getCredentials() now fetches the hvac-backend broker login from Settings' new internal service-client endpoint (GET /internal/mqtt-client/hvac-backend, bearer SETTINGS_SECRET) — same runtime-fetch pattern as newbook.js, no broker secret in this app's .env. Env MQTT_* vars remain a dev-only override. Drops the MQTT_USERNAME/PASSWORD compose passthrough added earlier. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
42 lines
992 B
YAML
42 lines
992 B
YAML
services:
|
|
backend:
|
|
build: ./backend
|
|
security_opt:
|
|
- apparmor=unconfined
|
|
environment:
|
|
- DATABASE_URL=${DATABASE_URL}
|
|
- CENTRAL_AUTH_SECRET=${CENTRAL_AUTH_SECRET}
|
|
- SETTINGS_URL=${SETTINGS_URL}
|
|
- SETTINGS_SECRET=${SETTINGS_SECRET}
|
|
- APP_SLUG=hvac
|
|
- OFFICE_IP_CHECK=${OFFICE_IP_CHECK:-disabled}
|
|
- NEWBOOK_LOCATION_ID=${NEWBOOK_LOCATION_ID:-}
|
|
volumes:
|
|
- uploads_data:/app/uploads
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "wget -qO- http://127.0.0.1:3001/health || exit 1"]
|
|
interval: 10s
|
|
retries: 5
|
|
start_period: 20s
|
|
restart: unless-stopped
|
|
|
|
frontend:
|
|
build:
|
|
context: ./frontend
|
|
args:
|
|
VITE_HOTEL_NAME: ${VITE_HOTEL_NAME}
|
|
security_opt:
|
|
- apparmor=unconfined
|
|
ports:
|
|
- "${FRONTEND_PORT:-3080}:80"
|
|
depends_on:
|
|
backend:
|
|
condition: service_healthy
|
|
restart: unless-stopped
|
|
|
|
networks:
|
|
default:
|
|
driver: bridge
|
|
|
|
volumes:
|
|
uploads_data:
|