feat(trn): replace TNC with shell traefik-network-watcher
Own watcher (docker:28-cli + handler.sh): attaches traefik to every docker network labelled traefik.enable=true (daemon-side filter), 5-min periodic resync + traefik-restart healing. dawarich/teslamate back on private networks with the net label set.
This commit is contained in:
1 parent
21ee8d9c98
commit
c136dafc5b
4 files changed
+208
-60
No files matched your search
+45
-39
@@ -1,27 +1,49 @@
|
|||||||
|
# Based on upstream https://github.com/Freika/dawarich/blob/master/docker/docker-compose.yml
|
||||||
|
# Local deviations:
|
||||||
|
# - image tags pinned (repo convention; Renovate bumps)
|
||||||
|
# - host port 3007 -> 3000: pangolin (newt) and LAN clients target
|
||||||
|
# 192.168.10.144:3007, so it must stay published on the host
|
||||||
|
# - traefik labels on dawarich_app: Atlas traefik does NOT sit on this
|
||||||
|
# network; traefik-network-connector (own stack) attaches it on start
|
||||||
|
# - RAILS_ENV production (upstream default; install predates the switch)
|
||||||
|
# - BACKGROUND_PROCESSING_CONCURRENCY 10 (upstream default 3; tuned for
|
||||||
|
# large imports)
|
||||||
|
# - local photon geocoding (photon container currently disabled)
|
||||||
|
networks:
|
||||||
|
dawarich:
|
||||||
|
labels:
|
||||||
|
- traefik.enable=true
|
||||||
|
|
||||||
services:
|
services:
|
||||||
dawarich_redis:
|
dawarich_redis:
|
||||||
image: redis:8.10-alpine
|
image: redis:7.4-alpine
|
||||||
container_name: dawarich_redis
|
container_name: dawarich_redis
|
||||||
command: redis-server
|
command: >
|
||||||
network_mode: bridge
|
redis-server
|
||||||
|
--save 900 1
|
||||||
|
--save 300 10
|
||||||
|
--appendonly no
|
||||||
|
networks:
|
||||||
|
- dawarich
|
||||||
volumes:
|
volumes:
|
||||||
- dawarich_shared:/data
|
- dawarich_shared:/data
|
||||||
restart: always
|
restart: always
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: [ "CMD-SHELL", "redis-cli --raw incr ping || exit 1" ]
|
test: [ "CMD", "redis-cli", "--raw", "incr", "ping" ]
|
||||||
interval: 10s
|
interval: 10s
|
||||||
retries: 5
|
retries: 5
|
||||||
start_period: 30s
|
start_period: 30s
|
||||||
timeout: 10s
|
timeout: 10s
|
||||||
|
|
||||||
dawarich_db:
|
dawarich_db:
|
||||||
image: postgis/postgis:17-3.5-alpine
|
image: postgis/postgis:17-3.5-alpine
|
||||||
shm_size: 1G
|
shm_size: 1G
|
||||||
container_name: dawarich_db
|
container_name: dawarich_db
|
||||||
network_mode: bridge
|
|
||||||
volumes:
|
volumes:
|
||||||
- dawarich_db_data:/var/lib/postgresql/data
|
- dawarich_db_data:/var/lib/postgresql/data
|
||||||
- dawarich_shared:/var/shared
|
- dawarich_shared:/var/shared
|
||||||
# - ./postgresql.conf:/etc/postgresql/postgresql.conf # Optional, uncomment if you want to use a custom config
|
networks:
|
||||||
|
- dawarich
|
||||||
environment:
|
environment:
|
||||||
POSTGRES_USER: postgres
|
POSTGRES_USER: postgres
|
||||||
POSTGRES_PASSWORD: password
|
POSTGRES_PASSWORD: password
|
||||||
@@ -33,29 +55,29 @@ services:
|
|||||||
retries: 5
|
retries: 5
|
||||||
start_period: 30s
|
start_period: 30s
|
||||||
timeout: 10s
|
timeout: 10s
|
||||||
# command: postgres -c config_file=/etc/postgresql/postgresql.conf # Use custom config, uncomment if you want to use a custom config
|
|
||||||
dawarich_app:
|
dawarich_app:
|
||||||
labels:
|
|
||||||
- traefik.constraint=proxy-public
|
|
||||||
- traefik.http.routers.nginx.rule=Host(`dawarich.arnoutvw.nl`)
|
|
||||||
image: freikin/dawarich:1.15.3
|
image: freikin/dawarich:1.15.3
|
||||||
container_name: dawarich_app
|
container_name: dawarich_app
|
||||||
network_mode: bridge
|
|
||||||
volumes:
|
volumes:
|
||||||
- dawarich_public:/var/app/public
|
- dawarich_public:/var/app/public
|
||||||
- dawarich_watched:/var/app/tmp/imports/watched
|
- dawarich_watched:/var/app/tmp/imports/watched
|
||||||
- dawarich_storage:/var/app/storage
|
- dawarich_storage:/var/app/storage
|
||||||
links:
|
- dawarich_db_data:/dawarich_db_data
|
||||||
- dawarich_db
|
networks:
|
||||||
- dawarich_redis
|
- dawarich
|
||||||
|
labels:
|
||||||
|
- traefik.enable=true
|
||||||
|
- traefik.http.routers.dawarich.rule=Host(`dawarich.arnoutvw.nl`)
|
||||||
|
- traefik.http.services.dawarich.loadbalancer.server.port=3000
|
||||||
ports:
|
ports:
|
||||||
|
# custom host port: pangolin/newt + LAN target 192.168.10.144:3007
|
||||||
- 3007:3000
|
- 3007:3000
|
||||||
- 9397:9394 # Prometheus exporter, uncomment if needed
|
|
||||||
stdin_open: true
|
stdin_open: true
|
||||||
tty: true
|
tty: true
|
||||||
entrypoint: web-entrypoint.sh
|
entrypoint: web-entrypoint.sh
|
||||||
command: [ 'bin/rails', 'server', '-p', '3000', '-b', '::' ]
|
command: [ 'bin/rails', 'server', '-p', '3000', '-b', '::' ]
|
||||||
restart: always
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
RAILS_ENV: production
|
RAILS_ENV: production
|
||||||
SECRET_KEY_BASE: 2f5e59518ddeaeb978c73bc265eea20a91d5fe203d2a45280bd8fbf62b447b57
|
SECRET_KEY_BASE: 2f5e59518ddeaeb978c73bc265eea20a91d5fe203d2a45280bd8fbf62b447b57
|
||||||
@@ -66,13 +88,6 @@ services:
|
|||||||
DATABASE_NAME: dawarich_development
|
DATABASE_NAME: dawarich_development
|
||||||
MIN_MINUTES_SPENT_IN_CITY: 60
|
MIN_MINUTES_SPENT_IN_CITY: 60
|
||||||
APPLICATION_HOSTS: localhost,dawarich.arnoutvw.nl,192.168.10.144
|
APPLICATION_HOSTS: localhost,dawarich.arnoutvw.nl,192.168.10.144
|
||||||
TIME_ZONE: Europe/London
|
|
||||||
APPLICATION_PROTOCOL: http
|
|
||||||
PROMETHEUS_EXPORTER_ENABLED: false
|
|
||||||
PROMETHEUS_EXPORTER_HOST: 0.0.0.0
|
|
||||||
PROMETHEUS_EXPORTER_PORT: 9394
|
|
||||||
SELF_HOSTED: "true"
|
|
||||||
STORE_GEODATA: "true"
|
|
||||||
PHOTON_API_HOST: 192.168.10.144:2322
|
PHOTON_API_HOST: 192.168.10.144:2322
|
||||||
PHOTON_API_USE_HTTPS: false
|
PHOTON_API_USE_HTTPS: false
|
||||||
logging:
|
logging:
|
||||||
@@ -96,8 +111,9 @@ services:
|
|||||||
deploy:
|
deploy:
|
||||||
resources:
|
resources:
|
||||||
limits:
|
limits:
|
||||||
cpus: '0.50' # Limit CPU usage to 50% of one core
|
cpus: '0.50'
|
||||||
memory: '4G' # Limit memory usage to 4GB
|
memory: '4G'
|
||||||
|
|
||||||
dawarich_sidekiq:
|
dawarich_sidekiq:
|
||||||
image: freikin/dawarich:1.15.3
|
image: freikin/dawarich:1.15.3
|
||||||
container_name: dawarich_sidekiq
|
container_name: dawarich_sidekiq
|
||||||
@@ -105,15 +121,13 @@ services:
|
|||||||
- dawarich_public:/var/app/public
|
- dawarich_public:/var/app/public
|
||||||
- dawarich_watched:/var/app/tmp/imports/watched
|
- dawarich_watched:/var/app/tmp/imports/watched
|
||||||
- dawarich_storage:/var/app/storage
|
- dawarich_storage:/var/app/storage
|
||||||
network_mode: bridge
|
networks:
|
||||||
links:
|
- dawarich
|
||||||
- dawarich_db
|
|
||||||
- dawarich_redis
|
|
||||||
stdin_open: true
|
stdin_open: true
|
||||||
tty: true
|
tty: true
|
||||||
entrypoint: sidekiq-entrypoint.sh
|
entrypoint: sidekiq-entrypoint.sh
|
||||||
command: [ 'sidekiq' ]
|
command: [ 'sidekiq' ]
|
||||||
restart: always
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
RAILS_ENV: production
|
RAILS_ENV: production
|
||||||
SECRET_KEY_BASE: 2f5e59518ddeaeb978c73bc265eea20a91d5fe203d2a45280bd8fbf62b447b57
|
SECRET_KEY_BASE: 2f5e59518ddeaeb978c73bc265eea20a91d5fe203d2a45280bd8fbf62b447b57
|
||||||
@@ -122,17 +136,9 @@ services:
|
|||||||
DATABASE_USERNAME: postgres
|
DATABASE_USERNAME: postgres
|
||||||
DATABASE_PASSWORD: password
|
DATABASE_PASSWORD: password
|
||||||
DATABASE_NAME: dawarich_development
|
DATABASE_NAME: dawarich_development
|
||||||
APPLICATION_HOSTS: localhost
|
|
||||||
BACKGROUND_PROCESSING_CONCURRENCY: 10
|
BACKGROUND_PROCESSING_CONCURRENCY: 10
|
||||||
APPLICATION_PROTOCOL: http
|
|
||||||
PROMETHEUS_EXPORTER_ENABLED: false
|
|
||||||
PROMETHEUS_EXPORTER_HOST: dawarich_app
|
|
||||||
PROMETHEUS_EXPORTER_PORT: 9394
|
|
||||||
SELF_HOSTED: "true"
|
|
||||||
STORE_GEODATA: "true"
|
|
||||||
PHOTON_API_HOST: 192.168.10.144:2322
|
PHOTON_API_HOST: 192.168.10.144:2322
|
||||||
PHOTON_API_USE_HTTPS: false
|
PHOTON_API_USE_HTTPS: false
|
||||||
|
|
||||||
logging:
|
logging:
|
||||||
driver: "json-file"
|
driver: "json-file"
|
||||||
options:
|
options:
|
||||||
@@ -160,4 +166,4 @@ volumes:
|
|||||||
dawarich_shared:
|
dawarich_shared:
|
||||||
dawarich_public:
|
dawarich_public:
|
||||||
dawarich_watched:
|
dawarich_watched:
|
||||||
dawarich_storage:
|
dawarich_storage:
|
||||||
+14
-21
@@ -1,11 +1,15 @@
|
|||||||
|
networks:
|
||||||
|
teslamate:
|
||||||
|
labels:
|
||||||
|
- traefik.enable=true
|
||||||
|
|
||||||
services:
|
services:
|
||||||
teslamate:
|
teslamate:
|
||||||
container_name: "teslamate"
|
container_name: "teslamate"
|
||||||
image: teslamate/teslamate:4.3.0
|
image: teslamate/teslamate:4.3.0
|
||||||
restart: always
|
restart: always
|
||||||
network_mode: "bridge"
|
networks:
|
||||||
links:
|
- teslamate
|
||||||
- postgresql17
|
|
||||||
environment:
|
environment:
|
||||||
- "DATABASE_USER=teslamate"
|
- "DATABASE_USER=teslamate"
|
||||||
- "DATABASE_NAME=teslamate"
|
- "DATABASE_NAME=teslamate"
|
||||||
@@ -35,7 +39,8 @@ services:
|
|||||||
container_name: "postgresql17"
|
container_name: "postgresql17"
|
||||||
image: postgres:17-alpine3.22
|
image: postgres:17-alpine3.22
|
||||||
restart: always
|
restart: always
|
||||||
network_mode: "bridge"
|
networks:
|
||||||
|
- teslamate
|
||||||
environment:
|
environment:
|
||||||
- "HOST_CONTAINERNAME=postgresql17"
|
- "HOST_CONTAINERNAME=postgresql17"
|
||||||
- "POSTGRES_USER=postgres"
|
- "POSTGRES_USER=postgres"
|
||||||
@@ -48,9 +53,8 @@ services:
|
|||||||
container_name: "teslamate-grafana"
|
container_name: "teslamate-grafana"
|
||||||
image: teslamate/grafana:4.3.0
|
image: teslamate/grafana:4.3.0
|
||||||
restart: always
|
restart: always
|
||||||
network_mode: "bridge"
|
networks:
|
||||||
links:
|
- teslamate
|
||||||
- postgresql17
|
|
||||||
environment:
|
environment:
|
||||||
- "GF_AUTH_GENERIC_OAUTH_SCOPES=openid profile email"
|
- "GF_AUTH_GENERIC_OAUTH_SCOPES=openid profile email"
|
||||||
- "GF_AUTH_GENERIC_OAUTH_TOKEN_URL=https://pass.arnoutvw.nl/api/oidc/token"
|
- "GF_AUTH_GENERIC_OAUTH_TOKEN_URL=https://pass.arnoutvw.nl/api/oidc/token"
|
||||||
@@ -122,9 +126,7 @@ services:
|
|||||||
restart: "always"
|
restart: "always"
|
||||||
teslamateapi:
|
teslamateapi:
|
||||||
container_name: "teslamateapi"
|
container_name: "teslamateapi"
|
||||||
network_mode: "bridge"
|
networks:
|
||||||
links:
|
|
||||||
- postgresql17
|
|
||||||
- teslamate
|
- teslamate
|
||||||
image: tobiasehlert/teslamateapi:1.25.0
|
image: tobiasehlert/teslamateapi:1.25.0
|
||||||
restart: always
|
restart: always
|
||||||
@@ -162,15 +164,6 @@ services:
|
|||||||
- pangolin.proxy-resources.teslamateapi.targets[0].healthcheck.port=4001
|
- pangolin.proxy-resources.teslamateapi.targets[0].healthcheck.port=4001
|
||||||
- pangolin.proxy-resources.teslamateapi.targets[0].healthcheck.enabled=true
|
- pangolin.proxy-resources.teslamateapi.targets[0].healthcheck.enabled=true
|
||||||
- pangolin.proxy-resources.teslamateapi.auth.sso-enabled=false
|
- pangolin.proxy-resources.teslamateapi.auth.sso-enabled=false
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[0].match=region
|
- pangolin.proxy-resources.teslamateapi.rules[0].match=ip
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[0].action=allow
|
- pangolin.proxy-resources.teslamateapi.rules[0].action=allow
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[0].value=EU
|
- pangolin.proxy-resources.teslamateapi.rules[0].value=172.21.0.1
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[1].match=ip
|
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[1].action=allow
|
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[1].value=172.21.0.1
|
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[2].match=ip
|
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[2].action=allow
|
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[2].value=212.227.105.183
|
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[3].match=country
|
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[3].action=deny
|
|
||||||
- pangolin.proxy-resources.teslamateapi.rules[3].value=ALL
|
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
# traefik-network-watcher — sh-script vervanging voor TNC
|
||||||
|
# (github.com/obeone/traefik_network_connector): koppelt traefik aan elk
|
||||||
|
# docker-netwerk met label traefik.enable=true, daemon-side filtering,
|
||||||
|
# periodieke resync (5 min) + traefik-restart herstel.
|
||||||
|
services:
|
||||||
|
traefik-network-watcher:
|
||||||
|
image: docker:28-cli
|
||||||
|
container_name: traefik-network-watcher
|
||||||
|
restart: unless-stopped
|
||||||
|
init: true
|
||||||
|
network_mode: bridge
|
||||||
|
entrypoint: ["/bin/sh", "/usr/local/bin/handler.sh"]
|
||||||
|
volumes:
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
|
- ./handler.sh:/usr/local/bin/handler.sh:ro
|
||||||
|
environment:
|
||||||
|
TZ: Europe/Amsterdam
|
||||||
|
TRAEFIK_CONTAINER: traefik
|
||||||
|
SYNC_INTERVAL: "300"
|
||||||
|
DETACH_UNLABELED: "false"
|
||||||
@@ -0,0 +1,129 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
#
|
||||||
|
# traefik-network-watcher
|
||||||
|
# Koppelt Traefik automatisch aan elke Docker-network die het label
|
||||||
|
# "traefik.enable=true" draagt. De filtering gebeurt daemon-side
|
||||||
|
# (docker network ls --filter label=...), dus zonder label gebeurt er
|
||||||
|
# niets: geen inspect-call, geen connect.
|
||||||
|
#
|
||||||
|
# Gedrag:
|
||||||
|
# - bij opstart: eenmalige scan over alle netwerken met het label
|
||||||
|
# - live: reactie op Docker-events (network create/connect)
|
||||||
|
# - herstelt zichzelf als de Traefik-container opnieuw opgestart wordt
|
||||||
|
# - optioneel: periodieke resync (SYNC_INTERVAL, standaard 300s)
|
||||||
|
# - optioneel: detachen van netwerken die het label verloren hebben
|
||||||
|
# (DETACH_UNLABELED=true, standaard uit)
|
||||||
|
#
|
||||||
|
set -u
|
||||||
|
|
||||||
|
TRAEFIK="${TRAEFIK_CONTAINER:-traefik}"
|
||||||
|
LABEL_SELECTOR="${TRAEFIK_NETWORK_LABEL:-label=traefik.enable=true}"
|
||||||
|
EXCLUDED="${EXCLUDED_NETWORKS:-bridge host none ingress docker_gwbridge}"
|
||||||
|
SYNC_INTERVAL="${SYNC_INTERVAL:-300}"
|
||||||
|
DETACH_UNLABELED="${DETACH_UNLABELED:-false}"
|
||||||
|
|
||||||
|
log() { echo "[watcher] $*"; }
|
||||||
|
warn() { echo "[watcher] $*" >&2; }
|
||||||
|
|
||||||
|
is_excluded() {
|
||||||
|
for n in $EXCLUDED; do
|
||||||
|
[ "$1" = "$n" ] && return 0
|
||||||
|
done
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
is_labeled() {
|
||||||
|
# True alleen als de daemon zelf dit netwerk met het label teruggeeft.
|
||||||
|
# Dit is de single source of truth; nergens anders wordt op het label
|
||||||
|
# gecontroleerd of geparst.
|
||||||
|
[ "$(docker network ls --filter "name=^$1\$" --filter "$LABEL_SELECTOR" --format '{{.Name}}')" = "$1" ]
|
||||||
|
}
|
||||||
|
|
||||||
|
networks_of() {
|
||||||
|
docker inspect "$TRAEFIK" --format \
|
||||||
|
'{{range $name, $_ := .NetworkSettings.Networks}}{{$name}}
|
||||||
|
{{end}}' 2>/dev/null
|
||||||
|
}
|
||||||
|
|
||||||
|
is_connected() {
|
||||||
|
networks_of | grep -qxF "$1"
|
||||||
|
}
|
||||||
|
|
||||||
|
attach() {
|
||||||
|
net="$1"
|
||||||
|
is_excluded "$net" && return 0
|
||||||
|
is_connected "$net" && return 0
|
||||||
|
log "attach: $TRAEFIK -> $net"
|
||||||
|
docker network connect "$net" "$TRAEFIK" >/dev/null 2>&1 || warn "attach $net mislukt"
|
||||||
|
}
|
||||||
|
|
||||||
|
detach() {
|
||||||
|
net="$1"
|
||||||
|
is_excluded "$net" && return 0
|
||||||
|
is_connected "$net" || return 0
|
||||||
|
log "detach: $TRAEFIK -/- $net"
|
||||||
|
docker network disconnect "$net" "$TRAEFIK" >/dev/null 2>&1 || warn "detach $net mislukt"
|
||||||
|
}
|
||||||
|
|
||||||
|
sync() {
|
||||||
|
# Alles met het label verbinden (idempotent, connect-check zit in attach)
|
||||||
|
docker network ls --filter "$LABEL_SELECTOR" --format '{{.Name}}' | while read -r net; do
|
||||||
|
attach "$net"
|
||||||
|
done
|
||||||
|
|
||||||
|
# Optioneel: alles zonder label weer loskoppelen
|
||||||
|
if [ "$DETACH_UNLABELED" = "true" ]; then
|
||||||
|
networks_of | while read -r net; do
|
||||||
|
is_excluded "$net" && continue
|
||||||
|
is_labeled "$net" || detach "$net"
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- opstart ------------------------------------------------------------
|
||||||
|
|
||||||
|
docker inspect "$TRAEFIK" >/dev/null 2>&1 || {
|
||||||
|
warn "container '$TRAEFIK' niet gevonden; restart:unless-stopped probeert het opnieuw";
|
||||||
|
exit 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
log "traefik='$TRAEFIK' label-selector='$LABEL_SELECTOR' sync-interval=${SYNC_INTERVAL}s"
|
||||||
|
|
||||||
|
if [ "$SYNC_INTERVAL" != "0" ]; then
|
||||||
|
(
|
||||||
|
while :; do
|
||||||
|
sleep "$SYNC_INTERVAL"
|
||||||
|
sync
|
||||||
|
done
|
||||||
|
) &
|
||||||
|
SYNC_PID=$!
|
||||||
|
trap 'kill "$SYNC_PID" 2>/dev/null; exit 0' INT TERM
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 1. bestaande netwerken nalopen
|
||||||
|
log "eerste scan..."
|
||||||
|
sync
|
||||||
|
|
||||||
|
# 2. live events volgen
|
||||||
|
# - network create/connect -> label-check op het betrokken netwerk,
|
||||||
|
# connect = connect (handmatige detaches worden ook gerepareerd)
|
||||||
|
# - container start (traefik zelf) -> volledige resync, zo herstellen
|
||||||
|
# de koppelingen na een 'docker compose up -d' van de traefik-stack,
|
||||||
|
# omdat die het container-object vernieuwt en alle endpoints wist
|
||||||
|
docker events \
|
||||||
|
--filter type=network \
|
||||||
|
--filter type=container \
|
||||||
|
--format '{{.Type}} {{.Action}} {{.Actor.Attributes.name}}' |
|
||||||
|
while read -r type action name; do
|
||||||
|
case "$type:$action" in
|
||||||
|
network:create | network:connect)
|
||||||
|
is_labeled "$name" && attach "$name"
|
||||||
|
;;
|
||||||
|
container:start)
|
||||||
|
if [ "$name" = "$TRAEFIK" ]; then
|
||||||
|
log "traefik opnieuw gestart, resync"
|
||||||
|
sync
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
Reference in new issue
Block a user