-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
98 lines (93 loc) · 3.78 KB
/
Copy pathdocker-compose.yml
File metadata and controls
98 lines (93 loc) · 3.78 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
# ── Production-like Local Stack (ADR-029) ──────────────────────────
# Creates a production-like stack locally.
# PostgreSQL is NOT exposed to the host — access only via Docker network.
#
# For actual production deployment (Render), use the dashboard or
# render.yaml. DATABASE_URL is injected by the PostgreSQL addon.
#
# Usage:
# docker compose --env-file .env.production up -d
services:
# ── MQTT Broker ────────────────────────────────────────────────
# Port 8883 (MQTTS, TLS) expuesto al host para firmware.
# Port 1883 (MQTT) NO se publica al host — solo accesible dentro de la
# red Docker (ISSUE-075/PR-A): el backend bridge usa MQTTS en 8883.
mosquitto:
image: eclipse-mosquitto:2@sha256:6f8d8a947c506f8a2290ec65cd4bd2bc7cb4d43fb5f6271f861cb013e2ef9797
container_name: mush2-mosquitto
restart: unless-stopped
ports:
- "8883:8883"
volumes:
- ./docker/mosquitto/prod:/mosquitto/config:ro
- ./docker/mosquitto/certs:/mosquitto/certs:ro
- mosquitto-data:/mosquitto/data
- mosquitto-log:/mosquitto/log
healthcheck:
test: ["CMD-SHELL", "nc -z 127.0.0.1 8883"]
interval: 30s
timeout: 5s
retries: 3
start_period: 10s
networks:
- mush2-internal
# ── PostgreSQL ─────────────────────────────────────────────────
# NO ports exposed to host — ADR-029 compliance.
# Access only via Docker network (postgres:5432).
postgres:
image: postgres:16-alpine@sha256:57c72fd2a128e416c7fcc499958864df5301e940bca0a56f58fddf30ffc07777
container_name: mush2-postgres
restart: unless-stopped
environment:
POSTGRES_DB: ${DB_NAME:-mush2}
POSTGRES_USER: ${DB_USER:-mush2}
POSTGRES_PASSWORD: ${DB_PASSWORD:?Set DB_PASSWORD in .env.production or shell}
volumes:
- pgdata:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${DB_USER:-mush2} -d ${DB_NAME:-mush2}"]
interval: 5s
timeout: 5s
retries: 10
start_period: 5s
networks:
- mush2-internal
# ── Backend ────────────────────────────────────────────────────
backend:
build:
context: .
dockerfile: Dockerfile
container_name: mush2-backend
restart: unless-stopped
ports:
- "3797:3797"
environment:
NODE_ENV: production
DATABASE_URL: postgresql://mush2:${DB_PASSWORD}@postgres:5432/mush2
# TLS obligatorio para el bridge en prod (ISSUE-015/PR-L). Requiere el
# listener 8883 activo con certs en docker/mosquitto/certs (I074/I075).
MQTT_BROKER_URL: mqtts://mosquitto:8883
MQTT_BROKER_USER: backend_bridge
MQTT_BROKER_PASS: ${MQTT_BROKER_PASS:?Set MQTT_BROKER_PASS in .env.production or shell}
volumes:
# Volumen compartido con el broker (montado :ro en mosquitto): el backend
# escribe el password_file que el broker lee/recarga (I081/INF-022).
- ./docker/mosquitto/prod:/app/docker/mosquitto/prod
# Socket de Docker: reload() envía SIGHUP a mush2-mosquitto (recarga sin
# downtime). SOLO stack prod-like local (ADR-029); en el PaaS el mecanismo
# de recarga se define en el runbook de despliegue (DECISION-011).
- /var/run/docker.sock:/var/run/docker.sock
depends_on:
mosquitto:
condition: service_healthy
postgres:
condition: service_healthy
networks:
- mush2-internal
networks:
mush2-internal:
driver: bridge
volumes:
pgdata:
mosquitto-data:
mosquitto-log: