docker-compose.services.yml 5.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123
  1. # The webserver and runner on zeus, in containers.
  2. #
  3. # docker compose -f docker-compose.services.yml up -d
  4. # docker compose -f docker-compose.services.yml logs -f
  5. #
  6. # The database is NOT here - it has its own compose file next to this one and
  7. # its own lifecycle. These two only talk to it.
  8. #
  9. # Build the image first (from the repo root):
  10. # REPO_PASS=$(grep -oP 'RepoPass:\s*\K.*' /data/smartbotics-deb-repo/.env)
  11. # docker buildx build -f packaging/Dockerfile.build \
  12. # --build-arg BASE_IMAGE=smartbotic-automation-build-base:debian13 \
  13. # --build-arg REPO_PASS="$REPO_PASS" \
  14. # --target runtime -t smartbotic-automation:current .
  15. name: smartbotic
  16. services:
  17. smartbotic-webserver:
  18. image: smartbotic-automation:current
  19. container_name: smartbotic-webserver
  20. command: ["/usr/bin/smartbotic-webserver"]
  21. restart: unless-stopped
  22. networks: [smartbotic]
  23. ports:
  24. - "8090:8090" # HTTP + WebUI
  25. - "8091:8091" # WebSocket, derived as http_port + 1
  26. # The database container publishes 9004 on the host and sits on the default
  27. # bridge. Rather than move it onto this network - which would mean
  28. # recreating a running database - these services reach it back through the
  29. # host gateway.
  30. extra_hosts:
  31. - "host.docker.internal:host-gateway"
  32. environment:
  33. TZ: Europe/Budapest
  34. LOG_LEVEL: info
  35. DATABASE_ADDRESS: host.docker.internal:9004
  36. DATABASE_PROJECT: smartbotic-automation
  37. # For anything that talks to OpenSSL directly. libcurl ignores it, which
  38. # is why the bundle is also mounted over curl's default CA path below -
  39. # see the volume comment.
  40. SSL_CERT_FILE: /etc/ssl/certs/ca-certificates.crt
  41. volumes:
  42. # Read-only: it carries the credentials master key and the JWT secret,
  43. # and nothing should be rewriting it from inside a container.
  44. - /data/dev/smartbotics/smartbotic/config:/var/lib/smartbotic/config:ro
  45. # Bind-mounted rather than used from the image so a node can be edited and
  46. # re-migrated without a rebuild, which is how they are worked on today.
  47. - /data/dev/smartbotics/smartbotic/nodes:/usr/share/smartbotic-automation/nodes:ro
  48. # Debian's CA set plus the extra certificates in ca/ - currently mulan's
  49. # self-signed SD.cpp cert. Regenerate with ca/build-bundle.sh.
  50. #
  51. # Mounted OVER curl's default CA file rather than beside it. The runner
  52. # never sets CURLOPT_CAINFO, so libcurl uses its compiled-in default,
  53. # which on Debian is exactly this path - and libcurl reads neither
  54. # SSL_CERT_FILE (that is OpenSSL's) nor CURL_CA_BUNDLE (that is the curl
  55. # command-line tool's). Pointing an environment variable at a bundle
  56. # somewhere else looks like it should work and silently does nothing.
  57. - /data/dev/smartbotics/smartbotic/deploy/zeus/ca/bundle.crt:/etc/ssl/certs/ca-certificates.crt:ro
  58. healthcheck:
  59. # bash's /dev/tcp, because a slim image carries no curl or wget.
  60. #
  61. # It must be CMD + bash, NOT CMD-SHELL: CMD-SHELL runs /bin/sh, which on
  62. # Debian is dash, and dash has no /dev/tcp - it fails with "cannot create
  63. # /dev/tcp/...: Directory nonexistent" on a webserver that is serving
  64. # perfectly well. The runner depends_on this being healthy, so getting it
  65. # wrong stops the runner from ever starting.
  66. test: ["CMD", "bash", "-c", "exec 3<>/dev/tcp/127.0.0.1/8090"]
  67. interval: 15s
  68. timeout: 5s
  69. retries: 5
  70. start_period: 20s
  71. smartbotic-runner:
  72. image: smartbotic-automation:current
  73. container_name: smartbotic-runner
  74. command: ["/usr/bin/smartbotic-runner"]
  75. restart: unless-stopped
  76. networks: [smartbotic]
  77. depends_on:
  78. smartbotic-webserver:
  79. condition: service_healthy
  80. extra_hosts:
  81. - "host.docker.internal:host-gateway"
  82. environment:
  83. TZ: Europe/Budapest
  84. LOG_LEVEL: info
  85. RUNNER_ID: runner-1
  86. DATABASE_ADDRESS: host.docker.internal:9004
  87. DATABASE_PROJECT: smartbotic-automation
  88. # Service names, not localhost: the two are separate containers even when
  89. # they share a host, so every one of these has to be stated.
  90. WEBSERVER_ADDRESS: smartbotic-webserver:8090
  91. NODE_SYNC_ADDRESS: smartbotic-webserver:9012
  92. CREDENTIAL_SERVICE_ADDRESS: smartbotic-webserver:9013
  93. # What the runner tells the webserver to reach it on. Left unset it says
  94. # "localhost:9011", which inside a container means the webserver's own
  95. # container - it registers, reports online, and every dispatch vanishes.
  96. ADVERTISE_ADDRESS: smartbotic-runner:9011
  97. # For anything that talks to OpenSSL directly. libcurl ignores it, which
  98. # is why the bundle is also mounted over curl's default CA path below -
  99. # see the volume comment.
  100. SSL_CERT_FILE: /etc/ssl/certs/ca-certificates.crt
  101. volumes:
  102. - /data/dev/smartbotics/smartbotic/config:/var/lib/smartbotic/config:ro
  103. - /data/dev/smartbotics/smartbotic/nodes:/usr/share/smartbotic-automation/nodes:ro
  104. # Written by imap-extract-attachments. A bind mount, so the 230 files
  105. # carried over from mulan stay where the host can see them.
  106. - /data/dev/smartbotics/smartbotic/data:/var/lib/smartbotic/data
  107. # Debian's CA set plus the extra certificates in ca/ - currently mulan's
  108. # self-signed SD.cpp cert. Regenerate with ca/build-bundle.sh.
  109. #
  110. # Mounted OVER curl's default CA file rather than beside it. The runner
  111. # never sets CURLOPT_CAINFO, so libcurl uses its compiled-in default,
  112. # which on Debian is exactly this path - and libcurl reads neither
  113. # SSL_CERT_FILE (that is OpenSSL's) nor CURL_CA_BUNDLE (that is the curl
  114. # command-line tool's). Pointing an environment variable at a bundle
  115. # somewhere else looks like it should work and silently does nothing.
  116. - /data/dev/smartbotics/smartbotic/deploy/zeus/ca/bundle.crt:/etc/ssl/certs/ca-certificates.crt:ro
  117. networks:
  118. smartbotic:
  119. name: smartbotic