Convert the app from the Windows/server2 share deployment to a Docker stack deployed through Portainer behind Nginx Proxy Manager. - Serve the Project Images library (it returned 403) from the mounted folder - Make the InDesign export work in a container: load app images from disk, run Chromium without the sandbox, and wait for its full output - Return error messages instead of stack traces; cap export request size - Warn at startup about missing sign-in settings or an unwritable data folder - compose.yaml: join NPM's network, take all settings from stack variables, require absolute host paths for data and the photo library - Add .dockerignore, .env.example, and .gitignore - Stop tracking data, Project Images, Backups, and InDesign Exports - Remove the share publishing, Windows host, and browser migration scripts - Rewrite the README for Portainer and NPM deployment Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
19 lines
999 B
Bash
19 lines
999 B
Bash
# Stack settings. In Portainer, enter these under the stack's "Environment variables".
|
|
# For the docker compose CLI, copy this file to .env next to compose.yaml. Never commit the completed file.
|
|
|
|
# Docker network Nginx Proxy Manager is attached to (Portainer > Networks shows the name).
|
|
NPM_NETWORK=npm_default
|
|
|
|
# Absolute host folders. The data folder must be writable by UID 1000.
|
|
PROPOSAL_BOT_DATA_HOST_PATH=/opt/proposal-bot/data
|
|
PROPOSAL_BOT_PROJECT_IMAGES_HOST_PATH=/opt/proposal-bot/Project Images
|
|
|
|
# Microsoft Entra sign-in. The redirect URI must be the HTTPS address NPM serves and must match the app registration exactly.
|
|
# PROPOSAL_BOT_AUTH_REQUIRED=false turns sign-in off: anyone who can reach the site can read and edit every project.
|
|
PROPOSAL_BOT_AUTH_REQUIRED=true
|
|
MICROSOFT_TENANT_ID=
|
|
MICROSOFT_CLIENT_ID=
|
|
MICROSOFT_CLIENT_SECRET=
|
|
MICROSOFT_REDIRECT_URI=https://proposals.example.com/auth/microsoft/callback
|
|
PROPOSAL_BOT_ALLOWED_EMAILS=person.one@example.com,person.two@example.com
|