Repository navigation
Expand file tree
/
Copy pathcompose.yml
More file actions
71 lines (69 loc) · 2.57 KB
/
Copy pathcompose.yml
File metadata and controls
71 lines (69 loc) · 2.57 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
# Base stack: backend + frontend. Usage:
# docker compose up -d --build → http://localhost:8080
#
# Configuration comes from .env in the repo root (optional, see .env.example)
# plus the environment below; backend/.env is still read as a fallback.
# APP_ENV defaults to production: docs are disabled and unsafe configurations
# (mock detector, insecure content logging, enabled but unconfigured llm
# detector) refuse to start.
#
# Layered variants:
# compose.dev.yml → source mount + hot reload
# compose.unlimited-ocr.yml → GPU sidecar serving baidu/Unlimited-OCR
services:
backend:
build:
context: .
dockerfile: Dockerfile.backend
image: ghcr.io/katherlab/deidentifier-backend:${DEIDENTIFIER_IMAGE_TAG:-latest}
restart: unless-stopped
env_file:
# Later files win: .env in the repo root is the canonical location,
# backend/.env the legacy fallback.
- path: backend/.env
required: false
- path: .env
required: false
environment:
- APP_ENV=${APP_ENV:-production}
# No published ports: the frontend proxies /api/ internally. Uncomment for
# direct backend access during debugging:
# ports: ["8000:8000"]
# No volumes: nothing is persisted; documents live in memory only.
read_only: true
tmpfs:
- /tmp
healthcheck:
test:
- CMD-SHELL
- python -c "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8000/health/live', timeout=5)"
interval: 10s
timeout: 5s
retries: 12
start_period: 15s
frontend:
# nginx re-resolves the backend hostname at request time (see
# frontend/docker-entrypoint.d/05-resolver.sh), so recreating the backend
# container does NOT require a frontend restart.
build:
context: .
dockerfile: Dockerfile.frontend
image: ghcr.io/katherlab/deidentifier-frontend:${DEIDENTIFIER_IMAGE_TAG:-latest}
restart: unless-stopped
ports:
- "${FRONTEND_PORT:-8080}:8080"
# nginx spools request bodies and large proxied responses to
# /tmp/{client,proxy}_temp — both carry document content. On a tmpfs they
# stay in RAM; without it they land on the container's writable layer, i.e.
# on disk. (The container itself cannot be read_only: the entrypoint
# rewrites /etc/nginx/conf.d/default.conf to inject the DNS resolver.)
tmpfs:
- /tmp
depends_on:
backend:
condition: service_healthy
healthcheck:
test: ["CMD", "wget", "-q", "--spider", "http://127.0.0.1:8080/"]
interval: 30s
timeout: 5s
retries: 5