Repository navigation
Expand file tree
/
Copy pathcompose.yml
More file actions
98 lines (89 loc) · 3.46 KB
/
Copy pathcompose.yml
File metadata and controls
98 lines (89 loc) · 3.46 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
# Local Postgres for development. Nothing else runs in here: the API and the
# web app run on the host, where they reload.
#
# docker compose up -d Postgres on 5436, ready to migrate.
# bun run db:migrate Apply packages/core/drizzle migrations to it.
# docker compose down -v Throw the data away.
#
# CI uses a service container with the same image and the same DATABASE_URL
# shape, so a migration that applies here applies there.
name: sugabots
services:
postgres:
container_name: sugabots_postgres
# Pinned to a major so local, CI and production agree on behaviour. The
# schema leans on 18: `uuidv7()` is built in from this release.
image: postgres:18-alpine
environment:
POSTGRES_USER: ${POSTGRES_USER:-sugabots}
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-sugabots}
POSTGRES_DB: ${POSTGRES_DB:-sugabots}
ports:
# 5436 to stay clear of a default Postgres and of sweet's 5435.
- "127.0.0.1:${POSTGRES_PORT:-5436}:5432"
restart: unless-stopped
volumes:
# Postgres 18 images store data in a major-version subdirectory so
# `pg_upgrade --link` works without crossing a mount boundary, so the
# mount goes at /var/lib/postgresql, NOT the /data path 17 and earlier
# used. An 18 image refuses to start against the old layout.
- sugabots_postgres_data:/var/lib/postgresql
- ./postgres/init:/docker-entrypoint-initdb.d:ro
healthcheck:
test:
- CMD-SHELL
- pg_isready -U ${POSTGRES_USER:-sugabots} -d ${POSTGRES_DB:-sugabots}
interval: 5s
timeout: 5s
retries: 12
start_period: 5s
# Sandboxes for local development, only with `--profile sandboxes`. It holds
# the Docker socket, so it can start containers on this machine: that is how
# it makes sandboxes, and why it is not started unless asked for.
opensandbox:
container_name: sugabots_opensandbox
profiles: [sandboxes]
image: opensandbox/server:release-1.1.0
environment:
SANDBOX_CONFIG_PATH: /etc/opensandbox/config.toml
configs:
- source: opensandbox_config
target: /etc/opensandbox/config.toml
extra_hosts:
- "host.docker.internal:host-gateway"
ports:
- "127.0.0.1:${OPENSANDBOX_PORT:-8090}:8090"
restart: unless-stopped
volumes:
- /var/run/docker.sock:/var/run/docker.sock
configs:
opensandbox_config:
content: |
[server]
host = "0.0.0.0"
port = 8090
api_key = "${OPENSANDBOX_API_KEY:-development-opensandbox-key}"
[runtime]
type = "docker"
execd_image = "opensandbox/execd:v1.1.0"
[egress]
image = "opensandbox/egress:v1.1.7"
mode = "dns+nft"
[docker]
network_mode = "bridge"
# Sandboxes' ports are published on Docker's bridge address, which this
# container can reach and nothing outside the machine can. 172.17.0.1 is
# Docker's default on Linux.
host_ip = "${OPENSANDBOX_HOST_IP:-172.17.0.1}"
publish_host = "${OPENSANDBOX_HOST_IP:-172.17.0.1}"
# Below Linux's ephemeral ports (32768 and up), which outgoing
# connections take, so a sandbox's port is never already in use.
port_range_min = 20000
port_range_max = 30000
drop_capabilities = ["AUDIT_WRITE", "MKNOD", "NET_ADMIN", "NET_RAW", "SYS_ADMIN", "SYS_MODULE", "SYS_PTRACE", "SYS_TIME", "SYS_TTY_CONFIG"]
no_new_privileges = true
pids_limit = 4096
[ingress]
mode = "direct"
volumes:
sugabots_postgres_data: