Add production Docker compose + on-startup PocketBase bootstrap
Introduce registry-pull production stacks (docker-compose.prod.yml) for both the multi-container Docker setup and the all-in-one Docker AIO image, with everything an operator needs (superuser, super-admin, ports, volumes) driven from .env. The API Server now bootstraps PocketBase on startup: a new internal/bootstrap package (Go port of setup-pocketbase.mjs) creates missing collections, reconciles existing ones, and creates the DriverVault super-admin from DRIVERVAULT_SUPERADMIN_* when absent. Idempotent and gated by PB_BOOTSTRAP. The PocketBase superuser is still upserted by the PocketBase container, since the REST API cannot bootstrap the first superuser. Move PocketBase to port 8070 (internal + published) and the web app to 8090 across both stacks, with matching CORS defaults. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
1e76c2b7f9
commit
30c9cdebe9
17 files changed
+1042
-23
No files matched your search
@@ -288,6 +288,15 @@ The Node scripts read `POCKETBASE_URL` / `POCKETBASE_ADMIN_EMAIL` /
|
||||
> adding a new car spec field, extend `DESIRED.cars` in `setup-pocketbase.mjs`,
|
||||
> add it to `models.Car` + the record mapping in `records.go`, then rebuild.
|
||||
|
||||
> **Startup bootstrap:** the server also runs this same create/reconcile on boot
|
||||
> (`internal/bootstrap`, a Go mirror of `setup-pocketbase.mjs`) whenever a service
|
||||
> account is configured, so the Docker prod stack needs no manual setup step. It
|
||||
> is idempotent and gated by `PB_BOOTSTRAP` (default `true`; set to `false` to
|
||||
> skip). With `DRIVERVAULT_SUPERADMIN_EMAIL` + `DRIVERVAULT_SUPERADMIN_PASSWORD`
|
||||
> set it also creates the first `superadmin` user when absent. **Keep the two
|
||||
> schemas in sync:** a change to `DESIRED` in the script must be mirrored in
|
||||
> `internal/bootstrap/schema.go` (guarded by `TestSchemaConsistency`).
|
||||
|
||||
## First-time setup
|
||||
|
||||
1. **Create the PocketBase collections** (idempotent — safe to re-run on an
|
||||
|
||||
Reference in new issue
Block a user