fix(compose): point the browser at a reachable API address in prod
Tessera CI/CD / Lint & Type Check (push) Successful in 45s
Tessera CI/CD / Tests (push) Successful in 49s
Tessera CI/CD / Build & Publish Images (push) Successful in 7s

NEXT_PUBLIC_API_URL is read by the browser, not by the web container, so
http://api:3001 could never work outside Docker. The test server had been
corrected by hand long ago; the fix never came back here, so the file we
would ship to a customer was the broken one.

Also adopts the server's TESSERA_FORCE_CHANGE default of true, so a fresh
install requires the initial admin password to be changed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-11 15:34:49 +02:00
parent 61948440ab
commit 9ca71ae92f
2 changed files with 34 additions and 2 deletions
+5 -2
View File
@@ -6,7 +6,10 @@ services:
- "3000:3000"
environment:
HOSTNAME: "0.0.0.0"
NEXT_PUBLIC_API_URL: http://api:3001
# Read by the browser, not by the web container, so it must be an address
# that resolves outside Docker. http://api:3001 only exists on the compose
# network and leaves the UI unable to reach the API.
NEXT_PUBLIC_API_URL: ${APP_URL:-http://localhost:3001}
API_INTERNAL_URL: "http://api:3001"
JWT_SECRET: ${JWT_SECRET}
networks:
@@ -33,7 +36,7 @@ services:
TESSERA_ADMIN_USER: ${TESSERA_ADMIN_USER:-admin}
TESSERA_ADMIN_EMAIL: ${TESSERA_ADMIN_EMAIL}
TESSERA_ADMIN_PASSWORD: ${TESSERA_ADMIN_PASSWORD}
TESSERA_FORCE_CHANGE: ${TESSERA_FORCE_CHANGE:-false}
TESSERA_FORCE_CHANGE: ${TESSERA_FORCE_CHANGE:-true}
TESSERA_SMTP_HOST: ${TESSERA_SMTP_HOST:-}
TESSERA_SMTP_PORT: ${TESSERA_SMTP_PORT:-587}
TESSERA_SMTP_SECURE: ${TESSERA_SMTP_SECURE:-false}