name: SnapOtter # NVIDIA GPU deployment — requires nvidia-container-toolkit. # Install: https://docs.nvidia.com/datacenter/cloud-native/container-toolkit/latest/install-guide.html # Usage: docker compose -f docker-compose-gpu.yml up -d # Verify: docker logs SnapOtter 2>&1 | grep GPU services: SnapOtter: build: context: .. dockerfile: docker/Dockerfile image: snapotter:latest container_name: SnapOtter ports: # For internet-facing deployments, bind to localhost only: # - "127.0.0.1:1349:1349" - "1349:1349" volumes: - SnapOtter-data:/data # Database, AI models, user files - SnapOtter-workspace:/tmp/workspace # Temp processing (auto-cleaned) environment: - AUTH_ENABLED=true - DEFAULT_USERNAME=admin # Set a strong password. Default is 'admin' -- CHANGE THIS for any non-local deployment. # - DEFAULT_PASSWORD=your-strong-password-here - DEFAULT_PASSWORD=admin - SKIP_MUST_CHANGE_PASSWORD=${SKIP_MUST_CHANGE_PASSWORD:-false} - MAX_UPLOAD_SIZE_MB=${MAX_UPLOAD_SIZE_MB:-0} - MAX_BATCH_SIZE=${MAX_BATCH_SIZE:-0} - MAX_MEGAPIXELS=${MAX_MEGAPIXELS:-0} - CONCURRENT_JOBS=${CONCURRENT_JOBS:-0} - MAX_WORKER_THREADS=${MAX_WORKER_THREADS:-0} - PROCESSING_TIMEOUT_S=${PROCESSING_TIMEOUT_S:-0} - MAX_PIPELINE_STEPS=${MAX_PIPELINE_STEPS:-0} - RATE_LIMIT_PER_MIN=${RATE_LIMIT_PER_MIN:-0} - MAX_USERS=${MAX_USERS:-0} - SESSION_DURATION_HOURS=${SESSION_DURATION_HOURS:-168} - TRUST_PROXY=${TRUST_PROXY:-true} # OIDC Authentication (optional) # - EXTERNAL_URL=https://photos.example.com # - OIDC_ENABLED=false # - OIDC_ISSUER_URL= # - OIDC_CLIENT_ID= # - OIDC_CLIENT_SECRET= # - OIDC_SCOPES=openid profile email # - OIDC_AUTO_CREATE_USERS=true # - OIDC_DEFAULT_ROLE=user # - OIDC_AUTO_LINK_USERS=false # - OIDC_PROVIDER_NAME= # - OIDC_USERNAME_CLAIM=preferred_username # - OIDC_CLOCK_TOLERANCE=30 # - COOKIE_SECRET= restart: unless-stopped # --- Security hardening --- mem_limit: 8g memswap_limit: 8g cpus: 8 pids_limit: 1024 cap_drop: - ALL cap_add: - CHOWN - SETUID - SETGID - DAC_OVERRIDE - FOWNER # NOTE: security_opt: [no-new-privileges:true] is intentionally omitted. # gosu requires setuid to drop from root to the snapotter user. # Mitigation: cap_drop: ALL limits available capabilities after privilege drop. # NOTE: read_only: true is not set because PUID/PGID remapping requires # writing to /etc/passwd and /etc/group. Consider using Docker --user flag # instead of PUID/PGID for read-only rootfs support. healthcheck: test: ["CMD", "curl", "-f", "http://localhost:1349/api/v1/health"] interval: 30s timeout: 5s start_period: 60s retries: 3 shm_size: "2gb" # Required for PyTorch CUDA shared memory deploy: resources: reservations: devices: - driver: nvidia count: all capabilities: [gpu] logging: driver: json-file options: max-size: "50m" max-file: "5" volumes: SnapOtter-data: SnapOtter-workspace: