feat(infra): add traefik-network-connector; dawarich off shared bridge

- new stack traefik-network-connector: attaches atlas traefik to networks
  of containers labelled traefik.enable=true (obeone/traefik_network_connector)
- dawarich: rewrite to upstream compose style (private dawarich network,
  no default-bridge sharing, no legacy links). Keep pinned image tags,
  host port 3007 (pangolin/newt target), photon override, concurrency 10.
  RAILS_ENV development -> production (+ SECRET_KEY_BASE, upstream default).
This commit is contained in:
Arnout van Westen committed 2026-10-03 07:53:12 +02:00
1 parent 122ca76eb8
commit 9ab0357f16
2 files changed
+62 -39

No files matched your search

+44 -39
View File
@@ -1,27 +1,47 @@
# Based on upstream https://github.com/Freika/dawarich/blob/master/docker/docker-compose.yml
# Local deviations:
# - image tags pinned (repo convention; Renovate bumps)
# - host port 3007 -> 3000: pangolin (newt) and LAN clients target
# 192.168.10.144:3007, so it must stay published on the host
# - traefik labels on dawarich_app: Atlas traefik does NOT sit on this
# network; traefik-network-connector (own stack) attaches it on start
# - RAILS_ENV production (upstream default; install predates the switch)
# - BACKGROUND_PROCESSING_CONCURRENCY 10 (upstream default 3; tuned for
# large imports)
# - local photon geocoding (photon container currently disabled)
networks:
dawarich:
services: services:
dawarich_redis: dawarich_redis:
image: redis:7.4-alpine image: redis:7.4-alpine
container_name: dawarich_redis container_name: dawarich_redis
command: redis-server command: >
network_mode: bridge redis-server
--save 900 1
--save 300 10
--appendonly no
networks:
- dawarich
volumes: volumes:
- dawarich_shared:/data - dawarich_shared:/data
restart: always restart: always
healthcheck: healthcheck:
test: [ "CMD-SHELL", "redis-cli --raw incr ping || exit 1" ] test: [ "CMD", "redis-cli", "--raw", "incr", "ping" ]
interval: 10s interval: 10s
retries: 5 retries: 5
start_period: 30s start_period: 30s
timeout: 10s timeout: 10s
dawarich_db: dawarich_db:
image: postgis/postgis:17-3.5-alpine image: postgis/postgis:17-3.5-alpine
shm_size: 1G shm_size: 1G
container_name: dawarich_db container_name: dawarich_db
network_mode: bridge
volumes: volumes:
- dawarich_db_data:/var/lib/postgresql/data - dawarich_db_data:/var/lib/postgresql/data
- dawarich_shared:/var/shared - dawarich_shared:/var/shared
# - ./postgresql.conf:/etc/postgresql/postgresql.conf # Optional, uncomment if you want to use a custom config networks:
- dawarich
environment: environment:
POSTGRES_USER: postgres POSTGRES_USER: postgres
POSTGRES_PASSWORD: password POSTGRES_PASSWORD: password
@@ -33,31 +53,32 @@ services:
retries: 5 retries: 5
start_period: 30s start_period: 30s
timeout: 10s timeout: 10s
# command: postgres -c config_file=/etc/postgresql/postgresql.conf # Use custom config, uncomment if you want to use a custom config
dawarich_app: dawarich_app:
labels:
- traefik.constraint=proxy-public
- traefik.http.routers.nginx.rule=Host(`dawarich.arnoutvw.nl`)
image: freikin/dawarich:1.15.3 image: freikin/dawarich:1.15.3
container_name: dawarich_app container_name: dawarich_app
network_mode: bridge
volumes: volumes:
- dawarich_public:/var/app/public - dawarich_public:/var/app/public
- dawarich_watched:/var/app/tmp/imports/watched - dawarich_watched:/var/app/tmp/imports/watched
- dawarich_storage:/var/app/storage - dawarich_storage:/var/app/storage
links: - dawarich_db_data:/dawarich_db_data
- dawarich_db networks:
- dawarich_redis - dawarich
labels:
- traefik.enable=true
- traefik.http.routers.dawarich.rule=Host(`dawarich.arnoutvw.nl`)
- traefik.http.services.dawarich.loadbalancer.server.port=3000
ports: ports:
# custom host port: pangolin/newt + LAN target 192.168.10.144:3007
- 3007:3000 - 3007:3000
- 9397:9394 # Prometheus exporter, uncomment if needed
stdin_open: true stdin_open: true
tty: true tty: true
entrypoint: web-entrypoint.sh entrypoint: web-entrypoint.sh
command: [ 'bin/rails', 'server', '-p', '3000', '-b', '::' ] command: [ 'bin/rails', 'server', '-p', '3000', '-b', '::' ]
restart: always restart: unless-stopped
environment: environment:
RAILS_ENV: development RAILS_ENV: production
SECRET_KEY_BASE: 2f5e59518ddeaeb978c73bc265eea20a91d5fe203d2a45280bd8fbf62b447b57
REDIS_URL: redis://dawarich_redis:6379 REDIS_URL: redis://dawarich_redis:6379
DATABASE_HOST: dawarich_db DATABASE_HOST: dawarich_db
DATABASE_USERNAME: postgres DATABASE_USERNAME: postgres
@@ -65,13 +86,6 @@ services:
DATABASE_NAME: dawarich_development DATABASE_NAME: dawarich_development
MIN_MINUTES_SPENT_IN_CITY: 60 MIN_MINUTES_SPENT_IN_CITY: 60
APPLICATION_HOSTS: localhost,dawarich.arnoutvw.nl,192.168.10.144 APPLICATION_HOSTS: localhost,dawarich.arnoutvw.nl,192.168.10.144
TIME_ZONE: Europe/London
APPLICATION_PROTOCOL: http
PROMETHEUS_EXPORTER_ENABLED: false
PROMETHEUS_EXPORTER_HOST: 0.0.0.0
PROMETHEUS_EXPORTER_PORT: 9394
SELF_HOSTED: "true"
STORE_GEODATA: "true"
PHOTON_API_HOST: 192.168.10.144:2322 PHOTON_API_HOST: 192.168.10.144:2322
PHOTON_API_USE_HTTPS: false PHOTON_API_USE_HTTPS: false
logging: logging:
@@ -95,8 +109,9 @@ services:
deploy: deploy:
resources: resources:
limits: limits:
cpus: '0.50' # Limit CPU usage to 50% of one core cpus: '0.50'
memory: '4G' # Limit memory usage to 4GB memory: '4G'
dawarich_sidekiq: dawarich_sidekiq:
image: freikin/dawarich:1.15.3 image: freikin/dawarich:1.15.3
container_name: dawarich_sidekiq container_name: dawarich_sidekiq
@@ -104,33 +119,23 @@ services:
- dawarich_public:/var/app/public - dawarich_public:/var/app/public
- dawarich_watched:/var/app/tmp/imports/watched - dawarich_watched:/var/app/tmp/imports/watched
- dawarich_storage:/var/app/storage - dawarich_storage:/var/app/storage
network_mode: bridge networks:
links: - dawarich
- dawarich_db
- dawarich_redis
stdin_open: true stdin_open: true
tty: true tty: true
entrypoint: sidekiq-entrypoint.sh entrypoint: sidekiq-entrypoint.sh
command: [ 'sidekiq' ] command: [ 'sidekiq' ]
restart: always restart: unless-stopped
environment: environment:
RAILS_ENV: development RAILS_ENV: production
REDIS_URL: redis://dawarich_redis:6379 REDIS_URL: redis://dawarich_redis:6379
DATABASE_HOST: dawarich_db DATABASE_HOST: dawarich_db
DATABASE_USERNAME: postgres DATABASE_USERNAME: postgres
DATABASE_PASSWORD: password DATABASE_PASSWORD: password
DATABASE_NAME: dawarich_development DATABASE_NAME: dawarich_development
APPLICATION_HOSTS: localhost
BACKGROUND_PROCESSING_CONCURRENCY: 10 BACKGROUND_PROCESSING_CONCURRENCY: 10
APPLICATION_PROTOCOL: http
PROMETHEUS_EXPORTER_ENABLED: false
PROMETHEUS_EXPORTER_HOST: dawarich_app
PROMETHEUS_EXPORTER_PORT: 9394
SELF_HOSTED: "true"
STORE_GEODATA: "true"
PHOTON_API_HOST: 192.168.10.144:2322 PHOTON_API_HOST: 192.168.10.144:2322
PHOTON_API_USE_HTTPS: false PHOTON_API_USE_HTTPS: false
logging: logging:
driver: "json-file" driver: "json-file"
options: options:
@@ -0,0 +1,18 @@
# Attaches the Atlas traefik (container_name "traefik", dockerman) to the
# docker networks of any container labelled `traefik.enable=true`, so stacks
# can use their own private compose network instead of sharing the default
# bridge with traefik. https://github.com/obeone/traefik_network_connector
# No version tags published yet — only :latest.
services:
traefik-network-connector:
image: ghcr.io/obeone/traefik_network_connector:latest
container_name: traefik-network-connector
restart: unless-stopped
init: true
network_mode: bridge
volumes:
- /var/run/docker.sock:/var/run/docker.sock
environment:
TZ: Europe/Amsterdam
TRAEFIK_CONTAINERNAME: traefik
LOGLEVEL: INFO