-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
87 lines (86 loc) · 5.42 KB
/
Copy pathdocker-compose.yml
File metadata and controls
87 lines (86 loc) · 5.42 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
services:
# Minimal backend-only stack. Sandbox containers are created dynamically
# by the UnoSim backend via the Docker socket and are not persistent services.
unosim-backend:
build:
context: .
dockerfile: Dockerfile
image: unosim-server:latest
container_name: unosim-server
restart: unless-stopped
group_add:
- "${DOCKER_GID:?Set DOCKER_GID to the numeric GID of /var/run/docker.sock}"
environment:
- PORT=3000
- UNOSIM_SERVER_MODE=docker
- NODE_ENV=production
# Public/multi-user deployments must sit behind an authenticating gateway.
# Compose fails before startup when either required secret is absent.
- UNOSIM_GATEWAY_SECRET=${UNOSIM_GATEWAY_SECRET:?Set UNOSIM_GATEWAY_SECRET to at least 32 characters}
- UNOSIM_TRUSTED_PROXY=${UNOSIM_TRUSTED_PROXY:?Set UNOSIM_TRUSTED_PROXY to the gateway IP or CIDR}
- UNOSIM_ALLOWED_WS_ORIGINS=${UNOSIM_ALLOWED_WS_ORIGINS:?Set UNOSIM_ALLOWED_WS_ORIGINS to the comma-separated browser origins}
# Public GitHub source; set SOURCE and REF both empty for built-ins only.
- UNOSIM_EXAMPLES_SOURCE=${UNOSIM_EXAMPLES_SOURCE-ttbombadil/unosim-examples}
- UNOSIM_EXAMPLES_REF=${UNOSIM_EXAMPLES_REF:-}
- UNOSIM_EXAMPLES_ALLOWED_HOSTS=${UNOSIM_EXAMPLES_ALLOWED_HOSTS:-api.github.com,raw.githubusercontent.com}
- UNOSIM_EXAMPLES_VALIDATE_RATE_LIMIT_MAX_REQUESTS=${UNOSIM_EXAMPLES_VALIDATE_RATE_LIMIT_MAX_REQUESTS:-5}
- UNOSIM_EXAMPLES_OVERRIDE_RATE_LIMIT_MAX_REQUESTS=${UNOSIM_EXAMPLES_OVERRIDE_RATE_LIMIT_MAX_REQUESTS:-60}
- UNOSIM_EXAMPLES_GLOBAL_LOAD_STARTS_PER_MINUTE=${UNOSIM_EXAMPLES_GLOBAL_LOAD_STARTS_PER_MINUTE:-20}
- UNOSIM_EXAMPLES_MAX_CONCURRENT_LOADS=${UNOSIM_EXAMPLES_MAX_CONCURRENT_LOADS:-4}
- UNOSIM_EXAMPLES_MAX_LOAD_QUEUE=${UNOSIM_EXAMPLES_MAX_LOAD_QUEUE:-32}
- UNOSIM_EXAMPLES_MAX_FILE_FETCH_CONCURRENCY=${UNOSIM_EXAMPLES_MAX_FILE_FETCH_CONCURRENCY:-8}
- UNOSIM_EXAMPLES_MAX_OUTBOUND_FETCHES=${UNOSIM_EXAMPLES_MAX_OUTBOUND_FETCHES:-16}
- UNOSIM_EXAMPLES_MAX_SOURCES=${UNOSIM_EXAMPLES_MAX_SOURCES:-32}
- UNOSIM_EXAMPLES_SNAPSHOT_CACHE_MAX_ENTRIES=${UNOSIM_EXAMPLES_SNAPSHOT_CACHE_MAX_ENTRIES:-64}
- UNOSIM_EXAMPLES_SNAPSHOT_CACHE_MAX_BYTES=${UNOSIM_EXAMPLES_SNAPSHOT_CACHE_MAX_BYTES:-67108864}
- UNOSIM_EXAMPLES_REFRESH_RETRY_MS=${UNOSIM_EXAMPLES_REFRESH_RETRY_MS:-30000}
- ARDUINO_CACHE_DIR=${PWD}/server/arduino-cache
- UNOSIM_SHARED_TEMP_DIR=${PWD}/temp
- DOCKER_HOST=unix:///var/run/docker.sock
- DOCKER_SANDBOX_IMAGE=unosim-sandbox:latest
# Logical simulation capacity grows on-demand; idle logical runners shrink after IDLE_TIMEOUT_MS.
# Admission still caps running plus waiting simulations at SIMULATION_ADMISSION_MAX
# (application default 25); see docs/CAPACITY_VALIDATION_PLAN.md before raising either.
- SIMULATION_MAX_CONCURRENT=200
- SANDBOX_POOL_IDLE_TIMEOUT_MS=300000
# Per-sandbox Docker resource limits
# ┌─ Scenario breakdown ────────────────────────────────────────────────────┐
# │ Dev (default, no docker-compose): uses config.ts defaults │
# │ SANDBOX_MEMORY_MB = 256 MB (safe floor: g++/cc1plus needs 150-300 MB │
# │ when compiling inside the container) │
# │ CI (GitHub Actions ubuntu-latest): same defaults, no override needed │
# │ Linux cgroup v2 hard-kills cc1plus at 64 MB → must be ≥ 256 │
# │ Production (this docker-compose): explicit override – can be tuned │
# │ 256 MB covers compile phase; AVR runtime alone only needs ~30 MB │
# └─────────────────────────────────────────────────────────────────────────┘
- SANDBOX_MEMORY_MB=256
- SANDBOX_CPU_LIMIT=0.25
# Compile capacity: workers, global compile limit, Docker-sandbox limit.
- WORKER_COUNT=${WORKER_COUNT:-8}
- COMPILE_MAX_CONCURRENT=${COMPILE_MAX_CONCURRENT:-8}
- SANDBOX_START_MAX_CONCURRENT=${SANDBOX_START_MAX_CONCURRENT:-8}
- SANDBOX_START_SLOT_TIMEOUT_MS=${SANDBOX_START_SLOT_TIMEOUT_MS:-30000}
- DOCKER_CONTROL_TIMEOUT_MS=${DOCKER_CONTROL_TIMEOUT_MS:-2000}
ports:
# Secure default: a host-local gateway can reach UnoSim, LAN clients cannot
# bypass it. Override only with a private gateway-facing bind address.
- "${UNOSIM_BIND_ADDRESS:-127.0.0.1}:3000:3000"
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ${PWD}/server/arduino-cache:${PWD}/server/arduino-cache
- ${PWD}/temp:${PWD}/temp
- ./storage:/app/storage
healthcheck:
test: ["CMD", "curl", "-sf", "http://localhost:3000/api/readiness"]
interval: 30s
timeout: 10s
retries: 3
start_period: 20s
# NOTE: The mcp/sonarqube MCP server is intentionally NOT part of this stack.
# It is a stdio-based dev tool managed by Docker Desktop MCP Toolkit and
# launched on-demand per VS Code session. Running it as a persistent service
# makes no sense and causes constant restart loops.
#
# SonarQube itself (sonarqube + sonar-db) lives in its own stack at
# ~/Documents/sonarqube/docker-compose.yml and is reached from the host
# via http://localhost:9000.