From f144261a1affb6d98a6ed146cec796fb5c5b31b4 Mon Sep 17 00:00:00 2001 From: Ivo Oskamp Date: Fri, 19 Jun 2026 13:19:33 +0200 Subject: [PATCH] Clearview stack: require env values (no defaults) + per-env naming Remove silent defaults (every per-deploy value via ${VAR:?}), hardcode the fixed structural constants in compose, and key container names + the Postgres data dir off CLEARVIEW_ENV (dev/prod) so dev and prod stacks coexist. Image tag stays CLEARVIEW_IMAGE_TAG (dev/latest). Co-Authored-By: Claude Opus 4.8 (1M context) --- docs/changelog-develop.md | 7 +++++++ stack/.env | 35 ++++++++++++++++++++++++----------- stack/docker-compose.yml | 30 +++++++++++++++--------------- 3 files changed, 46 insertions(+), 26 deletions(-) diff --git a/docs/changelog-develop.md b/docs/changelog-develop.md index 404dfb1..5223139 100644 --- a/docs/changelog-develop.md +++ b/docs/changelog-develop.md @@ -2,6 +2,13 @@ This file documents changes on the develop branch of this project. +## 2026-06-19 — Stack: no silent defaults + per-environment naming + +### Changed +- Reworked `stack/docker-compose.yml` + `.env` so the stack has **no baked default values**: every per-deployment value is required via `${VAR:?...}`, so `docker compose`/Portainer refuses to start when one is missing instead of falling back to an insecure default (the old `.env` shipped `POSTGRES_PASSWORD=clearview`). Verified: rendering fails with `required variable POSTGRES_PASSWORD is missing a value` when unset. +- Fixed structural constants are now hardcoded in the compose file (DB name/user `clearview`, internal host `postgres`, port `5432`, `TZ`), not env vars. The committed `.env` only carries the per-deploy values: `CLEARVIEW_IMAGE_TAG` (dev|latest), `CLEARVIEW_ENV` (dev|prod) and the host ports. Secrets (`POSTGRES_PASSWORD`, optional `ONBOARDING_*`) are documented but intentionally not shipped — they must be set in Portainer's stack environment. +- **Per-environment naming**, driven by `CLEARVIEW_ENV`: container names become `clearview-` / `clearview-postgres-` / `clearview-adminer-` and the Postgres data dir `/docker/appdata/clearview-/postgres`, so a dev and a prod stack run side by side without name/volume clashes. The image tag stays its own variable (`CLEARVIEW_IMAGE_TAG`); Compose can't map `latest`→`prod` from a single value, so tag and env are two variables (chosen over `-latest` naming). DB DNS still uses the `postgres` service name, so `DATABASE_URL` is unaffected by the container rename. + ## 2026-06-19 — Path-prefix routing support (run behind the landing proxy) ### Added diff --git a/stack/.env b/stack/.env index 5d63c08..4ce8514 100644 --- a/stack/.env +++ b/stack/.env @@ -1,15 +1,28 @@ +# Clearview stack environment. +# +# Only the values that genuinely differ per deployment live here; everything +# structural (DB name/user, internal host/port, TZ) is fixed in the compose +# file. The compose uses ${VAR:?...} for required values, so the stack REFUSES +# to start when a required variable is missing — there are no silent defaults. +# +# This file is the dev baseline. For the prod stack, override CLEARVIEW_IMAGE_TAG +# (latest), CLEARVIEW_ENV (prod) and the ports in Portainer's stack environment. +# +# CLEARVIEW_IMAGE_TAG drives the image tag; CLEARVIEW_ENV drives the container +# names (clearview-, clearview-postgres-, clearview-adminer-) and +# the Postgres data dir (/docker/appdata/clearview-/postgres), so a dev and +# a prod stack run side by side without clashing. + CLEARVIEW_IMAGE_TAG=dev +CLEARVIEW_ENV=dev CLEARVIEW_PORT=8080 -TZ=Europe/Amsterdam - -POSTGRES_HOST=postgres -POSTGRES_PORT=5432 -POSTGRES_DB=clearview -POSTGRES_USER=clearview -POSTGRES_PASSWORD=clearview - ADMINER_PORT=8081 -ONBOARDING_CLIENT_ID= -ONBOARDING_CLIENT_SECRET= -ONBOARDING_REDIRECT_URI= +# --- Required, NOT shipped here (set in Portainer's stack environment) ------- +# The stack will not start until POSTGRES_PASSWORD is provided. +# POSTGRES_PASSWORD=... + +# --- Optional: Microsoft onboarding OAuth (leave unset if unused) ------------ +# ONBOARDING_CLIENT_ID=... +# ONBOARDING_CLIENT_SECRET=... +# ONBOARDING_REDIRECT_URI=... diff --git a/stack/docker-compose.yml b/stack/docker-compose.yml index 8a74098..4206cfe 100644 --- a/stack/docker-compose.yml +++ b/stack/docker-compose.yml @@ -1,13 +1,13 @@ services: clearview: - image: gitea.oskamp.info/ivooskamp/clearview:${CLEARVIEW_IMAGE_TAG} - container_name: clearview + image: gitea.oskamp.info/ivooskamp/clearview:${CLEARVIEW_IMAGE_TAG:?set CLEARVIEW_IMAGE_TAG to dev or latest} + container_name: clearview-${CLEARVIEW_ENV:?set CLEARVIEW_ENV to dev or prod} restart: unless-stopped ports: - - "${CLEARVIEW_PORT}:80" + - "${CLEARVIEW_PORT:?set CLEARVIEW_PORT}:80" environment: - TZ: ${TZ} - DATABASE_URL: postgresql://${POSTGRES_USER}:${POSTGRES_PASSWORD}@${POSTGRES_HOST}:${POSTGRES_PORT}/${POSTGRES_DB} + TZ: Europe/Amsterdam + DATABASE_URL: postgresql://clearview:${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}@postgres:5432/clearview ONBOARDING_CLIENT_ID: ${ONBOARDING_CLIENT_ID} ONBOARDING_CLIENT_SECRET: ${ONBOARDING_CLIENT_SECRET} ONBOARDING_REDIRECT_URI: ${ONBOARDING_REDIRECT_URI} @@ -17,17 +17,17 @@ services: postgres: image: postgres:16-alpine - container_name: clearview-postgres + container_name: clearview-postgres-${CLEARVIEW_ENV:?set CLEARVIEW_ENV to dev or prod} restart: unless-stopped environment: - POSTGRES_DB: ${POSTGRES_DB} - POSTGRES_USER: ${POSTGRES_USER} - POSTGRES_PASSWORD: ${POSTGRES_PASSWORD} - TZ: ${TZ} + POSTGRES_DB: clearview + POSTGRES_USER: clearview + POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD} + TZ: Europe/Amsterdam volumes: - - /docker/appdata/clearview/postgres:/var/lib/postgresql/data + - /docker/appdata/clearview-${CLEARVIEW_ENV}/postgres:/var/lib/postgresql/data healthcheck: - test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER} -d ${POSTGRES_DB}"] + test: ["CMD-SHELL", "pg_isready -U clearview -d clearview"] interval: 10s timeout: 5s retries: 5 @@ -35,12 +35,12 @@ services: adminer: image: adminer:4-standalone - container_name: clearview-adminer + container_name: clearview-adminer-${CLEARVIEW_ENV:?set CLEARVIEW_ENV to dev or prod} restart: unless-stopped depends_on: postgres: condition: service_healthy ports: - - "${ADMINER_PORT}:8080" + - "${ADMINER_PORT:?set ADMINER_PORT}:8080" environment: - ADMINER_DEFAULT_SERVER: ${POSTGRES_HOST} + ADMINER_DEFAULT_SERVER: postgres