refactor(networks): private compose networks instead of shared bridge
traefik-network-connector attaches traefik to container networks labelled traefik.enable=true, so stacks no longer need the default bridge: - changedetection: app+sockpuppetbrowser on changedetection network, links out - postiz: postiz-network, legacy links out - teslamate: teslamate network, DB via service DNS (postgresql17), 5432 hostport dropped, teslamateapi -> teslamate:4000 internal - download: bookorbit+bookorbit-db on bookorbit network (5435 hostport dropped) - immich: immich network in .env host IP refs -> service/container DNS All published host ports kept unless removed above; pangolin target hostnames still point at 192.168.10.144 host ports.
This commit is contained in:
1 parent
9ab0357f16
commit
5e7ab46f71
6 files changed
+82
-48
No files matched your search
@@ -1,13 +1,15 @@
|
||||
networks:
|
||||
changedetection:
|
||||
|
||||
services:
|
||||
changedetection:
|
||||
image: ghcr.io/dgtlmoon/changedetection.io:0.60.8
|
||||
container_name: changedetection
|
||||
hostname: changedetection
|
||||
network_mode: "bridge"
|
||||
networks:
|
||||
- changedetection
|
||||
depends_on:
|
||||
- browser-sockpuppet-chrome
|
||||
links:
|
||||
- browser-sockpuppet-chrome
|
||||
volumes:
|
||||
- changedetection-data:/datastore
|
||||
# Configurable proxy list support, see https://github.com/dgtlmoon/changedetection.io/wiki/Proxy-configuration#proxy-list-support
|
||||
@@ -93,8 +95,9 @@ services:
|
||||
- "5353:5000"
|
||||
restart: unless-stopped
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.http.routers.changedetection.rule=Host(`changedetection.arnoutvw.nl`)
|
||||
- traefik.docker.network=changedetection_default
|
||||
- traefik.http.services.changedetection.loadbalancer.server.port=5000
|
||||
|
||||
# Used for fetching pages via WebDriver+Chrome where you need Javascript support.
|
||||
# Now working on arm64 (needs testing on rPi - tested on Oracle ARM instance)
|
||||
@@ -112,7 +115,8 @@ services:
|
||||
browser-sockpuppet-chrome:
|
||||
hostname: browser-sockpuppet-chrome
|
||||
image: dgtlmoon/sockpuppetbrowser@sha256:1d8f72d2ce2085faed4232e5ae1e65c02efe5b831a18e127829b267c260b4fb2
|
||||
network_mode: bridge
|
||||
networks:
|
||||
- changedetection
|
||||
cap_add:
|
||||
- SYS_ADMIN
|
||||
# SYS_ADMIN might be too much, but it can be needed on your platform https://github.com/puppeteer/puppeteer/blob/main/docs/troubleshooting.md#running-puppeteer-on-gitlabci
|
||||
|
||||
+12
-7
@@ -499,7 +499,8 @@ services:
|
||||
bookorbit:
|
||||
image: ghcr.io/bookorbit/bookorbit:3.2.0
|
||||
container_name: bookorbit-app
|
||||
network_mode: bridge
|
||||
networks:
|
||||
- bookorbit
|
||||
ports:
|
||||
- "3099:3000"
|
||||
environment:
|
||||
@@ -509,8 +510,8 @@ services:
|
||||
PUID: 99
|
||||
PGID: 100
|
||||
APP_URL: https://bookorbit.arnoutvw.nl
|
||||
POSTGRES_HOST: 192.168.10.144
|
||||
POSTGRES_PORT: 5435
|
||||
POSTGRES_HOST: bookorbit-db
|
||||
POSTGRES_PORT: 5432
|
||||
POSTGRES_USER: bookorbit
|
||||
POSTGRES_PASSWORD: ${BOOKORBIT_DB_PASSWORD}
|
||||
POSTGRES_DB: bookorbit
|
||||
@@ -539,7 +540,9 @@ services:
|
||||
stop_grace_period: 30s
|
||||
restart: unless-stopped
|
||||
labels:
|
||||
traefik.http.routers.bookorbit.rule: "Host(`bookorbit.arnoutvw.nl`)"
|
||||
- traefik.enable=true
|
||||
- traefik.http.routers.bookorbit.rule=Host(`bookorbit.arnoutvw.nl`)
|
||||
- traefik.http.services.bookorbit.loadbalancer.server.port=3000
|
||||
|
||||
shelfarr:
|
||||
container_name: shelfarr
|
||||
@@ -595,9 +598,8 @@ services:
|
||||
bookorbit-db:
|
||||
image: pgvector/pgvector:pg18
|
||||
container_name: bookorbit-db
|
||||
network_mode: bridge
|
||||
ports:
|
||||
- "5435:5432"
|
||||
networks:
|
||||
- bookorbit
|
||||
environment:
|
||||
TZ: Europe/Berlin
|
||||
POSTGRES_USER: bookorbit
|
||||
@@ -644,3 +646,6 @@ services:
|
||||
volumes:
|
||||
28eea8bfffd285350962765a88ff04ea9d580fe872771d5c06fd62afb26f2ef2:
|
||||
external: true
|
||||
|
||||
networks:
|
||||
bookorbit:
|
||||
+7
-7
@@ -11,7 +11,7 @@ DB_DATA_LOCATION=/mnt/user/appdata/PostgreSQL_Immich
|
||||
# To set a timezone, uncomment the next line and change Etc/UTC to a TZ identifier from this list: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List
|
||||
TZ=Europe/Berlin
|
||||
|
||||
IMMICH_MACHINE_LEARNING_URL=http://192.168.10.144:3003
|
||||
IMMICH_MACHINE_LEARNING_URL=http://immich-machine-learning:3003
|
||||
|
||||
# The Immich version to use. You can pin this to a specific version like "v2.1.0"
|
||||
IMMICH_VERSION=v2
|
||||
@@ -24,14 +24,14 @@ DB_PASSWORD=immich
|
||||
###################################################################################
|
||||
DB_USERNAME=immich
|
||||
DB_DATABASE_NAME=immich
|
||||
DB_HOSTNAME=192.168.10.144
|
||||
DB_HOST=192.168.10.144
|
||||
DB_PORT=5434
|
||||
DB_HOSTNAME=immich_postgres
|
||||
DB_HOST=immich_postgres
|
||||
DB_PORT=5432
|
||||
|
||||
#redis
|
||||
REDIS_PORT=6380
|
||||
REDIS_PORT=6379
|
||||
REDIS_PASSWORD=
|
||||
REDIS_HOSTNAME=192.168.10.144
|
||||
REDIS_HOSTNAME=immich_redis
|
||||
|
||||
#Machine learing
|
||||
MACHINE_LEARNING_HOST=0.0.0.0
|
||||
@@ -40,5 +40,5 @@ MACHINE_LEARNING_MAX_BATCH_SIZE__FACIAL_RECOGNITION=1
|
||||
MACHINE_LEARNING_CACHE_FOLDER=/config/machine-learning/models
|
||||
MACHINE_LEARNING_MAX_BATCH_SIZE__TEXT_RECOGNITION=3
|
||||
|
||||
IMMICH_URL = "http://192.168.10.144:8693" # Your immich instace ip address and port
|
||||
IMMICH_URL = "http://immich-server:2283" # internal container route (own compose network)
|
||||
EXTERNAL_IMMICH_URL = "https://photos.arnoutvw.nl" # External address of immich
|
||||
+22
-7
@@ -9,11 +9,17 @@
|
||||
|
||||
name: immich
|
||||
|
||||
networks:
|
||||
immich:
|
||||
|
||||
services:
|
||||
immich-server:
|
||||
network_mode: bridge
|
||||
networks:
|
||||
- immich
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.http.routers.immich.rule=Host(`photos.arnoutvw.nl`)
|
||||
- traefik.http.services.immich.loadbalancer.server.port=2283
|
||||
- pangolin.proxy-resources.immich.name=immich
|
||||
- pangolin.proxy-resources.immich.full-domain=photos.arnoutvw.nl
|
||||
- pangolin.proxy-resources.immich.protocol=http
|
||||
@@ -63,7 +69,8 @@ services:
|
||||
disable: false
|
||||
|
||||
immich-machine-learning:
|
||||
network_mode: bridge
|
||||
networks:
|
||||
- immich
|
||||
ports:
|
||||
- '3003:3003'
|
||||
container_name: immich_machine_learning
|
||||
@@ -85,7 +92,8 @@ services:
|
||||
redis:
|
||||
container_name: immich_redis
|
||||
image: docker.io/valkey/valkey:9.1.2-alpine
|
||||
network_mode: "bridge"
|
||||
networks:
|
||||
- immich
|
||||
ports:
|
||||
- '6380:6379'
|
||||
healthcheck:
|
||||
@@ -95,7 +103,8 @@ services:
|
||||
database:
|
||||
container_name: immich_postgres
|
||||
image: ghcr.io/immich-app/postgres:16-vectorchord0.4.2-pgvectors0.3.0
|
||||
network_mode: "bridge"
|
||||
networks:
|
||||
- immich
|
||||
ports:
|
||||
- '5434:5432'
|
||||
labels:
|
||||
@@ -134,9 +143,12 @@ services:
|
||||
power-tools:
|
||||
container_name: immich_power_tools
|
||||
image: ghcr.io/varun-raj/immich-power-tools:0.19.1
|
||||
network_mode: bridge
|
||||
networks:
|
||||
- immich
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.http.routers.immich-powertools.rule=Host(`immich-power-tools.arnoutvw.nl`)
|
||||
- traefik.http.services.immich-powertools.loadbalancer.server.port=3000
|
||||
ports:
|
||||
- "8029:3000"
|
||||
env_file:
|
||||
@@ -144,14 +156,17 @@ services:
|
||||
immich-proxy:
|
||||
container_name: immich_proxy
|
||||
image: ghcr.io/arnoutvw/yaiiu/immich-proxy:sha-8a197d0
|
||||
network_mode: bridge
|
||||
networks:
|
||||
- immich
|
||||
ports:
|
||||
- "8694:8080"
|
||||
environment:
|
||||
- IMMICH_SERVER_URL=http://192.168.10.144:8693
|
||||
- IMMICH_SERVER_URL=http://immich-server:2283
|
||||
- IMMICH_API_KEY=8FeEvF5Fdybpp9GM15x29VgchYtKqqgAgozX9Z5TbW4
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.http.routers.immich-proxy.rule=Host(`immich-proxy.arnoutvw.nl`)
|
||||
- traefik.http.services.immich-proxy.loadbalancer.server.port=8080
|
||||
- pangolin.proxy-resources.immich-proxy.name=immich-proxy
|
||||
- pangolin.proxy-resources.immich-proxy.full-domain=immich-proxy.arnoutvw.nl
|
||||
- pangolin.proxy-resources.immich-proxy.protocol=http
|
||||
|
||||
+11
-10
@@ -1,9 +1,14 @@
|
||||
networks:
|
||||
postiz-network:
|
||||
external: false
|
||||
|
||||
services:
|
||||
postiz:
|
||||
image: ghcr.io/gitroomhq/postiz-app:v2.25.0
|
||||
container_name: postiz
|
||||
restart: always
|
||||
network_mode: bridge
|
||||
networks:
|
||||
- postiz-network
|
||||
environment:
|
||||
# === Required Settings
|
||||
MAIN_URL: "https://postiz.arnoutvw.nl"
|
||||
@@ -117,13 +122,11 @@ services:
|
||||
ports:
|
||||
- "5000:5000"
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.routers.postiz.rule=Host(`postiz.arnoutvw.nl`)" # Replace with your domain
|
||||
- "traefik.http.services.postiz.loadbalancer.server.port=5000" # Internal port for postiz
|
||||
- "traefik.http.routers.postiz.entrypoints=https" # Postiz requires HTTPS
|
||||
- "traefik.http.routers.postiz.tls=true"
|
||||
links:
|
||||
- postiz-postgres
|
||||
- postiz-redis
|
||||
depends_on:
|
||||
postiz-postgres:
|
||||
condition: service_healthy
|
||||
@@ -134,7 +137,8 @@ services:
|
||||
image: postgres:17-alpine
|
||||
container_name: postiz-postgres
|
||||
restart: always
|
||||
network_mode: bridge
|
||||
networks:
|
||||
- postiz-network
|
||||
environment:
|
||||
POSTGRES_PASSWORD: postiz-password
|
||||
POSTGRES_USER: postiz-user
|
||||
@@ -150,7 +154,8 @@ services:
|
||||
image: redis:7.4
|
||||
container_name: postiz-redis
|
||||
restart: always
|
||||
network_mode: bridge
|
||||
networks:
|
||||
- postiz-network
|
||||
healthcheck:
|
||||
test: redis-cli ping
|
||||
interval: 10s
|
||||
@@ -170,8 +175,4 @@ volumes:
|
||||
external: false
|
||||
|
||||
postiz-uploads:
|
||||
external: false
|
||||
|
||||
networks:
|
||||
postiz-network:
|
||||
external: false
|
||||
+21
-12
@@ -1,13 +1,17 @@
|
||||
networks:
|
||||
teslamate:
|
||||
|
||||
services:
|
||||
teslamate:
|
||||
container_name: "teslamate"
|
||||
image: teslamate/teslamate:4.3.0
|
||||
restart: always
|
||||
network_mode: "bridge"
|
||||
networks:
|
||||
- teslamate
|
||||
environment:
|
||||
- "DATABASE_USER=teslamate"
|
||||
- "DATABASE_NAME=teslamate"
|
||||
- "DATABASE_HOST=192.168.10.144"
|
||||
- "DATABASE_HOST=postgresql17"
|
||||
- "DATABASE_PASS=${DATABASE_PASS}"
|
||||
- "DATABASE_PORT=5432"
|
||||
- "MQTT_HOST=192.168.10.54"
|
||||
@@ -25,15 +29,16 @@ services:
|
||||
cap_drop:
|
||||
- ALL
|
||||
labels:
|
||||
traefik.http.routers.teslamate.rule: "Host(`teslamate.arnoutvw.nl`)"
|
||||
- traefik.enable=true
|
||||
- traefik.http.routers.teslamate.rule=Host(`teslamate.arnoutvw.nl`)
|
||||
- traefik.http.services.teslamate.loadbalancer.server.port=4000
|
||||
|
||||
postgresql17:
|
||||
container_name: "postgresql17"
|
||||
image: postgres:17-alpine3.22
|
||||
restart: always
|
||||
network_mode: "bridge"
|
||||
ports:
|
||||
- "5432:5432"
|
||||
networks:
|
||||
- teslamate
|
||||
environment:
|
||||
- "HOST_CONTAINERNAME=postgresql17"
|
||||
- "POSTGRES_USER=postgres"
|
||||
@@ -46,13 +51,14 @@ services:
|
||||
container_name: "teslamate-grafana"
|
||||
image: teslamate/grafana:4.3.0
|
||||
restart: always
|
||||
network_mode: "bridge"
|
||||
networks:
|
||||
- teslamate
|
||||
environment:
|
||||
- "GF_AUTH_GENERIC_OAUTH_SCOPES=openid profile email"
|
||||
- "GF_AUTH_GENERIC_OAUTH_TOKEN_URL=https://pass.arnoutvw.nl/api/oidc/token"
|
||||
- "HOST_OS=Unraid"
|
||||
- "DATABASE_USER=teslamate"
|
||||
- "DATABASE_HOST=192.168.10.144"
|
||||
- "DATABASE_HOST=postgresql17"
|
||||
- "GF_AUTH_GENERIC_OAUTH_NAME=PocketID"
|
||||
- "GF_AUTH_GENERIC_OAUTH_ALLOW_SIGN_UP=true"
|
||||
- "GF_AUTH_DISABLE_LOGIN_FORM=false"
|
||||
@@ -83,7 +89,9 @@ services:
|
||||
- "/mnt/cache/appdata/teslamate-customdashboard/Teslamate-CustomGrafanaDashboards/dashboards:/TeslamateCustomDashboards"
|
||||
- "/mnt/user/appdata/telsamate-grafana:/var/lib/grafana"
|
||||
labels:
|
||||
traefik.http.routers.tesla.rule: "Host(`tesla.arnoutvw.nl`)"
|
||||
- traefik.enable=true
|
||||
- traefik.http.routers.tesla.rule=Host(`tesla.arnoutvw.nl`)
|
||||
- traefik.http.services.tesla.loadbalancer.server.port=3000
|
||||
|
||||
TeslaMate-ABRP:
|
||||
container_name: "TeslaMate-ABRP"
|
||||
@@ -116,7 +124,8 @@ services:
|
||||
restart: "always"
|
||||
teslamateapi:
|
||||
container_name: "teslamateapi"
|
||||
network_mode: "bridge"
|
||||
networks:
|
||||
- teslamate
|
||||
image: tobiasehlert/teslamateapi:1.25.0
|
||||
restart: always
|
||||
environment:
|
||||
@@ -124,7 +133,7 @@ services:
|
||||
- DATABASE_USER=teslamate
|
||||
- "DATABASE_PASS=${DATABASE_PASS}"
|
||||
- DATABASE_NAME=teslamate
|
||||
- DATABASE_HOST=192.168.10.144
|
||||
- DATABASE_HOST=postgresql17
|
||||
- "MQTT_HOST=192.168.10.54"
|
||||
- "MQTT_PASSWORD=${MQTT_PASSWORD}"
|
||||
- "MQTT_TLS_ACCEPT_INVALID_CERTS=true"
|
||||
@@ -133,7 +142,7 @@ services:
|
||||
- "MQTT_TLS=false"
|
||||
- "MQTT_PORT=1883"
|
||||
- TZ=Europe/Berlin
|
||||
- TESLAMATE_HOST=192.168.10.144
|
||||
- TESLAMATE_HOST=teslamate
|
||||
- TESLAMATE_PORT=4000
|
||||
- API_TOKEN=826d3b8b-daad-48c7-ad3b-8bdaade8c706
|
||||
ports:
|
||||
|
||||
Reference in new issue
Block a user