Files
DriverVault/Docker-AIO/docker-compose.prod.yml
tajniak81andClaude Opus 5 9258532952 Docker: give the panel's settings screens a permanent home in .env
ee4ac44 removed the api_data volume, which left the panel's Settings ->
PocketBase and Settings -> Web App screens with nowhere to persist to: they
apply at runtime and the container environment wins again on restart. That
is only acceptable if the environment is actually reachable by an operator,
and for two of those keys it was not - WEBAPP_URL was hardcoded in all four
compose files, and POCKETBASE_URL in the two multi-container ones, so
there was no supported way to change them at all.

Both are now ${VAR:-default} with the previous hardcoded value as the
default, so nothing moves for an existing .env while the keys become
settable. CORS_ALLOW_ORIGINS and the admin credentials already were.

The env examples grow a section naming every setting the panel can also
change, saying plainly that the panel's version lasts only for the life of
the container, and giving the commented-out line to make it stick. It also
records the trap in WEBAPP_URL: it is a container-to-container call, so it
has to be reachable from the API Server rather than from a browser, which
is why the default is a service name and not localhost. POCKETBASE_URL is
described as repointable in the multi-container stack and left alone in the
AIO image, where it addresses that container's own PocketBase.

Also dropped two leftovers from when there were two volumes: the storage
sections still said "either".

Checked by parsing all five compose files and asserting each interpolation
default matches the value it replaced, so this cannot have moved a default
by accident. go build and go test ./... still pass (untouched here). Not
verified: no Docker CLI, so no `docker compose config` render and no build.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 18:38:48 +02:00

68 lines
3.6 KiB
YAML

name: drivervault-aio
# Production all-in-one — pulls the prebuilt image from the registry instead of
# building. One container runs PocketBase + API Server + Web App (nginx).
# Everything an operator needs to set lives in .env.
#
# 1. cp .env.prod.example .env (then edit it)
# 2. docker compose -f docker-compose.prod.yml pull
# 3. docker compose -f docker-compose.prod.yml up -d
#
# On first boot PocketBase upserts the superuser from PB_ADMIN_*, and the API
# Server creates any missing collections and the DriverVault super-admin from
# DRIVERVAULT_SUPERADMIN_*. Both steps are idempotent.
services:
drivervault:
image: "${AIO_IMAGE:-10.2.1.10:5500/admin/drivervault-aio:latest}"
container_name: drivervault-aio
restart: unless-stopped
environment:
# Superuser (also used by the API Server to authenticate to PocketBase).
PB_ADMIN_EMAIL: "${PB_ADMIN_EMAIL:?set PB_ADMIN_EMAIL in .env}"
PB_ADMIN_PASSWORD: "${PB_ADMIN_PASSWORD:?set PB_ADMIN_PASSWORD in .env}"
# Match CORS to the web origin (only used if a browser calls the API directly).
CORS_ALLOW_ORIGINS: "${CORS_ALLOW_ORIGINS:-http://localhost:8090}"
# Probed by the panel status page. nginx serves the Web App on port 80
# inside this container, so plain localhost:8090 would never answer.
# Override WEBAPP_URL in .env to make a change from the panel's Web App
# screen permanent; the panel alone only holds it for the container's life.
WEBAPP_URL: "${WEBAPP_URL:-http://127.0.0.1:80}"
# Schema + super-admin bootstrap (idempotent). Leave this ON: a release can
# add collections or fields the server needs, and a stack that skips the
# bootstrap never gets them. The API Server self-heals exactly one thing —
# app_settings, the collection holding the plugin settings, which it
# creates on demand because it cannot serve the plugin panel without it.
# Every other schema change still depends on this flag. Turn it off only
# for a database you know already matches the release.
PB_BOOTSTRAP: "${PB_BOOTSTRAP:-true}"
DRIVERVAULT_SUPERADMIN_EMAIL: "${DRIVERVAULT_SUPERADMIN_EMAIL:-}"
DRIVERVAULT_SUPERADMIN_PASSWORD: "${DRIVERVAULT_SUPERADMIN_PASSWORD:-}"
DRIVERVAULT_SUPERADMIN_NAME: "${DRIVERVAULT_SUPERADMIN_NAME:-Administrator}"
# OCPP charger control (Anker Solix). This image serves plain HTTP, so a
# charger can only connect when TLS is terminated in front of it (set
# OCPP_PUBLIC_URL to the public wss:// base) — or, on a trusted network,
# with OCPP_REQUIRE_TLS=false.
OCPP_REQUIRE_TLS: "${OCPP_REQUIRE_TLS:-true}"
OCPP_PUBLIC_URL: "${OCPP_PUBLIC_URL:-}"
ports:
- "${WEB_PORT:-8090}:80" # Web App
- "${PB_PORT:-8070}:8070" # PocketBase admin UI / API
- "${API_PORT:-8080}:8080" # API Server + panel (root /) + /ocpp/{serial}
volumes:
# The only volume — named by default; set PB_DATA to a host path in .env
# for a bind mount. The API Server keeps no state on disk, so everything
# it owns (plugin settings included) is in here.
- "${PB_DATA:-pb_data}:/pb/pb_data"
healthcheck:
# All three processes must answer. Declared here as well as in the image so
# the check is visible, and works against an older pulled image.
test: ["CMD-SHELL", "wget -qO- http://127.0.0.1:8070/api/health >/dev/null && wget -qO- http://127.0.0.1:8080/healthz >/dev/null && wget -qO- http://127.0.0.1:80/healthz >/dev/null || exit 1"]
interval: 30s
timeout: 5s
retries: 3
start_period: 60s
volumes:
pb_data: