Repository navigation
Expand file tree
/
Copy pathdocker-compose.aws.yml
More file actions
44 lines (40 loc) · 1.92 KB
/
Copy pathdocker-compose.aws.yml
File metadata and controls
44 lines (40 loc) · 1.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
# AWS overlay: the same stack the smoke boots, on one EC2 instance.
#
# docker compose -f docker-compose.yml -f docker-compose.aws.yml up -d
#
# Three differences from the base file, and nothing else. The instance has no
# checkout, so the app runs the image built and pushed by CI rather than a
# build context. Object storage is S3 and the credentials come from the
# instance role, so the local object store does not run. TLS is not optional
# on a public address, so Caddy leaves the "tls" profile and starts with the
# rest.
#
# The `.env` this reads is written by the instance's user-data from SSM
# Parameter Store. It still has to carry OBJECT_STORE_ROOT_PASSWORD,
# OBJECT_STORE_BUCKET and LITESTREAM_BUCKET: Compose interpolates the base file
# before it applies this one, so their `:?` guards fire whether or not the
# services that use them are started. The AWS `.env` gives the local object
# store's password an unused value.
services:
app:
# No build context on the instance. `image` names the ECR tag CI pushed;
# resetting `build` is what makes `up` pull it instead of trying to build.
build: !reset null
image: ${CONTROL_PLANE_IMAGE:?CONTROL_PLANE_IMAGE must name the ECR image to run, including its tag}
# The base file waits for the local object store's buckets. On S3 the
# buckets are Terraform's, and nothing here creates them.
depends_on: !reset null
# Not started on AWS: S3 is the object store and the Litestream replica
# target. A profile no environment enables is how a service is left out of
# a merged stack; there is no way to delete one in an overlay.
object-store:
profiles: ["local-object-store"]
litestream:
# The base file also waits for the local object store here.
depends_on: !override
app:
condition: service_healthy
# TLS terminates on the instance, so Caddy is part of the stack rather than
# an opt-in profile.
caddy:
profiles: !reset []