- deploy/compose.yaml: replace generated placeholder with actual monolith
compose (Foundry, Caddy, media stack, famapp, Authentik, Watchtower, etc.)
- deploy/Caddyfile.snippet: replace with full production Caddyfile
- .env.production.example: update variable names to match production
(famapp_MINIO_ROOT_USER/PASSWORD/BUCKET, CF_API_TOKEN, etc.)
- scripts/apply-compose.ps1: add -Compose/-Caddy flags; push Caddyfile
and reload caddy in addition to compose restart
- PushOptIn now accepts vapidKey as a prop from its server-component
parent (settings page reads VAPID_PUBLIC_KEY at runtime) — eliminates
the NEXT_PUBLIC_* build-time dependency so pre-built GHCR images work
without a build arg.
- deploy/compose.yaml: famapp exposes 3010:3000, authentik-server exposes
9200:9000 so the existing Caddy stack can proxy by IP, matching every
other service in the homelab. NEXT_PUBLIC_APP_URL replaced by AUTH_URL
(correct next-auth v5 var).
- deploy/Caddyfile.snippet: updated to 192.168.1.69:3010 / :9200.
- .env.production.example: AUTH_URL, ntfy pre-wired to ntfy.ginnoir.com,
VAPID_SUBJECT prefilled with real email.
- typecheck and pnpm build both pass.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Multi-stage Dockerfile (pnpm fetch/offline, standalone output, non-root
nextjs user), deploy/compose.yaml with famapp + famapp-db + full Authentik
stack on famapp_net, Caddyfile.snippet for fam/auth.ginnoir.com, and
.env.production.example. Added .dockerignore and public/.gitkeep.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>