- JWT_SECRET is mandatory (no more "supersecret" fallback). - Pass OVPMON_INITIAL_ADMIN_USER/PASSWORD and OVPMON_CORS_ORIGINS to the APIs; add restart policy and drop the obsolete compose "version". - Publish only 80/tcp and 1194/udp; expose 5001 and 8000 on ovp-net. - CORS origins now come from OVPMON_CORS_ORIGINS instead of a hardcoded host (default: same-origin only). - Update Docker/native deployment docs and README accordingly. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>