Files
FlowReader/docker-compose.unraid.yaml
Antigravity AgentandClaude Opus 5.5 9eaed0aea4 chore(deploy): non-root image, reproducible builds, private database
- Dockerfile: Go 1.26, npm ci, go mod verify, non-root user, alpine 3.22.
- Compose: Postgres no longer published on the host, password and new
  security settings read from .env, GOMEMLIMIT.
- README: document new environment variables and reading shortcuts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-09 07:34:09 +02:00

58 lines
2.2 KiB
YAML

services:
app:
# Utilise l'image construite par GitHub Actions
image: ghcr.io/r0m1k3/flowreader:latest
container_name: flowreader-app
# build:
# context: .
# dockerfile: Dockerfile
ports:
- "8080:8080"
environment:
- PORT=8080
# Set a strong password in a .env file next to this compose file.
# Note: POSTGRES_PASSWORD only applies when the volume is first created.
- DATABASE_URL=postgres://flowreader:${POSTGRES_PASSWORD:-flowreader}@db:5432/flowreader?sslmode=disable
# Close public sign-ups once your account exists (the first account is admin).
- REGISTRATION_ENABLED=${REGISTRATION_ENABLED:-true}
# Behind a reverse proxy (Traefik, NPM, Caddy…): its IP/CIDR, so rate
# limiting sees real client IPs. Leave empty when exposed directly.
- TRUSTED_PROXIES=${TRUSTED_PROXIES:-}
# Force Secure cookies when served over HTTPS behind a proxy.
- COOKIE_SECURE=${COOKIE_SECURE:-}
- GOMEMLIMIT=48MiB
# Optional: AI summaries (OpenRouter). Leave empty to disable.
- OPENROUTER_API_KEY=${OPENROUTER_API_KEY:-}
depends_on:
db:
condition: service_healthy
restart: unless-stopped
# Mappage des logs si nécessaire
# volumes:
# - /mnt/user/appdata/flowreader/logs:/app/logs
db:
image: postgres:16-alpine
container_name: flowreader-db
environment:
- POSTGRES_USER=flowreader
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-flowreader}
- POSTGRES_DB=flowreader
volumes:
# Persistance des données sur Unraid (chemin typique)
- /mnt/user/appdata/flowreader/postgres_data:/var/lib/postgresql/data
# Not published on the host: only the app container needs the database.
# Uncomment for local debugging only (and bind to 127.0.0.1).
# ports:
# - "127.0.0.1:5432:5432"
restart: unless-stopped
healthcheck:
test: [ "CMD-SHELL", "pg_isready -U flowreader -d flowreader" ]
interval: 5s
timeout: 5s
retries: 5
command: >
postgres -c shared_buffers=24MB -c max_connections=20 -c work_mem=2MB
# Pas de volumes nommés globaux si on utilise des bind mounts directs pour Unraid