From 9ab0357f1698c189f0ed2198937523795ce29cff Mon Sep 17 00:00:00 2001 From: Arnout van Westen Date: Sat, 3 Oct 2026 07:53:09 +0200 Subject: [PATCH] feat(infra): add traefik-network-connector; dawarich off shared bridge - new stack traefik-network-connector: attaches atlas traefik to networks of containers labelled traefik.enable=true (obeone/traefik_network_connector) - dawarich: rewrite to upstream compose style (private dawarich network, no default-bridge sharing, no legacy links). Keep pinned image tags, host port 3007 (pangolin/newt target), photon override, concurrency 10. RAILS_ENV development -> production (+ SECRET_KEY_BASE, upstream default). --- dawarich/docker-compose.yml | 83 +++++++++++--------- traefik-network-connector/docker-compose.yml | 18 +++++ 2 files changed, 62 insertions(+), 39 deletions(-) create mode 100644 traefik-network-connector/docker-compose.yml diff --git a/dawarich/docker-compose.yml b/dawarich/docker-compose.yml index 9707b6c..961a50c 100644 --- a/dawarich/docker-compose.yml +++ b/dawarich/docker-compose.yml @@ -1,27 +1,47 @@ +# Based on upstream https://github.com/Freika/dawarich/blob/master/docker/docker-compose.yml +# Local deviations: +# - image tags pinned (repo convention; Renovate bumps) +# - host port 3007 -> 3000: pangolin (newt) and LAN clients target +# 192.168.10.144:3007, so it must stay published on the host +# - traefik labels on dawarich_app: Atlas traefik does NOT sit on this +# network; traefik-network-connector (own stack) attaches it on start +# - RAILS_ENV production (upstream default; install predates the switch) +# - BACKGROUND_PROCESSING_CONCURRENCY 10 (upstream default 3; tuned for +# large imports) +# - local photon geocoding (photon container currently disabled) +networks: + dawarich: + services: dawarich_redis: image: redis:7.4-alpine container_name: dawarich_redis - command: redis-server - network_mode: bridge + command: > + redis-server + --save 900 1 + --save 300 10 + --appendonly no + networks: + - dawarich volumes: - dawarich_shared:/data restart: always healthcheck: - test: [ "CMD-SHELL", "redis-cli --raw incr ping || exit 1" ] + test: [ "CMD", "redis-cli", "--raw", "incr", "ping" ] interval: 10s retries: 5 start_period: 30s timeout: 10s + dawarich_db: image: postgis/postgis:17-3.5-alpine shm_size: 1G container_name: dawarich_db - network_mode: bridge volumes: - dawarich_db_data:/var/lib/postgresql/data - dawarich_shared:/var/shared - # - ./postgresql.conf:/etc/postgresql/postgresql.conf # Optional, uncomment if you want to use a custom config + networks: + - dawarich environment: POSTGRES_USER: postgres POSTGRES_PASSWORD: password @@ -33,31 +53,32 @@ services: retries: 5 start_period: 30s timeout: 10s - # command: postgres -c config_file=/etc/postgresql/postgresql.conf # Use custom config, uncomment if you want to use a custom config + dawarich_app: - labels: - - traefik.constraint=proxy-public - - traefik.http.routers.nginx.rule=Host(`dawarich.arnoutvw.nl`) image: freikin/dawarich:1.15.3 container_name: dawarich_app - network_mode: bridge volumes: - dawarich_public:/var/app/public - dawarich_watched:/var/app/tmp/imports/watched - dawarich_storage:/var/app/storage - links: - - dawarich_db - - dawarich_redis + - dawarich_db_data:/dawarich_db_data + networks: + - dawarich + labels: + - traefik.enable=true + - traefik.http.routers.dawarich.rule=Host(`dawarich.arnoutvw.nl`) + - traefik.http.services.dawarich.loadbalancer.server.port=3000 ports: + # custom host port: pangolin/newt + LAN target 192.168.10.144:3007 - 3007:3000 - - 9397:9394 # Prometheus exporter, uncomment if needed stdin_open: true tty: true entrypoint: web-entrypoint.sh command: [ 'bin/rails', 'server', '-p', '3000', '-b', '::' ] - restart: always + restart: unless-stopped environment: - RAILS_ENV: development + RAILS_ENV: production + SECRET_KEY_BASE: 2f5e59518ddeaeb978c73bc265eea20a91d5fe203d2a45280bd8fbf62b447b57 REDIS_URL: redis://dawarich_redis:6379 DATABASE_HOST: dawarich_db DATABASE_USERNAME: postgres @@ -65,13 +86,6 @@ services: DATABASE_NAME: dawarich_development MIN_MINUTES_SPENT_IN_CITY: 60 APPLICATION_HOSTS: localhost,dawarich.arnoutvw.nl,192.168.10.144 - TIME_ZONE: Europe/London - APPLICATION_PROTOCOL: http - PROMETHEUS_EXPORTER_ENABLED: false - PROMETHEUS_EXPORTER_HOST: 0.0.0.0 - PROMETHEUS_EXPORTER_PORT: 9394 - SELF_HOSTED: "true" - STORE_GEODATA: "true" PHOTON_API_HOST: 192.168.10.144:2322 PHOTON_API_USE_HTTPS: false logging: @@ -95,8 +109,9 @@ services: deploy: resources: limits: - cpus: '0.50' # Limit CPU usage to 50% of one core - memory: '4G' # Limit memory usage to 4GB + cpus: '0.50' + memory: '4G' + dawarich_sidekiq: image: freikin/dawarich:1.15.3 container_name: dawarich_sidekiq @@ -104,33 +119,23 @@ services: - dawarich_public:/var/app/public - dawarich_watched:/var/app/tmp/imports/watched - dawarich_storage:/var/app/storage - network_mode: bridge - links: - - dawarich_db - - dawarich_redis + networks: + - dawarich stdin_open: true tty: true entrypoint: sidekiq-entrypoint.sh command: [ 'sidekiq' ] - restart: always + restart: unless-stopped environment: - RAILS_ENV: development + RAILS_ENV: production REDIS_URL: redis://dawarich_redis:6379 DATABASE_HOST: dawarich_db DATABASE_USERNAME: postgres DATABASE_PASSWORD: password DATABASE_NAME: dawarich_development - APPLICATION_HOSTS: localhost BACKGROUND_PROCESSING_CONCURRENCY: 10 - APPLICATION_PROTOCOL: http - PROMETHEUS_EXPORTER_ENABLED: false - PROMETHEUS_EXPORTER_HOST: dawarich_app - PROMETHEUS_EXPORTER_PORT: 9394 - SELF_HOSTED: "true" - STORE_GEODATA: "true" PHOTON_API_HOST: 192.168.10.144:2322 PHOTON_API_USE_HTTPS: false - logging: driver: "json-file" options: diff --git a/traefik-network-connector/docker-compose.yml b/traefik-network-connector/docker-compose.yml new file mode 100644 index 0000000..106d508 --- /dev/null +++ b/traefik-network-connector/docker-compose.yml @@ -0,0 +1,18 @@ +# Attaches the Atlas traefik (container_name "traefik", dockerman) to the +# docker networks of any container labelled `traefik.enable=true`, so stacks +# can use their own private compose network instead of sharing the default +# bridge with traefik. https://github.com/obeone/traefik_network_connector +# No version tags published yet — only :latest. +services: + traefik-network-connector: + image: ghcr.io/obeone/traefik_network_connector:latest + container_name: traefik-network-connector + restart: unless-stopped + init: true + network_mode: bridge + volumes: + - /var/run/docker.sock:/var/run/docker.sock + environment: + TZ: Europe/Amsterdam + TRAEFIK_CONTAINERNAME: traefik + LOGLEVEL: INFO \ No newline at end of file