# Isolated QA stack for the exhaustive tool QA sweep. # Uses an explicitly supplied immutable digest of the image under test. Set # QA_IMAGE to the 64-character hexadecimal digest (without the sha256: prefix). # Auth disabled (synthetic admin), high limits, fresh volumes, host port 13499 to avoid # clashing with a native dev server on 1349. # QA_IMAGE=<64-hex-digest> docker compose -f tests/qa/docker-compose.qa.yml up -d # open http://localhost:13499 # # Project/container names default to snapotter-qa. Two sessions on the same host # running this file verbatim at the same time will silently steal each other's # container (last `up` wins, no error) since container_name is fixed rather than # derived from the project name. A second concurrent stack also needs its own # host port (the default stack holds 13499), so override both: # QA_IMAGE= QA_PROJECT_NAME=snapotter-qa-2 QA_APP_PORT=13498 \ # docker compose -f tests/qa/docker-compose.qa.yml up -d name: ${QA_PROJECT_NAME:-snapotter-qa} services: app: image: ${QA_IMAGE_REPOSITORY:-snapotter/snapotter}@sha256:${QA_IMAGE:?QA_IMAGE must be the 64-character hexadecimal digest of the image under test} container_name: ${QA_PROJECT_NAME:-snapotter-qa} ports: - "${QA_APP_PORT:-13499}:1349" volumes: - qa-data:/data - qa-workspace:/tmp/workspace environment: - AUTH_ENABLED=false - RATE_LIMIT_PER_MIN=100000 - PROCESSING_TIMEOUT_S=600 - MAX_UPLOAD_SIZE_MB=0 - MAX_BATCH_SIZE=0 - MAX_MEGAPIXELS=0 - CONCURRENT_JOBS=0 - MAX_WORKER_THREADS=0 - MAX_PIPELINE_STEPS=50 - ANALYTICS_ENABLED=false # TRUST_PROXY is deliberately not pinned here. The other values in this # block are lifted so a QA sweep is not throttled by a product limit, but # pinning the proxy trust would mean QA containers stop exercising the # shipped default, which is exactly the setting SEC-20260726-002 was # about. Override it in the environment when a test needs a specific one. - DATABASE_URL=postgres://snapotter:snapotter@postgres:5432/snapotter - REDIS_URL=redis://redis:6379 depends_on: postgres: condition: service_healthy redis: condition: service_healthy shm_size: "2gb" healthcheck: test: ["CMD", "curl", "-sf", "--max-time", "5", "http://localhost:1349/api/v1/health"] interval: 15s timeout: 5s start_period: 90s retries: 5 restart: unless-stopped postgres: image: postgres:17-alpine@sha256:742f40ea20b9ff2ff31db5458d127452988a2164df9e17441e191f3b72252193 container_name: ${QA_PROJECT_NAME:-snapotter-qa}-postgres environment: POSTGRES_USER: snapotter POSTGRES_PASSWORD: snapotter POSTGRES_DB: snapotter volumes: - qa-pgdata:/var/lib/postgresql/data healthcheck: test: ["CMD-SHELL", "pg_isready -U snapotter"] interval: 10s timeout: 5s retries: 12 start_period: 15s redis: image: redis:8-alpine@sha256:9d317178eceac8454a2284a9e6df2466b93c745529947f0cd42a0fa9609d7005 container_name: ${QA_PROJECT_NAME:-snapotter-qa}-redis command: ["redis-server", "--maxmemory-policy", "noeviction", "--appendonly", "yes"] volumes: - qa-redisdata:/data healthcheck: test: ["CMD", "redis-cli", "ping"] interval: 10s timeout: 5s retries: 12 start_period: 10s volumes: qa-data: qa-workspace: qa-pgdata: qa-redisdata: