Compare commits

9 Commits
Author SHA1 Message Date
Renovate Bot 3e42185bbc chore(deps): update ghcr.io/immich-app/postgres docker tag to v17 2026-10-03 20:02:32 +00:00
Arnout van Westen 5e7ab46f71 refactor(networks): private compose networks instead of shared bridge
traefik-network-connector attaches traefik to container networks labelled
traefik.enable=true, so stacks no longer need the default bridge:
- changedetection: app+sockpuppetbrowser on changedetection network, links out
- postiz: postiz-network, legacy links out
- teslamate: teslamate network, DB via service DNS (postgresql17), 5432
  hostport dropped, teslamateapi -> teslamate:4000 internal
- download: bookorbit+bookorbit-db on bookorbit network (5435 hostport dropped)
- immich: immich network in .env host IP refs -> service/container DNS
All published host ports kept unless removed above; pangolin target
hostnames still point at 192.168.10.144 host ports.
2026-10-03 21:53:13 +02:00
Arnout van Westen 9ab0357f16 feat(infra): add traefik-network-connector; dawarich off shared bridge
- new stack traefik-network-connector: attaches atlas traefik to networks
  of containers labelled traefik.enable=true (obeone/traefik_network_connector)
- dawarich: rewrite to upstream compose style (private dawarich network,
  no default-bridge sharing, no legacy links). Keep pinned image tags,
  host port 3007 (pangolin/newt target), photon override, concurrency 10.
  RAILS_ENV development -> production (+ SECRET_KEY_BASE, upstream default).
2026-10-03 07:53:12 +02:00
renovate-bot 122ca76eb8 Merge pull request 'chore(deps): update n8nio/n8n docker tag to v2.42.2' (#436) from renovate/n8nio-n8n-2.x into main 2026-10-02 22:03:14 +02:00
renovate-bot 0e1806a8f3 Merge pull request 'chore(deps): update ghcr.io/gitroomhq/postiz-app docker tag to v2.25.0' (#435) from renovate/ghcr.io-gitroomhq-postiz-app-2.x into main 2026-10-02 22:02:38 +02:00
Renovate Bot 3bb40ad67e chore(deps): update n8nio/n8n docker tag to v2.42.2 2026-10-02 20:02:38 +00:00
Renovate Bot adbf36a9d3 chore(deps): update ghcr.io/gitroomhq/postiz-app docker tag to v2.25.0 2026-10-02 20:02:37 +00:00
renovate-bot a6fe126fbb Merge pull request 'chore(deps): update fosrl/newt docker tag to v1.18.1' (#434) from renovate/fosrl-newt-1.x into main 2026-10-02 22:02:36 +02:00
Renovate Bot 5fbdd7ffde chore(deps): update fosrl/newt docker tag to v1.18.1 2026-10-02 20:02:33 +00:00
10 changed files with 148 additions and 91 deletions

No files matched your search

+2 -2
View File
@@ -112,7 +112,7 @@ services:
hostname: "e6ea728334b3"
image: "fosrl/newt:1.12.5"
image: "fosrl/newt:1.18.1"
ipc: "private"
@@ -176,7 +176,7 @@ services:
hostname: "62a85da202e1"
image: "fosrl/newt:1.12.5"
image: "fosrl/newt:1.18.1"
ipc: "private"
+9 -5
View File
@@ -1,13 +1,15 @@
networks:
changedetection:
services:
changedetection:
image: ghcr.io/dgtlmoon/changedetection.io:0.60.8
container_name: changedetection
hostname: changedetection
network_mode: "bridge"
networks:
- changedetection
depends_on:
- browser-sockpuppet-chrome
links:
- browser-sockpuppet-chrome
volumes:
- changedetection-data:/datastore
# Configurable proxy list support, see https://github.com/dgtlmoon/changedetection.io/wiki/Proxy-configuration#proxy-list-support
@@ -93,8 +95,9 @@ services:
- "5353:5000"
restart: unless-stopped
labels:
- traefik.enable=true
- traefik.http.routers.changedetection.rule=Host(`changedetection.arnoutvw.nl`)
- traefik.docker.network=changedetection_default
- traefik.http.services.changedetection.loadbalancer.server.port=5000
# Used for fetching pages via WebDriver+Chrome where you need Javascript support.
# Now working on arm64 (needs testing on rPi - tested on Oracle ARM instance)
@@ -112,7 +115,8 @@ services:
browser-sockpuppet-chrome:
hostname: browser-sockpuppet-chrome
image: dgtlmoon/sockpuppetbrowser@sha256:1d8f72d2ce2085faed4232e5ae1e65c02efe5b831a18e127829b267c260b4fb2
network_mode: bridge
networks:
- changedetection
cap_add:
- SYS_ADMIN
# SYS_ADMIN might be too much, but it can be needed on your platform https://github.com/puppeteer/puppeteer/blob/main/docs/troubleshooting.md#running-puppeteer-on-gitlabci
+44 -39
View File
@@ -1,27 +1,47 @@
# Based on upstream https://github.com/Freika/dawarich/blob/master/docker/docker-compose.yml
# Local deviations:
# - image tags pinned (repo convention; Renovate bumps)
# - host port 3007 -> 3000: pangolin (newt) and LAN clients target
# 192.168.10.144:3007, so it must stay published on the host
# - traefik labels on dawarich_app: Atlas traefik does NOT sit on this
# network; traefik-network-connector (own stack) attaches it on start
# - RAILS_ENV production (upstream default; install predates the switch)
# - BACKGROUND_PROCESSING_CONCURRENCY 10 (upstream default 3; tuned for
# large imports)
# - local photon geocoding (photon container currently disabled)
networks:
dawarich:
services:
dawarich_redis:
image: redis:7.4-alpine
container_name: dawarich_redis
command: redis-server
network_mode: bridge
command: >
redis-server
--save 900 1
--save 300 10
--appendonly no
networks:
- dawarich
volumes:
- dawarich_shared:/data
restart: always
healthcheck:
test: [ "CMD-SHELL", "redis-cli --raw incr ping || exit 1" ]
test: [ "CMD", "redis-cli", "--raw", "incr", "ping" ]
interval: 10s
retries: 5
start_period: 30s
timeout: 10s
dawarich_db:
image: postgis/postgis:17-3.5-alpine
shm_size: 1G
container_name: dawarich_db
network_mode: bridge
volumes:
- dawarich_db_data:/var/lib/postgresql/data
- dawarich_shared:/var/shared
# - ./postgresql.conf:/etc/postgresql/postgresql.conf # Optional, uncomment if you want to use a custom config
networks:
- dawarich
environment:
POSTGRES_USER: postgres
POSTGRES_PASSWORD: password
@@ -33,31 +53,32 @@ services:
retries: 5
start_period: 30s
timeout: 10s
# command: postgres -c config_file=/etc/postgresql/postgresql.conf # Use custom config, uncomment if you want to use a custom config
dawarich_app:
labels:
- traefik.constraint=proxy-public
- traefik.http.routers.nginx.rule=Host(`dawarich.arnoutvw.nl`)
image: freikin/dawarich:1.15.3
container_name: dawarich_app
network_mode: bridge
volumes:
- dawarich_public:/var/app/public
- dawarich_watched:/var/app/tmp/imports/watched
- dawarich_storage:/var/app/storage
links:
- dawarich_db
- dawarich_redis
- dawarich_db_data:/dawarich_db_data
networks:
- dawarich
labels:
- traefik.enable=true
- traefik.http.routers.dawarich.rule=Host(`dawarich.arnoutvw.nl`)
- traefik.http.services.dawarich.loadbalancer.server.port=3000
ports:
# custom host port: pangolin/newt + LAN target 192.168.10.144:3007
- 3007:3000
- 9397:9394 # Prometheus exporter, uncomment if needed
stdin_open: true
tty: true
entrypoint: web-entrypoint.sh
command: [ 'bin/rails', 'server', '-p', '3000', '-b', '::' ]
restart: always
restart: unless-stopped
environment:
RAILS_ENV: development
RAILS_ENV: production
SECRET_KEY_BASE: 2f5e59518ddeaeb978c73bc265eea20a91d5fe203d2a45280bd8fbf62b447b57
REDIS_URL: redis://dawarich_redis:6379
DATABASE_HOST: dawarich_db
DATABASE_USERNAME: postgres
@@ -65,13 +86,6 @@ services:
DATABASE_NAME: dawarich_development
MIN_MINUTES_SPENT_IN_CITY: 60
APPLICATION_HOSTS: localhost,dawarich.arnoutvw.nl,192.168.10.144
TIME_ZONE: Europe/London
APPLICATION_PROTOCOL: http
PROMETHEUS_EXPORTER_ENABLED: false
PROMETHEUS_EXPORTER_HOST: 0.0.0.0
PROMETHEUS_EXPORTER_PORT: 9394
SELF_HOSTED: "true"
STORE_GEODATA: "true"
PHOTON_API_HOST: 192.168.10.144:2322
PHOTON_API_USE_HTTPS: false
logging:
@@ -95,8 +109,9 @@ services:
deploy:
resources:
limits:
cpus: '0.50' # Limit CPU usage to 50% of one core
memory: '4G' # Limit memory usage to 4GB
cpus: '0.50'
memory: '4G'
dawarich_sidekiq:
image: freikin/dawarich:1.15.3
container_name: dawarich_sidekiq
@@ -104,33 +119,23 @@ services:
- dawarich_public:/var/app/public
- dawarich_watched:/var/app/tmp/imports/watched
- dawarich_storage:/var/app/storage
network_mode: bridge
links:
- dawarich_db
- dawarich_redis
networks:
- dawarich
stdin_open: true
tty: true
entrypoint: sidekiq-entrypoint.sh
command: [ 'sidekiq' ]
restart: always
restart: unless-stopped
environment:
RAILS_ENV: development
RAILS_ENV: production
REDIS_URL: redis://dawarich_redis:6379
DATABASE_HOST: dawarich_db
DATABASE_USERNAME: postgres
DATABASE_PASSWORD: password
DATABASE_NAME: dawarich_development
APPLICATION_HOSTS: localhost
BACKGROUND_PROCESSING_CONCURRENCY: 10
APPLICATION_PROTOCOL: http
PROMETHEUS_EXPORTER_ENABLED: false
PROMETHEUS_EXPORTER_HOST: dawarich_app
PROMETHEUS_EXPORTER_PORT: 9394
SELF_HOSTED: "true"
STORE_GEODATA: "true"
PHOTON_API_HOST: 192.168.10.144:2322
PHOTON_API_USE_HTTPS: false
logging:
driver: "json-file"
options:
+12 -7
View File
@@ -499,7 +499,8 @@ services:
bookorbit:
image: ghcr.io/bookorbit/bookorbit:3.2.0
container_name: bookorbit-app
network_mode: bridge
networks:
- bookorbit
ports:
- "3099:3000"
environment:
@@ -509,8 +510,8 @@ services:
PUID: 99
PGID: 100
APP_URL: https://bookorbit.arnoutvw.nl
POSTGRES_HOST: 192.168.10.144
POSTGRES_PORT: 5435
POSTGRES_HOST: bookorbit-db
POSTGRES_PORT: 5432
POSTGRES_USER: bookorbit
POSTGRES_PASSWORD: ${BOOKORBIT_DB_PASSWORD}
POSTGRES_DB: bookorbit
@@ -539,7 +540,9 @@ services:
stop_grace_period: 30s
restart: unless-stopped
labels:
traefik.http.routers.bookorbit.rule: "Host(`bookorbit.arnoutvw.nl`)"
- traefik.enable=true
- traefik.http.routers.bookorbit.rule=Host(`bookorbit.arnoutvw.nl`)
- traefik.http.services.bookorbit.loadbalancer.server.port=3000
shelfarr:
container_name: shelfarr
@@ -595,9 +598,8 @@ services:
bookorbit-db:
image: pgvector/pgvector:pg18
container_name: bookorbit-db
network_mode: bridge
ports:
- "5435:5432"
networks:
- bookorbit
environment:
TZ: Europe/Berlin
POSTGRES_USER: bookorbit
@@ -644,3 +646,6 @@ services:
volumes:
28eea8bfffd285350962765a88ff04ea9d580fe872771d5c06fd62afb26f2ef2:
external: true
networks:
bookorbit:
+7 -7
View File
@@ -11,7 +11,7 @@ DB_DATA_LOCATION=/mnt/user/appdata/PostgreSQL_Immich
# To set a timezone, uncomment the next line and change Etc/UTC to a TZ identifier from this list: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List
TZ=Europe/Berlin
IMMICH_MACHINE_LEARNING_URL=http://192.168.10.144:3003
IMMICH_MACHINE_LEARNING_URL=http://immich-machine-learning:3003
# The Immich version to use. You can pin this to a specific version like "v2.1.0"
IMMICH_VERSION=v2
@@ -24,14 +24,14 @@ DB_PASSWORD=immich
###################################################################################
DB_USERNAME=immich
DB_DATABASE_NAME=immich
DB_HOSTNAME=192.168.10.144
DB_HOST=192.168.10.144
DB_PORT=5434
DB_HOSTNAME=immich_postgres
DB_HOST=immich_postgres
DB_PORT=5432
#redis
REDIS_PORT=6380
REDIS_PORT=6379
REDIS_PASSWORD=
REDIS_HOSTNAME=192.168.10.144
REDIS_HOSTNAME=immich_redis
#Machine learing
MACHINE_LEARNING_HOST=0.0.0.0
@@ -40,5 +40,5 @@ MACHINE_LEARNING_MAX_BATCH_SIZE__FACIAL_RECOGNITION=1
MACHINE_LEARNING_CACHE_FOLDER=/config/machine-learning/models
MACHINE_LEARNING_MAX_BATCH_SIZE__TEXT_RECOGNITION=3
IMMICH_URL = "http://192.168.10.144:8693" # Your immich instace ip address and port
IMMICH_URL = "http://immich-server:2283" # internal container route (own compose network)
EXTERNAL_IMMICH_URL = "https://photos.arnoutvw.nl" # External address of immich
+22 -7
View File
@@ -9,11 +9,17 @@
name: immich
networks:
immich:
services:
immich-server:
network_mode: bridge
networks:
- immich
labels:
- traefik.enable=true
- traefik.http.routers.immich.rule=Host(`photos.arnoutvw.nl`)
- traefik.http.services.immich.loadbalancer.server.port=2283
- pangolin.proxy-resources.immich.name=immich
- pangolin.proxy-resources.immich.full-domain=photos.arnoutvw.nl
- pangolin.proxy-resources.immich.protocol=http
@@ -63,7 +69,8 @@ services:
disable: false
immich-machine-learning:
network_mode: bridge
networks:
- immich
ports:
- '3003:3003'
container_name: immich_machine_learning
@@ -85,7 +92,8 @@ services:
redis:
container_name: immich_redis
image: docker.io/valkey/valkey:9.1.2-alpine
network_mode: "bridge"
networks:
- immich
ports:
- '6380:6379'
healthcheck:
@@ -95,7 +103,8 @@ services:
database:
container_name: immich_postgres
image: ghcr.io/immich-app/postgres:17-vectorchord0.4.2-pgvectors0.3.0
network_mode: "bridge"
networks:
- immich
ports:
- '5434:5432'
labels:
@@ -134,9 +143,12 @@ services:
power-tools:
container_name: immich_power_tools
image: ghcr.io/varun-raj/immich-power-tools:0.19.1
network_mode: bridge
networks:
- immich
labels:
- traefik.enable=true
- traefik.http.routers.immich-powertools.rule=Host(`immich-power-tools.arnoutvw.nl`)
- traefik.http.services.immich-powertools.loadbalancer.server.port=3000
ports:
- "8029:3000"
env_file:
@@ -144,14 +156,17 @@ services:
immich-proxy:
container_name: immich_proxy
image: ghcr.io/arnoutvw/yaiiu/immich-proxy:sha-8a197d0
network_mode: bridge
networks:
- immich
ports:
- "8694:8080"
environment:
- IMMICH_SERVER_URL=http://192.168.10.144:8693
- IMMICH_SERVER_URL=http://immich-server:2283
- IMMICH_API_KEY=8FeEvF5Fdybpp9GM15x29VgchYtKqqgAgozX9Z5TbW4
labels:
- traefik.enable=true
- traefik.http.routers.immich-proxy.rule=Host(`immich-proxy.arnoutvw.nl`)
- traefik.http.services.immich-proxy.loadbalancer.server.port=8080
- pangolin.proxy-resources.immich-proxy.name=immich-proxy
- pangolin.proxy-resources.immich-proxy.full-domain=immich-proxy.arnoutvw.nl
- pangolin.proxy-resources.immich-proxy.protocol=http
+1 -1
View File
@@ -13,7 +13,7 @@ services:
- "N8N_RELEASE_TYPE=stable"
- "NODE_ENV=production"
- "NPM_CONFIG_UPDATE_NOTIFIER=false"
image: "n8nio/n8n:2.41.6"
image: "n8nio/n8n:2.42.2"
ipc: "private"
logging:
driver: "json-file"
+12 -11
View File
@@ -1,9 +1,14 @@
networks:
postiz-network:
external: false
services:
postiz:
image: ghcr.io/gitroomhq/postiz-app:v2.24.0
image: ghcr.io/gitroomhq/postiz-app:v2.25.0
container_name: postiz
restart: always
network_mode: bridge
networks:
- postiz-network
environment:
# === Required Settings
MAIN_URL: "https://postiz.arnoutvw.nl"
@@ -117,13 +122,11 @@ services:
ports:
- "5000:5000"
labels:
- "traefik.enable=true"
- "traefik.http.routers.postiz.rule=Host(`postiz.arnoutvw.nl`)" # Replace with your domain
- "traefik.http.services.postiz.loadbalancer.server.port=5000" # Internal port for postiz
- "traefik.http.routers.postiz.entrypoints=https" # Postiz requires HTTPS
- "traefik.http.routers.postiz.tls=true"
links:
- postiz-postgres
- postiz-redis
depends_on:
postiz-postgres:
condition: service_healthy
@@ -134,7 +137,8 @@ services:
image: postgres:17-alpine
container_name: postiz-postgres
restart: always
network_mode: bridge
networks:
- postiz-network
environment:
POSTGRES_PASSWORD: postiz-password
POSTGRES_USER: postiz-user
@@ -150,7 +154,8 @@ services:
image: redis:7.4
container_name: postiz-redis
restart: always
network_mode: bridge
networks:
- postiz-network
healthcheck:
test: redis-cli ping
interval: 10s
@@ -170,8 +175,4 @@ volumes:
external: false
postiz-uploads:
external: false
networks:
postiz-network:
external: false
+21 -12
View File
@@ -1,13 +1,17 @@
networks:
teslamate:
services:
teslamate:
container_name: "teslamate"
image: teslamate/teslamate:4.3.0
restart: always
network_mode: "bridge"
networks:
- teslamate
environment:
- "DATABASE_USER=teslamate"
- "DATABASE_NAME=teslamate"
- "DATABASE_HOST=192.168.10.144"
- "DATABASE_HOST=postgresql17"
- "DATABASE_PASS=${DATABASE_PASS}"
- "DATABASE_PORT=5432"
- "MQTT_HOST=192.168.10.54"
@@ -25,15 +29,16 @@ services:
cap_drop:
- ALL
labels:
traefik.http.routers.teslamate.rule: "Host(`teslamate.arnoutvw.nl`)"
- traefik.enable=true
- traefik.http.routers.teslamate.rule=Host(`teslamate.arnoutvw.nl`)
- traefik.http.services.teslamate.loadbalancer.server.port=4000
postgresql17:
container_name: "postgresql17"
image: postgres:17-alpine3.22
restart: always
network_mode: "bridge"
ports:
- "5432:5432"
networks:
- teslamate
environment:
- "HOST_CONTAINERNAME=postgresql17"
- "POSTGRES_USER=postgres"
@@ -46,13 +51,14 @@ services:
container_name: "teslamate-grafana"
image: teslamate/grafana:4.3.0
restart: always
network_mode: "bridge"
networks:
- teslamate
environment:
- "GF_AUTH_GENERIC_OAUTH_SCOPES=openid profile email"
- "GF_AUTH_GENERIC_OAUTH_TOKEN_URL=https://pass.arnoutvw.nl/api/oidc/token"
- "HOST_OS=Unraid"
- "DATABASE_USER=teslamate"
- "DATABASE_HOST=192.168.10.144"
- "DATABASE_HOST=postgresql17"
- "GF_AUTH_GENERIC_OAUTH_NAME=PocketID"
- "GF_AUTH_GENERIC_OAUTH_ALLOW_SIGN_UP=true"
- "GF_AUTH_DISABLE_LOGIN_FORM=false"
@@ -83,7 +89,9 @@ services:
- "/mnt/cache/appdata/teslamate-customdashboard/Teslamate-CustomGrafanaDashboards/dashboards:/TeslamateCustomDashboards"
- "/mnt/user/appdata/telsamate-grafana:/var/lib/grafana"
labels:
traefik.http.routers.tesla.rule: "Host(`tesla.arnoutvw.nl`)"
- traefik.enable=true
- traefik.http.routers.tesla.rule=Host(`tesla.arnoutvw.nl`)
- traefik.http.services.tesla.loadbalancer.server.port=3000
TeslaMate-ABRP:
container_name: "TeslaMate-ABRP"
@@ -116,7 +124,8 @@ services:
restart: "always"
teslamateapi:
container_name: "teslamateapi"
network_mode: "bridge"
networks:
- teslamate
image: tobiasehlert/teslamateapi:1.25.0
restart: always
environment:
@@ -124,7 +133,7 @@ services:
- DATABASE_USER=teslamate
- "DATABASE_PASS=${DATABASE_PASS}"
- DATABASE_NAME=teslamate
- DATABASE_HOST=192.168.10.144
- DATABASE_HOST=postgresql17
- "MQTT_HOST=192.168.10.54"
- "MQTT_PASSWORD=${MQTT_PASSWORD}"
- "MQTT_TLS_ACCEPT_INVALID_CERTS=true"
@@ -133,7 +142,7 @@ services:
- "MQTT_TLS=false"
- "MQTT_PORT=1883"
- TZ=Europe/Berlin
- TESLAMATE_HOST=192.168.10.144
- TESLAMATE_HOST=teslamate
- TESLAMATE_PORT=4000
- API_TOKEN=826d3b8b-daad-48c7-ad3b-8bdaade8c706
ports:
@@ -0,0 +1,18 @@
# Attaches the Atlas traefik (container_name "traefik", dockerman) to the
# docker networks of any container labelled `traefik.enable=true`, so stacks
# can use their own private compose network instead of sharing the default
# bridge with traefik. https://github.com/obeone/traefik_network_connector
# No version tags published yet — only :latest.
services:
traefik-network-connector:
image: ghcr.io/obeone/traefik_network_connector:latest
container_name: traefik-network-connector
restart: unless-stopped
init: true
network_mode: bridge
volumes:
- /var/run/docker.sock:/var/run/docker.sock
environment:
TZ: Europe/Amsterdam
TRAEFIK_CONTAINERNAME: traefik
LOGLEVEL: INFO