Clearview stack: drop ONBOARDING_* from .env

Remove the onboarding vars from the committed .env. The compose still passes
them through as ${VAR:-} (optional), so onboarding stays configurable via
Portainer without cluttering .env or warning on deploy.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Ivo Oskamp 2026-06-19 13:37:15 +02:00
parent ee66a8cfc3
commit d98239ddde
3 changed files with 4 additions and 9 deletions

View File

@ -6,7 +6,7 @@ This file documents changes on the develop branch of this project.
### Changed
- Reworked `stack/docker-compose.yml` + `.env` so the stack has **no baked default values**: every per-deployment value is required via `${VAR:?...}`, so `docker compose`/Portainer refuses to start when one is missing instead of falling back to an insecure default (the old `.env` shipped `POSTGRES_PASSWORD=clearview`). Verified: rendering fails with `required variable POSTGRES_PASSWORD is missing a value` when unset.
- All configurable values stay in the env (referenced via `${VAR:?}`); the **only** thing pinned in the compose is the Postgres image version (`postgres:16-alpine`), since the app's migrations depend on it. Postgres config (`POSTGRES_HOST`/`PORT`/`DB`/`USER`/`PASSWORD`) and `TZ` are env vars. The committed `.env` is the dev baseline (image tag, env, ports, TZ, Postgres host/port/db/user); `POSTGRES_PASSWORD` ships empty (no default — set in Portainer, else the stack won't start) and `ONBOARDING_*` are optional.
- All configurable values stay in the env (referenced via `${VAR:?}`); the **only** thing pinned in the compose is the Postgres image version (`postgres:16-alpine`), since the app's migrations depend on it. Postgres config (`POSTGRES_HOST`/`PORT`/`DB`/`USER`/`PASSWORD`) and `TZ` are env vars. The committed `.env` is the dev baseline (image tag, env, ports, TZ, Postgres host/port/db/user); `POSTGRES_PASSWORD` ships empty (no default — set in Portainer, else the stack won't start). The optional `ONBOARDING_*` vars are no longer in `.env`; the compose passes them through as `${VAR:-}` so they can still be set in Portainer when onboarding is used.
- **Per-environment naming**, driven by `CLEARVIEW_ENV`: container names become `clearview-<env>` / `clearview-postgres-<env>` / `clearview-adminer-<env>` and the Postgres data dir `/docker/appdata/clearview-<env>/postgres`, so a dev and a prod stack run side by side without name/volume clashes. The image tag stays its own variable (`CLEARVIEW_IMAGE_TAG`); Compose can't map `latest`→`prod` from a single value, so tag and env are two variables (chosen over `-latest` naming). DB DNS still uses the `postgres` service name, so `DATABASE_URL` is unaffected by the container rename.
## 2026-06-19 — Path-prefix routing support (run behind the landing proxy)

View File

@ -24,8 +24,3 @@ POSTGRES_DB=clearview
POSTGRES_USER=clearview
# No default — set this in Portainer's stack environment, or the stack won't start.
POSTGRES_PASSWORD=
# Optional: Microsoft onboarding OAuth (leave blank if unused).
ONBOARDING_CLIENT_ID=
ONBOARDING_CLIENT_SECRET=
ONBOARDING_REDIRECT_URI=

View File

@ -8,9 +8,9 @@ services:
environment:
TZ: ${TZ:?set TZ}
DATABASE_URL: postgresql://${POSTGRES_USER:?set POSTGRES_USER}:${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}@${POSTGRES_HOST:?set POSTGRES_HOST}:${POSTGRES_PORT:?set POSTGRES_PORT}/${POSTGRES_DB:?set POSTGRES_DB}
ONBOARDING_CLIENT_ID: ${ONBOARDING_CLIENT_ID}
ONBOARDING_CLIENT_SECRET: ${ONBOARDING_CLIENT_SECRET}
ONBOARDING_REDIRECT_URI: ${ONBOARDING_REDIRECT_URI}
ONBOARDING_CLIENT_ID: ${ONBOARDING_CLIENT_ID:-}
ONBOARDING_CLIENT_SECRET: ${ONBOARDING_CLIENT_SECRET:-}
ONBOARDING_REDIRECT_URI: ${ONBOARDING_REDIRECT_URI:-}
depends_on:
postgres:
condition: service_healthy