-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
126 lines (118 loc) · 3.23 KB
/
Copy pathdocker-compose.yml
File metadata and controls
126 lines (118 loc) · 3.23 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
x-logging: &logging
driver: json-file
options:
max-size: "10m"
max-file: "5"
x-hardening: &hardening
read_only: true
tmpfs:
- /tmp
security_opt:
- no-new-privileges:true
x-api-image: &api-image ghcr.io/seraphinteractive/platform-api:${PLATFORM_API_TAG:-latest}
x-api-environment: &api-environment
NODE_ENV: production
HOST: 0.0.0.0
PORT: "3333"
LOG_LEVEL: ${LOG_LEVEL:-info}
APP_KEY: ${APP_KEY:?}
APP_URL: ${APP_URL:?}
CORS_ORIGIN: ${CORS_ORIGIN:?}
DB_HOST: postgres
DB_PORT: "5432"
DB_USER: ${DB_USER:-postgres}
DB_PASSWORD: ${DB_PASSWORD:?}
DB_DATABASE: ${DB_DATABASE:-platform}
REDIS_HOST: redis
REDIS_PORT: "6379"
REDIS_PASSWORD: ${REDIS_PASSWORD:?}
DISCORD_CLIENT_ID: ${DISCORD_CLIENT_ID:?}
DISCORD_CLIENT_SECRET: ${DISCORD_CLIENT_SECRET:?}
DISCORD_REDIRECT_URI: ${DISCORD_REDIRECT_URI:?}
DISCORD_BOT_TOKEN: ${DISCORD_BOT_TOKEN:-}
DISCORD_GUILD_ID: ${DISCORD_GUILD_ID:-}
DISCORD_CONTRIBUTOR_ROLE_ID: ${DISCORD_CONTRIBUTOR_ROLE_ID:-}
DISCORD_OBSERVER_ROLE_ID: ${DISCORD_OBSERVER_ROLE_ID:-}
ADMIN_DISCORD_IDS: ${ADMIN_DISCORD_IDS:-}
SUPERVISOR_DISCORD_IDS: ${SUPERVISOR_DISCORD_IDS:-}
MODERATOR_DISCORD_IDS: ${MODERATOR_DISCORD_IDS:-}
SENIOR_DISCORD_IDS: ${SENIOR_DISCORD_IDS:-}
S3_ENDPOINT: ${S3_ENDPOINT:-}
S3_REGION: ${S3_REGION:-}
S3_BUCKET: ${S3_BUCKET:-}
S3_ACCESS_KEY_ID: ${S3_ACCESS_KEY_ID:-}
S3_SECRET_ACCESS_KEY: ${S3_SECRET_ACCESS_KEY:-}
DISCORD_WEBHOOK_URL: ${DISCORD_WEBHOOK_URL:-}
DISCORD_SUPERVISOR_WEBHOOK_URL: ${DISCORD_SUPERVISOR_WEBHOOK_URL:-}
services:
postgres:
image: postgres:16-alpine
restart: unless-stopped
environment:
POSTGRES_USER: ${DB_USER:-postgres}
POSTGRES_PASSWORD: ${DB_PASSWORD:?}
POSTGRES_DB: ${DB_DATABASE:-platform}
volumes:
- postgres_data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U \"$$POSTGRES_USER\" -d \"$$POSTGRES_DB\""]
interval: 10s
timeout: 5s
retries: 5
security_opt:
- no-new-privileges:true
logging: *logging
redis:
image: redis:7-alpine
restart: unless-stopped
command:
- redis-server
- --requirepass
- ${REDIS_PASSWORD:?}
- --maxmemory
- ${REDIS_MAXMEMORY:-128mb}
- --maxmemory-policy
- allkeys-lru
- --save
- ""
environment:
REDISCLI_AUTH: ${REDIS_PASSWORD}
healthcheck:
test: ["CMD-SHELL", "redis-cli ping | grep -q PONG"]
interval: 10s
timeout: 5s
retries: 5
security_opt:
- no-new-privileges:true
logging: *logging
migrate:
<<: *hardening
image: *api-image
pull_policy: always
restart: "no"
command: ["node", "ace", "migration:run", "--force"]
environment: *api-environment
healthcheck:
disable: true
depends_on:
postgres:
condition: service_healthy
logging: *logging
api:
<<: *hardening
image: *api-image
pull_policy: always
restart: unless-stopped
expose:
- "3333"
environment: *api-environment
depends_on:
migrate:
condition: service_completed_successfully
postgres:
condition: service_healthy
redis:
condition: service_healthy
logging: *logging
volumes:
postgres_data: