revert(infra): back to bridge networking, remove TNC dependency

Per request: TNC removed, all stacks back on default bridge with legacy
links for inter-container DNS (default bridge has no embedded DNS —
verified: nameserver passthrough to AdGuard). Kept: traefik router labels
(dnsweaver records), dawarich prod + SECRET_KEY_BASE, teslamate/bookorbit
hostport removals (service DNS now via links), komodo periphery as
separate project with 8120 hostport + server address change.
This commit is contained in:
Arnout van Westen committed 2026-10-05 10:15:39 +02:00
1 parent fa790b3d37
commit 03b1607e79
9 files changed
+90 -126

No files matched your search

+5 -9
View File
@@ -1,15 +1,13 @@
networks:
changedetection:
services:
changedetection:
image: ghcr.io/dgtlmoon/changedetection.io:0.60.8
container_name: changedetection
hostname: changedetection
networks:
- changedetection
network_mode: "bridge"
depends_on:
- browser-sockpuppet-chrome
links:
- browser-sockpuppet-chrome
volumes:
- changedetection-data:/datastore
# Configurable proxy list support, see https://github.com/dgtlmoon/changedetection.io/wiki/Proxy-configuration#proxy-list-support
@@ -95,9 +93,8 @@ services:
- "5353:5000"
restart: unless-stopped
labels:
- traefik.enable=true
- traefik.http.routers.changedetection.rule=Host(`changedetection.arnoutvw.nl`)
- traefik.http.services.changedetection.loadbalancer.server.port=5000
- traefik.docker.network=changedetection_default
# Used for fetching pages via WebDriver+Chrome where you need Javascript support.
# Now working on arm64 (needs testing on rPi - tested on Oracle ARM instance)
@@ -115,8 +112,7 @@ services:
browser-sockpuppet-chrome:
hostname: browser-sockpuppet-chrome
image: dgtlmoon/sockpuppetbrowser@sha256:1d8f72d2ce2085faed4232e5ae1e65c02efe5b831a18e127829b267c260b4fb2
networks:
- changedetection
network_mode: bridge
cap_add:
- SYS_ADMIN
# SYS_ADMIN might be too much, but it can be needed on your platform https://github.com/puppeteer/puppeteer/blob/main/docs/troubleshooting.md#running-puppeteer-on-gitlabci
+38 -42
View File
@@ -1,47 +1,27 @@
# Based on upstream https://github.com/Freika/dawarich/blob/master/docker/docker-compose.yml
# Local deviations:
# - image tags pinned (repo convention; Renovate bumps)
# - host port 3007 -> 3000: pangolin (newt) and LAN clients target
# 192.168.10.144:3007, so it must stay published on the host
# - traefik labels on dawarich_app: Atlas traefik does NOT sit on this
# network; traefik-network-connector (own stack) attaches it on start
# - RAILS_ENV production (upstream default; install predates the switch)
# - BACKGROUND_PROCESSING_CONCURRENCY 10 (upstream default 3; tuned for
# large imports)
# - local photon geocoding (photon container currently disabled)
networks:
dawarich:
services:
dawarich_redis:
image: redis:7.4-alpine
container_name: dawarich_redis
command: >
redis-server
--save 900 1
--save 300 10
--appendonly no
networks:
- dawarich
command: redis-server
network_mode: bridge
volumes:
- dawarich_shared:/data
restart: always
healthcheck:
test: [ "CMD", "redis-cli", "--raw", "incr", "ping" ]
test: [ "CMD-SHELL", "redis-cli --raw incr ping || exit 1" ]
interval: 10s
retries: 5
start_period: 30s
timeout: 10s
dawarich_db:
image: postgis/postgis:17-3.5-alpine
shm_size: 1G
container_name: dawarich_db
network_mode: bridge
volumes:
- dawarich_db_data:/var/lib/postgresql/data
- dawarich_shared:/var/shared
networks:
- dawarich
# - ./postgresql.conf:/etc/postgresql/postgresql.conf # Optional, uncomment if you want to use a custom config
environment:
POSTGRES_USER: postgres
POSTGRES_PASSWORD: password
@@ -53,29 +33,29 @@ services:
retries: 5
start_period: 30s
timeout: 10s
# command: postgres -c config_file=/etc/postgresql/postgresql.conf # Use custom config, uncomment if you want to use a custom config
dawarich_app:
labels:
- traefik.constraint=proxy-public
- traefik.http.routers.nginx.rule=Host(`dawarich.arnoutvw.nl`)
image: freikin/dawarich:1.15.3
container_name: dawarich_app
network_mode: bridge
volumes:
- dawarich_public:/var/app/public
- dawarich_watched:/var/app/tmp/imports/watched
- dawarich_storage:/var/app/storage
- dawarich_db_data:/dawarich_db_data
networks:
- dawarich
labels:
- traefik.enable=true
- traefik.http.routers.dawarich.rule=Host(`dawarich.arnoutvw.nl`)
- traefik.http.services.dawarich.loadbalancer.server.port=3000
links:
- dawarich_db
- dawarich_redis
ports:
# custom host port: pangolin/newt + LAN target 192.168.10.144:3007
- 3007:3000
- 9397:9394 # Prometheus exporter, uncomment if needed
stdin_open: true
tty: true
entrypoint: web-entrypoint.sh
command: [ 'bin/rails', 'server', '-p', '3000', '-b', '::' ]
restart: unless-stopped
restart: always
environment:
RAILS_ENV: production
SECRET_KEY_BASE: 2f5e59518ddeaeb978c73bc265eea20a91d5fe203d2a45280bd8fbf62b447b57
@@ -86,6 +66,13 @@ services:
DATABASE_NAME: dawarich_development
MIN_MINUTES_SPENT_IN_CITY: 60
APPLICATION_HOSTS: localhost,dawarich.arnoutvw.nl,192.168.10.144
TIME_ZONE: Europe/London
APPLICATION_PROTOCOL: http
PROMETHEUS_EXPORTER_ENABLED: false
PROMETHEUS_EXPORTER_HOST: 0.0.0.0
PROMETHEUS_EXPORTER_PORT: 9394
SELF_HOSTED: "true"
STORE_GEODATA: "true"
PHOTON_API_HOST: 192.168.10.144:2322
PHOTON_API_USE_HTTPS: false
logging:
@@ -109,9 +96,8 @@ services:
deploy:
resources:
limits:
cpus: '0.50'
memory: '4G'
cpus: '0.50' # Limit CPU usage to 50% of one core
memory: '4G' # Limit memory usage to 4GB
dawarich_sidekiq:
image: freikin/dawarich:1.15.3
container_name: dawarich_sidekiq
@@ -119,13 +105,15 @@ services:
- dawarich_public:/var/app/public
- dawarich_watched:/var/app/tmp/imports/watched
- dawarich_storage:/var/app/storage
networks:
- dawarich
network_mode: bridge
links:
- dawarich_db
- dawarich_redis
stdin_open: true
tty: true
entrypoint: sidekiq-entrypoint.sh
command: [ 'sidekiq' ]
restart: unless-stopped
restart: always
environment:
RAILS_ENV: production
SECRET_KEY_BASE: 2f5e59518ddeaeb978c73bc265eea20a91d5fe203d2a45280bd8fbf62b447b57
@@ -134,9 +122,17 @@ services:
DATABASE_USERNAME: postgres
DATABASE_PASSWORD: password
DATABASE_NAME: dawarich_development
APPLICATION_HOSTS: localhost
BACKGROUND_PROCESSING_CONCURRENCY: 10
APPLICATION_PROTOCOL: http
PROMETHEUS_EXPORTER_ENABLED: false
PROMETHEUS_EXPORTER_HOST: dawarich_app
PROMETHEUS_EXPORTER_PORT: 9394
SELF_HOSTED: "true"
STORE_GEODATA: "true"
PHOTON_API_HOST: 192.168.10.144:2322
PHOTON_API_USE_HTTPS: false
logging:
driver: "json-file"
options:
@@ -164,4 +160,4 @@ volumes:
dawarich_shared:
dawarich_public:
dawarich_watched:
dawarich_storage:
dawarich_storage:
+4 -6
View File
@@ -517,8 +517,9 @@ services:
bookorbit:
image: ghcr.io/bookorbit/bookorbit:3.2.0
container_name: bookorbit-app
networks:
- bookorbit
network_mode: bridge
links:
- bookorbit-db
ports:
- "3099:3000"
environment:
@@ -616,8 +617,7 @@ services:
bookorbit-db:
image: pgvector/pgvector:pg18
container_name: bookorbit-db
networks:
- bookorbit
network_mode: bridge
environment:
TZ: Europe/Berlin
POSTGRES_USER: bookorbit
@@ -668,5 +668,3 @@ volumes:
28eea8bfffd285350962765a88ff04ea9d580fe872771d5c06fd62afb26f2ef2:
external: true
networks:
bookorbit:
+7 -7
View File
@@ -11,7 +11,7 @@ DB_DATA_LOCATION=/mnt/user/appdata/PostgreSQL_Immich
# To set a timezone, uncomment the next line and change Etc/UTC to a TZ identifier from this list: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List
TZ=Europe/Berlin
IMMICH_MACHINE_LEARNING_URL=http://immich-machine-learning:3003
IMMICH_MACHINE_LEARNING_URL=http://192.168.10.144:3003
# The Immich version to use. You can pin this to a specific version like "v2.1.0"
IMMICH_VERSION=v2
@@ -24,14 +24,14 @@ DB_PASSWORD=immich
###################################################################################
DB_USERNAME=immich
DB_DATABASE_NAME=immich
DB_HOSTNAME=immich_postgres
DB_HOST=immich_postgres
DB_PORT=5432
DB_HOSTNAME=192.168.10.144
DB_HOST=192.168.10.144
DB_PORT=5434
#redis
REDIS_PORT=6379
REDIS_PORT=6380
REDIS_PASSWORD=
REDIS_HOSTNAME=immich_redis
REDIS_HOSTNAME=192.168.10.144
#Machine learing
MACHINE_LEARNING_HOST=0.0.0.0
@@ -40,5 +40,5 @@ MACHINE_LEARNING_MAX_BATCH_SIZE__FACIAL_RECOGNITION=1
MACHINE_LEARNING_CACHE_FOLDER=/config/machine-learning/models
MACHINE_LEARNING_MAX_BATCH_SIZE__TEXT_RECOGNITION=3
IMMICH_URL = "http://immich-server:2283" # internal container route (own compose network)
IMMICH_URL = "http://192.168.10.144:8693"
EXTERNAL_IMMICH_URL = "https://photos.arnoutvw.nl" # External address of immich
+7 -29
View File
@@ -9,17 +9,11 @@
name: immich
networks:
immich:
services:
immich-server:
networks:
- immich
network_mode: bridge
labels:
- traefik.enable=true
- traefik.http.routers.immich.rule=Host(`photos.arnoutvw.nl`)
- traefik.http.services.immich.loadbalancer.server.port=2283
- pangolin.proxy-resources.immich.name=immich
- pangolin.proxy-resources.immich.full-domain=photos.arnoutvw.nl
- pangolin.proxy-resources.immich.protocol=http
@@ -69,18 +63,13 @@ services:
disable: false
immich-machine-learning:
networks:
- immich
network_mode: bridge
ports:
- '3003:3003'
container_name: immich_machine_learning
# For hardware acceleration, add one of -[armnn, cuda, rocm, openvino, rknn] to the image tag.
# Example tag: ${IMMICH_VERSION:-release}-cuda
image: ghcr.io/immich-app/immich-machine-learning:v3.2.4-openvino
labels:
- traefik.enable=true
- traefik.http.routers.immich_machine_learning.rule=Host(`immich_machine_learning.arnoutvw.nl`)
- traefik.http.services.immich_machine_learning.loadbalancer.server.port=3003
extends: # uncomment this section for hardware acceleration - see https://docs.immich.app/features/ml-hardware-acceleration
file: hwaccel.ml.yml
service: openvino # set to one of [armnn, cuda, rocm, openvino, openvino-wsl, rknn] for accelerated inference - use the `-wsl` version for WSL2 where applicable
@@ -96,8 +85,7 @@ services:
redis:
container_name: immich_redis
image: docker.io/valkey/valkey:9.1.2-alpine
networks:
- immich
network_mode: "bridge"
ports:
- '6380:6379'
healthcheck:
@@ -107,8 +95,7 @@ services:
database:
container_name: immich_postgres
image: ghcr.io/immich-app/postgres:16-vectorchord0.4.2-pgvectors0.3.0
networks:
- immich
network_mode: "bridge"
ports:
- '5434:5432'
labels:
@@ -138,9 +125,6 @@ services:
- "EXPORTER_LOG_LEVEL=INFO"
image: "friendlyfriend/prometheus-immich-exporter:1.2.4-dev"
labels:
traefik.enable: "true"
traefik.http.routers.prometheus-immich-exporter.rule: Host(`prometheus-immich-exporter.arnoutvw.nl`)
traefik.http.services.prometheus-immich-exporter.loadbalancer.server.port: "8000"
net.unraid.docker.icon: "https://github.com/friendlyFriend4000/prometheus-immich-exporter/blob/master/unraid/immich-logo.png?raw=true"
net.unraid.docker.managed: "dockerman"
net.unraid.docker.webui: "http://[IP]:[PORT:8000]"
@@ -150,12 +134,9 @@ services:
power-tools:
container_name: immich_power_tools
image: ghcr.io/varun-raj/immich-power-tools:0.19.1
networks:
- immich
network_mode: bridge
labels:
- traefik.enable=true
- traefik.http.routers.immich-powertools.rule=Host(`immich-power-tools.arnoutvw.nl`)
- traefik.http.services.immich-powertools.loadbalancer.server.port=3000
ports:
- "8029:3000"
env_file:
@@ -163,17 +144,14 @@ services:
immich-proxy:
container_name: immich_proxy
image: ghcr.io/arnoutvw/yaiiu/immich-proxy:sha-8a197d0
networks:
- immich
network_mode: bridge
ports:
- "8694:8080"
environment:
- IMMICH_SERVER_URL=http://immich-server:2283
- IMMICH_SERVER_URL=http://192.168.10.144:8693
- IMMICH_API_KEY=8FeEvF5Fdybpp9GM15x29VgchYtKqqgAgozX9Z5TbW4
labels:
- traefik.enable=true
- traefik.http.routers.immich-proxy.rule=Host(`immich-proxy.arnoutvw.nl`)
- traefik.http.services.immich-proxy.loadbalancer.server.port=8080
- pangolin.proxy-resources.immich-proxy.name=immich-proxy
- pangolin.proxy-resources.immich-proxy.full-domain=immich-proxy.arnoutvw.nl
- pangolin.proxy-resources.immich-proxy.protocol=http
+3 -2
View File
@@ -13,8 +13,9 @@ services:
container_name: komodo-periphery
restart: unless-stopped
init: true
networks:
- komodo-internal
network_mode: bridge
ports:
- "8120:8120"
logging:
driver: local
env_file: ../komodo/.env
+5 -9
View File
@@ -10,17 +10,13 @@
# labels. .env lives next to this file (env_file for core).
name: komodo
networks:
komodo-internal:
services:
mongo:
image: mongo:9.0
container_name: komodo-mongo
command: --quiet --wiredTigerCacheSizeGB 0.25
restart: unless-stopped
networks:
- komodo-internal
network_mode: bridge
logging:
driver: ${COMPOSE_LOGGING_DRIVER:-local}
volumes:
@@ -37,8 +33,9 @@ services:
container_name: komodo-core
restart: unless-stopped
init: true
networks:
- komodo-internal
network_mode: bridge
links:
- mongo
depends_on:
- mongo
logging:
@@ -77,8 +74,7 @@ services:
image: ghcr.io/myrikld/komodo-mcp:latest
container_name: komodo-mcp
init: true
networks:
- komodo-internal
network_mode: bridge
ports:
- "8333:8000"
environment:
+11 -12
View File
@@ -1,14 +1,9 @@
networks:
postiz-network:
external: false
services:
postiz:
image: ghcr.io/gitroomhq/postiz-app:v2.25.0
container_name: postiz
restart: always
networks:
- postiz-network
network_mode: bridge
environment:
# === Required Settings
MAIN_URL: "https://postiz.arnoutvw.nl"
@@ -122,11 +117,13 @@ services:
ports:
- "5000:5000"
labels:
- "traefik.enable=true"
- "traefik.http.routers.postiz.rule=Host(`postiz.arnoutvw.nl`)" # Replace with your domain
- "traefik.http.services.postiz.loadbalancer.server.port=5000" # Internal port for postiz
- "traefik.http.routers.postiz.entrypoints=https" # Postiz requires HTTPS
- "traefik.http.routers.postiz.tls=true"
links:
- postiz-postgres
- postiz-redis
depends_on:
postiz-postgres:
condition: service_healthy
@@ -137,8 +134,7 @@ services:
image: postgres:17-alpine
container_name: postiz-postgres
restart: always
networks:
- postiz-network
network_mode: bridge
environment:
POSTGRES_PASSWORD: postiz-password
POSTGRES_USER: postiz-user
@@ -154,8 +150,7 @@ services:
image: redis:7.4
container_name: postiz-redis
restart: always
networks:
- postiz-network
network_mode: bridge
healthcheck:
test: redis-cli ping
interval: 10s
@@ -175,4 +170,8 @@ volumes:
external: false
postiz-uploads:
external: false
external: false
networks:
postiz-network:
external: false
+10 -10
View File
@@ -1,13 +1,11 @@
networks:
teslamate:
services:
teslamate:
container_name: "teslamate"
image: teslamate/teslamate:4.3.0
restart: always
networks:
- teslamate
network_mode: "bridge"
links:
- postgresql17
environment:
- "DATABASE_USER=teslamate"
- "DATABASE_NAME=teslamate"
@@ -37,8 +35,7 @@ services:
container_name: "postgresql17"
image: postgres:17-alpine3.22
restart: always
networks:
- teslamate
network_mode: "bridge"
environment:
- "HOST_CONTAINERNAME=postgresql17"
- "POSTGRES_USER=postgres"
@@ -51,8 +48,9 @@ services:
container_name: "teslamate-grafana"
image: teslamate/grafana:4.3.0
restart: always
networks:
- teslamate
network_mode: "bridge"
links:
- postgresql17
environment:
- "GF_AUTH_GENERIC_OAUTH_SCOPES=openid profile email"
- "GF_AUTH_GENERIC_OAUTH_TOKEN_URL=https://pass.arnoutvw.nl/api/oidc/token"
@@ -124,7 +122,9 @@ services:
restart: "always"
teslamateapi:
container_name: "teslamateapi"
networks:
network_mode: "bridge"
links:
- postgresql17
- teslamate
image: tobiasehlert/teslamateapi:1.25.0
restart: always