x-logging: &default-logging driver: json-file options: max-size: '10m' max-file: '5' services: app: image: atcr.io/tlecommunity.com/app:latest container_name: app restart: unless-stopped volumes: - ./data/app-caddy-data:/data - ./data/app-caddy-config:/config alliance-starmap: image: atcr.io/tlecommunity.com/alliance-starmap:latest container_name: alliance-starmap restart: unless-stopped volumes: - ./data/alliance-starmap-caddy-data:/data - ./data/alliance-starmap-caddy-config:/config beanstalk-console: container_name: beanstalk-console restart: unless-stopped depends_on: - beanstalk image: schickling/beanstalkd-console beanstalk: container_name: beanstalk restart: unless-stopped image: schickling/beanstalkd logrotate: build: context: . dockerfile: Dockerfile.logrotate container_name: logrotate restart: unless-stopped volumes: - ./log:/home/lacuna/server/log - ./lacuna.logrotate:/etc/logrotate.d/lacuna:ro memcached: container_name: memcached restart: unless-stopped image: memcached # command: # # Persist cache in a file to save sessions (and other data) between restarts of the docker container # - --memory-file=/tempfs_mount/memory_file # volumes: # - ./data/memcached:/tempfs_mount mysql: container_name: mysql platform: linux/amd64 restart: unless-stopped environment: MYSQL_ROOT_PASSWORD: ${LACUNA_MYSQL_ROOT_PASSWORD:?error} image: mysql:5.5 volumes: - ./data/mysql:/var/lib/mysql - ./data/backups:/backups - ./mysql-dump.sh:/usr/local/bin/mysql-dump.sh:ro healthcheck: # mysqladmin ping exits 0 once mysqld accepts connections; passing creds # makes it a truer check (it would also exit 0 on an auth failure). test: ['CMD-SHELL', 'mysqladmin ping -h 127.0.0.1 -u root -p"$$MYSQL_ROOT_PASSWORD" --silent'] interval: 10s timeout: 5s retries: 10 start_period: 30s caddy: image: caddy:2.8-alpine container_name: caddy restart: unless-stopped logging: *default-logging depends_on: app: condition: service_started alliance-starmap: condition: service_started server: condition: service_healthy super-ui: condition: service_started v2-api: condition: service_started ports: - 80:80 - 443:443 - 443:443/udp environment: CADDY_DOMAIN: ${CADDY_DOMAIN:-meanjin-one.tlecommunity.com} volumes: - ./caddy/Caddyfile:/etc/caddy/Caddyfile:ro - ./data/public-captcha:/home/lacuna/server/public/captcha - ./data/public-network19:/home/lacuna/server/public/network19 - ./data/public-missioncommand:/home/lacuna/server/public/missioncommand - ./data/public-server:/home/lacuna/server/public/server - ./data/public-static:/home/lacuna/server/public:ro - ./log/caddy:/home/lacuna/server/log/caddy - ./data/caddy-data:/data - ./data/caddy-config:/config server: image: atcr.io/tlecommunity.com/server:latest command: '/bin/bash bin/start_lacuna.sh' container_name: server restart: unless-stopped depends_on: mysql: condition: service_healthy memcached: condition: service_started beanstalk: condition: service_started environment: # Root of the host-mounted log tree (see the ./../../log mount below). # Scripts fall back to this same path when the var is unset. LACUNA_LOG_DIR: /home/lacuna/server/log # Disables the prod-only size-limit / profiling middleware (bin/lacuna.psgi). TLE_NO_MIDDLEWARE: 1 logging: *default-logging volumes: - ./etc:/home/lacuna/server/etc - ./data/public-captcha:/home/lacuna/server/public/captcha - ./data/public-network19:/home/lacuna/server/public/network19 - ./data/public-missioncommand:/home/lacuna/server/public/missioncommand - ./data/public-server:/home/lacuna/server/public/server - ./tmp:/tmp - ./log:/home/lacuna/server/log healthcheck: # /starman_ping (bin/lacuna.psgi) returns "pong" only once the Lacuna app # has compiled and Starman is serving requests. curl is in the server image. test: ['CMD', 'curl', '-fsS', 'http://localhost:5000/starman_ping'] interval: 15s timeout: 10s retries: 5 start_period: 180s server-building-scheduler: image: atcr.io/tlecommunity.com/server:latest command: '/bin/bash bin/run_scheduler.sh schedule_building.pl --noquiet --nodaemonize --initialize' container_name: server-building-scheduler restart: unless-stopped depends_on: server: condition: service_healthy environment: LACUNA_LOG_DIR: /home/lacuna/server/log logging: *default-logging volumes: - ./tmp:/tmp - ./log:/home/lacuna/server/log - ./etc:/home/lacuna/server/etc server-ship-scheduler: image: atcr.io/tlecommunity.com/server:latest command: '/bin/bash bin/run_scheduler.sh schedule_ship_arrival.pl --noquiet --nodaemonize --initialize' container_name: server-ship-scheduler restart: unless-stopped depends_on: server: condition: service_healthy environment: LACUNA_LOG_DIR: /home/lacuna/server/log logging: *default-logging volumes: - ./tmp:/tmp - ./log:/home/lacuna/server/log - ./etc:/home/lacuna/server/etc server-captcha-scheduler: image: atcr.io/tlecommunity.com/server:latest command: '/bin/bash bin/run_scheduler.sh schedule_captcha.pl --noquiet --nodaemonize' container_name: server-captcha-scheduler restart: unless-stopped depends_on: server: condition: service_healthy environment: LACUNA_LOG_DIR: /home/lacuna/server/log logging: *default-logging volumes: - ./tmp:/tmp - ./log:/home/lacuna/server/log - ./etc:/home/lacuna/server/etc - ./data/public-captcha:/home/lacuna/server/public/captcha server-script-scheduler: container_name: server-script-scheduler image: mcuadros/ofelia:latest restart: unless-stopped depends_on: server: condition: service_healthy command: daemon logging: *default-logging volumes: - /var/run/docker.sock:/var/run/docker.sock:ro - ./schedule.ini:/etc/ofelia.conf super-ui: image: atcr.io/tlecommunity.com/super-ui:latest container_name: super-ui restart: unless-stopped volumes: - ./data/super-ui-caddy-data:/data - ./data/super-ui-caddy-config:/config v2-api: image: atcr.io/tlecommunity.com/v2-api:latest restart: unless-stopped container_name: v2-api command: node index.ts environment: PORT: 5999 # # Management # phpmyadmin-tailscale: image: tailscale/tailscale:latest container_name: phpmyadmin-tailscale hostname: tle-meanjin-one-phpmyadmin environment: - TS_AUTHKEY=${TAILSCALE_AUTHKEY:?error} - TS_EXTRA_ARGS=--advertise-tags=tag:container - TS_SERVE_CONFIG=/config/phpmyadmin.json - TS_STATE_DIR=/var/lib/tailscale - TS_USERSPACE=false - TS_ENABLE_HEALTH_CHECK=true healthcheck: test: ['CMD', 'wget', '--spider', '-q', 'http://127.0.0.1:9002/healthz'] interval: 10s timeout: 3s volumes: - ./data/tailscale-phpmyadmin:/var/lib/tailscale - ./tailscale/phpmyadmin:/config devices: - /dev/net/tun:/dev/net/tun cap_add: - net_admin - sys_module restart: unless-stopped phpmyadmin: container_name: phpmyadmin image: phpmyadmin:5.2-apache restart: unless-stopped network_mode: service:phpmyadmin-tailscale environment: PMA_HOST: mysql depends_on: - mysql portainer-agent-tailscale: image: tailscale/tailscale:latest container_name: portainer-agent-tailscale hostname: tle-meanjin-one-portainer-agent environment: - TS_AUTHKEY=${TAILSCALE_AUTHKEY:?error} - TS_EXTRA_ARGS=--advertise-tags=tag:container - TS_SERVE_CONFIG=/config/portainer-agent.json - TS_STATE_DIR=/var/lib/tailscale - TS_USERSPACE=false - TS_ENABLE_HEALTH_CHECK=true healthcheck: test: ['CMD', 'wget', '--spider', '-q', 'http://127.0.0.1:9002/healthz'] interval: 10s timeout: 3s volumes: - ./data/tailscale-portainer-agent:/var/lib/tailscale - ./tailscale/portainer-agent:/config devices: - /dev/net/tun:/dev/net/tun cap_add: - net_admin - sys_module restart: unless-stopped portainer-agent: image: portainer/agent:lts container_name: portainer-agent restart: always environment: - EDGE=1 - EDGE_INSECURE_POLL=1 - EDGE_ID=${PORTAINER_AGENT_EDGE_ID:?error} - EDGE_KEY=${PORTAINER_AGENT_EDGE_KEY:?error} volumes: - /var/run/docker.sock:/var/run/docker.sock - /var/lib/docker/volumes:/var/lib/docker/volumes - /:/host - ./data/portainer-agent:/data network_mode: service:portainer-agent-tailscale depends_on: portainer-agent-tailscale: condition: service_healthy deploy-trigger-tailscale: image: tailscale/tailscale:latest container_name: deploy-trigger-tailscale hostname: tle-meanjin-one-deploy-trigger environment: - TS_AUTHKEY=${TAILSCALE_AUTHKEY:?error} - TS_EXTRA_ARGS=--advertise-tags=tag:container - TS_SERVE_CONFIG=/config/deploy-trigger.json - TS_STATE_DIR=/var/lib/tailscale - TS_USERSPACE=false - TS_ENABLE_HEALTH_CHECK=true healthcheck: test: ['CMD', 'wget', '--spider', '-q', 'http://127.0.0.1:9002/healthz'] interval: 10s timeout: 3s volumes: - ./data/tailscale-deploy-trigger:/var/lib/tailscale - ./tailscale/deploy-trigger:/config devices: - /dev/net/tun:/dev/net/tun cap_add: - net_admin - sys_module restart: unless-stopped deploy-trigger: build: context: . dockerfile: Dockerfile.deploy-trigger container_name: deploy-trigger restart: unless-stopped network_mode: service:deploy-trigger-tailscale environment: DEPLOY_WEBHOOK_SECRET: ${DEPLOY_WEBHOOK_SECRET:?error} volumes: - ./deploy-trigger/hooks.json:/etc/webhook/hooks.json:ro - ./deploy-trigger/receive-deploy.sh:/scripts/receive-deploy.sh:ro - ./data/deploy-requests:/deploy-requests - ./log/deploy:/deploy-log command: ['-hooks=/etc/webhook/hooks.json', '-template', '-verbose'] depends_on: deploy-trigger-tailscale: condition: service_healthy beszel-agent-tailscale: image: tailscale/tailscale:latest container_name: beszel-agent-tailscale hostname: tle-meanjin-one-beszel-agent environment: - TS_AUTHKEY=${TAILSCALE_AUTHKEY:?error} - TS_EXTRA_ARGS=--advertise-tags=tag:container - TS_SERVE_CONFIG=/config/beszel-agent.json - TS_STATE_DIR=/var/lib/tailscale - TS_USERSPACE=false - TS_ENABLE_HEALTH_CHECK=true healthcheck: test: ['CMD', 'wget', '--spider', '-q', 'http://127.0.0.1:9002/healthz'] interval: 10s timeout: 3s volumes: - ./data/tailscale-beszel-agent:/var/lib/tailscale - ./tailscale/beszel-agent:/config devices: - /dev/net/tun:/dev/net/tun cap_add: - net_admin - sys_module restart: unless-stopped beszel-agent: image: henrygd/beszel-agent container_name: beszel-agent network_mode: service:beszel-agent-tailscale restart: unless-stopped volumes: - /var/run/docker.sock:/var/run/docker.sock:ro - ./data/beszel-agent-data:/var/lib/beszel-agent environment: LISTEN: 45876 KEY: ${BESZEL_KEY:?error} TOKEN: ${BESZEL_TOKEN:?error} HUB_URL: ${BESZEL_HUB_URL:?error} depends_on: beszel-agent-tailscale: condition: service_healthy networks: default: name: lacuna name: lacuna