The all-in-one image builds from the project root, and Docker only reads .dockerignore from the context root — so the ones under "API Server" and "Web App" never applied to it and every AIO build shipped the whole tree, "Phone App/build" included. A root .dockerignore allow-lists the paths that build actually copies. The dev split stack passed neither PB_BOOTSTRAP nor the SUPERADMIN vars, so it created the schema and then no user to log in with. It passes them now, and .env.example says so. WEBAPP_URL was never set anywhere, leaving the panel status page probing localhost:8090 — itself — and always reporting the Web App as down. Each compose file now points it at wherever the Web App really is, and the BFF grew a real /healthz instead of letting the SPA fallback answer probes with index.html and look healthy no matter what. In the AIO, PocketBase and the API Server drop to an unprivileged user; only nginx stays root to bind :80. The entrypoint takes ownership of the two volumes first, so data written by the old root-only image stays writable. All three images carry a HEALTHCHECK, every compose file declares one too (so depends_on still gates against an older pulled image), and web-app waits for the API Server to be serving rather than merely started. Also: pinned alpine/golang/node and PocketBase 0.39.11, so a rebuild months from now produces the same image; nginx forwards WebSocket upgrades instead of stripping them, with the map in http.d where Alpine actually reads it; and a .gitattributes keeps entrypoint.sh on LF, because a CRLF shebang from a Windows clone fails at container start with "no such file or directory". Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
42 lines
1.9 KiB
Bash
42 lines
1.9 KiB
Bash
# Copy to .env and fill in. Used by the root docker-compose.yml.
|
|
|
|
# --- PocketBase superuser (also used by the API Server to authenticate) ------
|
|
PB_ADMIN_EMAIL=admin@example.com
|
|
PB_ADMIN_PASSWORD=change-me-long-password
|
|
|
|
# --- DriverVault super-admin (app login) -------------------------------------
|
|
# The first application user, created by the API Server on boot with role
|
|
# "superadmin" if no user with this email exists yet. Leave these blank and the
|
|
# schema is still created but no user is, leaving a stack you cannot log into.
|
|
DRIVERVAULT_SUPERADMIN_EMAIL=owner@example.com
|
|
DRIVERVAULT_SUPERADMIN_PASSWORD=change-me-long-password
|
|
DRIVERVAULT_SUPERADMIN_NAME=Administrator
|
|
|
|
# Set to false to skip schema creation/reconcile once the database is set up.
|
|
PB_BOOTSTRAP=true
|
|
|
|
# --- API Server -------------------------------------------------------------
|
|
# Allowed CORS origin(s) for the web app (match WEB_PORT / your public URL).
|
|
# Native mobile apps are not subject to CORS.
|
|
CORS_ALLOW_ORIGINS=http://localhost:8090
|
|
AUTH_USERS_COLLECTION=users
|
|
|
|
# --- EV charging control (Anker Solix, OCPP) ---------------------------------
|
|
# Only relevant when a charger is set to own/proxy control mode. The charger
|
|
# dials in to /ocpp/{serial} on the API Server port, carrying its control token
|
|
# in an OCPP Basic-auth header — which a plaintext ws:// would expose, so
|
|
# non-TLS connections are rejected by default. This dev stack serves plain
|
|
# HTTP: either terminate TLS in front of it and set OCPP_PUBLIC_URL to the
|
|
# public wss:// base, or set OCPP_REQUIRE_TLS=false on a trusted network.
|
|
OCPP_REQUIRE_TLS=true
|
|
OCPP_PUBLIC_URL=
|
|
|
|
# --- Host port mappings (optional; defaults shown) --------------------------
|
|
PB_PORT=8070
|
|
API_PORT=8080
|
|
WEB_PORT=8090
|
|
|
|
# --- Web App build -----------------------------------------------------------
|
|
# Leave empty so the browser uses same-origin /api (proxied by the BFF).
|
|
VITE_API_BASE=
|