Files
tavolo/docker-compose.yml
T

130 lines
4.4 KiB
YAML

services:
postgres:
image: postgres:18-alpine
environment:
POSTGRES_DB: tavolo
POSTGRES_USER: tavolo
# Override via the DATABASE_PASSWORD env var (shell or root .env).
POSTGRES_PASSWORD: ${DATABASE_PASSWORD:-password}
ports:
- "5432:5432"
volumes:
- pgdata:/var/lib/postgresql
healthcheck:
test: ["CMD-SHELL", "pg_isready -U tavolo"]
interval: 5s
timeout: 3s
retries: 10
# Mock OIDC provider (navikt/mock-oauth2-server). Zero manual setup:
# interactive login accepts any username (no password). Pre-configured
# players: alice, bob, carol, dave; any other username works too.
# The mock does not validate clients, so any client id/secret works.
#
# It listens on 8180 both inside and outside the network so the OIDC
# issuer URL (http://mockoauth:8180/tavolo) is identical for
# container-to-container calls and for browser redirects (via the
# /etc/hosts entry documented in the README).
mockoauth:
# Derived image baking dev/mockoauth/config.json in (see
# dev/mockoauth/Dockerfile) — a bind mount would not work against
# containerized docker daemons.
build: ./server/dev/mockoauth
environment:
SERVER_PORT: "8180"
LOG_LEVEL: INFO
ports:
- "8180:8180"
# The JRE image has no usable healthcheck tooling; gate the app on the
# discovery endpoint being served instead.
mockoauth-init:
image: curlimages/curl
depends_on:
- mockoauth
entrypoint: >
/bin/sh -c "
until curl -sf http://mockoauth:8180/tavolo/.well-known/openid-configuration > /dev/null; do
echo 'waiting for mockoauth...'; sleep 2;
done
"
# Sessions + live game state. No volume: sessions are disposable (worst
# case, users log in again) and games in progress have a TTL.
redis:
image: redis:8-alpine
ports:
- "6379:6379"
healthcheck:
test: ["CMD", "redis-cli", "ping"]
interval: 5s
timeout: 3s
retries: 10
# One-shot: applies pending aerich migrations before the app starts
# (build cache makes the second build of the same Dockerfile instant).
db-migrate:
build:
context: .
dockerfile: server/Dockerfile
# aerich reads [tool.aerich] from /app/pyproject.toml (default config
# file) and finds migrations in ./migrations relative to working_dir.
working_dir: /app
command: ["aerich", "upgrade"]
environment:
DATABASE_ENGINE: postgres
DATABASE_HOST: postgres
DATABASE_PORT: "5432"
DATABASE_NAME: tavolo
DATABASE_USER: tavolo
DATABASE_PASSWORD: ${DATABASE_PASSWORD:-password}
depends_on:
postgres:
condition: service_healthy
tavolo:
build:
context: .
dockerfile: server/Dockerfile
depends_on:
postgres:
condition: service_healthy
db-migrate:
condition: service_completed_successfully
mockoauth-init:
condition: service_completed_successfully
redis:
condition: service_healthy
environment:
DATABASE_ENGINE: postgres
DATABASE_HOST: postgres
DATABASE_PORT: "5432"
DATABASE_NAME: tavolo
DATABASE_USER: tavolo
DATABASE_PASSWORD: ${DATABASE_PASSWORD:-password}
# By default the app and browsers reach the mock IdP under the same
# name (see README /etc/hosts note); override OIDC_ISSUER and
# OIDC_REDIRECT_URI to use a real provider or a different host port.
OIDC_ISSUER: ${OIDC_ISSUER:-http://mockoauth:8180/tavolo}
# The mock OIDC server does not validate clients: any id/secret works.
OIDC_CLIENT_ID: tavolo
OIDC_CLIENT_SECRET: ${OIDC_CLIENT_SECRET:-dev-secret}
OIDC_REDIRECT_URI: ${OIDC_REDIRECT_URI:-http://localhost:8080/auth/callback}
REDIS_URL: redis://redis:6379/0
HAND_ACK_TIMEOUT_SECONDS: ${HAND_ACK_TIMEOUT_SECONDS:-30}
TURN_TIMEOUT_SECONDS: ${TURN_TIMEOUT_SECONDS:-30}
# CORS is disabled unless CORS_ALLOW_ORIGINS or CORS_ALLOW_ORIGIN_REGEX
# is set (see server/.env.example for the full list of options).
CORS_ALLOW_ORIGINS: ${CORS_ALLOW_ORIGINS:-}
CORS_ALLOW_ORIGIN_REGEX: ${CORS_ALLOW_ORIGIN_REGEX:-}
CORS_ALLOW_METHODS: ${CORS_ALLOW_METHODS:-}
CORS_ALLOW_HEADERS: ${CORS_ALLOW_HEADERS:-}
CORS_ALLOW_CREDENTIALS: ${CORS_ALLOW_CREDENTIALS:-}
CORS_EXPOSE_HEADERS: ${CORS_EXPOSE_HEADERS:-}
CORS_MAX_AGE: ${CORS_MAX_AGE:-}
ports:
- "127.0.0.1:${APP_PORT:-8080}:8080"
volumes:
pgdata: