# Dawarich - Saját helyelőzmények (a Google Idővonal helyett) # Domain: ${SUBDOMAIN}.${DOMAIN} # Database: PostgreSQL 17 + PostGIS 3.5 (the major upstream's own compose runs — `09` decision 42's rule) + Redis + Sidekiq # RAM: ~900M (mem_limit: 2688M total — app 1024M + sidekiq 1024M + db 512M + redis 128M) | Pi-compatible: No (postgis/postgis is amd64-only) # # Environment variables: # DOMAIN - Your domain (e.g., demo-felhom.eu) # SECRET_KEY_BASE - Rails aláíró kulcs (generált) # DB_PASSWORD - Adatbázis jelszó (generált; csak a belső hálón) # ADMIN_PASSWORD - Az első bejelentkezés jelszava (generált; after_install állítja be) # # Mirrors upstream's docker/docker-compose.yml (app + sidekiq on the same image, postgis 17-3.5, redis 7.4), pinned. # THE KNOWN LOGIN: the app's entrypoint runs `rails db:seed`, which creates `demo@dawarich.app` / `safepassword` when no # user exists (db/seeds.rb). `after_install` replaces that password with the box's generated one, through Rails itself # (the password is ARGV, never pasted into code); until it succeeds the box holds the app behind the gate (R-741). # Reverse geocoding stays OFF (no PHOTON_API_HOST / NOMINATIM_API_HOST / GEOAPIFY / LOCATIONIQ set): no coordinate # leaves the box. The map's tiles are fetched by the household's BROWSER from Dawarich's default tile server (FIT.md). services: dawarich: image: freikin/dawarich:1.15.3 container_name: dawarich restart: unless-stopped entrypoint: web-entrypoint.sh command: ["bin/rails", "server", "-p", "3000", "-b", "::"] environment: TZ: Europe/Budapest TIME_ZONE: Europe/Budapest RAILS_ENV: production REDIS_URL: redis://dawarich-redis:6379 DATABASE_HOST: dawarich-db DATABASE_PORT: "5432" DATABASE_USERNAME: dawarich DATABASE_PASSWORD: ${DB_PASSWORD} DATABASE_NAME: dawarich APPLICATION_HOSTS: ${SUBDOMAIN}.${DOMAIN},localhost,127.0.0.1,::1 APPLICATION_PROTOCOL: http SECRET_KEY_BASE: ${SECRET_KEY_BASE} RAILS_LOG_TO_STDOUT: "true" SELF_HOSTED: "true" STORE_GEODATA: "true" WEB_CONCURRENCY: "1" PROMETHEUS_EXPORTER_ENABLED: "false" BACKGROUND_PROCESSING_CONCURRENCY: "3" # App-email (smtp_mapping; STARTTLS to the shim on :2525, its self-signed certificate accepted by # SMTP_OPENSSL_VERIFY_MODE=none; the shim takes no login, so SMTP_AUTHENTICATION=none). Empty SMTP_SERVER = mail OFF; # measured 2026-10-01 that a fresh install with mail OFF boots (checklist 7.1). DOMAIN builds the links in its mails. SMTP_SERVER: ${SMTP_SERVER:-} SMTP_PORT: ${SMTP_PORT:-587} SMTP_FROM: ${SMTP_FROM:-} SMTP_AUTHENTICATION: "none" SMTP_OPENSSL_VERIFY_MODE: "none" DOMAIN: ${SUBDOMAIN}.${DOMAIN} volumes: - dawarich_public:/var/app/public - dawarich_watched:/var/app/tmp/imports/watched - dawarich_storage:/var/app/storage networks: - traefik-public - dawarich-internal depends_on: dawarich-db: condition: service_healthy dawarich-redis: condition: service_healthy deploy: resources: limits: memory: 1024M healthcheck: test: ["CMD-SHELL", "wget -qO - http://127.0.0.1:3000/api/v1/health | grep -q '\"status\"'"] interval: 30s timeout: 10s retries: 10 start_period: 120s labels: - "traefik.enable=true" - "traefik.http.routers.dawarich.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)" - "traefik.http.routers.dawarich.entrypoints=websecure" - "traefik.http.routers.dawarich.tls=true" - "traefik.http.routers.dawarich.tls.certresolver=letsencrypt" - "traefik.http.services.dawarich.loadbalancer.server.port=3000" dawarich-sidekiq: image: freikin/dawarich:1.15.3 container_name: dawarich-sidekiq restart: unless-stopped entrypoint: sidekiq-entrypoint.sh command: ["sidekiq"] environment: TZ: Europe/Budapest TIME_ZONE: Europe/Budapest RAILS_ENV: production REDIS_URL: redis://dawarich-redis:6379 DATABASE_HOST: dawarich-db DATABASE_PORT: "5432" DATABASE_USERNAME: dawarich DATABASE_PASSWORD: ${DB_PASSWORD} DATABASE_NAME: dawarich APPLICATION_HOSTS: ${SUBDOMAIN}.${DOMAIN},localhost,127.0.0.1,::1 APPLICATION_PROTOCOL: http SECRET_KEY_BASE: ${SECRET_KEY_BASE} RAILS_LOG_TO_STDOUT: "true" SELF_HOSTED: "true" STORE_GEODATA: "true" WEB_CONCURRENCY: "1" PROMETHEUS_EXPORTER_ENABLED: "false" BACKGROUND_PROCESSING_CONCURRENCY: "3" # App-email (smtp_mapping; STARTTLS to the shim on :2525, its self-signed certificate accepted by # SMTP_OPENSSL_VERIFY_MODE=none; the shim takes no login, so SMTP_AUTHENTICATION=none). Empty SMTP_SERVER = mail OFF; # measured 2026-10-01 that a fresh install with mail OFF boots (checklist 7.1). DOMAIN builds the links in its mails. SMTP_SERVER: ${SMTP_SERVER:-} SMTP_PORT: ${SMTP_PORT:-587} SMTP_FROM: ${SMTP_FROM:-} SMTP_AUTHENTICATION: "none" SMTP_OPENSSL_VERIFY_MODE: "none" DOMAIN: ${SUBDOMAIN}.${DOMAIN} volumes: - dawarich_public:/var/app/public - dawarich_watched:/var/app/tmp/imports/watched - dawarich_storage:/var/app/storage networks: - dawarich-internal depends_on: dawarich: condition: service_healthy deploy: resources: limits: memory: 1024M healthcheck: test: ["CMD-SHELL", "pgrep -f sidekiq"] interval: 30s timeout: 10s retries: 10 start_period: 60s dawarich-db: image: postgis/postgis:17-3.5-alpine container_name: dawarich-db restart: unless-stopped shm_size: 1g environment: TZ: Europe/Budapest POSTGRES_USER: dawarich POSTGRES_PASSWORD: ${DB_PASSWORD} POSTGRES_DB: dawarich volumes: - dawarich_db_data:/var/lib/postgresql/data networks: - dawarich-internal deploy: resources: limits: memory: 512M healthcheck: test: ["CMD-SHELL", "pg_isready -U dawarich -d dawarich"] interval: 10s timeout: 5s retries: 10 start_period: 30s dawarich-redis: image: redis:7.4-alpine container_name: dawarich-redis restart: unless-stopped command: ["redis-server", "--save", "900", "1", "--save", "300", "10", "--appendonly", "no"] volumes: - dawarich_redis:/data networks: - dawarich-internal deploy: resources: limits: memory: 128M healthcheck: test: ["CMD", "redis-cli", "ping"] interval: 10s timeout: 5s retries: 5 volumes: dawarich_db_data: dawarich_redis: dawarich_public: dawarich_watched: dawarich_storage: networks: traefik-public: external: true dawarich-internal: