docker-compose.services.yml 4.0 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495
  1. # The webserver and runner on zeus, in containers.
  2. #
  3. # docker compose -f docker-compose.services.yml up -d
  4. # docker compose -f docker-compose.services.yml logs -f
  5. #
  6. # The database is NOT here - it has its own compose file next to this one and
  7. # its own lifecycle. These two only talk to it.
  8. #
  9. # Build the image first (from the repo root):
  10. # REPO_PASS=$(grep -oP 'RepoPass:\s*\K.*' /data/smartbotics-deb-repo/.env)
  11. # docker buildx build -f packaging/Dockerfile.build \
  12. # --build-arg BASE_IMAGE=smartbotic-automation-build-base:debian13 \
  13. # --build-arg REPO_PASS="$REPO_PASS" \
  14. # --target runtime -t smartbotic-automation:current .
  15. name: smartbotic
  16. services:
  17. smartbotic-webserver:
  18. image: smartbotic-automation:current
  19. container_name: smartbotic-webserver
  20. command: ["/usr/bin/smartbotic-webserver"]
  21. restart: unless-stopped
  22. networks: [smartbotic]
  23. ports:
  24. - "8090:8090" # HTTP + WebUI
  25. - "8091:8091" # WebSocket, derived as http_port + 1
  26. # The database container publishes 9004 on the host and sits on the default
  27. # bridge. Rather than move it onto this network - which would mean
  28. # recreating a running database - these services reach it back through the
  29. # host gateway.
  30. extra_hosts:
  31. - "host.docker.internal:host-gateway"
  32. environment:
  33. TZ: Europe/Budapest
  34. LOG_LEVEL: info
  35. DATABASE_ADDRESS: host.docker.internal:9004
  36. DATABASE_PROJECT: smartbotic-automation
  37. volumes:
  38. # Read-only: it carries the credentials master key and the JWT secret,
  39. # and nothing should be rewriting it from inside a container.
  40. - /data/dev/smartbotics/smartbotic/config:/var/lib/smartbotic/config:ro
  41. # Bind-mounted rather than used from the image so a node can be edited and
  42. # re-migrated without a rebuild, which is how they are worked on today.
  43. - /data/dev/smartbotics/smartbotic/nodes:/usr/share/smartbotic-automation/nodes:ro
  44. healthcheck:
  45. # bash's /dev/tcp, because a slim image carries no curl or wget.
  46. #
  47. # It must be CMD + bash, NOT CMD-SHELL: CMD-SHELL runs /bin/sh, which on
  48. # Debian is dash, and dash has no /dev/tcp - it fails with "cannot create
  49. # /dev/tcp/...: Directory nonexistent" on a webserver that is serving
  50. # perfectly well. The runner depends_on this being healthy, so getting it
  51. # wrong stops the runner from ever starting.
  52. test: ["CMD", "bash", "-c", "exec 3<>/dev/tcp/127.0.0.1/8090"]
  53. interval: 15s
  54. timeout: 5s
  55. retries: 5
  56. start_period: 20s
  57. smartbotic-runner:
  58. image: smartbotic-automation:current
  59. container_name: smartbotic-runner
  60. command: ["/usr/bin/smartbotic-runner"]
  61. restart: unless-stopped
  62. networks: [smartbotic]
  63. depends_on:
  64. smartbotic-webserver:
  65. condition: service_healthy
  66. extra_hosts:
  67. - "host.docker.internal:host-gateway"
  68. environment:
  69. TZ: Europe/Budapest
  70. LOG_LEVEL: info
  71. RUNNER_ID: runner-1
  72. DATABASE_ADDRESS: host.docker.internal:9004
  73. DATABASE_PROJECT: smartbotic-automation
  74. # Service names, not localhost: the two are separate containers even when
  75. # they share a host, so every one of these has to be stated.
  76. WEBSERVER_ADDRESS: smartbotic-webserver:8090
  77. NODE_SYNC_ADDRESS: smartbotic-webserver:9012
  78. CREDENTIAL_SERVICE_ADDRESS: smartbotic-webserver:9013
  79. # What the runner tells the webserver to reach it on. Left unset it says
  80. # "localhost:9011", which inside a container means the webserver's own
  81. # container - it registers, reports online, and every dispatch vanishes.
  82. ADVERTISE_ADDRESS: smartbotic-runner:9011
  83. volumes:
  84. - /data/dev/smartbotics/smartbotic/config:/var/lib/smartbotic/config:ro
  85. - /data/dev/smartbotics/smartbotic/nodes:/usr/share/smartbotic-automation/nodes:ro
  86. # Written by imap-extract-attachments. A bind mount, so the 230 files
  87. # carried over from mulan stay where the host can see them.
  88. - /data/dev/smartbotics/smartbotic/data:/var/lib/smartbotic/data
  89. networks:
  90. smartbotic:
  91. name: smartbotic