The all-in-one image builds from the project root, and Docker only reads .dockerignore from the context root — so the ones under "API Server" and "Web App" never applied to it and every AIO build shipped the whole tree, "Phone App/build" included. A root .dockerignore allow-lists the paths that build actually copies. The dev split stack passed neither PB_BOOTSTRAP nor the SUPERADMIN vars, so it created the schema and then no user to log in with. It passes them now, and .env.example says so. WEBAPP_URL was never set anywhere, leaving the panel status page probing localhost:8090 — itself — and always reporting the Web App as down. Each compose file now points it at wherever the Web App really is, and the BFF grew a real /healthz instead of letting the SPA fallback answer probes with index.html and look healthy no matter what. In the AIO, PocketBase and the API Server drop to an unprivileged user; only nginx stays root to bind :80. The entrypoint takes ownership of the two volumes first, so data written by the old root-only image stays writable. All three images carry a HEALTHCHECK, every compose file declares one too (so depends_on still gates against an older pulled image), and web-app waits for the API Server to be serving rather than merely started. Also: pinned alpine/golang/node and PocketBase 0.39.11, so a rebuild months from now produces the same image; nginx forwards WebSocket upgrades instead of stripping them, with the map in http.d where Alpine actually reads it; and a .gitattributes keeps entrypoint.sh on LF, because a CRLF shebang from a Windows clone fails at container start with "no such file or directory". Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
23 lines
649 B
Plaintext
23 lines
649 B
Plaintext
# Keep the build context small and avoid leaking local artifacts/secrets.
|
|
.env
|
|
*.log
|
|
bin/
|
|
tmp/
|
|
|
|
# Panel source & tooling — the built output in internal/api/dist is committed
|
|
# and embedded at compile time, so the source tree is not needed in the image.
|
|
# Excluding all of panel/ (not just its node_modules) also keeps edits to the
|
|
# panel source from invalidating the `COPY . .` layer on every rebuild.
|
|
panel/
|
|
|
|
# Runtime state written by a local (non-container) run. In the image this file
|
|
# lives on the /data volume, so a copy from the host would only bust the cache.
|
|
plugins.json
|
|
|
|
# VCS / editor noise
|
|
.git/
|
|
.gitignore
|
|
.claude/
|
|
.vscode/
|
|
.idea/
|