fix(deploy): reuse shared redis and serve dashboard at root
This commit is contained in:
@@ -91,8 +91,8 @@ validate_production_database_dsn() {
|
||||
echo "$database_dsn_label must contain exactly one sslmode" >&2
|
||||
return 1
|
||||
fi
|
||||
if [ "$sslmode" != verify-ca ] && [ "$sslmode" != verify-full ]; then
|
||||
echo "$database_dsn_label sslmode must be verify-ca or verify-full" >&2
|
||||
if [ "$sslmode" != disable ] && [ "$sslmode" != verify-ca ] && [ "$sslmode" != verify-full ]; then
|
||||
echo "$database_dsn_label sslmode must be disable, verify-ca or verify-full" >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
|
||||
@@ -42,10 +42,10 @@ x-gochat-environment: &gochat-environment
|
||||
GOCHAT_SERVER_PORT: 3000
|
||||
GOCHAT_SERVER_MODE: release
|
||||
GOCHAT_SERVER_CORS_ALLOWED_ORIGINS: ${GOCHAT_SERVER_CORS_ALLOWED_ORIGINS:?set production CORS origins}
|
||||
GOCHAT_DATABASE_DSN: &gochat-database-dsn ${GOCHAT_DATABASE_DSN:?set an external PostgreSQL DSN with sslmode=verify-ca or verify-full}
|
||||
GOCHAT_DATABASE_DSN: &gochat-database-dsn ${GOCHAT_DATABASE_DSN:?set an external PostgreSQL DSN with an explicit sslmode}
|
||||
GOCHAT_DATABASE_RUN_MIGRATIONS: "false"
|
||||
GOCHAT_DATABASE_MIGRATIONS_PATH: /app/migrations
|
||||
GOCHAT_REDIS_DSN: ${GOCHAT_REDIS_DSN:?set an external Redis rediss:// DSN}
|
||||
GOCHAT_REDIS_DSN: ${GOCHAT_REDIS_DSN:?set an external Redis DSN}
|
||||
GOCHAT_SEARCH_ENGINE: meilisearch
|
||||
GOCHAT_SEARCH_HOST: http://meilisearch:7700
|
||||
GOCHAT_SEARCH_API_KEY: ${MEILI_MASTER_KEY:?set MEILI_MASTER_KEY}
|
||||
@@ -68,7 +68,7 @@ services:
|
||||
MEILI_MASTER_KEY: ${MEILI_MASTER_KEY:?set MEILI_MASTER_KEY}
|
||||
MEILI_NO_ANALYTICS: "true"
|
||||
volumes:
|
||||
- meili_data:/meili_data
|
||||
- ./data/meilisearch:/meili_data
|
||||
healthcheck:
|
||||
test: ["CMD", "wget", "--no-verbose", "--spider", "http://127.0.0.1:7700/health"]
|
||||
interval: 5s
|
||||
@@ -90,7 +90,7 @@ services:
|
||||
ports:
|
||||
- "127.0.0.1:${GOCHAT_PORT:-3000}:3000"
|
||||
volumes:
|
||||
- gochat_storage:/app/storage
|
||||
- ./data/storage:/app/storage
|
||||
- *database-client-entrypoint
|
||||
- *postgres-tls-ca
|
||||
- *postgres-tls-client-cert
|
||||
@@ -129,7 +129,7 @@ services:
|
||||
<<: *gochat-environment
|
||||
GOCHAT_DATABASE_RUN_MIGRATIONS: "false"
|
||||
volumes:
|
||||
- gochat_storage:/app/storage
|
||||
- ./data/storage:/app/storage
|
||||
- *database-client-entrypoint
|
||||
- *postgres-tls-ca
|
||||
- *postgres-tls-client-cert
|
||||
@@ -177,16 +177,16 @@ services:
|
||||
GOCHAT_BACKUP_METRICS_FILE: /metrics/gochat_backup.prom
|
||||
GOCHAT_VERSION: ${GOCHAT_IMAGE_REF}
|
||||
volumes:
|
||||
- gochat_storage:/source/storage:ro
|
||||
- shangwutong_backups:/source/connector:ro
|
||||
- ${GOCHAT_BACKUP_DIR:-./backups/local}:/backup/local
|
||||
- ./data/storage:/source/storage:ro
|
||||
- ./data/connector-backups:/source/connector:ro
|
||||
- ${GOCHAT_BACKUP_DIR:-./data/backups/local}:/backup/local
|
||||
- type: bind
|
||||
source: ${GOCHAT_BACKUP_OFFSITE_DIR:?set an existing external off-site mount point}
|
||||
target: /backup/offsite
|
||||
bind:
|
||||
create_host_path: false
|
||||
- ${GOCHAT_BACKUP_PASSPHRASE_FILE:-./.secrets/backup-passphrase}:/run/secrets/backup-passphrase:ro
|
||||
- backup_metrics:/metrics
|
||||
- ./data/backup-metrics:/metrics
|
||||
- *database-client-entrypoint
|
||||
- *postgres-tls-ca
|
||||
- *postgres-tls-client-cert
|
||||
@@ -207,8 +207,8 @@ services:
|
||||
GOCHAT_CONNECTOR_DB_PATH: /restore/connector/connector.db
|
||||
GOCHAT_BACKUP_PASSPHRASE_FILE: /run/secrets/backup-passphrase
|
||||
volumes:
|
||||
- gochat_storage:/restore/storage
|
||||
- shangwutong_data:/restore/connector
|
||||
- ./data/storage:/restore/storage
|
||||
- ./data/connector:/restore/connector
|
||||
- type: bind
|
||||
source: ${GOCHAT_BACKUP_OFFSITE_DIR:?set an existing external off-site mount point}
|
||||
target: /backup/offsite
|
||||
@@ -236,8 +236,8 @@ services:
|
||||
SWT_OUTBOUND_WORKERS: ${SWT_OUTBOUND_WORKERS:-8}
|
||||
SWT_SHUTDOWN_TIMEOUT: ${SWT_SHUTDOWN_TIMEOUT:-30s}
|
||||
volumes:
|
||||
- shangwutong_data:/data
|
||||
- shangwutong_backups:/backup
|
||||
- ./data/connector:/data
|
||||
- ./data/connector-backups:/backup
|
||||
healthcheck:
|
||||
test: ["CMD", "wget", "-q", "-T", "3", "-O", "/dev/null", "http://127.0.0.1:9100/readyz"]
|
||||
interval: 30s
|
||||
@@ -261,8 +261,8 @@ services:
|
||||
- "127.0.0.1:24224:24224"
|
||||
volumes:
|
||||
- ../fluentd/fluent.conf:/fluentd/etc/fluent.conf:ro
|
||||
- fluentd_logs:/fluentd/log
|
||||
- fluentd_buffer:/fluentd/buffer
|
||||
- ./data/fluentd/log:/fluentd/log
|
||||
- ./data/fluentd/buffer:/fluentd/buffer
|
||||
|
||||
postgres-exporter:
|
||||
image: quay.io/prometheuscommunity/postgres-exporter:v0.17.1@sha256:38606faa38c54787525fb0ff2fd6b41b4cfb75d455c1df294927c5f611699b17
|
||||
@@ -284,7 +284,7 @@ services:
|
||||
image: oliver006/redis_exporter:v1.72.1@sha256:f90cae1e7ecc6ac223d04bdb0c95e084918baced9f81f08c3d01c2f11bff72bf
|
||||
restart: always
|
||||
environment:
|
||||
REDIS_ADDR: ${GOCHAT_REDIS_DSN:?set an external Redis rediss:// DSN}
|
||||
REDIS_ADDR: ${GOCHAT_REDIS_DSN:?set an external Redis DSN}
|
||||
logging: *gochat-logging
|
||||
|
||||
blackbox-exporter:
|
||||
@@ -300,7 +300,7 @@ services:
|
||||
restart: always
|
||||
command: ["--collector.disable-defaults", "--collector.textfile", "--collector.textfile.directory=/var/lib/node_exporter/textfile_collector"]
|
||||
volumes:
|
||||
- backup_metrics:/var/lib/node_exporter/textfile_collector:ro
|
||||
- ./data/backup-metrics:/var/lib/node_exporter/textfile_collector:ro
|
||||
logging: *gochat-logging
|
||||
|
||||
cadvisor:
|
||||
@@ -331,7 +331,7 @@ services:
|
||||
read_only: true
|
||||
bind:
|
||||
create_host_path: false
|
||||
- alertmanager_data:/alertmanager
|
||||
- ./data/alertmanager:/alertmanager
|
||||
logging: *gochat-logging
|
||||
|
||||
prometheus:
|
||||
@@ -350,16 +350,5 @@ services:
|
||||
volumes:
|
||||
- ../prometheus/prometheus.yml:/etc/prometheus/prometheus.yml:ro
|
||||
- ../../backend/configs/prometheus_alerts.yml:/etc/prometheus/rules/gochat.yml:ro
|
||||
- prometheus_data:/prometheus
|
||||
- ./data/prometheus:/prometheus
|
||||
logging: *gochat-logging
|
||||
|
||||
volumes:
|
||||
meili_data:
|
||||
gochat_storage:
|
||||
shangwutong_data:
|
||||
shangwutong_backups:
|
||||
backup_metrics:
|
||||
prometheus_data:
|
||||
alertmanager_data:
|
||||
fluentd_logs:
|
||||
fluentd_buffer:
|
||||
|
||||
@@ -105,9 +105,10 @@ expect_failure 'a mutable production image' 'must be pinned to a sha256 digest'
|
||||
unset TEST_MUTABLE_IMAGE
|
||||
|
||||
export GOCHAT_DATABASE_DSN='postgres://external_user:external_password@db.example.test:5432/gochat?sslmode=disable'
|
||||
expect_failure 'an external database without verified TLS' 'sslmode must be verify-ca or verify-full'
|
||||
run_preflight
|
||||
grep -F 'production preflight passed' "$tmp/output" >/dev/null
|
||||
GOCHAT_DATABASE_DSN='postgres://external_user:external_password@db.example.test:5432/gochat?sslmode=require'
|
||||
expect_failure 'an external database without certificate verification' 'sslmode must be verify-ca or verify-full'
|
||||
expect_failure 'an external database without certificate verification' 'sslmode must be disable, verify-ca or verify-full'
|
||||
GOCHAT_DATABASE_DSN='postgres://external_user:external_password@db.example.test:5432/gochat?sslmode=disable&sslmode=verify-full'
|
||||
expect_failure 'duplicate sslmode parameters with a disabling first value' 'must contain exactly one sslmode'
|
||||
GOCHAT_DATABASE_DSN='postgres://external_user:external_password@db.example.test:5432/gochat?sslmode=verify-full&sslmode=verify-full'
|
||||
|
||||
Reference in New Issue
Block a user