-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathdocker-compose.yml
125 lines (116 loc) · 3.5 KB
/
docker-compose.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
services:
traefik:
image: traefik
restart: always
command:
- "--certificatesresolvers.stackresolver.acme.email=$EMAIL"
- "--configFile=/etc/traefik.yml"
labels:
- "traefik.http.routers.dashboard.rule=Host(`$HOSTNAME`) && (PathPrefix(`/api`) || PathPrefix(`/dashboard`))"
- "traefik.http.routers.dashboard.tls.certresolver=stackresolver"
- "traefik.http.routers.dashboard.service=api@internal"
- "traefik.http.middlewares.auth.basicauth.users=$ADMIN:$ADMIN_PASS"
- "traefik.http.routers.dashboard.middlewares=auth"
ports:
- "80:80"
- "443:443"
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./logs/:/logs/:rw
- ./certs:/letsencrypt
- ./conf/traefik.yml:/etc/traefik.yml:ro
- ./conf/traefik/:/etc/traefik
depends_on:
- adminer
- logpager
- guac
- www
logpager:
image: ghcr.io/jonbirge/logpager:dev
restart: always
environment:
SQL_HOST: db
SQL_USER: sqluser
SQL_PASS: $SQL_PASS
labels:
- "traefik.http.routers.logpagerdev.rule=Host(`$HOSTNAME`) && PathPrefix(`/logs`)"
- "traefik.http.routers.logpagerdev.tls.certresolver=stackresolver"
- "traefik.http.middlewares.striplogdev.stripprefix.prefixes=/logs/"
- "traefik.http.routers.logpagerdev.middlewares=topten@file,striplogdev"
volumes:
- /var/log/auth.log:/auth.log:ro
- /var/log/auth.log.1:/auth.log.1:ro
- ./logs/access.log:/access.log:ro
- ./logs/access.log.1:/access.log.1:ro
- ./logs/blacklist.csv:/blacklist.csv:rw
- ../logpager/src:/var/www:ro # live development
depends_on:
- db
www:
image: nginx
restart: always
labels:
- "traefik.http.routers.www.rule=(Host(`$DOMAIN`) || Host(`www.$DOMAIN`)) && PathPrefix(`/`)"
- "traefik.http.routers.www.tls.certresolver=pubresolver"
volumes:
- ./www:/usr/share/nginx/html:rw
- ./conf/nginx.conf:/etc/nginx/nginx.conf:ro
depends_on:
- php
php:
image: bitnami/php-fpm
restart: always
volumes:
- ./www:/usr/share/nginx/html:rw
db:
image: mysql
restart: always
volumes:
- ./db:/var/lib/mysql
environment:
MYSQL_ROOT_PASSWORD: $SQL_ROOT_PASS
MYSQL_USER: sqluser
MYSQL_PASSWORD: $SQL_PASS
adminer:
image: adminer
restart: always
environment:
ADMINER_DESIGN: nette
labels:
- "traefik.http.routers.adminer.rule=Host(`$HOSTNAME`) && PathPrefix(`/adminer`)"
- "traefik.http.routers.adminer.tls.certresolver=stackresolver"
- "traefik.port=8080"
- "traefik.http.routers.adminer.middlewares=usonly@file"
depends_on:
- db
guacd:
image: guacamole/guacd
restart: always
guac:
image: guacamole/guacamole
restart: always
volumes:
- guac-config:/config
environment:
TOTP_ENABLED: "true"
MYSQL_HOSTNAME: db
MYSQL_DATABASE: guacamole_db
MYSQL_USER: sqluser
MYSQL_PASSWORD: $SQL_PASS
GUACAMOLE_HOME: /config
GUACD_HOSTNAME: guacd
labels:
- "traefik.http.routers.guacamole.rule=Host(`$HOSTNAME`) && PathPrefix(`/guacamole`)"
- "traefik.http.routers.guacamole.tls.certresolver=stackresolver"
- "traefik.http.routers.guacamole.middlewares=topten@file"
depends_on:
- db
- guacd
watchtower:
image: containrrr/watchtower
restart: always
volumes:
- /var/run/docker.sock:/var/run/docker.sock
command: --interval 3600
volumes:
guac-config: