Repository navigation
Expand file tree
/
Copy pathcompose.alpha.yaml
More file actions
101 lines (95 loc) · 3.53 KB
/
Copy pathcompose.alpha.yaml
File metadata and controls
101 lines (95 loc) · 3.53 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
# Overlay for OUR deployment only (M20.2 §3.3) — the published recipe is
# compose.production.yaml by itself. This adds the article-site container and
# swaps the front nginx to a /learn-proxying config:
#
# docker compose -f compose.production.yaml -f compose.alpha.yaml up -d
#
# Host .env additions the overlay reads (M21.1 §1.2/§1.3):
# CZ_SITE_TAG content-repo commit sha to serve (required; no latest)
# CZ_NGINX_TEMPLATES templates-frontdoor (default); the others predate the front door
# CZ_PUBLIC_SERVER_NAME the public apex; also names the stats host and the certificate lineage
# CZ_LEGACY_SERVER_NAME the retiring private hostname (transition template only)
# UMAMI_DB_PASSWORD, UMAMI_APP_SECRET, UMAMI_2FA_KEY
# self-hosted analytics secrets (M21.1 §2.2); generate on the box
services:
web:
# Fixed name so the certbot deploy hook can reload it by name (§2.8).
container_name: cz-nginx
environment:
CZ_PUBLIC_SERVER_NAME: ${CZ_PUBLIC_SERVER_NAME:-}
CZ_LEGACY_SERVER_NAME: ${CZ_LEGACY_SERVER_NAME:-}
# The shared front door holds ports 80/443, TLS, and the ACME webroot
# (its own stack, not this repo's); cz-nginx serves only behind it, over
# the frontdoor network. !reset and !override drop what compose.production.yaml gives
# a standalone web container.
ports: !reset []
volumes: !override
- ./docker/production/nginx/${CZ_NGINX_TEMPLATES:-templates-frontdoor}:/etc/nginx/templates:ro
- app-public:/var/www/html/public:ro
networks:
- default
- frontdoor
depends_on:
- app
- site
site:
# Pinned to a content-repo commit, like CZ_TAG pins the app; publish-site.sh
# moves it and the previous value is the rollback target.
image: ghcr.io/n8bar/cryptozing-site:${CZ_SITE_TAG:?set CZ_SITE_TAG in .env to the content-repo commit sha to serve}
restart: unless-stopped
logging:
driver: json-file
options:
max-size: "10m"
max-file: "3"
# Self-hosted analytics (M21.1 §2.2): Umami with its own database, reachable
# only through the front nginx at stats.${CZ_PUBLIC_SERVER_NAME}. Nothing
# here touches the app's database or network exposure.
umami:
image: ghcr.io/umami-software/umami:3.3.1
restart: unless-stopped
init: true
environment:
DATABASE_URL: postgresql://umami:${UMAMI_DB_PASSWORD:?set UMAMI_DB_PASSWORD in .env}@umami-db:5432/umami
APP_SECRET: ${UMAMI_APP_SECRET:?set UMAMI_APP_SECRET in .env}
TWO_FACTOR_ENCRYPTION_KEY: ${UMAMI_2FA_KEY:?set UMAMI_2FA_KEY in .env (openssl rand -hex 32)}
DISABLE_TELEMETRY: "1"
logging:
driver: json-file
options:
max-size: "10m"
max-file: "3"
depends_on:
umami-db:
condition: service_healthy
healthcheck:
test: ["CMD-SHELL", "curl -fsS http://localhost:3000/api/heartbeat"]
interval: 30s
timeout: 5s
retries: 5
start_period: 60s
umami-db:
image: postgres:16-alpine
restart: unless-stopped
environment:
POSTGRES_DB: umami
POSTGRES_USER: umami
POSTGRES_PASSWORD: ${UMAMI_DB_PASSWORD:?set UMAMI_DB_PASSWORD in .env}
volumes:
- umami-db:/var/lib/postgresql/data
logging:
driver: json-file
options:
max-size: "10m"
max-file: "3"
healthcheck:
test: ["CMD-SHELL", "pg_isready -U umami -d umami"]
interval: 15s
timeout: 5s
retries: 5
start_period: 30s
volumes:
umami-db:
networks:
frontdoor:
external: true