82 lines
2.9 KiB
YAML
82 lines
2.9 KiB
YAML
services:
|
|
postgres:
|
|
image: postgres:16-alpine
|
|
restart: unless-stopped
|
|
environment:
|
|
POSTGRES_USER: ${POSTGRES_USER:-omnex}
|
|
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-omnex}
|
|
POSTGRES_DB: ${POSTGRES_DB:-omnex}
|
|
volumes:
|
|
- pgdata:/var/lib/postgresql/data
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-omnex} -d ${POSTGRES_DB:-omnex}"]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 10
|
|
# Pas de port exposé : accès interne uniquement (défense en profondeur).
|
|
|
|
redis:
|
|
image: redis:7-alpine
|
|
restart: unless-stopped
|
|
command: ["redis-server", "--requirepass", "${REDIS_PASSWORD:-omnexredis}", "--maxmemory", "256mb", "--maxmemory-policy", "allkeys-lru"]
|
|
volumes:
|
|
- redisdata:/data
|
|
healthcheck:
|
|
test: ["CMD", "redis-cli", "-a", "${REDIS_PASSWORD:-omnexredis}", "ping"]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 10
|
|
|
|
web:
|
|
image: xor1234/omnex-web:latest
|
|
restart: unless-stopped
|
|
depends_on:
|
|
api:
|
|
condition: service_healthy
|
|
ports:
|
|
- "3000:80"
|
|
|
|
api:
|
|
image: xor1234/omnex-api:latest
|
|
restart: unless-stopped
|
|
depends_on:
|
|
postgres:
|
|
condition: service_healthy
|
|
redis:
|
|
condition: service_healthy
|
|
environment:
|
|
OMNEX_ENV: ${OMNEX_ENV:-dev}
|
|
OMNEX_ADDR: ":8080"
|
|
OMNEX_JWT_SECRET: ${OMNEX_JWT_SECRET}
|
|
OMNEX_ALLOWED_ORIGINS: ${OMNEX_ALLOWED_ORIGINS:-http://localhost:3000,http://localhost:5173}
|
|
OMNEX_DATABASE_URL: "host=postgres user=${POSTGRES_USER:-omnex} password=${POSTGRES_PASSWORD:-omnex} dbname=${POSTGRES_DB:-omnex} port=5432 sslmode=disable"
|
|
OMNEX_REDIS_URL: "redis://:${REDIS_PASSWORD:-omnexredis}@redis:6379/0"
|
|
OMNEX_SEED_USERNAME: ${OMNEX_SEED_USERNAME:-admin}
|
|
OMNEX_SEED_PASSWORD: ${OMNEX_SEED_PASSWORD}
|
|
OMNEX_DEMO_DOMAIN: ${OMNEX_DEMO_DOMAIN:-192.168.1.31.nip.io}
|
|
OMNEX_DEMO_HTTPS_PORT: ${OMNEX_DEMO_HTTPS_PORT:-443}
|
|
FRONTEND_IMAGE_APP: ${FRONTEND_IMAGE_APP:-xor1234/frontend-mln:helm}
|
|
BACKEND_IMAGE_APP: ${BACKEND_IMAGE_APP:-xor1234/backend-mln:helm}
|
|
LBTELEGRAM_IMAGE_APP: ${LBTELEGRAM_IMAGE_APP:-xor1234/lbtelegram:latest}
|
|
KUBECONFIG: /kubeconfig/config
|
|
volumes:
|
|
- ../deploy/chart-gestion:/charts:ro
|
|
- /home/xor_fakers/.kube/config:/kubeconfig/config:ro
|
|
healthcheck:
|
|
test: ["CMD", "curl", "-f", "http://localhost:8080/healthz"]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 10
|
|
# Le temps que le fix "EnsureSharedInfra en arrière-plan" soit déployé
|
|
# (voir control-plane/api/cmd/api/main.go) : laisse la marge pour que
|
|
# le "helm upgrade --install --wait --timeout 5m" bloquant échoue tout
|
|
# seul si le cluster est injoignable, plutôt que de faire échouer
|
|
# `docker compose up` avant même que le serveur HTTP démarre.
|
|
start_period: 330s
|
|
ports:
|
|
- "8080:8080"
|
|
|
|
volumes:
|
|
pgdata:
|
|
redisdata:
|