Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
50 lines (47 loc) · 2.04 KB
/
Copy pathdocker-compose.yml
File metadata and controls
50 lines (47 loc) · 2.04 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
# =============================================================================
# docker-compose.yml - rootresolver (standalone Compose project)
# -----------------------------------------------------------------------------
# Public, unauthenticated lookup service: GET /resolve?id=<did-or-namespace>.
# Deliberately its own Compose project, independent of rw-rrn's and
# recordfinder's compose files - it authenticates to the Fabric network with
# its own fixed identity (same .env conventions as recordfinder) but exposes
# no Fabric identity or peer-selection surface to its own callers.
#
# Like recordfinder, this service reaches its Fabric peer over the peer's
# public TLS endpoint (PEER_ENDPOINT), NOT via rw-rrn's internal `fabric_net`
# Docker network - it is meant to work identically whether the peer is on
# this VPS or anywhere else reachable over the network.
#
# Joins one EXTERNAL network, purely as a bridge:
# - tws-proxy (from the infra repo running nginx) - so the shared nginx
# reverse proxy (container `poc-nginx`) can reach this container by its
# Docker DNS hostname (`rootresolver`) for proxy_pass.
#
# Prerequisite: the infra repo's docker-compose.yml must already define the
# external network `tws-proxy`, with nginx attached to it.
# =============================================================================
name: rootresolver
services:
rootresolver:
build: .
container_name: rootresolver
restart: unless-stopped
env_file:
- .env
volumes:
# Read-only mount of this organisation's own crypto material, matching
# the paths referenced by CRYPTO_DIR / PEER_HOST_ALIAS in .env.
- ${CRYPTO_CONFIG_HOST_PATH:-/opt/rootresolver/crypto-config}:/crypto:ro
# No host port published by default: reached exclusively via nginx
# (tws-proxy). Uncomment for direct host access, e.g. during debugging.
# ports:
# - "3001:3000"
networks:
- rootresolver-net
- tws-proxy
networks:
rootresolver-net:
driver: bridge
tws-proxy:
external: true
name: tws-proxy