Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
204 lines (195 loc) · 6.03 KB
/
Copy pathdocker-compose.yml
File metadata and controls
204 lines (195 loc) · 6.03 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
services:
console:
container_name: oasm-console
image: oasm/oasm-console:${IMAGE_TAG:-latest}
networks:
- oasm
ports:
- '6276:80'
volumes:
- ./nginx.conf:/etc/nginx/conf.d/default.conf:ro
restart: on-failure
depends_on:
core-api:
condition: service_healthy
core-api:
container_name: oasm-api
image: oasm/oasm-api:${IMAGE_TAG:-latest}
networks:
- oasm
ports:
- '16276:16276'
environment:
- POSTGRES_HOST=${POSTGRES_HOST:-postgres}
- POSTGRES_USERNAME=${POSTGRES_USERNAME:-postgres}
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-postgres}
- POSTGRES_PORT=${POSTGRES_PORT:-5432}
- POSTGRES_DB=${POSTGRES_DB:-open_asm}
- POSTGRES_SSL=${POSTGRES_SSL:-false}
- PORT=${PORT:-6276}
- OASM_CLOUD_APIKEY=${OASM_CLOUD_APIKEY}
- REDIS_URL=${REDIS_URL:-redis://:open_asm@redis:6379/0}
- GEO_IP_URL=geo-ip-database:4360
- RUSTFS_ENDPOINT=${RUSTFS_ENDPOINT:-http://rustfs:9000}
- RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin}
- RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfssecret}
restart: on-failure
depends_on:
postgres:
condition: service_healthy
redis:
condition: service_healthy
geo-ip-database:
condition: service_healthy
migration:
condition: service_completed_successfully
healthcheck:
test: ['CMD', 'curl', '-f', 'http://localhost:${PORT:-6276}/api/health']
interval: 1s
timeout: 60s
retries: 10
rustfs:
container_name: oasm-rustfs
image: rustfs/rustfs:latest
networks:
- oasm
environment:
- RUSTFS_ACCESS_KEY=rustfsadmin
- RUSTFS_SECRET_KEY=rustfssecret
volumes:
- rustfs-data:/data:rw
restart: 'always'
logging:
driver: json-file
options:
max-size: 10m
max-file: '3'
command: ['/data']
migration:
container_name: oasm-migration
image: oasm/oasm-api:${IMAGE_TAG:-dev}
networks:
- oasm
environment:
- POSTGRES_HOST=${POSTGRES_HOST:-postgres}
- POSTGRES_USERNAME=${POSTGRES_USERNAME:-postgres}
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-postgres}
- POSTGRES_PORT=${POSTGRES_PORT:-5432}
- POSTGRES_DB=${POSTGRES_DB:-open_asm}
- POSTGRES_SSL=${POSTGRES_SSL:-false}
command: sh -c "npx typeorm migration:run -d dist/database/database-config.js"
restart: 'no'
depends_on:
postgres:
condition: service_healthy
oasm-worker:
image: oasm/oasm-worker:${IMAGE_TAG:-latest}
environment:
- WORKER_API_KEY=${OASM_CLOUD_APIKEY}
- WORKER_MODE=node
- WORKER_GRPC_HOST=core-api
- WORKER_GRPC_PORT=16276
- WORKER_MAX_CONCURRENCY=10
- WORKER_TOOL_PATH=/app/oasm-tools
# Required: spawned connector containers dial back to this address.
# They run on the host daemon (docker-outside-of-docker), so they reach
# the worker through host.docker.internal -> the published 26276 port.
# Do NOT use 0.0.0.0 or the container IP — containers cannot dial those.
- WORKER_CONNECTOR_ADDR=host.docker.internal:26276
logging:
driver: json-file
options:
max-size: 10m
max-file: '3'
volumes:
- worker-tools-cache:/app/oasm-tools:rw
# Node mode spawns connector containers via the Docker Engine API
# (internal/runtime/docker.go), so it MUST reach a daemon. SECURITY:
# docker.sock is root-equivalent on the host — only run trusted images.
- /var/run/docker.sock:/var/run/docker.sock
# Image runs as non-root uid/gid 1000; the mounted socket is owned by the
# host's docker group. Docker Desktop uses gid 0; native Linux engines
# usually use a dedicated `docker` group. Without the matching gid the
# daemon returns "permission denied".
# Find it with: stat -c '%g' /var/run/docker.sock
group_add:
- '${DOCKER_GID:-0}'
ports:
# Connector gRPC listen port. Spawned containers dial back through the
# host via WORKER_CONNECTOR_ADDR, which requires this published port.
- '26276:26276'
networks:
- oasm
restart: always
depends_on:
core-api:
condition: service_healthy
# Single instance: the connector port is published on the host, so a
# second replica cannot bind 26276 and would fail to spawn containers.
# Scale workers only by giving each a distinct WORKER_CONNECTOR_ADDR/port.
postgres:
container_name: oasm-postgres
image: postgres:17
restart: on-failure
environment:
- POSTGRES_USER=${POSTGRES_USERNAME:-postgres}
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-postgres}
- POSTGRES_DB=${POSTGRES_DB:-open_asm}
volumes:
- pgdata:/var/lib/postgresql/data:rw
networks:
- oasm
healthcheck:
test: ['CMD-SHELL', 'pg_isready -U ${POSTGRES_USERNAME:-postgres}']
interval: 1s
timeout: 5s
retries: 10
redis:
container_name: oasm-redis
image: redis:alpine
restart: on-failure
networks:
- oasm
volumes:
- redis-data:/data
command: redis-server --requirepass ${REDIS_PASSWORD} --appendonly yes --save 3600 1 --save 30 500 --save 300 100 --save 60 10000
environment:
REDIS_PASSWORD: ${REDIS_PASSWORD}
healthcheck:
test: ['CMD', 'redis-cli', '-a', '${REDIS_PASSWORD}', 'ping']
interval: 10s
timeout: 5s
retries: 5
start_period: 10s
deploy:
resources:
limits:
cpus: '1'
memory: 1500M
reservations:
cpus: '0.5'
memory: 512M
geo-ip-database:
container_name: geo-ip-database
image: ghcr.io/l1ttps/geoip-proxy:latest
platform: linux/amd64
networks:
- oasm
restart: on-failure
volumes:
- geoip-data:/app/data:rw
healthcheck:
test: ['CMD', 'curl', '-f', 'http://localhost:4360']
interval: 1s
timeout: 60s
retries: 10
volumes:
pgdata:
redis-data:
geoip-data:
rustfs-data:
worker-tools-cache:
networks:
oasm:
driver: bridge
name: oasm_net