No description
  • Vue 83.1%
  • TypeScript 14.9%
  • CSS 1.2%
  • Dockerfile 0.4%
  • JavaScript 0.2%
  • Other 0.2%
Find a file
2026-09-27 14:36:41 +02:00
.husky add precommit lint fix 2026-04-29 20:29:47 +02:00
.vscode fix: adjust .env vscode file nesting 2026-09-15 14:18:12 +02:00
app style: better auth dropdown button 2026-09-27 13:51:36 +02:00
public refactor: simplify favicon setup 2026-07-17 14:07:10 +02:00
scripts refactor(deploy): remove unused rollback hook 2026-09-09 14:47:14 +02:00
server feat(auth): add optional Google sign-in 2026-09-27 13:10:07 +02:00
.dockerignore build(docker): exclude non-build files from the build context 2026-09-27 14:36:41 +02:00
.dockiy.template.yml feat(template): clean inherited SOPS files 2026-09-15 15:40:04 +02:00
.editorconfig add vscode config 2026-05-29 12:16:39 +02:00
.enc.local.env ops: add google auth ids 2026-09-27 13:42:02 +02:00
.enc.production.env ops: add google auth ids 2026-09-27 13:42:02 +02:00
.enc.staging.env ops: add google auth ids 2026-09-27 13:42:02 +02:00
.env.example feat(auth): add optional Google sign-in 2026-09-27 13:10:07 +02:00
.gitignore chore: remove obsolete local config ignores 2026-09-09 14:47:14 +02:00
.sops.yaml fix(secrets): preserve encrypted environment filenames 2026-07-17 19:29:47 +02:00
AGENTS.md doc: add callout not to run pnpm dev 2026-07-14 11:26:37 +02:00
components.json run shadcn init 2026-04-29 20:57:02 +02:00
docker-compose.dockiy.yml fix(deploy): forward application environment variables 2026-09-27 12:38:39 +02:00
docker-compose.yml fix(db): make host ports configurable and align local defaults 2026-09-27 12:38:39 +02:00
Dockerfile build(docker): split Nuxt runtime output into reusable layers 2026-09-27 14:33:23 +02:00
dockiy.yml fix: use Better Auth template identity 2026-09-15 13:48:22 +02:00
drizzle.config.ts build(docker): add app and migration images 2026-07-14 16:51:24 +02:00
eslint.config.mjs doc: add some explanations for the eslint config 2026-07-08 12:36:20 +02:00
nuxt.config.ts feat(auth): add optional Google sign-in 2026-09-27 13:10:07 +02:00
package.json fix(auth): load and refresh the session with Nuxt fetch 2026-09-27 12:38:39 +02:00
pnpm-lock.yaml fix(auth): load and refresh the session with Nuxt fetch 2026-09-27 12:38:39 +02:00
pnpm-workspace.yaml add pnpm allowBuilds 2026-07-08 10:46:10 +02:00
README.md doc: clarify db port in staging/production 2026-09-27 13:33:14 +02:00
tsconfig.json initial commit 2026-04-29 19:52:03 +02:00

DockIY logo

DockIY Nuxt Better Auth template

A full-stack Nuxt starter with Better Auth, PostgreSQL, and Drizzle, deployed with DockIY.

Docs for this template

Requirements

Install Node.js 24+, pnpm 11+, Docker Engine, Docker Compose, and the DockIY CLI. Install SOPS and age for encrypted environment files.

Local development

Create a project with dockiy app init nuxt-betterauth my-app, or clone this repo. Copy .env.example to .env and set:

  • NUXT_BETTER_AUTH_SECRET: output of openssl rand -base64 32.
  • NUXT_BREVO_*: API key and verified sender for email signup/reset.
  • NUXT_BETTER_AUTH_URL: http://localhost:3000 locally.
cp .env.example .env
# Edit .env, then:
docker compose up -d
pnpm install --frozen-lockfile
pnpm db:migrate
pnpm dev

Nuxt and Drizzle load .env. The example connects to PostgreSQL at localhost:5432; if you change POSTGRES_DOCKER_PORT, update the port in NUXT_DATABASE_URL too. pgAdmin: http://localhost:82, login admin@m.com / admin, database host db:5432, credentials from POSTGRES_*.

Encrypted local values

Create .enc.local.env with your own SOPS configuration, then wrap the normal commands:

sops exec-env .enc.local.env 'docker compose up -d'
sops exec-env .enc.local.env 'pnpm db:migrate'
sops exec-env .enc.local.env 'pnpm dev'

You can put the wrapper in package.json, e.g. "dev": "sops exec-env .enc.local.env 'nuxt dev'". Keep plaintext env files uncommitted; replace the template's encrypted files with your own.

Staging and production

Set the app name and environment hosts in dockiy.yml. Use sops edit to create .enc.staging.env and .enc.production.env from the example's keys:

Setting Staging / production
POSTGRES_* credentials, NUXT_BETTER_AUTH_SECRET Separate values per environment
NUXT_DATABASE_URL postgresql://USER:PASSWORD@db:5432/DATABASE; URL-encode credentials
POSTGRES_DOCKER_PORT Unused, distinct VPS ports, e.g. 5434 / 5435
NUXT_BETTER_AUTH_URL Public HTTPS origin matching that environment's host
NUXT_BREVO_* Working email credentials and sender

The NUXT_DATABASE_URL db port is always 5432. It is the internal port from within the container. The POSTGRES_DOCKER_PORT is the port exposed to the host machine so you can connect to the database with SSH from your local machine.

DockIY forwards the selected file's variables and applies committed migrations. After schema edits: pnpm db:generate, review/commit the SQL, then pnpm db:migrate locally. Deploy with dockiy app deploy staging or dockiy app deploy production --version v1.0.0.

Authentication

Email/password and google auth are preconfigured.

Google auth setup

  1. In Google Cloud Console, select a project and configure Google Auth Platform → Branding / Audience. For external testing, add your test users.
  2. Under Clients, create a Web application OAuth client. Add http://localhost:3000/api/auth/callback/google and each deployed origin plus /api/auth/callback/google to Authorized redirect URIs.
  3. Set NUXT_GOOGLE_CLIENT_ID and NUXT_GOOGLE_CLIENT_SECRET in the environment's dotenv file. NUXT_BETTER_AUTH_URL must match its origin exactly. Restart locally or redeploy, then use Continue with Google.

See the template guide for auth examples, Google launch settings, and deployment prerequisites.