Files
FlowReader/docker-compose.yaml
Antigravity AgentandClaude Opus 5.5 9eaed0aea4 chore(deploy): non-root image, reproducible builds, private database
- Dockerfile: Go 1.26, npm ci, go mod verify, non-root user, alpine 3.22.
- Compose: Postgres no longer published on the host, password and new
  security settings read from .env, GOMEMLIMIT.
- README: document new environment variables and reading shortcuts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-09 07:34:09 +02:00

64 lines
2.0 KiB
YAML

services:
app:
build:
context: .
dockerfile: Dockerfile
ports:
- "8080:8080"
environment:
- PORT=8080
# Set a strong password in a .env file next to this compose file.
# Note: POSTGRES_PASSWORD only applies when the volume is first created.
- DATABASE_URL=postgres://flowreader:${POSTGRES_PASSWORD:-flowreader}@db:5432/flowreader?sslmode=disable
# Close public sign-ups once your account exists (the first account is admin).
- REGISTRATION_ENABLED=${REGISTRATION_ENABLED:-true}
# Behind a reverse proxy (Traefik, NPM, Caddy…): its IP/CIDR, so rate
# limiting sees real client IPs. Leave empty when exposed directly.
- TRUSTED_PROXIES=${TRUSTED_PROXIES:-}
# Force Secure cookies when served over HTTPS behind a proxy.
- COOKIE_SECURE=${COOKIE_SECURE:-}
- GOMEMLIMIT=48MiB
depends_on:
db:
condition: service_healthy
restart: unless-stopped
healthcheck:
test: [ "CMD", "wget", "-q", "--spider", "http://localhost:8080/health" ]
interval: 10s
timeout: 5s
retries: 3
start_period: 10s
deploy:
resources:
limits:
memory: 64M
db:
image: postgres:16-alpine
environment:
- POSTGRES_USER=flowreader
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-flowreader}
- POSTGRES_DB=flowreader
volumes:
- postgres_data:/var/lib/postgresql/data
# Not published on the host: only the app container needs the database.
# Uncomment for local debugging only (and bind to 127.0.0.1).
# ports:
# - "127.0.0.1:5432:5432"
restart: unless-stopped
healthcheck:
test: [ "CMD-SHELL", "pg_isready -U flowreader -d flowreader" ]
interval: 5s
timeout: 5s
retries: 5
# RAM Optimization (from Architecture NFR1)
command: >
postgres -c shared_buffers=24MB -c max_connections=20 -c work_mem=2MB
deploy:
resources:
limits:
memory: 80M
volumes:
postgres_data: