refactor(networks): private compose networks instead of shared bridge

traefik-network-connector attaches traefik to container networks labelled
traefik.enable=true, so stacks no longer need the default bridge:
- changedetection: app+sockpuppetbrowser on changedetection network, links out
- postiz: postiz-network, legacy links out
- teslamate: teslamate network, DB via service DNS (postgresql17), 5432
  hostport dropped, teslamateapi -> teslamate:4000 internal
- download: bookorbit+bookorbit-db on bookorbit network (5435 hostport dropped)
- immich: immich network in .env host IP refs -> service/container DNS
All published host ports kept unless removed above; pangolin target
hostnames still point at 192.168.10.144 host ports.
This commit is contained in:
Arnout van Westen committed 2026-10-03 21:53:13 +02:00
1 parent 9ab0357f16
commit 5e7ab46f71
6 files changed
+82 -48

No files matched your search

+9 -5
View File
@@ -1,13 +1,15 @@
networks:
changedetection:
services:
changedetection:
image: ghcr.io/dgtlmoon/changedetection.io:0.60.8
container_name: changedetection
hostname: changedetection
network_mode: "bridge"
networks:
- changedetection
depends_on:
- browser-sockpuppet-chrome
links:
- browser-sockpuppet-chrome
volumes:
- changedetection-data:/datastore
# Configurable proxy list support, see https://github.com/dgtlmoon/changedetection.io/wiki/Proxy-configuration#proxy-list-support
@@ -93,8 +95,9 @@ services:
- "5353:5000"
restart: unless-stopped
labels:
- traefik.enable=true
- traefik.http.routers.changedetection.rule=Host(`changedetection.arnoutvw.nl`)
- traefik.docker.network=changedetection_default
- traefik.http.services.changedetection.loadbalancer.server.port=5000
# Used for fetching pages via WebDriver+Chrome where you need Javascript support.
# Now working on arm64 (needs testing on rPi - tested on Oracle ARM instance)
@@ -112,7 +115,8 @@ services:
browser-sockpuppet-chrome:
hostname: browser-sockpuppet-chrome
image: dgtlmoon/sockpuppetbrowser@sha256:1d8f72d2ce2085faed4232e5ae1e65c02efe5b831a18e127829b267c260b4fb2
network_mode: bridge
networks:
- changedetection
cap_add:
- SYS_ADMIN
# SYS_ADMIN might be too much, but it can be needed on your platform https://github.com/puppeteer/puppeteer/blob/main/docs/troubleshooting.md#running-puppeteer-on-gitlabci
+12 -7
View File
@@ -499,7 +499,8 @@ services:
bookorbit:
image: ghcr.io/bookorbit/bookorbit:3.2.0
container_name: bookorbit-app
network_mode: bridge
networks:
- bookorbit
ports:
- "3099:3000"
environment:
@@ -509,8 +510,8 @@ services:
PUID: 99
PGID: 100
APP_URL: https://bookorbit.arnoutvw.nl
POSTGRES_HOST: 192.168.10.144
POSTGRES_PORT: 5435
POSTGRES_HOST: bookorbit-db
POSTGRES_PORT: 5432
POSTGRES_USER: bookorbit
POSTGRES_PASSWORD: ${BOOKORBIT_DB_PASSWORD}
POSTGRES_DB: bookorbit
@@ -539,7 +540,9 @@ services:
stop_grace_period: 30s
restart: unless-stopped
labels:
traefik.http.routers.bookorbit.rule: "Host(`bookorbit.arnoutvw.nl`)"
- traefik.enable=true
- traefik.http.routers.bookorbit.rule=Host(`bookorbit.arnoutvw.nl`)
- traefik.http.services.bookorbit.loadbalancer.server.port=3000
shelfarr:
container_name: shelfarr
@@ -595,9 +598,8 @@ services:
bookorbit-db:
image: pgvector/pgvector:pg18
container_name: bookorbit-db
network_mode: bridge
ports:
- "5435:5432"
networks:
- bookorbit
environment:
TZ: Europe/Berlin
POSTGRES_USER: bookorbit
@@ -644,3 +646,6 @@ services:
volumes:
28eea8bfffd285350962765a88ff04ea9d580fe872771d5c06fd62afb26f2ef2:
external: true
networks:
bookorbit:
+7 -7
View File
@@ -11,7 +11,7 @@ DB_DATA_LOCATION=/mnt/user/appdata/PostgreSQL_Immich
# To set a timezone, uncomment the next line and change Etc/UTC to a TZ identifier from this list: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List
TZ=Europe/Berlin
IMMICH_MACHINE_LEARNING_URL=http://192.168.10.144:3003
IMMICH_MACHINE_LEARNING_URL=http://immich-machine-learning:3003
# The Immich version to use. You can pin this to a specific version like "v2.1.0"
IMMICH_VERSION=v2
@@ -24,14 +24,14 @@ DB_PASSWORD=immich
###################################################################################
DB_USERNAME=immich
DB_DATABASE_NAME=immich
DB_HOSTNAME=192.168.10.144
DB_HOST=192.168.10.144
DB_PORT=5434
DB_HOSTNAME=immich_postgres
DB_HOST=immich_postgres
DB_PORT=5432
#redis
REDIS_PORT=6380
REDIS_PORT=6379
REDIS_PASSWORD=
REDIS_HOSTNAME=192.168.10.144
REDIS_HOSTNAME=immich_redis
#Machine learing
MACHINE_LEARNING_HOST=0.0.0.0
@@ -40,5 +40,5 @@ MACHINE_LEARNING_MAX_BATCH_SIZE__FACIAL_RECOGNITION=1
MACHINE_LEARNING_CACHE_FOLDER=/config/machine-learning/models
MACHINE_LEARNING_MAX_BATCH_SIZE__TEXT_RECOGNITION=3
IMMICH_URL = "http://192.168.10.144:8693" # Your immich instace ip address and port
IMMICH_URL = "http://immich-server:2283" # internal container route (own compose network)
EXTERNAL_IMMICH_URL = "https://photos.arnoutvw.nl" # External address of immich
+22 -7
View File
@@ -9,11 +9,17 @@
name: immich
networks:
immich:
services:
immich-server:
network_mode: bridge
networks:
- immich
labels:
- traefik.enable=true
- traefik.http.routers.immich.rule=Host(`photos.arnoutvw.nl`)
- traefik.http.services.immich.loadbalancer.server.port=2283
- pangolin.proxy-resources.immich.name=immich
- pangolin.proxy-resources.immich.full-domain=photos.arnoutvw.nl
- pangolin.proxy-resources.immich.protocol=http
@@ -63,7 +69,8 @@ services:
disable: false
immich-machine-learning:
network_mode: bridge
networks:
- immich
ports:
- '3003:3003'
container_name: immich_machine_learning
@@ -85,7 +92,8 @@ services:
redis:
container_name: immich_redis
image: docker.io/valkey/valkey:9.1.2-alpine
network_mode: "bridge"
networks:
- immich
ports:
- '6380:6379'
healthcheck:
@@ -95,7 +103,8 @@ services:
database:
container_name: immich_postgres
image: ghcr.io/immich-app/postgres:16-vectorchord0.4.2-pgvectors0.3.0
network_mode: "bridge"
networks:
- immich
ports:
- '5434:5432'
labels:
@@ -134,9 +143,12 @@ services:
power-tools:
container_name: immich_power_tools
image: ghcr.io/varun-raj/immich-power-tools:0.19.1
network_mode: bridge
networks:
- immich
labels:
- traefik.enable=true
- traefik.http.routers.immich-powertools.rule=Host(`immich-power-tools.arnoutvw.nl`)
- traefik.http.services.immich-powertools.loadbalancer.server.port=3000
ports:
- "8029:3000"
env_file:
@@ -144,14 +156,17 @@ services:
immich-proxy:
container_name: immich_proxy
image: ghcr.io/arnoutvw/yaiiu/immich-proxy:sha-8a197d0
network_mode: bridge
networks:
- immich
ports:
- "8694:8080"
environment:
- IMMICH_SERVER_URL=http://192.168.10.144:8693
- IMMICH_SERVER_URL=http://immich-server:2283
- IMMICH_API_KEY=8FeEvF5Fdybpp9GM15x29VgchYtKqqgAgozX9Z5TbW4
labels:
- traefik.enable=true
- traefik.http.routers.immich-proxy.rule=Host(`immich-proxy.arnoutvw.nl`)
- traefik.http.services.immich-proxy.loadbalancer.server.port=8080
- pangolin.proxy-resources.immich-proxy.name=immich-proxy
- pangolin.proxy-resources.immich-proxy.full-domain=immich-proxy.arnoutvw.nl
- pangolin.proxy-resources.immich-proxy.protocol=http
+11 -10
View File
@@ -1,9 +1,14 @@
networks:
postiz-network:
external: false
services:
postiz:
image: ghcr.io/gitroomhq/postiz-app:v2.25.0
container_name: postiz
restart: always
network_mode: bridge
networks:
- postiz-network
environment:
# === Required Settings
MAIN_URL: "https://postiz.arnoutvw.nl"
@@ -117,13 +122,11 @@ services:
ports:
- "5000:5000"
labels:
- "traefik.enable=true"
- "traefik.http.routers.postiz.rule=Host(`postiz.arnoutvw.nl`)" # Replace with your domain
- "traefik.http.services.postiz.loadbalancer.server.port=5000" # Internal port for postiz
- "traefik.http.routers.postiz.entrypoints=https" # Postiz requires HTTPS
- "traefik.http.routers.postiz.tls=true"
links:
- postiz-postgres
- postiz-redis
depends_on:
postiz-postgres:
condition: service_healthy
@@ -134,7 +137,8 @@ services:
image: postgres:17-alpine
container_name: postiz-postgres
restart: always
network_mode: bridge
networks:
- postiz-network
environment:
POSTGRES_PASSWORD: postiz-password
POSTGRES_USER: postiz-user
@@ -150,7 +154,8 @@ services:
image: redis:7.4
container_name: postiz-redis
restart: always
network_mode: bridge
networks:
- postiz-network
healthcheck:
test: redis-cli ping
interval: 10s
@@ -170,8 +175,4 @@ volumes:
external: false
postiz-uploads:
external: false
networks:
postiz-network:
external: false
+21 -12
View File
@@ -1,13 +1,17 @@
networks:
teslamate:
services:
teslamate:
container_name: "teslamate"
image: teslamate/teslamate:4.3.0
restart: always
network_mode: "bridge"
networks:
- teslamate
environment:
- "DATABASE_USER=teslamate"
- "DATABASE_NAME=teslamate"
- "DATABASE_HOST=192.168.10.144"
- "DATABASE_HOST=postgresql17"
- "DATABASE_PASS=${DATABASE_PASS}"
- "DATABASE_PORT=5432"
- "MQTT_HOST=192.168.10.54"
@@ -25,15 +29,16 @@ services:
cap_drop:
- ALL
labels:
traefik.http.routers.teslamate.rule: "Host(`teslamate.arnoutvw.nl`)"
- traefik.enable=true
- traefik.http.routers.teslamate.rule=Host(`teslamate.arnoutvw.nl`)
- traefik.http.services.teslamate.loadbalancer.server.port=4000
postgresql17:
container_name: "postgresql17"
image: postgres:17-alpine3.22
restart: always
network_mode: "bridge"
ports:
- "5432:5432"
networks:
- teslamate
environment:
- "HOST_CONTAINERNAME=postgresql17"
- "POSTGRES_USER=postgres"
@@ -46,13 +51,14 @@ services:
container_name: "teslamate-grafana"
image: teslamate/grafana:4.3.0
restart: always
network_mode: "bridge"
networks:
- teslamate
environment:
- "GF_AUTH_GENERIC_OAUTH_SCOPES=openid profile email"
- "GF_AUTH_GENERIC_OAUTH_TOKEN_URL=https://pass.arnoutvw.nl/api/oidc/token"
- "HOST_OS=Unraid"
- "DATABASE_USER=teslamate"
- "DATABASE_HOST=192.168.10.144"
- "DATABASE_HOST=postgresql17"
- "GF_AUTH_GENERIC_OAUTH_NAME=PocketID"
- "GF_AUTH_GENERIC_OAUTH_ALLOW_SIGN_UP=true"
- "GF_AUTH_DISABLE_LOGIN_FORM=false"
@@ -83,7 +89,9 @@ services:
- "/mnt/cache/appdata/teslamate-customdashboard/Teslamate-CustomGrafanaDashboards/dashboards:/TeslamateCustomDashboards"
- "/mnt/user/appdata/telsamate-grafana:/var/lib/grafana"
labels:
traefik.http.routers.tesla.rule: "Host(`tesla.arnoutvw.nl`)"
- traefik.enable=true
- traefik.http.routers.tesla.rule=Host(`tesla.arnoutvw.nl`)
- traefik.http.services.tesla.loadbalancer.server.port=3000
TeslaMate-ABRP:
container_name: "TeslaMate-ABRP"
@@ -116,7 +124,8 @@ services:
restart: "always"
teslamateapi:
container_name: "teslamateapi"
network_mode: "bridge"
networks:
- teslamate
image: tobiasehlert/teslamateapi:1.25.0
restart: always
environment:
@@ -124,7 +133,7 @@ services:
- DATABASE_USER=teslamate
- "DATABASE_PASS=${DATABASE_PASS}"
- DATABASE_NAME=teslamate
- DATABASE_HOST=192.168.10.144
- DATABASE_HOST=postgresql17
- "MQTT_HOST=192.168.10.54"
- "MQTT_PASSWORD=${MQTT_PASSWORD}"
- "MQTT_TLS_ACCEPT_INVALID_CERTS=true"
@@ -133,7 +142,7 @@ services:
- "MQTT_TLS=false"
- "MQTT_PORT=1883"
- TZ=Europe/Berlin
- TESLAMATE_HOST=192.168.10.144
- TESLAMATE_HOST=teslamate
- TESLAMATE_PORT=4000
- API_TOKEN=826d3b8b-daad-48c7-ad3b-8bdaade8c706
ports: