- Replace upstream blocks with variable-based proxy_pass + Docker DNS
resolver (127.0.0.11) so nginx resolves hostnames dynamically on
each request instead of caching at startup only.
- Add explicit 'docker compose restart proxy' in CI deploy step
(belt-and-suspenders: also forces nginx restart after deploy).
- Remove no-op sed commands from CI (docker-compose.yml already uses
GitLab registry, no ghcr.io replacements needed).
Root cause: docker compose up -d only recreates containers whose image
changed. When backend container is recreated (new Docker IP), nginx
still caches the old IP → 502 Bad Gateway on /api/*
Remove Docker-in-Docker, registry push/pull, SCP complexity.
Pipeline now just SSHs into VPS and rebuilds from source.
Secrets configured:
VPS_HOST, VPS_USERNAME, VPS_SSH_KEY (file type)