name: SnapOtter # NVIDIA GPU deployment — requires nvidia-container-toolkit. # Install: https://docs.nvidia.com/datacenter/cloud-native/container-toolkit/latest/install-guide.html # Usage: docker compose -f docker-compose-gpu.yml up -d # Verify: docker logs SnapOtter 2>&1 | grep GPU services: SnapOtter: build: context: .. dockerfile: docker/Dockerfile image: snapotter/snapotter:latest container_name: SnapOtter ports: # For internet-facing deployments, bind to localhost only: # - "127.0.0.1:1349:1349" - "1349:1349" volumes: - SnapOtter-data:/data # Database, AI models, user files - SnapOtter-workspace:/tmp/workspace # Temp processing (auto-cleaned) environment: - AUTH_ENABLED=true - DEFAULT_USERNAME=admin # Set a strong password. Default is 'admin' -- CHANGE THIS for any non-local deployment. # - DEFAULT_PASSWORD=your-strong-password-here - DEFAULT_PASSWORD=admin - SKIP_MUST_CHANGE_PASSWORD=${SKIP_MUST_CHANGE_PASSWORD:-false} - MAX_UPLOAD_SIZE_MB=${MAX_UPLOAD_SIZE_MB:-0} - MAX_BATCH_SIZE=${MAX_BATCH_SIZE:-0} - MAX_MEGAPIXELS=${MAX_MEGAPIXELS:-0} - CONCURRENT_JOBS=${CONCURRENT_JOBS:-0} - MAX_WORKER_THREADS=${MAX_WORKER_THREADS:-0} - PROCESSING_TIMEOUT_S=${PROCESSING_TIMEOUT_S:-0} - MAX_PIPELINE_STEPS=${MAX_PIPELINE_STEPS:-20} - RATE_LIMIT_PER_MIN=${RATE_LIMIT_PER_MIN:-1000} - MAX_USERS=${MAX_USERS:-0} - SESSION_DURATION_HOURS=${SESSION_DURATION_HOURS:-168} - TRUST_PROXY=${TRUST_PROXY:-true} # OIDC Authentication (optional) # - EXTERNAL_URL=https://photos.example.com # - OIDC_ENABLED=false # - OIDC_ISSUER_URL= # - OIDC_CLIENT_ID= # - OIDC_CLIENT_SECRET= # - OIDC_SCOPES=openid profile email # - OIDC_AUTO_CREATE_USERS=true # - OIDC_DEFAULT_ROLE=user # - OIDC_AUTO_LINK_USERS=false # - OIDC_PROVIDER_NAME= # - OIDC_USERNAME_CLAIM=preferred_username # - OIDC_CLOCK_TOLERANCE=30 # - COOKIE_SECRET= # # Docker secrets (_FILE convention): mount secrets as files instead of # passing them as plain-text env vars. Supported for sensitive vars only. # - DEFAULT_PASSWORD_FILE=/run/secrets/snapotter_password # - S3_ACCESS_KEY_ID_FILE=/run/secrets/s3_access_key # - S3_SECRET_ACCESS_KEY_FILE=/run/secrets/s3_secret_key # - OIDC_CLIENT_SECRET_FILE=/run/secrets/oidc_secret # - COOKIE_SECRET_FILE=/run/secrets/cookie_secret # - SNAPOTTER_LICENSE_KEY_FILE=/run/secrets/license_key restart: unless-stopped # --- Security hardening --- mem_limit: 8g memswap_limit: 8g cpus: 8 pids_limit: 1024 cap_drop: - ALL cap_add: - CHOWN - SETUID - SETGID - DAC_OVERRIDE - FOWNER # NOTE: security_opt: [no-new-privileges:true] is intentionally omitted. # gosu requires setuid to drop from root to the snapotter user. # Mitigation: cap_drop: ALL limits available capabilities after privilege drop. # NOTE: read_only: true is not set because PUID/PGID remapping requires # writing to /etc/passwd and /etc/group. Consider using Docker --user flag # instead of PUID/PGID for read-only rootfs support. healthcheck: test: ["CMD", "curl", "-sf", "--max-time", "5", "http://localhost:1349/api/v1/health"] interval: 30s timeout: 5s start_period: 60s retries: 3 shm_size: "2gb" # Required for PyTorch CUDA shared memory deploy: resources: reservations: devices: - driver: nvidia count: all capabilities: [gpu] logging: driver: json-file options: max-size: "50m" max-file: "5" # Uncomment to use Docker secrets (requires Docker Swarm or compose v2.23+): # secrets: # snapotter_password: # file: ./secrets/snapotter_password.txt # oidc_secret: # file: ./secrets/oidc_secret.txt volumes: SnapOtter-data: SnapOtter-workspace: