-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
98 lines (97 loc) · 4.2 KB
/
Copy pathdocker-compose.yml
File metadata and controls
98 lines (97 loc) · 4.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
services:
# Edge gateway: TLS/routing/coarse IP rate-limit in front of apps/gateway (host :3000).
# ponytail: file provider (not docker labels) because apps/gateway runs on the host, not in compose.
traefik:
image: traefik:v3.1
command:
- --entrypoints.web.address=:80
- --providers.file.filename=/etc/traefik/dynamic.yml
# 8000 = edge in, 4000 = the buyer app's origin (app + /ws), 8081 = dashboard/api.
# Two host ports onto the same container port: both land on the `web` entrypoint, and the
# host rules in traefik-dynamic.yml decide what each one serves.
ports: ['8000:80', '4000:80', '8081:8080']
extra_hosts: ['host.docker.internal:host-gateway'] # reach host apps/gateway on Linux
volumes: ['./traefik-dynamic.yml:/etc/traefik/dynamic.yml:ro']
postgres:
image: postgres:17
environment:
POSTGRES_USER: tickethub
POSTGRES_PASSWORD: tickethub
POSTGRES_DB: tickethub
ports: ['5432:5432']
healthcheck:
test: ['CMD-SHELL', 'pg_isready -U tickethub']
interval: 5s
timeout: 3s
retries: 10
volumes:
- 'pgdata:/var/lib/postgresql/data'
- './docker/postgres-init:/docker-entrypoint-initdb.d:ro'
redis:
image: redis:7
ports: ['6379:6379']
healthcheck: { test: ['CMD', 'redis-cli', 'ping'], interval: 5s, retries: 10 }
# Web UI for Redis/BullMQ. Add redis://redis:6379 once in the UI. ponytail: dev-only viewer.
redisinsight:
image: redis/redisinsight:latest
ports: ['5540:5540']
depends_on: [redis]
rabbitmq:
image: rabbitmq:4-management
ports: ['5672:5672', '15672:15672']
healthcheck: { test: ['CMD', 'rabbitmq-diagnostics', 'ping'], interval: 10s, retries: 10 }
# S3-compatible object storage (replaces LocalStack S3; Community LocalStack gates Lambda/CDK behind Pro).
minio:
image: minio/minio
command: server /data --console-address ":9001"
ports: ['9000:9000', '9001:9001'] # 9000 API, 9001 web console
environment:
MINIO_ROOT_USER: tickethub
MINIO_ROOT_PASSWORD: tickethub
# Poster upload is the one request that leaves the browser for a non-gateway origin: the
# organizer PUTs straight here with a presigned URL. Without CORS the preflight fails in the
# browser and nowhere else — every test still passes, because none of them are a browser.
# Editing this line does NOT reach a container that already exists: `docker compose up -d`
# reports it "Running" and changes nothing. Use `docker compose up -d --force-recreate minio`.
MINIO_API_CORS_ALLOW_ORIGIN: 'http://admin.localhost:4001,http://app.localhost:4000'
volumes: ['miniodata:/data']
# One-shot: create the posters/tickets buckets, then exit. ponytail: retries until MinIO is up.
minio-setup:
image: minio/mc
depends_on: [minio]
entrypoint: >
/bin/sh -c "
until mc alias set local http://minio:9000 tickethub tickethub; do sleep 1; done &&
mc mb -p local/posters local/tickets &&
mc anonymous set download local/posters"
# Fake SMTP server for local email testing (apps/tickets sends PDF tickets here).
mailpit:
image: axllent/mailpit:latest
ports: ['1025:1025', '8025:8025'] # 1025 SMTP, 8025 web UI
loki:
image: grafana/loki:3.0.0
ports: ['3100:3100']
grafana:
image: grafana/grafana:11.0.0
ports: ['3001:3000']
environment: { GF_AUTH_ANONYMOUS_ENABLED: 'true', GF_AUTH_ANONYMOUS_ORG_ROLE: 'Admin' }
volumes:
- ./observability/grafana-datasources.yml:/etc/grafana/provisioning/datasources/loki.yml:ro
promtail:
image: grafana/promtail:3.0.0
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./promtail-config.yml:/etc/promtail/config.yml
command: -config.file=/etc/promtail/config.yml
# Forwards Stripe test webhooks to the host-run gateway (apps run via ts-node, not in compose).
# `stripe listen` prints the whsec_… signing secret on start — copy it into STRIPE_WEBHOOK_SECRET.
stripe-cli:
image: stripe/stripe-cli:latest
command: listen --forward-to http://host.docker.internal:3000/webhooks/stripe
environment:
STRIPE_API_KEY: ${STRIPE_SECRET_KEY}
extra_hosts:
- 'host.docker.internal:host-gateway'
volumes:
pgdata:
miniodata: