# DriverVault — production stack config. # Copy to .env and fill in, then: # docker compose -f docker-compose.prod.yml pull # docker compose -f docker-compose.prod.yml up -d # --- Registry images --------------------------------------------------------- # Defaults point at the internal registry; override to pin a tag or use a mirror. PB_IMAGE=10.2.1.10:5500/admin/drivervault-pocketbase:latest API_IMAGE=10.2.1.10:5500/admin/drivervault-api-server:latest WEB_IMAGE=10.2.1.10:5500/admin/drivervault-web-app:latest # --- PocketBase superuser ---------------------------------------------------- # Created/updated on the PocketBase container's first boot. The API Server uses # these same credentials to manage the database. REQUIRED. PB_ADMIN_EMAIL=admin@example.com PB_ADMIN_PASSWORD=change-me-long-password # --- DriverVault super-admin (app login) ------------------------------------- # The first application user, created by the API Server on boot with role # "superadmin" if no user with this email exists yet. Leave blank to skip and # create the first user by hand. This is the account you log in to the web app # with — distinct from the PocketBase superuser above. DRIVERVAULT_SUPERADMIN_EMAIL=owner@example.com DRIVERVAULT_SUPERADMIN_PASSWORD=change-me-long-password DRIVERVAULT_SUPERADMIN_NAME=Administrator # Set to false to skip schema creation/reconcile once the database is set up. PB_BOOTSTRAP=true # --- API Server -------------------------------------------------------------- # Allowed CORS origin(s) for the web app (match your public URL / WEB_PORT). CORS_ALLOW_ORIGINS=http://localhost:8090 AUTH_USERS_COLLECTION=users # --- EV charging control (Anker Solix, OCPP) --------------------------------- # Only relevant when a charger is set to own/proxy control mode. The charger # dials in to /ocpp/{serial} on the API Server port, carrying its control token # in an OCPP Basic-auth header — which a plaintext ws:// would expose, so # non-TLS connections are rejected by default. Keep the default and terminate # TLS in a reverse proxy in front of this stack, setting OCPP_PUBLIC_URL to the # public wss:// base the charger should be pointed at (deriving it from request # headers is unreliable behind a proxy). Turning the check off is for trusted # networks only. OCPP_REQUIRE_TLS=true OCPP_PUBLIC_URL= # --- Ports ------------------------------------------------------------------- # WEB_PORT is the public front door (bound on all interfaces). WEB_PORT=8090 # PocketBase admin UI and the API panel are bound to localhost only by default. # Set PB_BIND / API_BIND to 0.0.0.0 to expose them on the network. PB_PORT=8070 PB_BIND=127.0.0.1 API_PORT=8080 API_BIND=127.0.0.1 # --- Storage ----------------------------------------------------------------- # Defaults are Docker-managed named volumes. To store either on a host path # instead, set it to an absolute path, e.g. PB_DATA=/srv/drivervault/pb_data. # PB_DATA — the PocketBase database and uploads. # API_DATA — the API Server's plugins.json and the .env the panel writes back # when a superadmin retargets the PocketBase connection. PB_DATA=pb_data API_DATA=api_data