241 lines
8.1 KiB
YAML
241 lines
8.1 KiB
YAML
# pangolin primary VPS (ionos) — pangolin edge stack.
|
|
# Moved off files_on_host /root/docker-compose.yml into the repo, so Renovate
|
|
# can handle updates (config lives on the host at /root/config + /root/backups
|
|
# etc.; mounts are absolute paths for that reason — systemd periphery has
|
|
# direct host access). crowdsec-manager is pointed at the repo-managed
|
|
# compose file. Original: /root/docker-compose.yml (left in place as backup).
|
|
name: pangolin
|
|
networks:
|
|
default:
|
|
driver: bridge
|
|
enable_ipv6: true
|
|
name: pangolin
|
|
|
|
services:
|
|
crowdsec:
|
|
container_name: crowdsec
|
|
environment:
|
|
COLLECTIONS: crowdsecurity/traefik crowdsecurity/appsec-virtual-patching crowdsecurity/appsec-generic-rules crowdsecurity/linux crowdsecurity/iptables
|
|
ENROLL_INSTANCE_NAME: pangolin-crowdsec
|
|
ENROLL_TAGS: docker
|
|
GID: "1000"
|
|
PARSERS: crowdsecurity/whitelists
|
|
healthcheck:
|
|
interval: 60s
|
|
retries: 15
|
|
test:
|
|
- CMD
|
|
- cscli
|
|
- lapi
|
|
- status
|
|
timeout: 30s
|
|
image: docker.io/crowdsecurity/crowdsec:v1.8.1
|
|
labels:
|
|
- traefik.enable=false
|
|
ports:
|
|
- 127.0.0.1:6060:6060
|
|
- 127.0.0.1:8080:8080
|
|
restart: unless-stopped
|
|
volumes:
|
|
- /root/config/crowdsec:/etc/crowdsec
|
|
- /root/config/crowdsec/db:/var/lib/crowdsec/data
|
|
- /root/config/traefik/logs:/var/log/traefik
|
|
- /var/log/auth.log:/var/log/auth.log:ro
|
|
- /var/log/syslog:/var/log/syslog:ro
|
|
gerbil:
|
|
cap_add:
|
|
- NET_ADMIN
|
|
- SYS_MODULE
|
|
command:
|
|
- --reachableAt=http://gerbil:3004
|
|
- --generateAndSaveKeyTo=/var/config/key
|
|
- --remoteConfig=http://pangolin:3001/api/v1/
|
|
container_name: gerbil
|
|
depends_on:
|
|
pangolin:
|
|
condition: service_healthy
|
|
image: docker.io/fosrl/gerbil:1.5.2
|
|
ports:
|
|
- 51820:51820/udp
|
|
- 21820:21820/udp
|
|
- 443:443
|
|
- 80:80
|
|
- 32400:32400
|
|
- 8082:8082
|
|
restart: unless-stopped
|
|
volumes:
|
|
- /root/config/:/var/config
|
|
pangolin:
|
|
container_name: pangolin
|
|
hostname: pangolin
|
|
healthcheck:
|
|
interval: 10s
|
|
retries: 15
|
|
test:
|
|
- CMD
|
|
- curl
|
|
- -f
|
|
- http://localhost:3001/api/v1/
|
|
timeout: 10s
|
|
image: docker.io/fosrl/pangolin:ee-1.24.0
|
|
restart: unless-stopped
|
|
volumes:
|
|
- /root/config:/app/config
|
|
traefik:
|
|
command:
|
|
- --configFile=/etc/traefik/traefik_config.yml
|
|
container_name: traefik
|
|
depends_on:
|
|
crowdsec:
|
|
condition: service_healthy
|
|
pangolin:
|
|
condition: service_healthy
|
|
image: docker.io/traefik:v3.7
|
|
network_mode: service:gerbil
|
|
restart: unless-stopped
|
|
environment:
|
|
- CF_API_EMAILL=4v792wk2b2@privaterelay.appleid.com
|
|
- CF_DNS_API_TOKEN=yt9Q41S9jg92mxpZaWyd6MyOP6Y7OeC5GdUl1tRD
|
|
volumes:
|
|
- /root/config/traefik:/etc/traefik:ro
|
|
- /root/config/letsencrypt:/letsencrypt
|
|
- /root/config/traefik/logs:/var/log/traefik
|
|
# Traefik Log Dashboard Agent
|
|
traefik-agent:
|
|
image: hhftechnology/traefik-log-dashboard-agent:latest
|
|
restart: unless-stopped
|
|
ports:
|
|
- "5000:5000"
|
|
volumes:
|
|
- /root/data/positions:/data
|
|
- /root/config/traefik/logs:/logs:ro
|
|
- /root/config/maxmind:/geoip:ro
|
|
environment:
|
|
# Log Paths
|
|
- TRAEFIK_LOG_DASHBOARD_ACCESS_PATH=/logs/access.log
|
|
- TRAEFIK_LOG_DASHBOARD_ERROR_PATH=/logs/traefik.log
|
|
# Authentication
|
|
- TRAEFIK_LOG_DASHBOARD_AUTH_TOKEN=VZwCZobpojOAMxJ4X5UGFLebe7WHXiuqCsSE9ahWXzoICTQBVPvXcOP6qVgxczfw
|
|
# System Monitoring
|
|
- TRAEFIK_LOG_DASHBOARD_SYSTEM_MONITORING=true
|
|
# GeoIP Configuration
|
|
- TRAEFIK_LOG_DASHBOARD_GEOIP_ENABLED=true
|
|
- TRAEFIK_LOG_DASHBOARD_GEOIP_CITY_DB=/geoip/GeoLite2-City.mmdb
|
|
- TRAEFIK_LOG_DASHBOARD_GEOIP_COUNTRY_DB=/geoip/GeoLite2-Country.mmdb
|
|
# Log Format
|
|
- TRAEFIK_LOG_DASHBOARD_LOG_FORMAT=json
|
|
# Server Port
|
|
- PORT=5000
|
|
healthcheck:
|
|
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:5000/api/logs/status"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 3
|
|
start_period: 10s
|
|
# Traefik Log Dashboard - Web UI
|
|
traefik-dashboard:
|
|
image: hhftechnology/traefik-log-dashboard:latest
|
|
container_name: traefik-log-dashboard
|
|
restart: unless-stopped
|
|
ports:
|
|
- "3000:3000"
|
|
environment:
|
|
# Agent Configuration
|
|
- AGENT_API_URL=http://traefik-agent:5000
|
|
- AGENT_API_TOKEN=VZwCZobpojOAMxJ4X5UGFLebe7WHXiuqCsSE9ahWXzoICTQBVPvXcOP6qVgxczfw
|
|
- NODE_ENV=production
|
|
- PORT=3000
|
|
depends_on:
|
|
traefik-agent:
|
|
condition: service_healthy
|
|
healthcheck:
|
|
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://127.0.0.1:3000"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 3
|
|
start_period: 30s
|
|
# Optional: MaxMind GeoIP Database Updater
|
|
# maxmind-updater:
|
|
# image: alpine:latest
|
|
# restart: "no"
|
|
# volumes:
|
|
# - /root/config/maxmind:/data
|
|
# environment:
|
|
# - MAXMIND_LICENSE_KEY=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
|
|
# command: >
|
|
# sh -c "
|
|
# apk add --no-cache wget tar &&
|
|
# cd /data &&
|
|
# if [ ! -f GeoLite2-City.mmdb ] || [ \"$(find . -name 'GeoLite2-City.mmdb' -mtime +7)\" ]; then
|
|
# echo 'Updating GeoLite2-City database...'
|
|
# wget -O GeoLite2-City.tar.gz 'https://download.maxmind.com/app/geoip_download?edition_id=GeoLite2-City&lic...'
|
|
# tar --wildcards -xzf GeoLite2-City.tar.gz --strip-components=1 '*/GeoLite2-City.mmdb' &&
|
|
# rm -f GeoLite2-City.tar.gz
|
|
# fi &&
|
|
# if [ ! -f GeoLite2-Country.mmdb ] || [ \"$(find . -name 'GeoLite2-Country.mmdb' -mtime +7)\" ]; then
|
|
# echo 'Updating GeoLite2-Country database...'
|
|
# wget -O GeoLite2-Country.tar.gz 'https://download.maxmind.com/app/geoip_download?edition_id=GeoLite2-Country&lic...'
|
|
# tar --wildcards -xzf GeoLite2-Country.tar.gz --strip-components=1 '*/GeoLite2-Country.mmdb' &&
|
|
# rm -f GeoLite2-Country.tar.gz
|
|
# fi &&
|
|
# echo 'GeoIP databases updated successfully.'
|
|
# "
|
|
prometheus:
|
|
container_name: prometheus
|
|
image: prom/prometheus:latest
|
|
restart: unless-stopped
|
|
command:
|
|
- "--config.file=/etc/prometheus/prometheus.yml"
|
|
- "--web.route-prefix=/prometheus"
|
|
- "--web.external-url=https://powersync.arnoutvw.nl/prometheus"
|
|
ports:
|
|
- 9090:9090
|
|
volumes:
|
|
# - /etc/timezone:/etc/timezone:ro
|
|
# - /etc/localtime:/etc/localtime:ro
|
|
- /root/config/prometheus/prometheus.yml:/etc/prometheus/prometheus.yml
|
|
- /root/config/prometheus/data:/prometheus
|
|
grafana:
|
|
image: grafana/grafana:latest
|
|
container_name: grafana
|
|
restart: unless-stopped
|
|
# dns: ['127.0.0.53', '8.8.8.8']
|
|
ports:
|
|
- 3003:3000
|
|
environment:
|
|
GF_SERVER_ROOT_URL: "https://powersync.arnoutvw.nl/grafana"
|
|
GF_SERVER_SERVE_FROM_SUBPATH: grafana
|
|
volumes:
|
|
# - /etc/timezone:/etc/timezone:ro
|
|
# - /etc/localtime:/etc/localtime:ro
|
|
- /root/config/grafana/data:/var/lib/grafana
|
|
crowdsec-manager:
|
|
image: hhftechnology/crowdsec-manager:latest
|
|
container_name: crowdsec-manager
|
|
restart: unless-stopped
|
|
ports:
|
|
- 8384:8080
|
|
environment:
|
|
- PORT=8080
|
|
- ENVIRONMENT=production
|
|
- DOCKER_HOST=unix:///var/run/docker.sock
|
|
- COMPOSE_FILE=/app/docker-compose.yml
|
|
- PANGOLIN_DIR=/app
|
|
- CONFIG_DIR=/app/config
|
|
- DATABASE_PATH=/app/data/settings.db
|
|
- TRAEFIK_DYNAMIC_CONFIG=/dynamic_config.yml
|
|
- TRAEFIK_STATIC_CONFIG=/etc/traefik/traefik_config.yml
|
|
- TRAEFIK_ACCESS_LOG=/var/log/traefik/access.log
|
|
- TRAEFIK_ERROR_LOG=/var/log/traefik/traefik.log
|
|
- CROWDSEC_ACQUIS_FILE=/etc/crowdsec/acquis.yaml
|
|
- BACKUP_DIR=/app/backups
|
|
- RETENTION_DAYS=60
|
|
- INCLUDE_CROWDSEC=false
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock
|
|
- /root/config:/app/config
|
|
- /etc/komodo/repos/compose-files/pangolin/docker-compose.yml:/app/docker-compose.yml
|
|
- /root/backups:/app/backups
|
|
- /root/config/traefik/logs:/app/logs
|
|
- /root/data:/app/data
|
|
- /root/config/traefik/logs:/var/log/traefik |