Files
project-manager/docker-compose.yml
T
aneurinandClaude Sonnet 5 8732e0e5f5
Build / build-and-push (push) Successful in 14s
Add APP_EMAIL_ALLOWLIST gate on account creation
An optional comma-separated list of glob patterns restricting which
addresses may register, applied on top of APP_ALLOW_REGISTRATION. A
non-matching new address is silently ignored exactly like registration
being off; an address that already has an account can still sign in.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-06 21:26:33 +01:00

60 lines
2.5 KiB
YAML

name: php-project-manager
services:
app:
build: .
image: php-project-manager
ports:
- "8080:80"
environment:
APP_DEBUG: "${APP_DEBUG:-false}"
# Generated files (SQLite DB + JWT signing key) go here, on the `storage`
# volume below.
STORAGE_PATH: /var/www/storage
# Leave blank to auto-generate a secret into the storage volume on first run.
JWT_SECRET: "${JWT_SECRET:-}"
JWT_TTL: "${JWT_TTL:-86400}"
# Set to false to stop new accounts being created (existing users can
# still sign in).
APP_ALLOW_REGISTRATION: "${APP_ALLOW_REGISTRATION:-true}"
# Optional comma-separated glob allowlist for addresses that may register,
# e.g. "*@example.com, *@*.example.org". Blank means any address.
APP_EMAIL_ALLOWLIST: "${APP_EMAIL_ALLOWLIST:-}"
# 0 here (unlike the app's own default of 60) so magic links can be
# resent immediately while developing -- override if that gets in the way.
MAGIC_LINK_RESEND_SECONDS: "${MAGIC_LINK_RESEND_SECONDS:-0}"
# The SPA and the API are both served from this container.
APP_URL: "${APP_URL:-http://localhost:8080}"
# Passkeys: defaults to APP_URL's host (localhost). Browsers require
# `localhost` or a real domain over HTTPS -- a LAN IP won't work.
WEBAUTHN_RP_ID: "${WEBAUTHN_RP_ID:-}"
WEBAUTHN_RP_NAME: "${WEBAUTHN_RP_NAME:-Projects}"
# Deliver to the Mailpit catcher below; read mail at http://localhost:8025.
MAIL_TRANSPORT: "${MAIL_TRANSPORT:-smtp}"
MAIL_FROM: "${MAIL_FROM:-no-reply@todo.test}"
MAIL_SMTP_HOST: "${MAIL_SMTP_HOST:-mailpit}"
MAIL_SMTP_PORT: "${MAIL_SMTP_PORT:-1025}"
MAIL_SMTP_USERNAME: "${MAIL_SMTP_USERNAME:-}"
MAIL_SMTP_PASSWORD: "${MAIL_SMTP_PASSWORD:-}"
MAIL_SMTP_ENCRYPTION: "${MAIL_SMTP_ENCRYPTION:-none}"
volumes:
# Only generated state is mounted. The app itself — PHP source and the
# built frontend — is baked into the image; rebuild to pick up changes:
# docker compose up -d --build
- storage:/var/www/storage
depends_on:
- mailpit
restart: unless-stopped
# Development mail catcher (Mailpit — the maintained MailHog successor). ~15 MB,
# single Go binary, messages held in memory. Web UI: http://localhost:8025
mailpit:
image: axllent/mailpit:v1.31
ports:
- "8025:8025" # web UI + REST API
- "1025:1025" # SMTP (also reachable in-network as mailpit:1025)
restart: unless-stopped
volumes:
storage: