-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
147 lines (140 loc) · 4.61 KB
/
Copy pathdocker-compose.yml
File metadata and controls
147 lines (140 loc) · 4.61 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
name: nvisy
services:
postgres:
image: postgres:18
container_name: nvisy-postgres
restart: unless-stopped
ports:
- "${POSTGRES_PORT:-5432}:5432"
environment:
POSTGRES_USER: ${POSTGRES_USER:-nvisy}
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?POSTGRES_PASSWORD is required}
POSTGRES_DB: ${POSTGRES_DB:-nvisy}
volumes:
- postgres_data:/var/lib/postgresql/data
healthcheck:
test: [
"CMD-SHELL",
"pg_isready -U ${POSTGRES_USER:-nvisy} -d ${POSTGRES_DB:-nvisy}",
]
interval: 5s
timeout: 5s
retries: 5
start_period: 10s
networks:
- nvisy
nats:
image: nats:2.14.2-alpine
container_name: nvisy-nats
restart: unless-stopped
ports:
- "${NATS_PORT:-4222}:4222"
- "${NATS_MONITOR_PORT:-8222}:8222"
command:
- "-c"
- "/etc/nats/nats.conf"
volumes:
- nats_data:/data
- ./nats/nats.conf:/etc/nats/nats.conf:ro
healthcheck:
test: ["CMD", "wget", "-qO-", "http://localhost:8222/healthz"]
interval: 5s
timeout: 5s
retries: 5
start_period: 5s
networks:
- nvisy
rustfs:
image: rustfs/rustfs:1.0.0-rc.5
container_name: nvisy-rustfs
restart: unless-stopped
# No host ports: the server reaches RustFS over the internal network at
# http://rustfs:9000. Expose the console deliberately (an SSH tunnel or a
# temporary compose override) rather than publishing it by default.
environment:
RUSTFS_ACCESS_KEY: ${S3_ACCESS_KEY_ID:?S3_ACCESS_KEY_ID is required}
RUSTFS_SECRET_KEY: ${S3_SECRET_ACCESS_KEY:?S3_SECRET_ACCESS_KEY is required}
RUSTFS_CONSOLE_ENABLE: "true"
RUSTFS_CONSOLE_ADDRESS: ":9001"
volumes:
- rustfs_data:/data
# /health/ready (not /health) confirms storage is initialized, so bucket
# init only runs once RustFS can actually serve requests.
healthcheck:
test: ["CMD", "curl", "-fsS", "http://localhost:9000/health/ready"]
interval: 5s
timeout: 5s
retries: 5
start_period: 10s
networks:
- nvisy
# Creates the first-party bucket once RustFS is up (RustFS does not
# auto-create buckets). Exits after provisioning; safe to re-run.
rustfs-init:
image: rustfs/rc:v0.1.31
container_name: nvisy-rustfs-init
depends_on:
rustfs:
condition: service_healthy
# Configuration is passed through the environment and consumed by the
# mounted script, so a credential containing shell metacharacters cannot
# alter the command.
environment:
S3_ENDPOINT: http://rustfs:9000
S3_ACCESS_KEY_ID: ${S3_ACCESS_KEY_ID:?S3_ACCESS_KEY_ID is required}
S3_SECRET_ACCESS_KEY: ${S3_SECRET_ACCESS_KEY:?S3_SECRET_ACCESS_KEY is required}
S3_BUCKET: ${S3_BUCKET:-nvisy}
entrypoint: ["/bin/sh", "/init.sh"]
volumes:
- ./rustfs/init.sh:/init.sh:ro
networks:
- nvisy
server:
build:
context: ..
dockerfile: docker/Dockerfile
image: nvisy/server:${VERSION:-latest}
container_name: nvisy-server
restart: unless-stopped
ports:
- "${SERVER_PORT:-8080}:8080"
environment:
HOST: 0.0.0.0
PORT: 8080
REQUEST_TIMEOUT: ${REQUEST_TIMEOUT:-30s}
SHUTDOWN_TIMEOUT: ${SHUTDOWN_TIMEOUT:-30s}
POSTGRES_URL: postgresql://${POSTGRES_USER:-nvisy}:${POSTGRES_PASSWORD:?POSTGRES_PASSWORD is required}@postgres:5432/${POSTGRES_DB:-nvisy}
NATS_URL: nats://nats:4222
S3_BUCKET: ${S3_BUCKET:-nvisy}
S3_REGION: ${S3_REGION:-us-east-1}
S3_ENDPOINT: http://rustfs:9000
S3_FORCE_PATH_STYLE: "true"
S3_ACCESS_KEY_ID: ${S3_ACCESS_KEY_ID:?S3_ACCESS_KEY_ID is required}
S3_SECRET_ACCESS_KEY: ${S3_SECRET_ACCESS_KEY:?S3_SECRET_ACCESS_KEY is required}
AUTH_PUBLIC_PEM_FILEPATH: ${AUTH_PUBLIC_PEM_FILEPATH:-/etc/nvisy/public.pem}
AUTH_PRIVATE_PEM_FILEPATH: ${AUTH_PRIVATE_PEM_FILEPATH:-/etc/nvisy/private.pem}
ENCRYPTION_KEY_FILEPATH: ${ENCRYPTION_KEY_FILEPATH:-/etc/nvisy/encryption.key}
ENGINE_CONFIG_FILEPATH: ${ENGINE_CONFIG_FILEPATH:-/etc/nvisy/engine.toml}
CORS_ORIGINS: ${CORS_ORIGINS:-}
CORS_MAX_AGE: ${CORS_MAX_AGE:-1h}
HEALTH_CACHE_DURATION: ${HEALTH_CACHE_DURATION:-30s}
RUST_LOG: ${RUST_LOG:-info}
RUST_BACKTRACE: ${RUST_BACKTRACE:-0}
depends_on:
postgres:
condition: service_healthy
nats:
condition: service_healthy
rustfs:
condition: service_healthy
rustfs-init:
condition: service_completed_successfully
networks:
- nvisy
volumes:
postgres_data:
nats_data:
rustfs_data:
networks:
nvisy:
driver: bridge