-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.sql.yml
More file actions
31 lines (31 loc) · 1.46 KB
/
Copy pathdocker-compose.sql.yml
File metadata and controls
31 lines (31 loc) · 1.46 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
# Optional SQL-only sandbox; the ordinary code sandbox stays on sandbox-net.
# docker compose -f docker-compose.yml -f docker-compose.sql.yml up -d --build
services:
talos-app:
environment:
- TALOS_SQL_SANDBOX_URL=http://talos-sql-sandbox:7800
- TALOS_SQL_SANDBOX_KEY=${TALOS_SQL_SANDBOX_KEY:?Set a separate SQL sandbox secret}
- TALOS_MCP_SQL_HEADER_HOST=${TALOS_MCP_SQL_HEADER_HOST:-macs-sql-host}
- TALOS_MCP_SQL_HEADER_DATABASE=${TALOS_MCP_SQL_HEADER_DATABASE:-macs-sql-database}
- TALOS_MCP_SQL_HEADER_USER=${TALOS_MCP_SQL_HEADER_USER:-macs-sql-user}
- TALOS_MCP_SQL_HEADER_PASSWORD=${TALOS_MCP_SQL_HEADER_PASSWORD:-macs-sql-password}
talos-sql-sandbox:
build: ./sandbox
image: talos-sql-sandbox:local
user: "65534:65534"
entrypoint: ["/usr/bin/tini", "--"]
command: ["/opt/talos-sandbox-venv/bin/uvicorn", "sql_sandbox:app", "--host", "0.0.0.0", "--port", "7800", "--no-access-log"]
environment:
- TALOS_SQL_SANDBOX_KEY=${TALOS_SQL_SANDBOX_KEY:?Set a separate SQL sandbox secret}
# Empty = every host the caller names is accepted. Narrow it when you can:
# exact names, *.domain suffixes, or * for any.
- TALOS_SQL_ALLOWED_HOSTS=${TALOS_SQL_ALLOWED_HOSTS:-}
- TALOS_SQL_PORT=${TALOS_SQL_PORT:-1433}
read_only: true
cap_drop: [ALL]
security_opt: ["no-new-privileges:true"]
mem_limit: 512m
cpus: 1
pids_limit: 64
networks: [default]
restart: unless-stopped