diff --git a/docs/changelog-develop.md b/docs/changelog-develop.md index e2a3830..599267f 100644 --- a/docs/changelog-develop.md +++ b/docs/changelog-develop.md @@ -6,7 +6,7 @@ This file documents changes on the develop branch of this project. ### Changed - Reworked `stack/docker-compose.yml` + `.env` so the stack has **no baked default values**: every per-deployment value is required via `${VAR:?...}`, so `docker compose`/Portainer refuses to start when one is missing instead of falling back to an insecure default (the old `.env` shipped `POSTGRES_PASSWORD=clearview`). Verified: rendering fails with `required variable POSTGRES_PASSWORD is missing a value` when unset. -- All configurable values stay in the env (referenced via `${VAR:?}`); the **only** thing pinned in the compose is the Postgres image version (`postgres:16-alpine`), since the app's migrations depend on it. Postgres config (`POSTGRES_HOST`/`PORT`/`DB`/`USER`/`PASSWORD`) and `TZ` are env vars. The committed `.env` is the dev baseline (image tag, env, ports, TZ, Postgres host/port/db/user); `POSTGRES_PASSWORD` ships empty (no default — set in Portainer, else the stack won't start) and `ONBOARDING_*` are optional. +- All configurable values stay in the env (referenced via `${VAR:?}`); the **only** thing pinned in the compose is the Postgres image version (`postgres:16-alpine`), since the app's migrations depend on it. Postgres config (`POSTGRES_HOST`/`PORT`/`DB`/`USER`/`PASSWORD`) and `TZ` are env vars. The committed `.env` is the dev baseline (image tag, env, ports, TZ, Postgres host/port/db/user); `POSTGRES_PASSWORD` ships empty (no default — set in Portainer, else the stack won't start). The optional `ONBOARDING_*` vars are no longer in `.env`; the compose passes them through as `${VAR:-}` so they can still be set in Portainer when onboarding is used. - **Per-environment naming**, driven by `CLEARVIEW_ENV`: container names become `clearview-` / `clearview-postgres-` / `clearview-adminer-` and the Postgres data dir `/docker/appdata/clearview-/postgres`, so a dev and a prod stack run side by side without name/volume clashes. The image tag stays its own variable (`CLEARVIEW_IMAGE_TAG`); Compose can't map `latest`→`prod` from a single value, so tag and env are two variables (chosen over `-latest` naming). DB DNS still uses the `postgres` service name, so `DATABASE_URL` is unaffected by the container rename. ## 2026-06-19 — Path-prefix routing support (run behind the landing proxy) diff --git a/stack/.env b/stack/.env index 9f6b2cf..bc7dd09 100644 --- a/stack/.env +++ b/stack/.env @@ -24,8 +24,3 @@ POSTGRES_DB=clearview POSTGRES_USER=clearview # No default — set this in Portainer's stack environment, or the stack won't start. POSTGRES_PASSWORD= - -# Optional: Microsoft onboarding OAuth (leave blank if unused). -ONBOARDING_CLIENT_ID= -ONBOARDING_CLIENT_SECRET= -ONBOARDING_REDIRECT_URI= diff --git a/stack/docker-compose.yml b/stack/docker-compose.yml index 69d98f1..539fe3b 100644 --- a/stack/docker-compose.yml +++ b/stack/docker-compose.yml @@ -8,9 +8,9 @@ services: environment: TZ: ${TZ:?set TZ} DATABASE_URL: postgresql://${POSTGRES_USER:?set POSTGRES_USER}:${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}@${POSTGRES_HOST:?set POSTGRES_HOST}:${POSTGRES_PORT:?set POSTGRES_PORT}/${POSTGRES_DB:?set POSTGRES_DB} - ONBOARDING_CLIENT_ID: ${ONBOARDING_CLIENT_ID} - ONBOARDING_CLIENT_SECRET: ${ONBOARDING_CLIENT_SECRET} - ONBOARDING_REDIRECT_URI: ${ONBOARDING_REDIRECT_URI} + ONBOARDING_CLIENT_ID: ${ONBOARDING_CLIENT_ID:-} + ONBOARDING_CLIENT_SECRET: ${ONBOARDING_CLIENT_SECRET:-} + ONBOARDING_REDIRECT_URI: ${ONBOARDING_REDIRECT_URI:-} depends_on: postgres: condition: service_healthy