Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
142 lines (135 loc) · 5.17 KB
/
Copy pathdocker-compose.yml
File metadata and controls
142 lines (135 loc) · 5.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
#
# Docker Compose uses .env and, when present, .env.extra via the Makefile wrappers.
#
volumes:
postgres_data:
clamav_data:
trivy_cache:
services:
postgres:
image: postgres:${POSTGRES_VERSION}
environment:
POSTGRES_DB: ${POSTGRES_DB_NAME}
POSTGRES_USER: ${POSTGRES_SUPER_USER}
POSTGRES_PASSWORD: ${POSTGRES_SUPER_PASSWORD}
container_name: ${POSTGRES_CONTAINER_NAME}
ports:
- "${POSTGRES_PORT}:5432"
volumes:
- postgres_data:/var/lib/postgresql/data
- ./postgres/init-keycloak.sql:/docker-entrypoint-initdb.d/init-keycloak.sql
- ./postgres/init-app.sql:/docker-entrypoint-initdb.d/init-app.sql
- ./test-data:/test-data:ro
# Probe over TCP (-h localhost), not the default unix socket. While the entrypoint
# runs initdb and the /docker-entrypoint-initdb.d scripts, it serves a temporary
# server with listen_addresses='', which answers on the socket but not on TCP - a
# socket probe would report healthy mid-init. start_period covers that first-boot
# work without burning the retries.
healthcheck:
test: ["CMD-SHELL", "pg_isready -h localhost -U ${POSTGRES_SUPER_USER} -d ${POSTGRES_DB_NAME}"]
interval: 2s
timeout: 5s
retries: 5
start_period: 30s
keycloak:
# Optimized image, see keycloak/Dockerfile (build-time options baked in)
build:
context: ./keycloak
dockerfile: Dockerfile
args:
KC_VERSION: ${KC_VERSION}
KC_DB: ${KC_DB}
image: ${APP_PREFIX}-keycloak:${KC_VERSION}
container_name: ${KC_CONTAINER_NAME}
ports:
- "${KC_PORT}:8080"
environment:
# https://www.keycloak.org/server/configuration#_creating_the_initial_admin_user
# KC_BOOTSTRAP_ADMIN_USERNAME is a fixed Keycloak variable name, do not rename
KC_BOOTSTRAP_ADMIN_USERNAME: ${KC_ADMIN_REALM_ADMIN_USERNAME}
KC_BOOTSTRAP_ADMIN_PASSWORD: ${KC_ADMIN_REALM_ADMIN_PASSWORD}
# https://www.keycloak.org/server/containers
KC_DB_URL: ${KC_DB_URL}
KC_DB_USERNAME: ${KC_DB_USERNAME}
KC_DB_PASSWORD: ${KC_DB_PASSWORD}
# https://www.keycloak.org/server/all-config#category-hostname_v2
KC_HOSTNAME_STRICT_HTTPS: ${KC_HOSTNAME_STRICT_HTTPS}
KC_HOSTNAME_STRICT: ${KC_HOSTNAME_STRICT}
KC_HTTP_ENABLED: ${KC_HTTP_ENABLED}
command: start --optimized
depends_on:
postgres:
condition: service_healthy
clamav:
image: clamav/clamav:stable
ports:
# Map host port to container port, defaults to 3310:3310
- "${MALWARE_SCAN_CLAMAV_PORT:-3310}:3310"
volumes:
- clamav_data:/var/lib/clamav
restart: unless-stopped
backend:
build:
context: ./backend
dockerfile: Dockerfile
network: host
# Use public Docker Hub image for local development (avoids dependency on custom image registry)
args:
PYTHON_IMAGE: python:3.14-slim
# Local development only, the deployments set their own DNS. Public resolvers plus
# an internal one (10.10.12.5), kept on purpose for the local network setup.
dns:
- 8.8.8.8
- 8.8.4.4
- 10.10.12.5
image: ${BACKEND_IMAGE_NAME}:${BACKEND_IMAGE_VERSION:-latest}
container_name: ${BACKEND_CONTAINER_NAME}
ports:
- "${BACKEND_PORT}:8000"
environment:
KC_BASE_URL: ${BACKEND_KC_BASE_URL}
# Value comes from .env
CLIENT_SECRET_AUTH_ENABLED: ${CLIENT_SECRET_AUTH_ENABLED}
API_ALPHA_ENABLED: ${API_ALPHA_ENABLED}
POSTGRES_HOST: ${POSTGRES_CONTAINER_NAME}
POSTGRES_PORT: 5432
POSTGRES_DB_NAME: ${POSTGRES_DB_NAME}
POSTGRES_DB_USER: ${POSTGRES_DB_USER}
POSTGRES_DB_PASSWORD: ${POSTGRES_DB_PASSWORD}
MALWARE_SCAN_CLAMAV_HOST: clamav
MALWARE_SCAN_CLAMAV_PORT: ${MALWARE_SCAN_CLAMAV_PORT}
MALWARE_SCAN_ENABLED: ${MALWARE_SCAN_ENABLED}
restart: unless-stopped
healthcheck:
test: ["CMD-SHELL", "python -c \"import urllib.request; urllib.request.urlopen('${BACKEND_BASE_URL}/api/health')\" || exit 1"]
interval: 10s
timeout: 5s
retries: 5
start_period: 30s
depends_on:
postgres:
condition: service_healthy
clamav:
condition: service_started
run-trivy-scan:
# Only started on demand via `make test-cve` (docker compose run, which enables
# this profile for the named service). Excluded from `docker compose up` so a
# routine `make up` never launches the (root) scanner - it would re-create
# root-owned files under tmp/ and break later writes such as .keycloak-admin.
profiles: ["trivy"]
image: ${TRIVY_IMAGE:-aquasec/trivy:0.72.0}
entrypoint: ["/bin/sh"]
command: ["./scripts/run-trivy-scan.sh"]
working_dir: /work
environment:
IMAGE: ${BACKEND_IMAGE_NAME}:${BACKEND_IMAGE_VERSION:-latest}
BUILD_IMAGE: "false"
OUTPUT_DIR: tmp/trivy-scan
SEVERITY: CRITICAL,HIGH,MEDIUM,LOW,UNKNOWN
# Passed through so `TRIVY_SKIP_DB_REFRESH=1 make test-cve` can reuse the cached
# vulnerability DB; by default every scan downloads the current one.
TRIVY_SKIP_DB_REFRESH: ${TRIVY_SKIP_DB_REFRESH:-0}
volumes:
- ./:/work
- /var/run/docker.sock:/var/run/docker.sock
- trivy_cache:/root/.cache/trivy