services: postgres: image: postgres:16-alpine restart: unless-stopped environment: POSTGRES_USER: ${POSTGRES_USER:-omnex} POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-omnex} POSTGRES_DB: ${POSTGRES_DB:-omnex} volumes: - pgdata:/var/lib/postgresql/data healthcheck: test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-omnex} -d ${POSTGRES_DB:-omnex}"] interval: 5s timeout: 3s retries: 10 # Pas de port exposé : accès interne uniquement (défense en profondeur). redis: image: redis:7-alpine restart: unless-stopped command: ["redis-server", "--requirepass", "${REDIS_PASSWORD:-omnexredis}", "--maxmemory", "256mb", "--maxmemory-policy", "allkeys-lru"] volumes: - redisdata:/data healthcheck: test: ["CMD", "redis-cli", "-a", "${REDIS_PASSWORD:-omnexredis}", "ping"] interval: 5s timeout: 3s retries: 10 web: image: xor1234/omnex-web:latest restart: unless-stopped depends_on: api: condition: service_healthy ports: - "3000:80" api: image: xor1234/omnex-api:latest restart: unless-stopped depends_on: postgres: condition: service_healthy redis: condition: service_healthy environment: OMNEX_ENV: ${OMNEX_ENV:-dev} OMNEX_ADDR: ":8080" OMNEX_JWT_SECRET: ${OMNEX_JWT_SECRET} OMNEX_ALLOWED_ORIGINS: ${OMNEX_ALLOWED_ORIGINS:-http://localhost:3000,http://localhost:5173} OMNEX_DATABASE_URL: "host=postgres user=${POSTGRES_USER:-omnex} password=${POSTGRES_PASSWORD:-omnex} dbname=${POSTGRES_DB:-omnex} port=5432 sslmode=disable" OMNEX_REDIS_URL: "redis://:${REDIS_PASSWORD:-omnexredis}@redis:6379/0" OMNEX_SEED_USERNAME: ${OMNEX_SEED_USERNAME:-admin} OMNEX_SEED_PASSWORD: ${OMNEX_SEED_PASSWORD} OMNEX_DEMO_DOMAIN: ${OMNEX_DEMO_DOMAIN:-192.168.1.31.nip.io} OMNEX_DEMO_HTTPS_PORT: ${OMNEX_DEMO_HTTPS_PORT:-443} FRONTEND_IMAGE_APP: ${FRONTEND_IMAGE_APP:-xor1234/frontend-mln:helm} BACKEND_IMAGE_APP: ${BACKEND_IMAGE_APP:-xor1234/backend-mln:helm} LBTELEGRAM_IMAGE_APP: ${LBTELEGRAM_IMAGE_APP:-xor1234/lbtelegram:helm} KUBECONFIG: /kubeconfig/config volumes: - ../deploy/chart-gestion:/charts:ro - /home/xor_fakers/.kube/config:/kubeconfig/config:ro healthcheck: test: ["CMD", "curl", "-f", "http://localhost:8080/healthz"] interval: 5s timeout: 3s retries: 10 # Le temps que le fix "EnsureSharedInfra en arrière-plan" soit déployé # (voir control-plane/api/cmd/api/main.go) : laisse la marge pour que # le "helm upgrade --install --wait --timeout 5m" bloquant échoue tout # seul si le cluster est injoignable, plutôt que de faire échouer # `docker compose up` avant même que le serveur HTTP démarre. start_period: 330s ports: - "8080:8080" volumes: pgdata: redisdata: