Repository navigation
Expand file tree
/
Copy pathcompose.yaml
More file actions
135 lines (133 loc) · 5.08 KB
/
Copy pathcompose.yaml
File metadata and controls
135 lines (133 loc) · 5.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
configs:
ts-serve:
content: |
{"TCP":{"443":{"HTTPS":true}},
"Web":{"$${TS_CERT_DOMAIN}:443":
{"Handlers":{"/":
{"Proxy":"http://127.0.0.1:8080"}}}},
"AllowFunnel":{"$${TS_CERT_DOMAIN}:443":false}}
services:
# Make sure you have updated/checked the .env file with the correct variables.
# Every variable used in this file must be defined there.
# Tailscale Sidecar Configuration
tailscale:
image: tailscale/tailscale:latest # Image to be used
container_name: tailscale-${SERVICE} # Name for local container management
hostname: ${SERVICE} # Name used within your Tailscale environment
environment:
- TS_AUTHKEY=${TS_AUTHKEY}
- TS_STATE_DIR=/var/lib/tailscale
- TS_SERVE_CONFIG=/config/serve.json # Tailscale Serve configuration to expose the web interface on your local Tailnet - remove this line if not required
- TS_USERSPACE=false
- TS_ENABLE_HEALTH_CHECK=true # Enable healthcheck endpoint: "/healthz"
- TS_LOCAL_ADDR_PORT=127.0.0.1:41234 # The <addr>:<port> for the healthz endpoint
#- TS_ACCEPT_DNS=true # Uncomment only if the service must resolve MagicDNS names - this replaces Docker DNS, so Compose service names no longer resolve
- TS_AUTH_ONCE=true
configs:
- source: ts-serve
target: /config/serve.json
volumes:
- ./config:/config # Config folder used to store Tailscale files - you may need to change the path
- ./ts/state:/var/lib/tailscale # Tailscale requirement - you may need to change the path
devices:
- /dev/net/tun:/dev/net/tun # Network configuration for Tailscale to work
cap_add:
- net_admin # Tailscale requirement
# If any DNS issues arise, use your preferred DNS provider by uncommenting the config below
#dns:
# - ${DNS_SERVER}
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:41234/healthz"] # Check Tailscale has a Tailnet IP and is operational
interval: 1m # How often to perform the check
timeout: 10s # Time to wait for the check to succeed
retries: 3 # Number of retries before marking as unhealthy
start_period: 10s # Time to wait before starting health checks
restart: always
# Application
netbox: &netbox
image: ${IMAGE_URL} # Image to be used
network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale
container_name: ${SERVICE} # Name for local container management
environment:
- SECRET_KEY=${SECRET_KEY:?Set SECRET_KEY in .env}
- TZ=${TZ}
volumes:
- ./config:/etc/netbox/config:z,ro
- ./${SERVICE}/media:/opt/netbox/netbox/media
- ./${SERVICE}/reports:/opt/netbox/netbox/reports
- ./${SERVICE}/scripts:/opt/netbox/netbox/scripts
depends_on:
tailscale:
condition: service_healthy
postgres:
condition: service_healthy
redis:
condition: service_healthy
redis-cache:
condition: service_healthy
healthcheck:
test: curl -f http://localhost:8080/login/ || exit 1 # Check if the service is responding
start_period: 600s # The first start runs database migrations that can take several minutes, longer on slow hosts
timeout: 3s
interval: 15s
restart: always
env_file: ./.env
netbox-worker:
<<: *netbox
container_name: worker-${SERVICE} # Name for local container management
depends_on:
netbox:
condition: service_healthy
command:
- /opt/netbox/venv/bin/python
- /opt/netbox/netbox/manage.py
- rqworker
healthcheck:
test: ps -aux | grep -v grep | grep -q rqworker || exit 1
start_period: 20s
timeout: 3s
interval: 15s
# postgres
postgres:
image: docker.io/postgres:17-alpine
container_name: ${SERVICE}-postgres
env_file: ./.env
healthcheck:
test: pg_isready -h 127.0.0.1 -q -t 2 -d $$POSTGRES_DB -U $$POSTGRES_USER # Check if PostgreSQL accepts connections
start_period: 20s
timeout: 30s
interval: 10s
retries: 5
volumes:
- ./${SERVICE}/postgres/data:/var/lib/postgresql/data
restart: always
# redis
redis:
container_name: ${SERVICE}-redis
image: docker.io/valkey/valkey:8.1-alpine
env_file: ./.env
command:
- sh
- -c # this is to evaluate the $REDIS_PASSWORD from the env
- valkey-server --appendonly yes --requirepass $$REDIS_PASSWORD ## $$ because of docker-compose
healthcheck: &redis-healthcheck
test: '[ $$(valkey-cli --pass "$${REDIS_PASSWORD}" ping) = ''PONG'' ]'
start_period: 5s
timeout: 3s
interval: 1s
retries: 5
volumes:
- ./${SERVICE}/redis/data:/data
restart: always
redis-cache:
container_name: ${SERVICE}-rediscache
image: docker.io/valkey/valkey:8.1-alpine
env_file: ./.env
command:
- sh
- -c # this is to evaluate the $REDIS_PASSWORD from the env
- valkey-server --requirepass $$REDIS_PASSWORD ## $$ because of docker-compose
healthcheck: *redis-healthcheck
volumes:
- ./${SERVICE}/redis/cache:/data
restart: always