Adds a puzzle-relay service (docker-compose.yml) running the same
image as php but executing app:puzzle-relay instead of php-fpm, kept
off the host network - only nginx can reach it. nginx proxies
wss://dmtools.fvandenberg.nl/puzzle-ws/ through to it
(docker/nginx/default.conf), with the public URL set via a new
.env.prod. setup.sh/restart.sh now rebuild, restart, and clean up the
new container alongside the existing ones.
Still needs "Websockets Support" enabled on the NPM proxy host for
this domain, or the upgrade headers never reach the container.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
NPM (nginx_app_1) is connected to each stack's own default network by
hand, not to a shared docker_default. Drop the unused external `proxy`
network from the compose file; nginx just lives on dmtools_default.
setup.sh now connects NPM to it (no-op if already connected) and prints
the proxy-host settings.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
DB_PORT was doing double duty - the container-internal port baked into
DATABASE_URL (must be 3306) and the host-published port in
docker-compose.yml. Setting it to 3306 for the URL made compose try to
publish host :3306, which collides with another stack's MySQL.
DATABASE_URL now hardcodes database:3306 (always correct inside the
compose network); the host publish uses ${DB_HOST_PORT:-3310}.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>