feat: add Linux server operational delivery assets
This commit is contained in:
@@ -0,0 +1,68 @@
|
||||
# Production-shaped Linux server deployment. Copy server.toml from docs/examples/
|
||||
# and supply the TLS certificate/key as read-only files.
|
||||
#
|
||||
# `rvbox-server` stays private to this Compose network: nginx is the only public
|
||||
# listener. JSON-RPC remains disabled in server.toml by default.
|
||||
name: rvbox-server
|
||||
|
||||
services:
|
||||
server:
|
||||
image: "${RVBOX_SERVER_IMAGE:?set RVBOX_SERVER_IMAGE to a pinned rvbox-server image}"
|
||||
restart: unless-stopped
|
||||
command: ["--config", "/etc/rvbox/server.toml"]
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /tmp:mode=1777,size=32m
|
||||
volumes:
|
||||
- type: bind
|
||||
source: ./server.toml
|
||||
target: /etc/rvbox/server.toml
|
||||
read_only: true
|
||||
- type: bind
|
||||
source: ./state
|
||||
target: /var/lib/rvbox-server
|
||||
- type: bind
|
||||
source: ./run
|
||||
target: /run/rvbox
|
||||
expose:
|
||||
- "6899"
|
||||
- "6901"
|
||||
healthcheck:
|
||||
test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:6901/readyz"]
|
||||
interval: 15s
|
||||
timeout: 5s
|
||||
retries: 4
|
||||
start_period: 20s
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
cap_drop: ["ALL"]
|
||||
|
||||
nginx:
|
||||
image: nginx:1.27.5-alpine
|
||||
restart: unless-stopped
|
||||
read_only: true
|
||||
depends_on:
|
||||
server:
|
||||
condition: service_healthy
|
||||
ports:
|
||||
- "${RVBOX_HTTPS_PORT:-443}:443"
|
||||
tmpfs:
|
||||
- /var/cache/nginx:uid=101,gid=101,mode=0755,size=16m
|
||||
- /var/run:uid=101,gid=101,mode=0755,size=4m
|
||||
volumes:
|
||||
- type: bind
|
||||
source: ./nginx.conf
|
||||
target: /etc/nginx/conf.d/default.conf
|
||||
read_only: true
|
||||
- type: bind
|
||||
source: ${RVBOX_TLS_CERT:?set RVBOX_TLS_CERT to the public certificate path}
|
||||
target: /etc/nginx/tls/server.pem
|
||||
read_only: true
|
||||
- type: bind
|
||||
source: ${RVBOX_TLS_KEY:?set RVBOX_TLS_KEY to the private key path}
|
||||
target: /etc/nginx/tls/server-key.pem
|
||||
read_only: true
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
cap_drop: ["ALL"]
|
||||
cap_add: ["NET_BIND_SERVICE"]
|
||||
Reference in New Issue
Block a user