72247a387e
gates / gates (push) Successful in 3s
Location history with PostGIS 17 + Redis + Sidekiq. The seeded known login replaced by after_install behind the install hold; geocoding off; SECRET_KEY_BASE a data_key; smtp_mapping with mail-off boot measured. onboarding/dawarich.md complete. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
193 lines
6.8 KiB
YAML
193 lines
6.8 KiB
YAML
# Dawarich - Saját helyelőzmények (a Google Idővonal helyett)
|
|
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
|
# Database: PostgreSQL 17 + PostGIS 3.5 (the major upstream's own compose runs — `09` decision 42's rule) + Redis + Sidekiq
|
|
# RAM: ~900M (mem_limit: 2688M total — app 1024M + sidekiq 1024M + db 512M + redis 128M) | Pi-compatible: No (postgis/postgis is amd64-only)
|
|
#
|
|
# Environment variables:
|
|
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
|
# SECRET_KEY_BASE - Rails aláíró kulcs (generált)
|
|
# DB_PASSWORD - Adatbázis jelszó (generált; csak a belső hálón)
|
|
# ADMIN_PASSWORD - Az első bejelentkezés jelszava (generált; after_install állítja be)
|
|
#
|
|
# Mirrors upstream's docker/docker-compose.yml (app + sidekiq on the same image, postgis 17-3.5, redis 7.4), pinned.
|
|
# THE KNOWN LOGIN: the app's entrypoint runs `rails db:seed`, which creates `demo@dawarich.app` / `safepassword` when no
|
|
# user exists (db/seeds.rb). `after_install` replaces that password with the box's generated one, through Rails itself
|
|
# (the password is ARGV, never pasted into code); until it succeeds the box holds the app behind the gate (R-741).
|
|
# Reverse geocoding stays OFF (no PHOTON_API_HOST / NOMINATIM_API_HOST / GEOAPIFY / LOCATIONIQ set): no coordinate
|
|
# leaves the box. The map's tiles are fetched by the household's BROWSER from Dawarich's default tile server (FIT.md).
|
|
|
|
services:
|
|
dawarich:
|
|
image: freikin/dawarich:1.15.3
|
|
container_name: dawarich
|
|
restart: unless-stopped
|
|
entrypoint: web-entrypoint.sh
|
|
command: ["bin/rails", "server", "-p", "3000", "-b", "::"]
|
|
environment:
|
|
TZ: Europe/Budapest
|
|
TIME_ZONE: Europe/Budapest
|
|
RAILS_ENV: production
|
|
REDIS_URL: redis://dawarich-redis:6379
|
|
DATABASE_HOST: dawarich-db
|
|
DATABASE_PORT: "5432"
|
|
DATABASE_USERNAME: dawarich
|
|
DATABASE_PASSWORD: ${DB_PASSWORD}
|
|
DATABASE_NAME: dawarich
|
|
APPLICATION_HOSTS: ${SUBDOMAIN}.${DOMAIN},localhost,127.0.0.1,::1
|
|
APPLICATION_PROTOCOL: http
|
|
SECRET_KEY_BASE: ${SECRET_KEY_BASE}
|
|
RAILS_LOG_TO_STDOUT: "true"
|
|
SELF_HOSTED: "true"
|
|
STORE_GEODATA: "true"
|
|
WEB_CONCURRENCY: "1"
|
|
PROMETHEUS_EXPORTER_ENABLED: "false"
|
|
BACKGROUND_PROCESSING_CONCURRENCY: "3"
|
|
# App-email (smtp_mapping; STARTTLS to the shim on :2525, its self-signed certificate accepted by
|
|
# SMTP_OPENSSL_VERIFY_MODE=none; the shim takes no login, so SMTP_AUTHENTICATION=none). Empty SMTP_SERVER = mail OFF;
|
|
# measured 2026-10-01 that a fresh install with mail OFF boots (checklist 7.1). DOMAIN builds the links in its mails.
|
|
SMTP_SERVER: ${SMTP_SERVER:-}
|
|
SMTP_PORT: ${SMTP_PORT:-587}
|
|
SMTP_FROM: ${SMTP_FROM:-}
|
|
SMTP_AUTHENTICATION: "none"
|
|
SMTP_OPENSSL_VERIFY_MODE: "none"
|
|
DOMAIN: ${SUBDOMAIN}.${DOMAIN}
|
|
volumes:
|
|
- dawarich_public:/var/app/public
|
|
- dawarich_watched:/var/app/tmp/imports/watched
|
|
- dawarich_storage:/var/app/storage
|
|
networks:
|
|
- traefik-public
|
|
- dawarich-internal
|
|
depends_on:
|
|
dawarich-db:
|
|
condition: service_healthy
|
|
dawarich-redis:
|
|
condition: service_healthy
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 1024M
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "wget -qO - http://127.0.0.1:3000/api/v1/health | grep -q '\"status\"'"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 10
|
|
start_period: 120s
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.dawarich.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
|
- "traefik.http.routers.dawarich.entrypoints=websecure"
|
|
- "traefik.http.routers.dawarich.tls=true"
|
|
- "traefik.http.routers.dawarich.tls.certresolver=letsencrypt"
|
|
- "traefik.http.services.dawarich.loadbalancer.server.port=3000"
|
|
|
|
dawarich-sidekiq:
|
|
image: freikin/dawarich:1.15.3
|
|
container_name: dawarich-sidekiq
|
|
restart: unless-stopped
|
|
entrypoint: sidekiq-entrypoint.sh
|
|
command: ["sidekiq"]
|
|
environment:
|
|
TZ: Europe/Budapest
|
|
TIME_ZONE: Europe/Budapest
|
|
RAILS_ENV: production
|
|
REDIS_URL: redis://dawarich-redis:6379
|
|
DATABASE_HOST: dawarich-db
|
|
DATABASE_PORT: "5432"
|
|
DATABASE_USERNAME: dawarich
|
|
DATABASE_PASSWORD: ${DB_PASSWORD}
|
|
DATABASE_NAME: dawarich
|
|
APPLICATION_HOSTS: ${SUBDOMAIN}.${DOMAIN},localhost,127.0.0.1,::1
|
|
APPLICATION_PROTOCOL: http
|
|
SECRET_KEY_BASE: ${SECRET_KEY_BASE}
|
|
RAILS_LOG_TO_STDOUT: "true"
|
|
SELF_HOSTED: "true"
|
|
STORE_GEODATA: "true"
|
|
WEB_CONCURRENCY: "1"
|
|
PROMETHEUS_EXPORTER_ENABLED: "false"
|
|
BACKGROUND_PROCESSING_CONCURRENCY: "3"
|
|
# App-email (smtp_mapping; STARTTLS to the shim on :2525, its self-signed certificate accepted by
|
|
# SMTP_OPENSSL_VERIFY_MODE=none; the shim takes no login, so SMTP_AUTHENTICATION=none). Empty SMTP_SERVER = mail OFF;
|
|
# measured 2026-10-01 that a fresh install with mail OFF boots (checklist 7.1). DOMAIN builds the links in its mails.
|
|
SMTP_SERVER: ${SMTP_SERVER:-}
|
|
SMTP_PORT: ${SMTP_PORT:-587}
|
|
SMTP_FROM: ${SMTP_FROM:-}
|
|
SMTP_AUTHENTICATION: "none"
|
|
SMTP_OPENSSL_VERIFY_MODE: "none"
|
|
DOMAIN: ${SUBDOMAIN}.${DOMAIN}
|
|
volumes:
|
|
- dawarich_public:/var/app/public
|
|
- dawarich_watched:/var/app/tmp/imports/watched
|
|
- dawarich_storage:/var/app/storage
|
|
networks:
|
|
- dawarich-internal
|
|
depends_on:
|
|
dawarich:
|
|
condition: service_healthy
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 1024M
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pgrep -f sidekiq"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 10
|
|
start_period: 60s
|
|
|
|
dawarich-db:
|
|
image: postgis/postgis:17-3.5-alpine
|
|
container_name: dawarich-db
|
|
restart: unless-stopped
|
|
shm_size: 1g
|
|
environment:
|
|
TZ: Europe/Budapest
|
|
POSTGRES_USER: dawarich
|
|
POSTGRES_PASSWORD: ${DB_PASSWORD}
|
|
POSTGRES_DB: dawarich
|
|
volumes:
|
|
- dawarich_db_data:/var/lib/postgresql/data
|
|
networks:
|
|
- dawarich-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 512M
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U dawarich -d dawarich"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 10
|
|
start_period: 30s
|
|
|
|
dawarich-redis:
|
|
image: redis:7.4-alpine
|
|
container_name: dawarich-redis
|
|
restart: unless-stopped
|
|
command: ["redis-server", "--save", "900", "1", "--save", "300", "10", "--appendonly", "no"]
|
|
volumes:
|
|
- dawarich_redis:/data
|
|
networks:
|
|
- dawarich-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 128M
|
|
healthcheck:
|
|
test: ["CMD", "redis-cli", "ping"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
|
|
volumes:
|
|
dawarich_db_data:
|
|
dawarich_redis:
|
|
dawarich_public:
|
|
dawarich_watched:
|
|
dawarich_storage:
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|
|
dawarich-internal:
|