-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathdocker-compose.yml
51 lines (49 loc) · 1.7 KB
/
docker-compose.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
services:
backend:
image: ghcr.io/malakhite/bastion-backend:main
environment:
DATABASE_URL: ${DATABASE_URL}
HOST: ${HOST}
ACCESS_TOKEN_SECRET: ${ACCESS_TOKEN_SECRET}
ACCESS_TOKEN_EXPIRATION: ${ACCESS_TOKEN_EXPIRATION}
SYNCRHONIZE_DB: true
labels:
traefik.enable: true
traefik.docker.network: bastion_default
traefik.http.routers.backend.tls.certresolver: prod
traefik.http.routers.backend.rule: Host(`${HOST}`)
traefik.http.services.backend.server.port: 3333
traefik.http.services.backend.server.scheme: http
networks:
- default
restart: unless-stopped
proxy:
image: traefik:v2.6
command:
- --log.level=INFO
- --api=true
- --providers.docker=true
- --entrypoints.web.address=:80
- --entrypoints.web.http.redirections.entrypoint.to=websecure
- --entrypoints.web.http.redirections.entrypoint.scheme=https
- --entrypoints.websecure.address=:443
- --certificatesResolvers.prod.acme.tlschallenge=true
- --certificatesResolvers.prod.acme.storage=/etc/traefik/acme.json
- --certificatesResolvers.prod.acme.email=${ACME_EMAIL}
- --certificatesResolvers.prod.acme.caserver=https://acme-v02.api.letsencrypt.org/directory
environment:
TZ: ${TZ}
labels:
traefik.enable: true
traefik.docker.network: bastion_default
traefik.http.routers.traefik.tls.certresolver: prod
traefik.http.routers.traefik.rule: Host(`${TRAEFIK_HOST}`)
networks:
- default
ports:
- 80:80/tcp
- 433:433/tcp
restart: unless-stopped
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- ${CONFIG_DIR}/traefik:/etc/traefik:rw