feat(map): add cache-first Cesium gateway and AMD egress
This commit is contained in:
@@ -0,0 +1,47 @@
|
||||
services:
|
||||
dc-amd-connector:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
container_name: dc-amd-connector
|
||||
image: nodedc/dc-amd-connector:local
|
||||
restart: unless-stopped
|
||||
# This is a byte-forwarding gateway, not a map renderer. These are circuit
|
||||
# breakers for the shared workstation, not normal throughput limits.
|
||||
cpus: "1.00"
|
||||
mem_limit: 256m
|
||||
pids_limit: 64
|
||||
ulimits:
|
||||
nofile:
|
||||
soft: 4096
|
||||
hard: 4096
|
||||
env_file:
|
||||
- .env
|
||||
environment:
|
||||
PORT: "8791"
|
||||
AMD_CONNECTOR_ACCESS_TOKEN_FILE: /run/dc-amd-secrets/connector-access
|
||||
# Bind only to the stable LAN address of the AMD host, never all Windows
|
||||
# interfaces and never the OpenVPN adapter address.
|
||||
ports:
|
||||
- "${AMD_CONNECTOR_BIND_IP:?set AMD_CONNECTOR_BIND_IP}:${AMD_CONNECTOR_PORT:-8791}:8791"
|
||||
volumes:
|
||||
- type: bind
|
||||
source: ./runtime/connector-access
|
||||
target: /run/dc-amd-secrets/connector-access
|
||||
read_only: true
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /tmp:rw,noexec,nosuid,size=8m
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
cap_drop:
|
||||
- ALL
|
||||
healthcheck:
|
||||
test:
|
||||
- CMD-SHELL
|
||||
- >
|
||||
node -e "const fs=require('fs'),http=require('http');const t=fs.readFileSync('/run/dc-amd-secrets/connector-access','utf8').trim();const r=http.get({host:'127.0.0.1',port:8791,path:'/healthz',headers:{'proxy-authorization':'Bearer '+t}},x=>process.exit(x.statusCode===200?0:1));r.on('error',()=>process.exit(1))"
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
retries: 3
|
||||
start_period: 10s
|
||||
Reference in New Issue
Block a user