mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
## What changed Bind the development Compose stack's published PostgreSQL, Redis, Adminer, Keycloak, MinIO, and Prometheus ports to `127.0.0.1`. ## Why Docker publishes a host port on every interface when no host address is specified. Running the development stack on a remote workstation or VPS therefore exposes its infrastructure services to that machine's public networks. Loopback bindings retain host-local development access and Docker's internal `buzz-net` connectivity without making those services Internet-reachable. ## Impact Local workflows continue using the same ports. Deliberate remote administration now requires an SSH tunnel or another trusted private-network path. ## Validation - `docker compose -f docker-compose.yml config --quiet` - Recreated the six affected services with their existing named volumes and Docker network - PostgreSQL remained healthy and retained all 54 application tables - Redis, MinIO, and Prometheus health checks passed - All affected ports were closed on the host's public IPv4 and IPv6 addresses while remaining available on loopback Origin: `buzz://message?channel=199eb7bc-3feb-484f-ae0e-4995123721ea&id=1c5bc387e86e21bb31677f56e1c862d4d9a17943bce91f8d93e825d029ce7f72` Signed-off-by: Paweł Karniej <karniej.p@gmail.com>
192 lines
4.3 KiB
YAML
192 lines
4.3 KiB
YAML
name: buzz
|
|
|
|
services:
|
|
postgres:
|
|
image: postgres:17-alpine
|
|
container_name: buzz-postgres
|
|
environment:
|
|
POSTGRES_USER: buzz
|
|
POSTGRES_PASSWORD: buzz_dev
|
|
POSTGRES_DB: buzz
|
|
PGDATA: /var/lib/postgresql/data
|
|
ports:
|
|
- "127.0.0.1:5432:5432"
|
|
volumes:
|
|
- postgres-data:/var/lib/postgresql/data
|
|
networks:
|
|
- buzz-net
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U buzz"]
|
|
interval: 5s
|
|
timeout: 5s
|
|
retries: 10
|
|
start_period: 10s
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 512m
|
|
labels:
|
|
com.buzz.service: "postgres"
|
|
com.buzz.env: "dev"
|
|
restart: unless-stopped
|
|
|
|
redis:
|
|
image: redis:7-alpine
|
|
container_name: buzz-redis
|
|
ports:
|
|
- "127.0.0.1:6379:6379"
|
|
networks:
|
|
- buzz-net
|
|
healthcheck:
|
|
test: ["CMD", "redis-cli", "ping"]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 10
|
|
start_period: 5s
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 128m
|
|
labels:
|
|
com.buzz.service: "redis"
|
|
com.buzz.env: "dev"
|
|
restart: unless-stopped
|
|
|
|
adminer:
|
|
image: adminer:latest
|
|
container_name: buzz-adminer
|
|
ports:
|
|
- "127.0.0.1:8082:8080"
|
|
networks:
|
|
- buzz-net
|
|
depends_on:
|
|
postgres:
|
|
condition: service_healthy
|
|
environment:
|
|
ADMINER_DEFAULT_SERVER: postgres
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 64m
|
|
labels:
|
|
com.buzz.service: "adminer"
|
|
com.buzz.env: "dev"
|
|
restart: unless-stopped
|
|
|
|
keycloak:
|
|
image: quay.io/keycloak/keycloak:26.0
|
|
container_name: buzz-keycloak
|
|
command: start-dev --http-port=8080
|
|
environment:
|
|
KC_DB: dev-mem
|
|
KEYCLOAK_ADMIN: admin
|
|
KEYCLOAK_ADMIN_PASSWORD: admin
|
|
ports:
|
|
- "127.0.0.1:8180:8080"
|
|
networks:
|
|
- buzz-net
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "exec 3<>/dev/tcp/localhost/8080 && echo -e 'GET /health/ready HTTP/1.1\\r\\nHost: localhost\\r\\nConnection: close\\r\\n\\r\\n' >&3 && cat <&3 | grep -q '200 OK'"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 15
|
|
start_period: 30s
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 512m
|
|
labels:
|
|
com.buzz.service: "keycloak"
|
|
com.buzz.env: "dev"
|
|
restart: unless-stopped
|
|
|
|
minio:
|
|
image: minio/minio:latest
|
|
container_name: buzz-minio
|
|
command: server /data --console-address ":9001"
|
|
environment:
|
|
MINIO_ROOT_USER: buzz_dev
|
|
MINIO_ROOT_PASSWORD: buzz_dev_secret
|
|
ports:
|
|
- "127.0.0.1:9000:9000"
|
|
- "127.0.0.1:9001:9001"
|
|
volumes:
|
|
- minio-data:/data
|
|
networks:
|
|
- buzz-net
|
|
healthcheck:
|
|
test: ["CMD", "curl", "-f", "http://localhost:9000/minio/health/live"]
|
|
interval: 5s
|
|
timeout: 5s
|
|
retries: 10
|
|
start_period: 10s
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 256m
|
|
labels:
|
|
com.buzz.service: "minio"
|
|
com.buzz.env: "dev"
|
|
restart: unless-stopped
|
|
|
|
minio-init:
|
|
image: minio/mc:latest
|
|
container_name: buzz-minio-init
|
|
depends_on:
|
|
minio:
|
|
condition: service_healthy
|
|
networks:
|
|
- buzz-net
|
|
entrypoint: >
|
|
/bin/sh -c "
|
|
mc alias set local http://minio:9000 buzz_dev buzz_dev_secret &&
|
|
mc mb --ignore-existing local/buzz-media &&
|
|
mc anonymous set none local/buzz-media
|
|
"
|
|
labels:
|
|
com.buzz.service: "minio-init"
|
|
com.buzz.env: "dev"
|
|
restart: "no"
|
|
|
|
prometheus:
|
|
image: prom/prometheus:latest
|
|
container_name: buzz-prometheus
|
|
ports:
|
|
- "127.0.0.1:9090:9090"
|
|
volumes:
|
|
- ./prometheus.yml:/etc/prometheus/prometheus.yml:ro
|
|
- prometheus-data:/prometheus
|
|
networks:
|
|
- buzz-net
|
|
extra_hosts:
|
|
- "host.docker.internal:host-gateway"
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 128m
|
|
labels:
|
|
com.buzz.service: "prometheus"
|
|
com.buzz.env: "dev"
|
|
restart: unless-stopped
|
|
|
|
volumes:
|
|
postgres-data:
|
|
name: buzz-postgres-data
|
|
labels:
|
|
com.buzz.volume: "postgres"
|
|
minio-data:
|
|
name: buzz-minio-data
|
|
labels:
|
|
com.buzz.volume: "minio"
|
|
prometheus-data:
|
|
name: buzz-prometheus-data
|
|
labels:
|
|
com.buzz.volume: "prometheus"
|
|
|
|
networks:
|
|
buzz-net:
|
|
name: buzz-net
|
|
driver: bridge
|
|
labels:
|
|
com.buzz.network: "dev"
|