The all-in-one image builds from the project root, and Docker only reads .dockerignore from the context root — so the ones under "API Server" and "Web App" never applied to it and every AIO build shipped the whole tree, "Phone App/build" included. A root .dockerignore allow-lists the paths that build actually copies. The dev split stack passed neither PB_BOOTSTRAP nor the SUPERADMIN vars, so it created the schema and then no user to log in with. It passes them now, and .env.example says so. WEBAPP_URL was never set anywhere, leaving the panel status page probing localhost:8090 — itself — and always reporting the Web App as down. Each compose file now points it at wherever the Web App really is, and the BFF grew a real /healthz instead of letting the SPA fallback answer probes with index.html and look healthy no matter what. In the AIO, PocketBase and the API Server drop to an unprivileged user; only nginx stays root to bind :80. The entrypoint takes ownership of the two volumes first, so data written by the old root-only image stays writable. All three images carry a HEALTHCHECK, every compose file declares one too (so depends_on still gates against an older pulled image), and web-app waits for the API Server to be serving rather than merely started. Also: pinned alpine/golang/node and PocketBase 0.39.11, so a rebuild months from now produces the same image; nginx forwards WebSocket upgrades instead of stripping them, with the map in http.d where Alpine actually reads it; and a .gitattributes keeps entrypoint.sh on LF, because a CRLF shebang from a Windows clone fails at container start with "no such file or directory". Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
63 lines
3.0 KiB
YAML
63 lines
3.0 KiB
YAML
name: drivervault-aio
|
|
|
|
# Production all-in-one — pulls the prebuilt image from the registry instead of
|
|
# building. One container runs PocketBase + API Server + Web App (nginx).
|
|
# Everything an operator needs to set lives in .env.
|
|
#
|
|
# 1. cp .env.prod.example .env (then edit it)
|
|
# 2. docker compose -f docker-compose.prod.yml pull
|
|
# 3. docker compose -f docker-compose.prod.yml up -d
|
|
#
|
|
# On first boot PocketBase upserts the superuser from PB_ADMIN_*, and the API
|
|
# Server creates any missing collections and the DriverVault super-admin from
|
|
# DRIVERVAULT_SUPERADMIN_*. Both steps are idempotent.
|
|
|
|
services:
|
|
drivervault:
|
|
image: "${AIO_IMAGE:-10.2.1.10:5500/admin/drivervault-aio:latest}"
|
|
container_name: drivervault-aio
|
|
restart: unless-stopped
|
|
environment:
|
|
# Superuser (also used by the API Server to authenticate to PocketBase).
|
|
PB_ADMIN_EMAIL: "${PB_ADMIN_EMAIL:?set PB_ADMIN_EMAIL in .env}"
|
|
PB_ADMIN_PASSWORD: "${PB_ADMIN_PASSWORD:?set PB_ADMIN_PASSWORD in .env}"
|
|
# Match CORS to the web origin (only used if a browser calls the API directly).
|
|
CORS_ALLOW_ORIGINS: "${CORS_ALLOW_ORIGINS:-http://localhost:8090}"
|
|
# Probed by the panel status page. nginx serves the Web App on port 80
|
|
# inside this container, so the default (localhost:8090) would never answer.
|
|
WEBAPP_URL: "http://127.0.0.1:80"
|
|
# Schema + super-admin bootstrap on boot (idempotent). Set PB_BOOTSTRAP=false
|
|
# to skip once the database is established.
|
|
PB_BOOTSTRAP: "${PB_BOOTSTRAP:-true}"
|
|
DRIVERVAULT_SUPERADMIN_EMAIL: "${DRIVERVAULT_SUPERADMIN_EMAIL:-}"
|
|
DRIVERVAULT_SUPERADMIN_PASSWORD: "${DRIVERVAULT_SUPERADMIN_PASSWORD:-}"
|
|
DRIVERVAULT_SUPERADMIN_NAME: "${DRIVERVAULT_SUPERADMIN_NAME:-Administrator}"
|
|
# OCPP charger control (Anker Solix). This image serves plain HTTP, so a
|
|
# charger can only connect when TLS is terminated in front of it (set
|
|
# OCPP_PUBLIC_URL to the public wss:// base) — or, on a trusted network,
|
|
# with OCPP_REQUIRE_TLS=false.
|
|
OCPP_REQUIRE_TLS: "${OCPP_REQUIRE_TLS:-true}"
|
|
OCPP_PUBLIC_URL: "${OCPP_PUBLIC_URL:-}"
|
|
ports:
|
|
- "${WEB_PORT:-8090}:80" # Web App
|
|
- "${PB_PORT:-8070}:8070" # PocketBase admin UI / API
|
|
- "${API_PORT:-8080}:8080" # API Server + panel (root /) + /ocpp/{serial}
|
|
volumes:
|
|
# Named volumes by default; set PB_DATA / API_DATA to host paths in .env
|
|
# for bind mounts.
|
|
- "${PB_DATA:-pb_data}:/pb/pb_data"
|
|
# plugins.json + the .env the panel writes back.
|
|
- "${API_DATA:-api_data}:/data"
|
|
healthcheck:
|
|
# All three processes must answer. Declared here as well as in the image so
|
|
# the check is visible, and works against an older pulled image.
|
|
test: ["CMD-SHELL", "wget -qO- http://127.0.0.1:8070/api/health >/dev/null && wget -qO- http://127.0.0.1:8080/healthz >/dev/null && wget -qO- http://127.0.0.1:80/healthz >/dev/null || exit 1"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 60s
|
|
|
|
volumes:
|
|
pb_data:
|
|
api_data:
|