Repository navigation
Expand file tree
/
Copy pathdocker-compose.dev.yml
More file actions
82 lines (80 loc) · 2.7 KB
/
Copy pathdocker-compose.dev.yml
File metadata and controls
82 lines (80 loc) · 2.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
# Development stack: local images and checkout-mounted bootstrap files.
# Build images with make docker-compose-build before starting.
name: repowatch-trial
x-logging: &container-logging
driver: json-file
options:
max-size: "10m"
max-file: "3"
services:
init:
logging: *container-logging
image: ${DOCKER_IMAGE:-repowatch:local}
pull_policy: never
user: "0:0"
network_mode: none
environment:
REPOWATCH_GID: ${REPOWATCH_GID:-10001}
entrypoint: ["python", "/bootstrap/init.py"]
command: []
restart: "no"
volumes:
- ./docker/compose/init.py:/bootstrap/init.py:ro
- ./docker/compose/config.example.yaml:/bootstrap/config.yaml:ro
- ./config:/etc/repowatch
- ./data/state:/var/lib/repowatch
- ./data/nix:/nix
- ./data/cache:/var/cache/nginx/repowatch
nginx:
logging: *container-logging
user: "0:${REPOWATCH_GID:-10001}"
image: ${DOCKER_NGINX_IMAGE:-repowatch-nginx:trial}
pull_policy: never
depends_on:
init:
condition: service_completed_successfully
restart: unless-stopped
stop_grace_period: 30s
security_opt: ["no-new-privileges:true"]
ports:
- "127.0.0.1:18080:8080"
# Published here because repowatch shares this network namespace.
- "127.0.0.1:18085:8085"
volumes:
- ./config:/etc/repowatch:ro
# The existing helper uses SQLite for dedup; UID/GID is coordinated by init.
- ./data/state:/var/lib/repowatch
- ./data/cache:/var/cache/nginx/repowatch
healthcheck:
test: ["CMD", "python", "-c", "from pathlib import Path; import urllib.request; assert Path('/run/repowatch-nginx.ready').exists(); assert urllib.request.urlopen('http://127.0.0.1:8081/healthz', timeout=2).status == 200"]
interval: 5s
timeout: 3s
retries: 12
start_period: 10s
repowatch:
logging: *container-logging
user: "10001:${REPOWATCH_GID:-10001}"
image: ${DOCKER_IMAGE:-repowatch:local}
pull_policy: never
network_mode: service:nginx
depends_on:
init:
condition: service_completed_successfully
nginx:
condition: service_healthy
restart: true
restart: unless-stopped
stop_grace_period: 30s
security_opt: ["no-new-privileges:true"]
cap_drop: ["ALL"]
volumes:
- ./config:/etc/repowatch
- ./data/state:/var/lib/repowatch
# Empty in the base variant; ready for the optional Nix image.
- ./data/nix:/nix
healthcheck:
test: ["CMD", "python", "-c", "import json, urllib.request; assert json.load(urllib.request.urlopen('http://127.0.0.1:8085/healthz', timeout=2))['healthy']"]
interval: 10s
timeout: 3s
retries: 6
start_period: 15s