48 lines
2.4 KiB
YAML
48 lines
2.4 KiB
YAML
# Server registry example. Copy to a reviewed, untracked operator directory and set host paths
|
|
# and Git values in its .env. The core remains non-root (UID 10001) and never receives secrets
|
|
# through the Git checkout.
|
|
name: thothii-workspace-registry-server
|
|
|
|
services:
|
|
core:
|
|
image: thothii-core:local
|
|
build:
|
|
context: ../../..
|
|
dockerfile: docker/core.Dockerfile
|
|
environment:
|
|
HOST: 0.0.0.0
|
|
PORT: "8787"
|
|
AUTH_MODE: upstream
|
|
THOTH_PUBLIC_EXPOSURE: "true"
|
|
THT_HARNESS_DIR: /app/harness
|
|
THT_BIN: /opt/venv/bin/tht
|
|
SETTINGS_FILE: /data/settings/settings.json
|
|
THT_WORKSPACE_REGISTRY_ROOT: /data/workspace-registry
|
|
THT_WORKSPACE_GIT_REMOTE: ${THT_WORKSPACE_GIT_REMOTE:-ssh://git@git.example.invalid/platform/thoth-workspaces.git}
|
|
THT_WORKSPACE_GIT_BRANCH: ${THT_WORKSPACE_GIT_BRANCH:-main}
|
|
THT_WORKSPACE_INSTALLATION_ID: ${THT_WORKSPACE_INSTALLATION_ID:-production-1}
|
|
THT_WORKSPACE_GIT_AUTHOR_NAME: ${THT_WORKSPACE_GIT_AUTHOR_NAME:-Thoth Workspace Registry}
|
|
THT_WORKSPACE_GIT_AUTHOR_EMAIL: ${THT_WORKSPACE_GIT_AUTHOR_EMAIL:-thoth-workspace-registry@localhost}
|
|
THT_WORKSPACE_SECRET_ROOTS: /run/secrets
|
|
GIT_CONFIG_COUNT: "2"
|
|
GIT_CONFIG_KEY_0: credential.helper
|
|
GIT_CONFIG_VALUE_0: store --file=/run/secrets/workspace-registry-git-credentials
|
|
GIT_CONFIG_KEY_1: http.sslCAInfo
|
|
GIT_CONFIG_VALUE_1: /run/secrets/workspace-registry-git-ca
|
|
GIT_SSH_COMMAND: ssh -i /run/secrets/workspace-registry-git-ssh-key -o IdentitiesOnly=yes -o StrictHostKeyChecking=yes -o UserKnownHostsFile=/run/secrets/workspace-registry-git-known-hosts
|
|
volumes:
|
|
- ${THT_HOST_DATA_ROOT:-/srv/thothii/data}:/data
|
|
- ${THT_WORKSPACE_REGISTRY_HOST_PATH:-/srv/thothii/workspace-registry}:/data/workspace-registry
|
|
- ${THT_WORKSPACE_GIT_CREDENTIALS_FILE:-/srv/thothii/secrets/git-credentials}:/run/secrets/workspace-registry-git-credentials:ro
|
|
- ${THT_WORKSPACE_GIT_CA_FILE:-/srv/thothii/secrets/git-ca.pem}:/run/secrets/workspace-registry-git-ca:ro
|
|
- ${THT_WORKSPACE_GIT_SSH_KEY_FILE:-/srv/thothii/secrets/git-ssh-key}:/run/secrets/workspace-registry-git-ssh-key:ro
|
|
- ${THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE:-/srv/thothii/secrets/git-known-hosts}:/run/secrets/workspace-registry-git-known-hosts:ro
|
|
networks:
|
|
- portal
|
|
restart: unless-stopped
|
|
|
|
networks:
|
|
portal:
|
|
external: true
|
|
name: ${THT_PORTAL_NETWORK:-omics_portal_omics_network}
|