services: app: build: context: . dockerfile: Dockerfile ports: - "8080:8080" environment: - PORT=8080 # Set a strong password in a .env file next to this compose file. # Note: POSTGRES_PASSWORD only applies when the volume is first created. - DATABASE_URL=postgres://flowreader:${POSTGRES_PASSWORD:-flowreader}@db:5432/flowreader?sslmode=disable # Close public sign-ups once your account exists (the first account is admin). - REGISTRATION_ENABLED=${REGISTRATION_ENABLED:-true} # Behind a reverse proxy (Traefik, NPM, Caddy…): its IP/CIDR, so rate # limiting sees real client IPs. Leave empty when exposed directly. - TRUSTED_PROXIES=${TRUSTED_PROXIES:-} # Force Secure cookies when served over HTTPS behind a proxy. - COOKIE_SECURE=${COOKIE_SECURE:-} - GOMEMLIMIT=48MiB depends_on: db: condition: service_healthy restart: unless-stopped healthcheck: test: [ "CMD", "wget", "-q", "--spider", "http://localhost:8080/health" ] interval: 10s timeout: 5s retries: 3 start_period: 10s deploy: resources: limits: memory: 64M db: image: postgres:16-alpine environment: - POSTGRES_USER=flowreader - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-flowreader} - POSTGRES_DB=flowreader volumes: - postgres_data:/var/lib/postgresql/data # Not published on the host: only the app container needs the database. # Uncomment for local debugging only (and bind to 127.0.0.1). # ports: # - "127.0.0.1:5432:5432" restart: unless-stopped healthcheck: test: [ "CMD-SHELL", "pg_isready -U flowreader -d flowreader" ] interval: 5s timeout: 5s retries: 5 # RAM Optimization (from Architecture NFR1) command: > postgres -c shared_buffers=24MB -c max_connections=20 -c work_mem=2MB deploy: resources: limits: memory: 80M volumes: postgres_data: