Repository navigation
Expand file tree
/
Copy pathcompose.yml
More file actions
90 lines (85 loc) · 2.83 KB
/
Copy pathcompose.yml
File metadata and controls
90 lines (85 loc) · 2.83 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
name: odbdesign
services:
### use remote image build from github container registry
server:
image: ghcr.io/nam20485/odbdesign:nam20485-latest
# The container runs as the non-root odbdesign user (uid/gid 10001). The
# bind mount below replaces the image-layer designs dir, and on a fresh
# host Docker creates ./compose-designs root-owned, so uploads would fail
# with EACCES. Prepare the host directory once before first use:
# mkdir -p ./compose-designs && sudo chown -R 10001:10001 ./compose-designs
volumes:
- ./compose-designs:/OdbDesign/designs
# No host-published ports — nginx (the `proxy` service below) is the
# only public ingress. Loopback-only 8888/50051 are kept for local debug.
ports:
- 127.0.0.1:8888:8888
- 127.0.0.1:50051:50051
expose:
- 8888
- 50051
environment:
- ODBDESIGN_SERVER_REQUEST_USERNAME
- ODBDESIGN_SERVER_REQUEST_PASSWORD
healthcheck:
# Default: HTTP check (works out of the box)
test: ["CMD", "curl", "-f", "http://localhost:8888/healthz/live"]
interval: 30s
timeout: 3s
retries: 3
start_period: 10s
### use local image built from Dockerfile
# server:
# build:
# context: .
# dockerfile: Dockerfile
# volumes:
# - ./compose-designs:/OdbDesign/designs
# ports:
# - 127.0.0.1:8888:8888
# - 127.0.0.1:50051:50051
# expose:
# - 8888
# - 50051
# environment:
# - ODBDESIGN_SERVER_REQUEST_USERNAME
# - ODBDESIGN_SERVER_REQUEST_PASSWORD
# healthcheck:
# # Default: HTTP check (works out of the box)
# test: ["CMD", "curl", "-f", "http://localhost:8888/healthz/live"]
# interval: 30s
# timeout: 3s
# retries: 3
# start_period: 10s
swagger-ui:
image: ghcr.io/nam20485/odbdesignserver-swaggerui:nam20485-latest
depends_on:
- server
# Loopback-only; nginx routes / → swagger-ui:8080.
ports:
- 127.0.0.1:8080:8080
expose:
- 8080
# Single public ingress: TLS termination + path-based routing.
# Pulls certs from ./ssl/ (host) and mounts the config from deploy/nginx/.
# See deploy/nginx/README.md for endpoint reference and cert setup.
proxy:
image: nginx:1.27-alpine
depends_on:
- server
- swagger-ui
ports:
- "443:443"
- "80:80"
volumes:
- ./deploy/nginx/nginx.conf:/etc/nginx/nginx.conf:ro
- ./ssl:/etc/nginx/ssl:ro
# wget is present in nginx:alpine; spider the swagger-ui container which
# in turn depends on the REST server. This is a smoke check, not a deep
# health probe — use /healthz behind the proxy for real probes.
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://swagger-ui:8080/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 10s