# DriverVault all-in-one — production config. # Copy to .env and fill in, then: # docker compose -f docker-compose.prod.seaweedfs.yml pull # docker compose -f docker-compose.prod.seaweedfs.yml up -d # --- Registry image ---------------------------------------------------------- AIO_IMAGE=10.2.1.10:5500/admin/drivervault-aio:latest # --- PocketBase superuser (required) ----------------------------------------- # Created/updated on first boot. The API Server uses these to manage the database. PB_ADMIN_EMAIL=admin@example.com PB_ADMIN_PASSWORD=change-me-long-password # --- DriverVault super-admin (app login) ------------------------------------- # The first application user, created by the API Server on boot with role # "superadmin" if no user with this email exists yet. Leave blank to skip. DRIVERVAULT_SUPERADMIN_EMAIL=owner@example.com DRIVERVAULT_SUPERADMIN_PASSWORD=change-me-long-password DRIVERVAULT_SUPERADMIN_NAME=Administrator # Schema creation/reconcile on boot. Leave this true: a release can add # collections or fields the server needs, and a stack that skips the bootstrap # never gets them. (The API Server creates app_settings, which holds the plugin # settings, on demand — but only that one.) Set false only for a database you # know already matches the release. PB_BOOTSTRAP=true # Allowed CORS origin(s) — match your public web URL / WEB_PORT. CORS_ALLOW_ORIGINS=http://localhost:8090 # --- EV charging control (Anker Solix, OCPP) --------------------------------- # Only relevant when a charger is set to own/proxy control mode. The charger # dials in to /ocpp/{serial} on the API Server port, carrying its control token # in an OCPP Basic-auth header — which a plaintext ws:// would expose, so # non-TLS connections are rejected by default. This image serves plain HTTP, so # terminate TLS in a reverse proxy in front of it and set OCPP_PUBLIC_URL to the # public wss:// base the charger should be pointed at. Turning the check off is # for trusted networks only. OCPP_REQUIRE_TLS=true OCPP_PUBLIC_URL= # --- Host port mappings (optional; defaults shown) -------------------------- WEB_PORT=8090 PB_PORT=8070 API_PORT=8080 # --- Settings the API Server panel can also change --------------------------- # The panel's Settings screens apply these immediately, but only for the life of # the container — the value below is re-applied on every restart and wins. Set it # here to make a change permanent. (POCKETBASE_URL is fixed to this container's # own PocketBase and is not meant to be repointed.) # WEBAPP_URL the Web App address the panel status page probes; nginx # serves it on port 80 inside this container. # CORS_ALLOW_ORIGINS browser origins allowed to call the API Server directly. # WEBAPP_URL=http://127.0.0.1:80 # --- Storage ----------------------------------------------------------------- # One Docker-managed named volume by default. Set it to an absolute host path # for a bind mount, e.g. PB_DATA=/srv/drivervault/pb_data. # PB_DATA — the PocketBase database and uploads. It is the only volume in the # image: the API Server keeps no state on disk, so everything it owns (plugin # settings included) is backed up by backing up this one path. PB_DATA=pb_data # --- File storage: SeaweedFS ------------------------------------------------- # PocketBase keeps its record files — document scans, service and refill # receipts, workshop invoices, part photos — in the bucket below instead of on # PB_DATA. The database and PocketBase's own backups stay where they are. # # The credentials do double duty: they configure the SeaweedFS gateway's single # identity *and* are what PocketBase authenticates with. There are no safe # defaults, and the stack refuses to start without them. PB_S3_ACCESS_KEY= PB_S3_SECRET= # The bucket. Created on first boot by the seaweedfs-init container. PB_S3_BUCKET=drivervault # SeaweedFS ignores the region; PocketBase insists on having one. PB_S3_REGION=us-east-1 # SEAWEED_DATA — where SeaweedFS keeps the files. A Docker-managed named volume # by default; set an absolute host path for a bind mount, the same way PB_DATA # works above. Back it up alongside PB_DATA: from here on the attachments live # here, not in the database volume. SEAWEED_DATA=seaweed_data # The gateway image, pinned so a redeploy months from now brings up the same one. # SEAWEED_IMAGE=chrislusf/seaweedfs:4.45 # The S3 port is published on loopback only — the stack reaches the gateway over # the compose network, and this is for tools like aws-cli. Set # SEAWEED_S3_BIND=0.0.0.0 to expose it to other hosts, and mean it. # SEAWEED_S3_BIND=127.0.0.1 # SEAWEED_S3_PORT=8333 # Existing uploads are NOT migrated when this is switched on: PocketBase copies # nothing, so attachments made before the switch stop resolving. Read the file # storage section of README.md first.