159 lines
4.7 KiB
YAML
159 lines
4.7 KiB
YAML
services:
|
|
device-postgres:
|
|
image: postgres:16-alpine
|
|
pull_policy: missing
|
|
restart: unless-stopped
|
|
environment:
|
|
POSTGRES_DB: device_plane
|
|
POSTGRES_USER: device_plane
|
|
POSTGRES_PASSWORD_FILE: /run/nodedc-secrets/postgres-password
|
|
volumes:
|
|
- type: volume
|
|
source: device-plane-postgres-data
|
|
target: /var/lib/postgresql/data
|
|
- type: bind
|
|
source: /volume1/docker/nodedc-device-plane/secrets/postgres-password
|
|
target: /run/nodedc-secrets/postgres-password
|
|
read_only: true
|
|
bind:
|
|
create_host_path: false
|
|
networks:
|
|
- device-plane-private
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U device_plane -d device_plane"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 12
|
|
start_period: 20s
|
|
|
|
device-control-core:
|
|
image: nodedc/device-control-core:local
|
|
pull_policy: never
|
|
restart: unless-stopped
|
|
user: "1000:1000"
|
|
read_only: true
|
|
tmpfs:
|
|
- /tmp:size=16m,mode=1777
|
|
environment:
|
|
HOST: 0.0.0.0
|
|
PORT: "18120"
|
|
DEVICE_DATABASE_HOST: device-postgres
|
|
DEVICE_DATABASE_PORT: "5432"
|
|
DEVICE_DATABASE_NAME: device_plane
|
|
DEVICE_DATABASE_USER: device_plane
|
|
DEVICE_DATABASE_PASSWORD_FILE: /run/nodedc-secrets/postgres-password
|
|
DEVICE_DATABASE_POOL_SIZE: "10"
|
|
DEVICE_DISCOVERY_INGEST_ENABLED: "true"
|
|
DEVICE_GATEWAY_CORE_TOKEN_FILE: /run/nodedc-secrets/gateway-core-token
|
|
DEVICE_IDENTIFIER_PEPPER_FILE: /run/nodedc-secrets/identifier-pepper
|
|
volumes:
|
|
- type: bind
|
|
source: /volume1/docker/nodedc-device-plane/secrets/postgres-password
|
|
target: /run/nodedc-secrets/postgres-password
|
|
read_only: true
|
|
bind:
|
|
create_host_path: false
|
|
- type: bind
|
|
source: /volume1/docker/nodedc-device-plane/secrets/gateway-core-token
|
|
target: /run/nodedc-secrets/gateway-core-token
|
|
read_only: true
|
|
bind:
|
|
create_host_path: false
|
|
- type: bind
|
|
source: /volume1/docker/nodedc-device-plane/secrets/identifier-pepper
|
|
target: /run/nodedc-secrets/identifier-pepper
|
|
read_only: true
|
|
bind:
|
|
create_host_path: false
|
|
ports:
|
|
- "127.0.0.1:18120:18120"
|
|
networks:
|
|
- device-plane-private
|
|
- device-plane-control
|
|
depends_on:
|
|
device-postgres:
|
|
condition: service_healthy
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
cap_drop:
|
|
- ALL
|
|
healthcheck:
|
|
test:
|
|
- CMD
|
|
- node
|
|
- -e
|
|
- fetch('http://127.0.0.1:18120/healthz').then(r=>{if(!r.ok)process.exit(1)}).catch(()=>process.exit(1))
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 12
|
|
start_period: 20s
|
|
|
|
device-gateway:
|
|
image: nodedc/device-gateway:local
|
|
pull_policy: never
|
|
restart: unless-stopped
|
|
user: "1000:1000"
|
|
read_only: true
|
|
tmpfs:
|
|
- /tmp:size=16m,mode=1777
|
|
environment:
|
|
DEVICE_GATEWAY_HEALTH_HOST: 0.0.0.0
|
|
DEVICE_GATEWAY_HEALTH_PORT: "18121"
|
|
DEVICE_GATEWAY_LISTEN_ENABLED: "true"
|
|
DEVICE_GATEWAY_PUBLIC_INGRESS_ENABLED: "true"
|
|
DEVICE_GATEWAY_TCP_HOST: 0.0.0.0
|
|
DEVICE_GATEWAY_TCP_PORT: "9921"
|
|
DEVICE_GATEWAY_CORE_URL: http://device-control-core:18120
|
|
DEVICE_GATEWAY_CORE_TOKEN_FILE: /run/nodedc-secrets/gateway-core-token
|
|
DEVICE_GATEWAY_CORE_TIMEOUT_MS: "5000"
|
|
DEVICE_GATEWAY_MAX_BUFFERED_BYTES: "65536"
|
|
DEVICE_GATEWAY_MAX_SESSIONS: "100"
|
|
DEVICE_GATEWAY_MAX_SESSIONS_PER_ADDRESS: "10"
|
|
DEVICE_GATEWAY_MAX_CONNECTIONS_PER_MINUTE_PER_ADDRESS: "30"
|
|
DEVICE_GATEWAY_SESSION_TIMEOUT_MS: "10000"
|
|
volumes:
|
|
- type: bind
|
|
source: /volume1/docker/nodedc-device-plane/secrets/gateway-core-token
|
|
target: /run/nodedc-secrets/gateway-core-token
|
|
read_only: true
|
|
bind:
|
|
create_host_path: false
|
|
ports:
|
|
- "127.0.0.1:18121:18121"
|
|
- "0.0.0.0:9921:9921"
|
|
networks:
|
|
- device-plane-private
|
|
- device-plane-control
|
|
depends_on:
|
|
device-control-core:
|
|
condition: service_healthy
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
cap_drop:
|
|
- ALL
|
|
healthcheck:
|
|
test:
|
|
- CMD
|
|
- node
|
|
- -e
|
|
- fetch('http://127.0.0.1:18121/healthz').then(r=>{if(!r.ok)process.exit(1)}).catch(()=>process.exit(1))
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 12
|
|
start_period: 10s
|
|
|
|
networks:
|
|
device-plane-private:
|
|
name: nodedc-device-plane-private
|
|
internal: true
|
|
device-plane-control:
|
|
name: nodedc-device-plane-control
|
|
driver: bridge
|
|
internal: false
|
|
driver_opts:
|
|
com.docker.network.bridge.enable_ip_masquerade: "false"
|
|
|
|
volumes:
|
|
device-plane-postgres-data:
|
|
name: nodedc-device-plane-postgres-data
|