-
Notifications
You must be signed in to change notification settings - Fork 0
Deployment
The live site, https://bookstorebd-loum.onrender.com, is one Render web service in Singapore. It serves both the API and the built site, and its database is a MongoDB Atlas cluster in the same region.
- Push to
master, or merge a pull request into it. - Render builds automatically: it installs both packages and runs
npm run build. - It starts
npm start, waits for/healthto answer, and switches traffic over.
A deploy takes a few minutes. On GitHub at the same time, CI runs the checks, CodeQL scans the code, and a Docker image of the same build is published to GitHub Packages. The service runs on Node.js 24.
The service is described in
render.yaml.
Secrets are set on the service's Environment page in Render:
| Variable | What |
|---|---|
MONGO |
The Atlas connection string |
ADMIN_EMAILS |
Who becomes an administrator |
SMTP_USER |
The Gmail address e-mails come from |
GMAIL_CLIENT_ID, GMAIL_CLIENT_SECRET, GMAIL_REFRESH_TOKEN
|
Gmail's web API, used because Render's free plan blocks SMTP |
CLOUDINARY_CLOUD_NAME, CLOUDINARY_API_KEY, CLOUDINARY_API_SECRET
|
Image hosting |
DATA_ENCRYPTION_KEY |
Encrypts phone numbers, addresses and bKash numbers. Make one with openssl rand -base64 32 and keep a copy: without it those fields cannot be read |
TURNSTILE_SITE_KEY, TURNSTILE_SECRET_KEY
|
The bot check on sign-in and sign-up, from Cloudflare Turnstile. Off until both are set |
GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET
|
Continue with Google: a "Web application" OAuth client whose redirect URI is https://bookstorebd-loum.onrender.com/api/auth/google/callback
|
Render generates JWT_SECRET. Change settings on the Environment page, not
with a Blueprint sync: the service was renamed, so a sync would create a second
service.
-
Encrypting existing records. After setting
DATA_ENCRYPTION_KEY, new and updated records are encrypted. To encrypt the ones already there, runnpm run encrypt:existinginserver/once, with the sameMONGOand key. Records are read correctly either way. -
Cold starts. On the free plan the service sleeps after about 15 idle minutes, and the next visit can take up to a minute while it wakes.
-
E-mail goes through Gmail's web API, since SMTP ports are blocked.
-
Separate databases. The team's original MernBookstore must never share this database: at start-up this version drops any index its schemas do not define.
export JWT_SECRET=$(openssl rand -hex 48)
docker compose -f docker-compose.prod.yml up --buildThis serves a real production build on http://localhost:8080.
BookStoreBD · MIT License · Questions: support.utsha@gmail.com
Using the shop
Working on it
Links