The API Server tells a charger to dial the host it was itself asked on. The panel asks through the Web App, so the address handed out is the Web App's — which proxied /api/ and nothing else, and answered the WebSocket handshake at /ocpp/ with index.html. A charger pointed at the endpoint the screen showed could never connect to it, and the screen went on saying "Not connected" without a hint as to why. Both front doors now carry /ocpp/ through to the API Server: the BFF via the same reverse proxy, which relays the 101 by hijacking, and the all-in-one image's nginx via a location of its own, with timeouts long enough for a session that is idle between heartbeats. The proxied hop also has to say how the client arrived, since the API Server reads X-Forwarded-Proto to decide a charger reached it over TLS. That header is set from this server's own connection and overwrites whatever came in: believing a client on that point would let a plaintext charger claim wss and walk past OCPP_REQUIRE_TLS. TRUST_FORWARDED_PROTO opts into the inbound value for the one deployment where it is true — TLS ending at a proxy in front of the stack. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
69 lines
3.6 KiB
Bash
69 lines
3.6 KiB
Bash
# Copy to .env and fill in. Used by the root docker-compose.yml.
|
|
|
|
# --- PocketBase superuser (also used by the API Server to authenticate) ------
|
|
PB_ADMIN_EMAIL=admin@example.com
|
|
PB_ADMIN_PASSWORD=change-me-long-password
|
|
|
|
# --- DriverVault super-admin (app login) -------------------------------------
|
|
# The first application user, created by the API Server on boot with role
|
|
# "superadmin" if no user with this email exists yet. Leave these blank and the
|
|
# schema is still created but no user is, leaving a stack you cannot log into.
|
|
DRIVERVAULT_SUPERADMIN_EMAIL=owner@example.com
|
|
DRIVERVAULT_SUPERADMIN_PASSWORD=change-me-long-password
|
|
DRIVERVAULT_SUPERADMIN_NAME=Administrator
|
|
|
|
# Schema creation/reconcile on boot. Leave this true: a release can add
|
|
# collections or fields the server needs, and a stack that skips the bootstrap
|
|
# never gets them. (The API Server creates app_settings, which holds the plugin
|
|
# settings, on demand — but only that one.) Set false only for a database you
|
|
# know already matches the release.
|
|
PB_BOOTSTRAP=true
|
|
|
|
# --- API Server -------------------------------------------------------------
|
|
# Allowed CORS origin(s) for the web app (match WEB_PORT / your public URL).
|
|
# Native mobile apps are not subject to CORS.
|
|
CORS_ALLOW_ORIGINS=http://localhost:8090
|
|
AUTH_USERS_COLLECTION=users
|
|
|
|
# --- EV charging control (Anker Solix, OCPP) ---------------------------------
|
|
# Only relevant when a charger is set to own/proxy control mode. The charger
|
|
# dials in to /ocpp/{serial} on the API Server port, carrying its control token
|
|
# in an OCPP Basic-auth header — which a plaintext ws:// would expose, so
|
|
# non-TLS connections are rejected by default. This dev stack serves plain
|
|
# HTTP: either terminate TLS in front of it and set OCPP_PUBLIC_URL to the
|
|
# public wss:// base, or set OCPP_REQUIRE_TLS=false on a trusted network.
|
|
OCPP_REQUIRE_TLS=true
|
|
OCPP_PUBLIC_URL=
|
|
# The charger can dial either door: the API Server port directly, or the Web
|
|
# App port, whose BFF now proxies /ocpp/ through to it. The endpoint the panel
|
|
# shows is the API Server port only when OCPP_PUBLIC_URL says so — left blank it
|
|
# is whichever host the panel itself was reached on, which is the Web App.
|
|
# TRUST_FORWARDED_PROTO lets the BFF pass an inbound X-Forwarded-Proto to the
|
|
# API Server: needed when TLS ends at a proxy in front of the stack and
|
|
# OCPP_REQUIRE_TLS stays on, and unsafe otherwise, since the header is then
|
|
# whatever the client said it was.
|
|
TRUST_FORWARDED_PROTO=false
|
|
|
|
# --- Host port mappings (optional; defaults shown) --------------------------
|
|
PB_PORT=8070
|
|
API_PORT=8080
|
|
WEB_PORT=8090
|
|
|
|
# --- Web App build -----------------------------------------------------------
|
|
# Leave empty so the browser uses same-origin /api (proxied by the BFF).
|
|
VITE_API_BASE=
|
|
|
|
# --- Settings the API Server panel can also change ---------------------------
|
|
# The panel's Settings screens apply these immediately, but only for the life of
|
|
# the container — the values below are re-applied on every restart and win. Set
|
|
# them here to make a change permanent.
|
|
# POCKETBASE_URL where the API Server looks for the database. Defaults to
|
|
# the bundled pocketbase service; set it to reach one
|
|
# outside this stack.
|
|
# WEBAPP_URL the Web App address the panel status page probes. It is
|
|
# a container-to-container call, so it must be reachable
|
|
# from the API Server, not from your browser.
|
|
# CORS_ALLOW_ORIGINS browser origins allowed to call the API Server directly.
|
|
# POCKETBASE_URL=http://pocketbase:8070
|
|
# WEBAPP_URL=http://web-app:8090
|