# Production-shaped Linux server deployment. Copy server.toml from docs/examples/ # and supply the TLS certificate/key as read-only files. # # `rvbox-server` stays private to this Compose network: nginx is the only public # listener. JSON-RPC remains disabled in server.toml by default. name: rvbox-server services: init: image: "${RVBOX_SERVER_IMAGE:?set RVBOX_SERVER_IMAGE to a pinned rvbox-server image}" user: "0:0" entrypoint: ["/bin/sh", "-ec"] command: >- mkdir -p /var/lib/rvbox-server /run/rvbox && chown 65532:65532 /var/lib/rvbox-server /run/rvbox && chmod 0700 /var/lib/rvbox-server /run/rvbox read_only: true tmpfs: - /tmp:mode=1777,size=8m volumes: - server-data:/var/lib/rvbox-server - server-run:/run/rvbox security_opt: - no-new-privileges:true cap_drop: ["ALL"] cap_add: ["CHOWN", "FOWNER"] server: image: "${RVBOX_SERVER_IMAGE:?set RVBOX_SERVER_IMAGE to a pinned rvbox-server image}" restart: unless-stopped command: ["--config", "/etc/rvbox/server.toml"] read_only: true tmpfs: - /tmp:mode=1777,size=32m volumes: - type: bind source: ./server.toml target: /etc/rvbox/server.toml read_only: true - type: volume source: server-data target: /var/lib/rvbox-server - type: volume source: server-run target: /run/rvbox expose: - "6899" - "6901" healthcheck: test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:6901/readyz"] interval: 15s timeout: 5s retries: 4 start_period: 20s security_opt: - no-new-privileges:true cap_drop: ["ALL"] depends_on: init: condition: service_completed_successfully nginx: image: nginx:1.27.5-alpine restart: unless-stopped read_only: true depends_on: server: condition: service_healthy ports: - "${RVBOX_HTTPS_PORT:-443}:443" tmpfs: - /var/cache/nginx:uid=101,gid=101,mode=0755,size=16m - /var/run:uid=101,gid=101,mode=0755,size=4m volumes: - type: bind source: ./nginx.conf target: /etc/nginx/conf.d/default.conf read_only: true - type: bind source: ${RVBOX_TLS_CERT:?set RVBOX_TLS_CERT to the public certificate path} target: /etc/nginx/tls/server.pem read_only: true - type: bind source: ${RVBOX_TLS_KEY:?set RVBOX_TLS_KEY to the private key path} target: /etc/nginx/tls/server-key.pem read_only: true security_opt: - no-new-privileges:true cap_drop: ["ALL"] cap_add: ["NET_BIND_SERVICE"] volumes: server-data: server-run: