This commit introduces a new feature for global role synchronization in Discord, allowing for periodic reconciliation of managed roles. A new environment variable, `DISCORD_GLOBAL_SYNC_INTERVAL`, has been added to configure the synchronization interval, defaulting to 5 minutes. The `RoleWorker` has been updated to schedule global sync jobs, ensuring that missing managed roles are restored and extra assignments are removed without affecting unrelated server roles. Database schema changes support the new synchronization logic, and tests have been added to validate the functionality of the global reconciliation process.
3.9 KiB
Coolify deployment
Resource
Create a project and add this repository as a Docker Compose resource. Use the root compose.yaml. Assign the public domain to the web service on port 80.
Do not add custom Compose networks or Traefik labels. Coolify creates the deployment network and connects its proxy. The web service proxies /api and the SSE stream to api; api and db remain internal.
Required variables
Set these as production variables in Coolify:
PUBLIC_URL=https://mix.example.comPOSTGRES_DBPOSTGRES_USERPOSTGRES_PASSWORD— generate a unique valueDATABASE_URL=postgres://<user>:<password>@db:5432/<database>?sslmode=disableDISCORD_CLIENT_IDDISCORD_CLIENT_SECRETDISCORD_REDIRECT_URL=https://mix.example.com/api/auth/discord/callbackADMIN_DISCORD_IDS— comma-separated Discord user IDsDISCORD_BOT_TOKEN— bot token from the Developer Portal; never expose it to the frontendDISCORD_ANNOUNCEMENT_CHANNEL_ID— numeric ID of the text channel for new mix announcementsDISCORD_ANNOUNCEMENT_LOCALE=ru— announcement language,ruorenDISCORD_GUILD_ID— numeric ID of the server where roster roles are synchronizedDISCORD_GLOBAL_SYNC_INTERVAL=5m— interval for exact managed-role reconciliation
Do not copy production values into .env in the repository.
Discord
In the Discord Developer Portal:
- Create an application.
- Add the exact production callback URL.
- Use only the
identifyOAuth scope. - Store the client secret only in Coolify.
For event announcements, add the bot to the server with the bot scope. In the announcement channel grant only View Channel, Send Messages, Embed Links, and Mention Everyone. Copy the channel ID with Discord Developer Mode and store it in DISCORD_ANNOUNCEMENT_CHANNEL_ID. The bot token is separate from the OAuth client secret and must also remain only in Coolify. If either the token or channel ID is omitted, announcements stay disabled.
For role synchronization, grant the bot Manage Roles, copy the server ID to DISCORD_GUILD_ID, and place the bot's own role above all roles it creates. The bot creates event-specific RSVP status roles, global Tank, Damage, and Support roles, plus temporary team and team-captain roles after roster confirmation. It does not need Administrator. Role synchronization stays disabled when DISCORD_GUILD_ID is empty.
Enable Server Members Intent under Developer Portal → Bot → Privileged Gateway Intents. The five-minute global reconciliation uses the guild member inventory to restore missing managed assignments and remove extra managed assignments without touching unrelated server roles. Message Content Intent and Presence Intent remain disabled.
Storage and backups
PostgreSQL uses the postgres_data named volume. Confirm that Coolify recognizes it as persistent storage before accepting users.
Persistent storage is not a backup. Schedule an encrypted pg_dump to storage outside the VPS, define retention, and test restoration before launch. Back up before schema migrations.
Deployment verification
- Ensure
migrationsexits successfully. - Ensure
db,api, andwebbecome healthy. - Open
/healththrough the public domain. - Complete Discord login and verify the admin role.
- Create a test event and RSVP.
- Confirm the bot posts one announcement with an
@everyonemention and a working registration button. - Confirm test rosters and verify dynamic team, captain, and slot roles in Discord.
- Rename a live team and verify both managed role names change.
- Complete or cancel the test event and verify temporary roles are removed.
- Restart/redeploy and confirm the event remains.
- Verify SSE remains connected through the proxy.
Rollback application images only when the database migration is backward-compatible. Otherwise restore the matching database backup.