# Copy to .env and fill in. Used by the Docker-AIO # docker-compose.seaweedfs.split.yml — the same stack as .env.seaweedfs.example, # with SeaweedFS running as separate master / volume / filer / S3 containers # plus the SeaweedFS admin UI. # --- Required (no defaults) -------------------------------------------------- # PocketBase superuser, also used by the API Server to authenticate. PB_ADMIN_EMAIL=admin@example.com PB_ADMIN_PASSWORD=change-me-long-password # --- DriverVault super-admin (app login) ------------------------------------- # The first application user, created by the API Server on boot with role # "superadmin" if no user with this email exists yet. Leave blank to skip. DRIVERVAULT_SUPERADMIN_EMAIL=owner@example.com DRIVERVAULT_SUPERADMIN_PASSWORD=change-me-long-password DRIVERVAULT_SUPERADMIN_NAME=Administrator # Schema creation/reconcile on boot. Leave this true: a release can add # collections or fields the server needs, and a stack that skips the bootstrap # never gets them. (The API Server creates app_settings, which holds the plugin # settings, on demand — but only that one.) Set false only for a database you # know already matches the release. PB_BOOTSTRAP=true # Allowed CORS origin(s) — match your web origin / WEB_PORT. CORS_ALLOW_ORIGINS=http://localhost:8090 # --- EV charging control (Anker Solix, OCPP) --------------------------------- # Only relevant when a charger is set to own/proxy control mode. The charger # dials in to /ocpp/{serial} on the API Server port, carrying its control token # in an OCPP Basic-auth header — which a plaintext ws:// would expose, so # non-TLS connections are rejected by default. This image serves plain HTTP: # either terminate TLS in front of it and set OCPP_PUBLIC_URL to the public # wss:// base, or set OCPP_REQUIRE_TLS=false on a trusted network. OCPP_REQUIRE_TLS=true OCPP_PUBLIC_URL= # --- Host port mappings (optional; defaults shown) -------------------------- WEB_PORT=8090 PB_PORT=8070 # API Server + its embedded web panel (served at the API root, http://host:8080/). API_PORT=8080 # --- Build args (optional) --------------------------------------------------- # Leave empty so the browser uses same-origin /api (proxied by nginx). VITE_API_BASE= # PocketBase version. The Dockerfile already pins one; set this only to build a # different version. Leaving it commented out keeps the pin (an empty value here # is passed through as-is and would resolve the latest release at build time). #PB_VERSION=0.39.11 # --- Settings the API Server panel can also change --------------------------- # The panel's Settings screens apply these immediately, but only for the life of # the container — the value below is re-applied on every restart and wins. Set it # here to make a change permanent. (POCKETBASE_URL is fixed to this container's # own PocketBase and is not meant to be repointed.) # WEBAPP_URL the Web App address the panel status page probes; nginx # serves it on port 80 inside this container. # CORS_ALLOW_ORIGINS browser origins allowed to call the API Server directly. # WEBAPP_URL=http://127.0.0.1:80 # --- File storage: SeaweedFS ------------------------------------------------- # PocketBase keeps its record files — document scans, service and refill # receipts, workshop invoices, part photos — in the bucket below instead of on # pb_data. The database and PocketBase's own backups stay where they are. # # The credentials do double duty: seaweedfs-init writes them into the filer's # IAM store as the identity named "drivervault" *and* they are what PocketBase # authenticates with. There are no safe defaults, and the stack refuses to start # without them. Change them here and restart to rotate: the seed updates the # identity in place rather than adding a second one. PB_S3_ACCESS_KEY= PB_S3_SECRET= # The bucket. Created on first boot by the seaweedfs-init container. PB_S3_BUCKET=drivervault # SeaweedFS ignores the region; PocketBase insists on having one. PB_S3_REGION=us-east-1 # The SeaweedFS image, pinned so a rebuild months from now brings up the same # one. All five SeaweedFS containers run it. # SEAWEED_IMAGE=chrislusf/seaweedfs:4.45 # --- SeaweedFS admin UI ------------------------------------------------------ # http://localhost:23646 — cluster topology, volumes, buckets, and # Object Store → Users, where further S3 identities are created and revoked. # They land in the filer's IAM store, the same one seeded above, and the gateway # picks them up without a restart. # # REQUIRED: weed disables authentication entirely when the password is empty, # and this panel can mint credentials for the bucket. SEAWEED_ADMIN_USER=admin SEAWEED_ADMIN_PASSWORD= # SEAWEED_ADMIN_PORT=23646 # --- SeaweedFS host ports (optional; defaults shown) ------------------------- # Published for aws-cli, `weed shell` and poking around while developing. The # stack itself reaches every one of these over the compose network. # Note SEAWEED_VOLUME_PORT: the volume server serves file content by id with NO # authentication, so do not carry this mapping over to a shared machine. It # lands on 8081 because API_PORT already has 8080. # SEAWEED_MASTER_PORT=9333 # SEAWEED_VOLUME_PORT=8081 # SEAWEED_FILER_PORT=8888 # SEAWEED_S3_PORT=8333 # Existing uploads are NOT migrated when this is switched on: PocketBase copies # nothing, so attachments made before the switch stop resolving. Read the file # storage section of README.md first.