The web client for the Change Control module of a Quality Management System. Change records move through a six-state workflow with two approval gates, every decision is captured by an electronic signature, and what a user may edit depends on both their role and the record's current state.
Built with Svelte 5 and SvelteKit as a single-page application; served here by Caddy.
Caddy, with the built application copied in. It is both the web server and a
reverse proxy: it serves the static files, and it forwards everything under
/api/ to the API.
It cannot work alone. There is no API and no database inside it. It needs
something reachable at API_UPSTREAM, which defaults to api:1304 — a default
that suits any Docker network whose API service is named api.
The container starts whether or not the API is there, because Caddy resolves the upstream per request rather than at boot. A missing API shows up as a 502 on the first call, not as a container that fails to start.
| Tag | Platforms |
|---|---|
1.0.0, latest | linux/amd64, linux/arm64 under one tag — docker pull resolves the right variant |
Against an API running on your host:
docker run -d --rm -p 8080:80 \
-e API_UPSTREAM=host.docker.internal:1304 \
20dumpling/ea-qms-frontend:1.0.0
Against the API's own Compose stack, joined to its network:
docker run -d --rm -p 8080:80 --network docker_default \
20dumpling/ea-qms-frontend:1.0.0
Then open http://localhost:8080.
| Variable | |
|---|---|
API_UPSTREAM | Host and port of the API. Default api:1304. Read when Caddy starts, so changing it needs a restart, not a reload |
That is the only runtime variable.
⚠ The API's URL is baked in at build time, as the relative path /api, which
is what puts the app and the API on one origin. It is not runtime-configurable —
serving the API from somewhere other than /api on the same origin means
rebuilding the image with --build-arg PUBLIC_API_URL=…. Under normal use you
want the default, and you want API_UPSTREAM instead.
/qms/ serves a blank page. That is a
rebuild, not a proxy setting.localStorage.ALLOWED_ORIGINS to the origin the browser uses, e.g.
http://localhost:8080. CORS no longer applies once the proxy puts both on one
origin, but the API logs a warning for every unrecognised Origin it sees, and
browsers send one on every POST and PUT regardless.Seeded by the API image. All four share the password DevPassw0rd!:
[email protected], [email protected], [email protected],
[email protected].
Content type
Image
Digest
sha256:6f1c318a9…
Size
23.2 MB
Last updated
11 days ago
docker pull 20dumpling/ea-qms-frontend