# Tomter Vel's own platform: one host, four containers, everything # behind Caddy. The content (pages, forms, desks) is not here: portal # fetches it from tomtervel/questions on prosjekt.klingenbergbygg.no # and hot-reloads it over NATS. This repo owns the host: identity, # the bus, TLS, and which portal version runs. # # bootstrap.sh first time on a fresh host: renders configs from # .env, makes Kanidm's internal cert, starts it all, # recovers the Kanidm admin, creates the portal client # and desk groups. # docker compose up -d --build every time after that. name: tomtervel services: caddy: image: caddy:2 restart: unless-stopped ports: - "80:80" - "443:443" - "443:443/udp" environment: PORTAL_HOST: ${PORTAL_HOST} ID_HOST: ${ID_HOST} volumes: - ./Caddyfile:/etc/caddy/Caddyfile:ro - caddy_data:/data - caddy_config:/config depends_on: - portal - kanidm nats: image: nats:2.14.6-alpine restart: unless-stopped command: ["-c", "/etc/nats/nats.conf"] volumes: - ./nats/nats.conf:/etc/nats/nats.conf:ro - nats_data:/data # Published so a runner or a person on the host can `nats pub # portal.content.reload ""`; password-protected (see nats.conf). ports: - "127.0.0.1:4222:4222" healthcheck: test: ["CMD", "wget", "--spider", "-q", "http://localhost:8222/healthz"] interval: 10s timeout: 5s retries: 3 kanidm: image: kanidm/server:1.11.1 restart: unless-stopped environment: KANIDM_CONFIG_PATH: /data/server.toml volumes: - kanidm_data:/data - ./kanidm/server.toml:/data/server.toml:ro # Internal self-signed TLS: Caddy terminates the public # certificate and proxies here without verification. - ./certs/kanidm-chain.pem:/data/chain.pem:ro - ./certs/kanidm-key.pem:/data/key.pem:ro # No published ports: only Caddy talks to it. portal: build: context: ./portal args: PORTAL_RELEASE: ${PORTAL_RELEASE} restart: unless-stopped env_file: portal.env environment: LEPTOS_SITE_ADDR: 0.0.0.0:3000 LEPTOS_SITE_ROOT: site LEPTOS_HASH_FILES: "true" depends_on: nats: condition: service_healthy kanidm: condition: service_started # Optional: a Gitea Actions runner on this host, so the content repo's # lint-and-reload can reach this NATS. Register it once against # prosjekt.klingenbergbygg.no with the label `tomtervel`, then give # the content repo a reload job with `runs-on: tomtervel`. # docker compose --profile runner up -d runner: profiles: ["runner"] image: gitea/act_runner:latest restart: unless-stopped environment: GITEA_INSTANCE_URL: https://prosjekt.klingenbergbygg.no GITEA_RUNNER_REGISTRATION_TOKEN: ${RUNNER_REGISTRATION_TOKEN:-} GITEA_RUNNER_NAME: tomtervel GITEA_RUNNER_LABELS: tomtervel:host volumes: - runner_data:/data - /var/run/docker.sock:/var/run/docker.sock volumes: caddy_data: caddy_config: nats_data: kanidm_data: runner_data: