Useful? React with 👍 / 👎.

@Eoic Eoic changed the title Serve the public website with automatic HTTPS Separate app services from the shared HTTPS proxy Oct 5, 2026
@Eoic
Eoic merged commit 88ab3a1 into master Oct 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants