admin/ and adminsite/ are extracted with their history to
gitea.hostxtra.co.uk/vantage/vantage-admin, where they are named server/
and web/ for what they are rather than for the services they run. Their
images move with them, to vantage/vantage-admin/{server,web}.
Nothing here imported them, so the cut is clean: the only coupling was
always at runtime, through admin writing into the control plane's
database. The parts of that contract this side enforces are unchanged and
still documented here — hq-sourced users, POST /license answering 409
cloud_managed, and FREE_INSTANCE_REAP_AFTER needing to match.
LICENSE_SIGNING_KEY now appears in no compose file in this repository.
Keeping it out used to be a rule someone had to remember; it is the
repository boundary now.
docker-compose.site.yml loses both services and gains a note on how the
host composes the three files together.
47 lines
1.8 KiB
YAML
47 lines
1.8 KiB
YAML
services:
|
|
site:
|
|
image: gitea.hostxtra.co.uk/mrhid6/vantage/site:latest
|
|
restart: unless-stopped
|
|
ports:
|
|
- 3003:3000
|
|
depends_on:
|
|
- sitesvc
|
|
sitesvc:
|
|
image: gitea.hostxtra.co.uk/mrhid6/vantage/sitesvc:latest
|
|
restart: unless-stopped
|
|
ports:
|
|
- 8082:8082
|
|
environment:
|
|
PORT: "8082"
|
|
PUBLIC_URL: ${PUBLIC_URL:-}
|
|
SITE_ORIGIN: ${SITE_ORIGIN:-}
|
|
TRUST_PROXY: ${SITE_TRUST_PROXY:-false}
|
|
SMTP_HOST: ${SMTP_HOST:-}
|
|
SMTP_PORT: ${SMTP_PORT:-587}
|
|
SMTP_USERNAME: ${SMTP_USERNAME:-}
|
|
SMTP_PASSWORD: ${SMTP_PASSWORD:-}
|
|
SMTP_FROM: ${SMTP_FROM:-}
|
|
SMTP_TO: ${SMTP_TO:-support@hostxtra.co.uk}
|
|
# admin and adminsite are NOT here. They live in the vantage-admin
|
|
# repository, which carries its own fragment; the host composes all three
|
|
# files together:
|
|
#
|
|
# docker compose \
|
|
# -f vantage/deploy/docker/docker-compose.yml \
|
|
# -f vantage/deploy/docker/docker-compose.site.yml \
|
|
# -f vantage-admin/deploy/docker-compose.yml \
|
|
# up -d
|
|
#
|
|
# LICENSE_SIGNING_KEY went with them, and must never appear in this file:
|
|
# admin is the only signer and the control plane must not hold the key.
|
|
# Static docs, served by nginx at vantage.hostxtra.co.uk/docs through its own
|
|
# proxy location. That location must sort ABOVE the catch-all forwarding to
|
|
# site:3003, or Next serves its own 404 for /docs. The container serves from
|
|
# /usr/share/nginx/html/docs because the proxy forwards the full path.
|
|
docsite:
|
|
image: gitea.hostxtra.co.uk/mrhid6/vantage/docsite:latest
|
|
restart: unless-stopped
|
|
ports:
|
|
- 3005:80
|
|
networks: {}
|