Deployment
Live: https://gdocs.gstack.esempla.systems. Rulează pe caseta AWS partajată gStack (edge nginx + rețea gstack-web + realm Keycloak comun).
Imagini
Section titled “Imagini”Două imagini (ca gnotify/interdictii), în registry-ul GitLab:
registry.esempla.systems/govtech/gstack/gdocs:backend-0.0.1— jar Spring Boot (Dockerfile.backend).registry.esempla.systems/govtech/gstack/gdocs:frontend-0.0.1— nginx servindtarget/classes/static, proxy/api,/management,/oauth2,/login→gdocs-backend:8095(nginx/frontend.conf).
docker-compose-server.yml rulează frontend + backend + postgres pe rețeaua internal + externă gstack-web; secretele vin dintr-un .env alăturat (POSTGRES_PASSWORD, JWT_SECRET).
Build (offline, fără JDK local)
Section titled “Build (offline, fără JDK local)”Backend — container maven, se sare peste client + teste:
docker run --rm --user "$(id -u):$(id -g)" -e HOME=/tmp \ -v "$PWD":/app -w /app -v /home/katko/.m2:/m2 \ maven:3.9-eclipse-temurin-21 \ mvn -ntp -Dmaven.repo.local=/m2 -Pprod -DskipTests \ -Dmaven.test.skip=true -Dskip.npm -Dskip.installnodenpm clean packageFrontend — ng build --configuration production. optimization.fonts trebuie false în angular.json (config production): altfel inlining-ul Google Fonts eșuează offline (getaddrinfo EAI_AGAIN fonts.googleapis.com) → index.html nu se generează → nginx servește pagina implicită.
Deploy pe casetă
Section titled “Deploy pe casetă”SSH ubuntu@gstack.tech.esempla.systems (cheie ~/.ssh/gstack-demo.pem; rețea instabilă → bucle de retry). Tipar save | gzip | ssh | load + recreate:
docker save gdocs-backend:latest gdocs-frontend:latest | gzip | \ ssh -i ~/.ssh/gstack-demo.pem ubuntu@gstack.tech.esempla.systems 'gunzip | docker load'ssh ... 'cd ~/gdocs && docker compose -f docker-compose-server.yml up -d --force-recreate'Edge & TLS
Section titled “Edge & TLS”vhost nginx edge → serviciul gdocs-frontend prin rețeaua gstack-web; TLS prin cert-ul partajat *.gstack.esempla.systems. CSP setat în application.yml (include blob: pentru previzualizare).
Autentificare
Section titled “Autentificare”JWT user/parolă activ implicit. Keycloak OIDC (realm comun, profil oidc) opt-in via env. API-ul mașină folosește client-credentials Keycloak (scope → nivel de acces).
Verificare
Section titled “Verificare”curl -s https://gdocs.gstack.esempla.systems/management/health # {"status":"UP"}curl -s -X POST https://gdocs.gstack.esempla.systems/api/authenticate \ -H 'Content-Type: application/json' -d '{"username":"admin","password":"admin"}'Backing services
Section titled “Backing services”Postgres (compose). MinIO/S3, Elasticsearch, RabbitMQ — declarate în stack; MinIO implicit pentru bucket-urile fără conexiune proprie (vezi Multi-Tenancy).