diff --git a/.claude/rules/environment-and-secrets.md b/.claude/rules/environment-and-secrets.md index 8f4e36c..3873738 100644 --- a/.claude/rules/environment-and-secrets.md +++ b/.claude/rules/environment-and-secrets.md @@ -53,3 +53,8 @@ Compose interpolation reads the deploying shell's environment before the already exports. `HOSTNAME` is the trap: it is set inside every container, including the one Coolify itself runs in, and would silently win. Hence `SERVICE_HOSTNAME` in `code-server`, `code-server-lsio` and `paseo`. + +A value stored in the Coolify app's environment, including its preview copy, +beats the `${VAR:-default}` default in `compose.yml`. Changing a default in the +repo does nothing while that stored value exists; clear it in Coolify, then +redeploy. diff --git a/.claude/skills/debug-service/SKILL.md b/.claude/skills/debug-service/SKILL.md index 4f28b03..6099459 100644 --- a/.claude/skills/debug-service/SKILL.md +++ b/.claude/skills/debug-service/SKILL.md @@ -44,7 +44,10 @@ either. 3. `get_logs` only when the resource is running; otherwise follow the returned reason and `next_tools` rather than retrying. 4. `list_env_keys` to confirm every variable in `.env.example` is set - (names only; values are never returned). + (names only; values are never returned). When a changed + `${VAR:-default}` in `compose.yml` has no effect, check here first: a value + stored in Coolify, including its preview copy, overrides the default. + Confirm the live value from the container logs. If neither server has it, the service is likely on Dokploy, which has no MCP here: ask the user to paste the container logs and deploy output. diff --git a/CLAUDE.md b/CLAUDE.md index c585952..a7a968b 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -27,6 +27,7 @@ compatibility, and do not block on Dokploy-only issues. ## Service READMEs stay inside their directory +This rule has high priority: editing one service must never redeploy another. A service's `README.md` describes that service and nothing else. It does not name, link to, or compare itself with another service, and it does not link up to the root README, CLAUDE.md or `.claude/rules/`. Shared conventions — the workspace volume @@ -48,8 +49,13 @@ Cross-cutting changes to every compose file (a new restart policy, say) are the one legitimate case where a push redeploys several services. Every Coolify app created from this repo sets its watch path to `/**`. -An app with no watch path deploys on every push to the repository — -`traffmonetizer` leaves it unset on purpose, to get restarted that often. +After creating one, check `watch_paths` with the Coolify MCP `get_application`; +`null` means the app deploys on every push to the repository. Only these are +`null` and expected — do not flag or "fix" them: + +- `traffmonetizer`, on both `miti-sg` and `miti-jp`, leaves it unset on purpose + to be restarted on every push. +- `gitea-mirror` on `miti-jp` is not a real setup; skip it. ## Service directories hold deploy files only @@ -81,7 +87,9 @@ unprompted: - **No `ports:`.** Coolify and Dokploy attach the container to their proxy network and map a domain to the internal port. Publishing a port is redundant - and would additionally expose it on the host. + and would additionally expose it on the host. Coolify's `ports_exposes` + field (often a prefilled `3000`) is never read for compose apps; the proxy + port comes from the compose `expose:` entry or the domain's port. Leave it. - **No `container_name:`.** Let Compose derive it from the directory. More generally: these files are tuned to one person's setup and are not meant