25ffd89ea6
The ONLY image move in this commit. Written by upgrade-test.py --write-ladder from both venues: - bench LXC 9401 (harness v4): converted 16 -> 18 in 21.4 s, check equal over 31 tables, the seeded poll read back, 10-minute memory watch peak 61.6 % (anon), 0 kills, 0 restarts; - box 9202 (controller 0.283.1, the product's guarded Update, drill catalog): converted, done in 32.8 s, PG_VERSION 18, the poll read back through the front door. Undo case on 9202 first: the load failing (adminpack, which 18 lacks) -> undone in 57.5 s, back on 16, the poll read back. Target 18: rallly's own upstream compose runs postgres:18-alpine at /var/lib/postgresql at v4.11.1 (09 decision 42's rule). The data mount moves with the image (pg_mounts_for). Evidence: felhom.eu/documentation/audits/pg-last-six-2026-09-30/ Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
93 lines
3.5 KiB
YAML
93 lines
3.5 KiB
YAML
# Rallly - Időpont szavazás (Doodle alternatíva)
|
|
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
|
# Database: postgres
|
|
# RAM: ~50M (mem_limit: 256M) | Pi-compatible: Yes
|
|
#
|
|
# Environment variables:
|
|
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
|
# SECRET_PASSWORD - Titkosítási kulcs (auto-generated)
|
|
# DB_PASSWORD - Adatbázis jelszó (auto-generated)
|
|
|
|
services:
|
|
rallly:
|
|
image: lukevella/rallly:4.11.1
|
|
container_name: rallly
|
|
restart: unless-stopped
|
|
depends_on:
|
|
rallly-postgres:
|
|
condition: service_healthy
|
|
environment:
|
|
- TZ=Europe/Budapest
|
|
- DATABASE_URL=postgresql://rallly:${DB_PASSWORD}@rallly-postgres:5432/rallly
|
|
- SECRET_PASSWORD=${SECRET_PASSWORD}
|
|
- NEXT_PUBLIC_BASE_URL=https://${SUBDOMAIN}.${DOMAIN}
|
|
# App-email (managed relay). Injected by the controller only when app-email is on (global +
|
|
# per-app); empty SMTP_HOST keeps Rallly mail disabled. Rallly (Nodemailer) reads these at send
|
|
# time. SMTP_SECURE=false → STARTTLS to the shim; SMTP_REJECT_UNAUTHORIZED=false accepts the
|
|
# shim's self-signed cert (v4 flag; v3.x accepts self-signed by default). See .felhom.yml smtp_mapping.
|
|
- SMTP_HOST=${SMTP_HOST:-}
|
|
- SMTP_PORT=${SMTP_PORT:-587}
|
|
- SMTP_SECURE=${SMTP_SECURE:-false}
|
|
- SMTP_REJECT_UNAUTHORIZED=${SMTP_REJECT_UNAUTHORIZED:-true}
|
|
# NOREPLY_EMAIL + SUPPORT_EMAIL are REQUIRED by Rallly at boot (it refuses to start without valid
|
|
# emails), independent of whether mail can actually send. Default them to valid addresses so Rallly
|
|
# boots with app-email OFF; the relay overrides NOREPLY_EMAIL to rallly@felhom.eu when ON.
|
|
- NOREPLY_EMAIL=${NOREPLY_EMAIL:-noreply@${DOMAIN}}
|
|
- NOREPLY_EMAIL_NAME=${NOREPLY_EMAIL_NAME:-Felhom}
|
|
- SUPPORT_EMAIL=${SUPPORT_EMAIL:-noreply@${DOMAIN}}
|
|
networks:
|
|
- traefik-public
|
|
- rallly-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 768M
|
|
# The rallly image has NO wget/curl — the old wget healthcheck always failed (exit 127), marking the
|
|
# container unhealthy, which made Traefik refuse to publish a route to it. Use Node (always present).
|
|
# rallly's "/" returns 307 → /login, so accept any status < 500.
|
|
healthcheck:
|
|
test: ["CMD", "node", "-e", "require('http').get('http://127.0.0.1:3000',r=>process.exit(r.statusCode<500?0:1)).on('error',()=>process.exit(1))"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 30s
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.rallly.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
|
- "traefik.http.routers.rallly.entrypoints=websecure"
|
|
- "traefik.http.routers.rallly.tls=true"
|
|
- "traefik.http.routers.rallly.tls.certresolver=letsencrypt"
|
|
- "traefik.http.services.rallly.loadbalancer.server.port=3000"
|
|
|
|
rallly-postgres:
|
|
image: postgres:18-alpine
|
|
container_name: rallly-postgres
|
|
restart: unless-stopped
|
|
environment:
|
|
- POSTGRES_USER=rallly
|
|
- POSTGRES_PASSWORD=${DB_PASSWORD}
|
|
- POSTGRES_DB=rallly
|
|
- TZ=Europe/Budapest
|
|
volumes:
|
|
- rallly_postgres_data:/var/lib/postgresql
|
|
networks:
|
|
- rallly-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 256M
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U rallly -d rallly"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
start_period: 20s
|
|
|
|
volumes:
|
|
rallly_postgres_data:
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|
|
rallly-internal:
|