services: api-server: build: context: . dockerfile: Dockerfile image: drivervault-api container_name: drivervault-api restart: unless-stopped ports: - "${API_PORT:-8080}:8080" environment: # Container always listens on 8080; map the host port above. API_ADDR: ":8080" # External PocketBase instance (all DB access goes through this server). POCKETBASE_URL: "${PB_URL:-http://10.2.1.10:8027}" # Superuser service account. Leave unset and the server still starts — a # superadmin can configure it from the panel; management endpoints 503 until then. POCKETBASE_ADMIN_EMAIL: "${PB_ADMIN_EMAIL}" POCKETBASE_ADMIN_PASSWORD: "${PB_ADMIN_PASSWORD}" # Probed by the panel status page. Point it at wherever the Web App runs # as seen from THIS container — the default (localhost:8090) is this # container itself, so it must be set for the status page to be accurate. WEBAPP_URL: "${WEBAPP_URL:-http://host.docker.internal:8090}" # Browser origins allowed by CORS (native apps are exempt). Point this at # the Web App origin; add http://localhost:5173 when running Vite in dev. CORS_ALLOW_ORIGINS: "${CORS_ALLOW_ORIGINS:-http://localhost:8090}" AUTH_USERS_COLLECTION: "${AUTH_USERS_COLLECTION:-users}" # OCPP charger control (Anker Solix). Chargers are rejected unless they # connect over TLS; set false only when terminating TLS elsewhere or for # local dev on a trusted network. OCPP_PUBLIC_URL overrides the ws(s):// # base derived from request headers (set it when behind a reverse proxy). OCPP_REQUIRE_TLS: "${OCPP_REQUIRE_TLS:-true}" OCPP_PUBLIC_URL: "${OCPP_PUBLIC_URL:-}" extra_hosts: # Makes host.docker.internal resolve on Linux too (Docker Desktop provides # it already), so the WEBAPP_URL default above can reach a Web App running # on the host rather than in this compose file. - "host.docker.internal:host-gateway" healthcheck: test: ["CMD-SHELL", "wget -qO- http://127.0.0.1:8080/healthz || exit 1"] interval: 10s timeout: 3s retries: 12 start_period: 20s