Initial commit
This commit is contained in:
72
docker-compose.prod.yml
Normal file
72
docker-compose.prod.yml
Normal file
@@ -0,0 +1,72 @@
|
||||
# Production stack.
|
||||
#
|
||||
# docker compose -f docker-compose.prod.yml up -d
|
||||
#
|
||||
# No reverse proxy here by design: TLS is terminated by the central reverse
|
||||
# proxy on a separate machine, which connects to the published port below over
|
||||
# the LAN. Example proxy configs for that machine live in docker/reverse-proxy/.
|
||||
#
|
||||
# Add `--profile syncthing` to also run Syncthing in this stack; omit it if
|
||||
# Syncthing already runs on the host and merely shares VAULT_PATH.
|
||||
|
||||
services:
|
||||
markdown-to-caldav:
|
||||
build: .
|
||||
image: markdown-to-caldav:latest
|
||||
container_name: markdown-to-caldav
|
||||
restart: unless-stopped
|
||||
|
||||
# Must match the uid/gid that owns the vault (the Syncthing folder), or
|
||||
# write-back fails and Syncthing sees permission churn.
|
||||
user: "${VAULT_UID:?set VAULT_UID}:${VAULT_GID:?set VAULT_GID}"
|
||||
|
||||
ports:
|
||||
# Reachable by the reverse-proxy machine over the LAN. BIND_ADDRESS
|
||||
# defaults to all interfaces; set it to this host's LAN address to avoid
|
||||
# listening anywhere else. Restrict to the proxy's IP at the firewall —
|
||||
# this port is plain HTTP and speaks for your notes.
|
||||
- "${BIND_ADDRESS:-0.0.0.0}:${BIND_PORT:-5233}:5232"
|
||||
|
||||
volumes:
|
||||
- ${VAULT_PATH:?set VAULT_PATH}:/vault
|
||||
- ./docker:/config:ro
|
||||
- ./data:/data
|
||||
|
||||
environment:
|
||||
MDCALDAV_CONFIG: /config/mdcaldav.toml
|
||||
|
||||
# Hardening. The app writes only to /vault and /data; everything else can
|
||||
# be immutable.
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /tmp:size=64m
|
||||
cap_drop: [ALL]
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
|
||||
mem_limit: 512m
|
||||
cpus: 1.0
|
||||
logging: &logging
|
||||
driver: json-file
|
||||
options: { max-size: "10m", max-file: "3" }
|
||||
|
||||
# Optional: run Syncthing here too, sharing the vault and uid.
|
||||
syncthing:
|
||||
image: syncthing/syncthing:latest
|
||||
container_name: mdcaldav-syncthing
|
||||
profiles: [syncthing]
|
||||
restart: unless-stopped
|
||||
user: "${VAULT_UID:?set VAULT_UID}:${VAULT_GID:?set VAULT_GID}"
|
||||
hostname: mdcaldav-syncthing
|
||||
volumes:
|
||||
- ${VAULT_PATH:?set VAULT_PATH}:/var/syncthing/vault
|
||||
- syncthing-config:/var/syncthing/config
|
||||
ports:
|
||||
- "${BIND_ADDRESS:-0.0.0.0}:8384:8384" # web UI — firewall this too
|
||||
- "22000:22000/tcp" # sync protocol
|
||||
- "22000:22000/udp"
|
||||
- "21027:21027/udp" # discovery
|
||||
logging: *logging
|
||||
|
||||
volumes:
|
||||
syncthing-config:
|
||||
Reference in New Issue
Block a user