- Replace upstream blocks with variable-based proxy_pass + Docker DNS
resolver (127.0.0.11) so nginx resolves hostnames dynamically on
each request instead of caching at startup only.
- Add explicit 'docker compose restart proxy' in CI deploy step
(belt-and-suspenders: also forces nginx restart after deploy).
- Remove no-op sed commands from CI (docker-compose.yml already uses
GitLab registry, no ghcr.io replacements needed).
Root cause: docker compose up -d only recreates containers whose image
changed. When backend container is recreated (new Docker IP), nginx
still caches the old IP → 502 Bad Gateway on /api/*
- Add proxy to build matrix
- Replace heredoc docker-compose generation with appleboy/scp-action
- Fix nginx upstream backend port to 3000 (matches prod WEBSERVER_PORT)
- Copy docker-compose.yml and nginx.conf from repo via SCP staging
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add nginx service with /api, /ws, and / location routing
- Move traefik labels to proxy service only (port 80)
- Remove traefik labels from backend and frontend services
- Backend routes to :3001 via nginx upstream
- WebSocket upgrade enabled for /ws path
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>