Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
63 lines (55 loc) · 1.95 KB
/
Copy pathdocker-compose.yml
File metadata and controls
63 lines (55 loc) · 1.95 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
# HAProxy Controller - single self-contained service.
#
# One service, one image. HAProxy is compiled from the source vendored in
# third_party/haproxy, so the build pulls nothing from the network, and the
# controller supervises it as a child process at runtime. There is no second
# service, no database container and no init system to add.
#
# Powered by Ebdaa.me - https://ebdaa.me
services:
haproxy-controller:
build:
context: .
args:
VERSION: "1.0.0"
image: haproxy-controller:latest
container_name: haproxy-controller
restart: unless-stopped
ports:
# Control panel. Bind it to localhost and reach it over a tunnel unless
# you have enabled TLS and restricted access at the network layer.
- "0.0.0.0:9000:9000"
# Traffic ports. These must match the listeners you define in the panel.
- "8080:80"
- "8443:443"
environment:
HC_LISTEN_PORT: "9000"
HC_LOG_LEVEL: "info"
# Uncomment to name the first administrator something other than "admin".
# HC_ADMIN_USER: "operator"
volumes:
# The SQLite database, config versions and backups.
- controller-data:/var/lib/haproxy-controller
# The generated haproxy.cfg, certificates and error pages.
- haproxy-etc:/etc/haproxy
# The controller's own settings file, including its session secret.
- controller-conf:/etc/haproxy-controller
# Binding ports below 1024 is the only elevated capability needed.
cap_drop: ["ALL"]
cap_add: ["NET_BIND_SERVICE", "SETUID", "SETGID", "CHOWN", "DAC_OVERRIDE"]
security_opt: ["no-new-privileges:true"]
healthcheck:
test: ["CMD", "/usr/local/bin/haproxy-controller", "-healthcheck"]
interval: 30s
timeout: 5s
retries: 3
start_period: 15s
# HAProxy keeps many sockets open under load.
ulimits:
nofile:
soft: 65535
hard: 65535
volumes:
controller-data:
haproxy-etc:
controller-conf: