# DriverVault — production stack config. # Copy to .env and fill in, then: # docker compose -f docker-compose.prod.yml pull # docker compose -f docker-compose.prod.yml up -d # --- Registry images --------------------------------------------------------- # Defaults point at the internal registry; override to pin a tag or use a mirror. PB_IMAGE=10.2.1.10:5500/admin/drivervault-pocketbase:latest API_IMAGE=10.2.1.10:5500/admin/drivervault-api-server:latest WEB_IMAGE=10.2.1.10:5500/admin/drivervault-web-app:latest # --- PocketBase superuser ---------------------------------------------------- # Created/updated on the PocketBase container's first boot. The API Server uses # these same credentials to manage the database. REQUIRED. PB_ADMIN_EMAIL=admin@example.com PB_ADMIN_PASSWORD=change-me-long-password # --- DriverVault super-admin (app login) ------------------------------------- # The first application user, created by the API Server on boot with role # "superadmin" if no user with this email exists yet. Leave blank to skip and # create the first user by hand. This is the account you log in to the web app # with — distinct from the PocketBase superuser above. DRIVERVAULT_SUPERADMIN_EMAIL=owner@example.com DRIVERVAULT_SUPERADMIN_PASSWORD=change-me-long-password DRIVERVAULT_SUPERADMIN_NAME=Administrator # Schema creation/reconcile on boot. Leave this true: a release can add # collections or fields the server needs, and a stack that skips the bootstrap # never gets them. (The API Server creates app_settings, which holds the plugin # settings, on demand — but only that one.) Set false only for a database you # know already matches the release. PB_BOOTSTRAP=true # --- API Server -------------------------------------------------------------- # Allowed CORS origin(s) for the web app (match your public URL / WEB_PORT). CORS_ALLOW_ORIGINS=http://localhost:8090 AUTH_USERS_COLLECTION=users # --- EV charging control (Anker Solix, OCPP) --------------------------------- # Only relevant when a charger is set to own/proxy control mode. The charger # dials in to /ocpp/{serial} on the API Server port, carrying its control token # in an OCPP Basic-auth header — which a plaintext ws:// would expose, so # non-TLS connections are rejected by default. Keep the default and terminate # TLS in a reverse proxy in front of this stack, setting OCPP_PUBLIC_URL to the # public wss:// base the charger should be pointed at (deriving it from request # headers is unreliable behind a proxy). Turning the check off is for trusted # networks only. OCPP_REQUIRE_TLS=true OCPP_PUBLIC_URL= # Diagnostic only. Set to 1 to log every frame the charger publishes over Anker's # cloud broker — the ones DriverVault decodes and the ones it cannot, with their # bytes. It is how an unnamed frame gets named: hold a control read open, do the # thing in the Anker app, then read the frames back out of the container log. # Leave blank on a normal stack; a triggered charger writes a line every few # seconds. ANKER_MQTT_FRAME_LOG= # The charger can dial either door: the API Server port directly, or the Web # App port, whose BFF now proxies /ocpp/ through to it. The endpoint the panel # shows is the API Server port only when OCPP_PUBLIC_URL says so — left blank it # is whichever host the panel itself was reached on, which is the Web App. # TRUST_FORWARDED_PROTO lets the BFF pass an inbound X-Forwarded-Proto to the # API Server: needed when TLS ends at a proxy in front of the stack and # OCPP_REQUIRE_TLS stays on, and unsafe otherwise, since the header is then # whatever the client said it was. TRUST_FORWARDED_PROTO=false # --- Ports ------------------------------------------------------------------- # WEB_PORT is the public front door (bound on all interfaces). WEB_PORT=8090 # PocketBase admin UI and the API panel are bound to localhost only by default. # Set PB_BIND / API_BIND to 0.0.0.0 to expose them on the network. PB_PORT=8070 PB_BIND=127.0.0.1 API_PORT=8080 API_BIND=127.0.0.1 # --- Settings the API Server panel can also change --------------------------- # The panel's Settings screens apply these immediately, but only for the life of # the container — the values below are re-applied on every restart and win. Set # them here to make a change permanent. # POCKETBASE_URL where the API Server looks for the database. Defaults to # the bundled pocketbase service; set it to reach one # outside this stack. # WEBAPP_URL the Web App address the panel status page probes. It is # a container-to-container call, so it must be reachable # from the API Server, not from your browser. # CORS_ALLOW_ORIGINS browser origins allowed to call the API Server directly. # POCKETBASE_URL=http://pocketbase:8070 # WEBAPP_URL=http://web-app:8090 # --- Storage ----------------------------------------------------------------- # One Docker-managed named volume by default. To store it on a host path # instead, set an absolute path, e.g. PB_DATA=/srv/drivervault/pb_data. # PB_DATA — the PocketBase database and uploads. It is the only volume in the # stack: the API Server keeps no state on disk, so everything it owns (plugin # settings included) is backed up by backing up this one path. PB_DATA=pb_data # --- Public hostname + TLS (docker-compose.tls.yml) -------------------------- # Only read when the TLS overlay is layered on. DV_DOMAIN must resolve to this # host from the internet, with ports 80 and 443 reaching it; the certificate is # issued automatically on first boot. Setting it also points chargers at # wss://DV_DOMAIN, which is what lets OCPP_REQUIRE_TLS stay on. DV_DOMAIN= DV_ACME_EMAIL=