-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.cloud.yml
More file actions
56 lines (53 loc) · 1.93 KB
/
Copy pathdocker-compose.cloud.yml
File metadata and controls
56 lines (53 loc) · 1.93 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
# FileMorph — Cloud Edition overlay (Postgres + JWT + Stripe)
#
# Layers on top of docker-compose.yml. Adds the database the Cloud
# Edition needs (user accounts, JWT auth, Stripe billing, admin
# cockpit, audit-log, daily metrics) and switches the app into
# Cloud-Edition mode by setting DATABASE_URL.
#
# When DATABASE_URL is set, the entrypoint runs ``alembic upgrade
# head`` before uvicorn starts so the schema is in place on first
# boot.
#
# Usage:
#
# # First-time setup
# cp .env.example .env
# # edit .env to set strong POSTGRES_PASSWORD and JWT_SECRET (≥ 32 chars)
#
# docker compose -f docker-compose.yml -f docker-compose.cloud.yml up -d
#
# # Stop:
# docker compose -f docker-compose.yml -f docker-compose.cloud.yml down
#
# Stripe + SMTP envs (STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET,
# SMTP_HOST etc.) are read from the same .env. They are optional —
# the app boots without them but the billing and email flows won't
# work until set. See docs/self-hosting.md and .env.example.
services:
postgres:
image: postgres:16-alpine
environment:
POSTGRES_DB: filemorph
POSTGRES_USER: filemorph
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-changeme}
volumes:
- postgres_data:/var/lib/postgresql/data
restart: unless-stopped
healthcheck:
test: ["CMD-SHELL", "pg_isready -U filemorph"]
interval: 5s
timeout: 5s
retries: 10
filemorph:
environment:
DATABASE_URL: postgresql+asyncpg://filemorph:${POSTGRES_PASSWORD:-changeme}@postgres/filemorph
# No fallback: any default here would be public, and every deployment
# started without JWT_SECRET would sign its logins with it. The app
# itself also refuses a published or shorter-than-32-character secret.
JWT_SECRET: ${JWT_SECRET:?set JWT_SECRET in .env to at least 32 random characters, see .env.example}
depends_on:
postgres:
condition: service_healthy
volumes:
postgres_data: