-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
99 lines (94 loc) · 2.72 KB
/
Copy pathdocker-compose.yml
File metadata and controls
99 lines (94 loc) · 2.72 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
services:
web-api:
image: ${DOCKER_REGISTRY-}webapi
container_name: web-api
build:
context: .
dockerfile: src/Web.Api/Dockerfile
ports:
- 5000:8080
- 5001:8081
environment:
- ClamAv__Enabled=true
- ClamAv__Host=clamav
- ClamAv__Port=3310
depends_on:
postgres:
condition: service_healthy
redis:
condition: service_healthy
keycloak:
condition: service_healthy
clamav:
condition: service_healthy
keycloak:
image: quay.io/keycloak/keycloak:26.0
container_name: keycloak
# start-dev uses embedded H2 — no postgres dependency needed for local dev.
# --import-realm imports keycloak/realm-export.json on first boot.
# Keycloak 24+ substitutes ${VAR} references in the realm JSON from environment variables.
command: start-dev --import-realm
environment:
- KEYCLOAK_ADMIN=admin
- KEYCLOAK_ADMIN_PASSWORD=${KEYCLOAK_ADMIN_PASSWORD}
- KEYCLOAK_CLIENT_SECRET=${KEYCLOAK_CLIENT_SECRET}
# M2M ingestion (statement-generator) client secret; falls back to the API client secret in dev.
- KEYCLOAK_INGEST_CLIENT_SECRET=${KEYCLOAK_INGEST_CLIENT_SECRET:-${KEYCLOAK_CLIENT_SECRET}}
volumes:
- ./keycloak:/opt/keycloak/data/import
ports:
- 8080:8080
healthcheck:
test: ["CMD-SHELL", "curl -sf http://localhost:8080/health/ready || exit 1"]
interval: 10s
timeout: 5s
retries: 20
start_period: 60s
postgres:
image: postgres:17
container_name: postgres
environment:
- POSTGRES_DB=secure_statements
- POSTGRES_USER=postgres
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD}
volumes:
- ./.containers/db:/var/lib/postgresql/data
ports:
- 5432:5432
healthcheck:
test: ["CMD-SHELL", "pg_isready -U postgres -d secure_statements"]
interval: 5s
timeout: 5s
retries: 10
redis:
image: redis:7-alpine
container_name: redis
ports:
- 6379:6379
healthcheck:
test: ["CMD", "redis-cli", "ping"]
interval: 5s
timeout: 5s
retries: 10
seq:
image: datalust/seq:2024.3
container_name: seq
environment:
- ACCEPT_EULA=Y
ports:
- 8081:80
clamav:
image: clamav/clamav:1.4
container_name: clamav
# Raise StreamMaxLength above the 50 MB upload limit (image default is 25 MB).
volumes:
- ./clamav/clamd.conf:/etc/clamav/clamd.conf:ro
ports:
- 3310:3310
healthcheck:
# clamdcheck.sh PINGs clamd; only healthy once the signature DB has loaded (~1-2 min first run).
test: ["CMD-SHELL", "clamdcheck.sh || exit 1"]
interval: 15s
timeout: 10s
retries: 20
start_period: 120s