feat(pangolin): move ionos primary compose from files_on_host into repo
Same stack (pangolin ee-1.23.0, gerbil 1.5.1, traefik v3.7, crowdsec, grafana, prometheus, dashboards, project pangolin); mounts absolute to /root on the VPS; crowdsec-manager now mounted on the repo-managed compose file so it edits the git-tracked source. Enables Renovate version bumps.
This commit is contained in:
1 parent
f2d14badb4
commit
4eb5d0914f
1 file changed
+241
@@ -0,0 +1,241 @@
|
||||
# pangolin primary VPS (ionos) — pangolin edge stack.
|
||||
# Moved off files_on_host /root/docker-compose.yml into the repo, so Renovate
|
||||
# can handle updates (config lives on the host at /root/config + /root/backups
|
||||
# etc.; mounts are absolute paths for that reason — systemd periphery has
|
||||
# direct host access). crowdsec-manager is pointed at the repo-managed
|
||||
# compose file. Original: /root/docker-compose.yml (left in place as backup).
|
||||
name: pangolin
|
||||
networks:
|
||||
default:
|
||||
driver: bridge
|
||||
enable_ipv6: true
|
||||
name: pangolin
|
||||
|
||||
services:
|
||||
crowdsec:
|
||||
container_name: crowdsec
|
||||
environment:
|
||||
COLLECTIONS: crowdsecurity/traefik crowdsecurity/appsec-virtual-patching crowdsecurity/appsec-generic-rules crowdsecurity/linux crowdsecurity/iptables
|
||||
ENROLL_INSTANCE_NAME: pangolin-crowdsec
|
||||
ENROLL_TAGS: docker
|
||||
GID: "1000"
|
||||
PARSERS: crowdsecurity/whitelists
|
||||
healthcheck:
|
||||
interval: 60s
|
||||
retries: 15
|
||||
test:
|
||||
- CMD
|
||||
- cscli
|
||||
- lapi
|
||||
- status
|
||||
timeout: 30s
|
||||
image: docker.io/crowdsecurity/crowdsec:v1.8.1
|
||||
labels:
|
||||
- traefik.enable=false
|
||||
ports:
|
||||
- 127.0.0.1:6060:6060
|
||||
- 127.0.0.1:8080:8080
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- /root/config/crowdsec:/etc/crowdsec
|
||||
- /root/config/crowdsec/db:/var/lib/crowdsec/data
|
||||
- /root/config/traefik/logs:/var/log/traefik
|
||||
- /var/log/auth.log:/var/log/auth.log:ro
|
||||
- /var/log/syslog:/var/log/syslog:ro
|
||||
gerbil:
|
||||
cap_add:
|
||||
- NET_ADMIN
|
||||
- SYS_MODULE
|
||||
command:
|
||||
- --reachableAt=http://gerbil:3004
|
||||
- --generateAndSaveKeyTo=/var/config/key
|
||||
- --remoteConfig=http://pangolin:3001/api/v1/
|
||||
container_name: gerbil
|
||||
depends_on:
|
||||
pangolin:
|
||||
condition: service_healthy
|
||||
image: docker.io/fosrl/gerbil:1.5.1
|
||||
ports:
|
||||
- 51820:51820/udp
|
||||
- 21820:21820/udp
|
||||
- 443:443
|
||||
- 80:80
|
||||
- 32400:32400
|
||||
- 8082:8082
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- /root/config/:/var/config
|
||||
pangolin:
|
||||
container_name: pangolin
|
||||
hostname: pangolin
|
||||
healthcheck:
|
||||
interval: 10s
|
||||
retries: 15
|
||||
test:
|
||||
- CMD
|
||||
- curl
|
||||
- -f
|
||||
- http://localhost:3001/api/v1/
|
||||
timeout: 10s
|
||||
image: docker.io/fosrl/pangolin:ee-1.23.0
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- /root/config:/app/config
|
||||
traefik:
|
||||
command:
|
||||
- --configFile=/etc/traefik/traefik_config.yml
|
||||
container_name: traefik
|
||||
depends_on:
|
||||
crowdsec:
|
||||
condition: service_healthy
|
||||
pangolin:
|
||||
condition: service_healthy
|
||||
image: docker.io/traefik:v3.7
|
||||
network_mode: service:gerbil
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- CF_API_EMAILL=4v792wk2b2@privaterelay.appleid.com
|
||||
- CF_DNS_API_TOKEN=yt9Q41S9jg92mxpZaWyd6MyOP6Y7OeC5GdUl1tRD
|
||||
volumes:
|
||||
- /root/config/traefik:/etc/traefik:ro
|
||||
- /root/config/letsencrypt:/letsencrypt
|
||||
- /root/config/traefik/logs:/var/log/traefik
|
||||
# Traefik Log Dashboard Agent
|
||||
traefik-agent:
|
||||
image: hhftechnology/traefik-log-dashboard-agent:latest
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "5000:5000"
|
||||
volumes:
|
||||
- /root/data/positions:/data
|
||||
- /root/config/traefik/logs:/logs:ro
|
||||
- /root/config/maxmind:/geoip:ro
|
||||
environment:
|
||||
# Log Paths
|
||||
- TRAEFIK_LOG_DASHBOARD_ACCESS_PATH=/logs/access.log
|
||||
- TRAEFIK_LOG_DASHBOARD_ERROR_PATH=/logs/traefik.log
|
||||
# Authentication
|
||||
- TRAEFIK_LOG_DASHBOARD_AUTH_TOKEN=VZwCZobpojOAMxJ4X5UGFLebe7WHXiuqCsSE9ahWXzoICTQBVPvXcOP6qVgxczfw
|
||||
# System Monitoring
|
||||
- TRAEFIK_LOG_DASHBOARD_SYSTEM_MONITORING=true
|
||||
# GeoIP Configuration
|
||||
- TRAEFIK_LOG_DASHBOARD_GEOIP_ENABLED=true
|
||||
- TRAEFIK_LOG_DASHBOARD_GEOIP_CITY_DB=/geoip/GeoLite2-City.mmdb
|
||||
- TRAEFIK_LOG_DASHBOARD_GEOIP_COUNTRY_DB=/geoip/GeoLite2-Country.mmdb
|
||||
# Log Format
|
||||
- TRAEFIK_LOG_DASHBOARD_LOG_FORMAT=json
|
||||
# Server Port
|
||||
- PORT=5000
|
||||
healthcheck:
|
||||
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:5000/api/logs/status"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
start_period: 10s
|
||||
# Traefik Log Dashboard - Web UI
|
||||
traefik-dashboard:
|
||||
image: hhftechnology/traefik-log-dashboard:latest
|
||||
container_name: traefik-log-dashboard
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "3000:3000"
|
||||
environment:
|
||||
# Agent Configuration
|
||||
- AGENT_API_URL=http://traefik-agent:5000
|
||||
- AGENT_API_TOKEN=VZwCZobpojOAMxJ4X5UGFLebe7WHXiuqCsSE9ahWXzoICTQBVPvXcOP6qVgxczfw
|
||||
- NODE_ENV=production
|
||||
- PORT=3000
|
||||
depends_on:
|
||||
traefik-agent:
|
||||
condition: service_healthy
|
||||
healthcheck:
|
||||
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://127.0.0.1:3000"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
start_period: 30s
|
||||
# Optional: MaxMind GeoIP Database Updater
|
||||
# maxmind-updater:
|
||||
# image: alpine:latest
|
||||
# restart: "no"
|
||||
# volumes:
|
||||
# - /root/config/maxmind:/data
|
||||
# environment:
|
||||
# - MAXMIND_LICENSE_KEY=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
|
||||
# command: >
|
||||
# sh -c "
|
||||
# apk add --no-cache wget tar &&
|
||||
# cd /data &&
|
||||
# if [ ! -f GeoLite2-City.mmdb ] || [ \"$(find . -name 'GeoLite2-City.mmdb' -mtime +7)\" ]; then
|
||||
# echo 'Updating GeoLite2-City database...'
|
||||
# wget -O GeoLite2-City.tar.gz 'https://download.maxmind.com/app/geoip_download?edition_id=GeoLite2-City&lic...'
|
||||
# tar --wildcards -xzf GeoLite2-City.tar.gz --strip-components=1 '*/GeoLite2-City.mmdb' &&
|
||||
# rm -f GeoLite2-City.tar.gz
|
||||
# fi &&
|
||||
# if [ ! -f GeoLite2-Country.mmdb ] || [ \"$(find . -name 'GeoLite2-Country.mmdb' -mtime +7)\" ]; then
|
||||
# echo 'Updating GeoLite2-Country database...'
|
||||
# wget -O GeoLite2-Country.tar.gz 'https://download.maxmind.com/app/geoip_download?edition_id=GeoLite2-Country&lic...'
|
||||
# tar --wildcards -xzf GeoLite2-Country.tar.gz --strip-components=1 '*/GeoLite2-Country.mmdb' &&
|
||||
# rm -f GeoLite2-Country.tar.gz
|
||||
# fi &&
|
||||
# echo 'GeoIP databases updated successfully.'
|
||||
# "
|
||||
prometheus:
|
||||
container_name: prometheus
|
||||
image: prom/prometheus:latest
|
||||
restart: unless-stopped
|
||||
command:
|
||||
- "--config.file=/etc/prometheus/prometheus.yml"
|
||||
- "--web.route-prefix=/prometheus"
|
||||
- "--web.external-url=https://powersync.arnoutvw.nl/prometheus"
|
||||
ports:
|
||||
- 9090:9090
|
||||
volumes:
|
||||
# - /etc/timezone:/etc/timezone:ro
|
||||
# - /etc/localtime:/etc/localtime:ro
|
||||
- /root/config/prometheus/prometheus.yml:/etc/prometheus/prometheus.yml
|
||||
- /root/config/prometheus/data:/prometheus
|
||||
grafana:
|
||||
image: grafana/grafana:latest
|
||||
container_name: grafana
|
||||
restart: unless-stopped
|
||||
# dns: ['127.0.0.53', '8.8.8.8']
|
||||
ports:
|
||||
- 3003:3000
|
||||
environment:
|
||||
GF_SERVER_ROOT_URL: "https://powersync.arnoutvw.nl/grafana"
|
||||
GF_SERVER_SERVE_FROM_SUBPATH: grafana
|
||||
volumes:
|
||||
# - /etc/timezone:/etc/timezone:ro
|
||||
# - /etc/localtime:/etc/localtime:ro
|
||||
- /root/config/grafana/data:/var/lib/grafana
|
||||
crowdsec-manager:
|
||||
image: hhftechnology/crowdsec-manager:latest
|
||||
container_name: crowdsec-manager
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- 8384:8080
|
||||
environment:
|
||||
- PORT=8080
|
||||
- ENVIRONMENT=production
|
||||
- DOCKER_HOST=unix:///var/run/docker.sock
|
||||
- COMPOSE_FILE=/app/docker-compose.yml
|
||||
- PANGOLIN_DIR=/app
|
||||
- CONFIG_DIR=/app/config
|
||||
- DATABASE_PATH=/app/data/settings.db
|
||||
- TRAEFIK_DYNAMIC_CONFIG=/dynamic_config.yml
|
||||
- TRAEFIK_STATIC_CONFIG=/etc/traefik/traefik_config.yml
|
||||
- TRAEFIK_ACCESS_LOG=/var/log/traefik/access.log
|
||||
- TRAEFIK_ERROR_LOG=/var/log/traefik/traefik.log
|
||||
- CROWDSEC_ACQUIS_FILE=/etc/crowdsec/acquis.yaml
|
||||
- BACKUP_DIR=/app/backups
|
||||
- RETENTION_DAYS=60
|
||||
- INCLUDE_CROWDSEC=false
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- /root/config:/app/config
|
||||
- /etc/komodo/repos/compose-files/pangolin/docker-compose.yml:/app/docker-compose.yml
|
||||
- /root/backups:/app/backups
|
||||
- /root/config/traefik/logs:/app/logs
|
||||
- /root/data:/app/data
|
||||
- /root/config/traefik/logs:/var/log/traefik
|
||||
Reference in new issue
Block a user