Docker: a build context that isn't 3.6GB, and health you can see

The all-in-one image builds from the project root, and Docker only reads
.dockerignore from the context root — so the ones under "API Server" and
"Web App" never applied to it and every AIO build shipped the whole tree,
"Phone App/build" included. A root .dockerignore allow-lists the paths that
build actually copies.

The dev split stack passed neither PB_BOOTSTRAP nor the SUPERADMIN vars, so
it created the schema and then no user to log in with. It passes them now,
and .env.example says so.

WEBAPP_URL was never set anywhere, leaving the panel status page probing
localhost:8090 — itself — and always reporting the Web App as down. Each
compose file now points it at wherever the Web App really is, and the BFF
grew a real /healthz instead of letting the SPA fallback answer probes with
index.html and look healthy no matter what.

In the AIO, PocketBase and the API Server drop to an unprivileged user;
only nginx stays root to bind :80. The entrypoint takes ownership of the
two volumes first, so data written by the old root-only image stays
writable. All three images carry a HEALTHCHECK, every compose file declares
one too (so depends_on still gates against an older pulled image), and
web-app waits for the API Server to be serving rather than merely started.

Also: pinned alpine/golang/node and PocketBase 0.39.11, so a rebuild months
from now produces the same image; nginx forwards WebSocket upgrades instead
of stripping them, with the map in http.d where Alpine actually reads it;
and a .gitattributes keeps entrypoint.sh on LF, because a CRLF shebang from
a Windows clone fails at container start with "no such file or directory".

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tajniak81
2026-08-20 17:07:52 +02:00
co-authored by Claude Opus 5
parent 9487de84b0
commit f08849e50c
16 changed files with 284 additions and 38 deletions
+15
View File
@@ -17,6 +17,10 @@ services:
# superadmin can configure it from the panel; management endpoints 503 until then.
POCKETBASE_ADMIN_EMAIL: "${PB_ADMIN_EMAIL}"
POCKETBASE_ADMIN_PASSWORD: "${PB_ADMIN_PASSWORD}"
# Probed by the panel status page. Point it at wherever the Web App runs
# as seen from THIS container — the default (localhost:8090) is this
# container itself, so it must be set for the status page to be accurate.
WEBAPP_URL: "${WEBAPP_URL:-http://host.docker.internal:8090}"
# Browser origins allowed by CORS (native apps are exempt). Point this at
# the Web App origin; add http://localhost:5173 when running Vite in dev.
CORS_ALLOW_ORIGINS: "${CORS_ALLOW_ORIGINS:-http://localhost:8090}"
@@ -27,9 +31,20 @@ services:
# base derived from request headers (set it when behind a reverse proxy).
OCPP_REQUIRE_TLS: "${OCPP_REQUIRE_TLS:-true}"
OCPP_PUBLIC_URL: "${OCPP_PUBLIC_URL:-}"
extra_hosts:
# Makes host.docker.internal resolve on Linux too (Docker Desktop provides
# it already), so the WEBAPP_URL default above can reach a Web App running
# on the host rather than in this compose file.
- "host.docker.internal:host-gateway"
volumes:
# Holds plugins.json and the .env the panel writes back — see Dockerfile.
- api_data:/data
healthcheck:
test: ["CMD-SHELL", "wget -qO- http://127.0.0.1:8080/healthz || exit 1"]
interval: 10s
timeout: 3s
retries: 12
start_period: 20s
volumes:
api_data: