mirror of
https://github.com/R0m1k3/FlowReader.git
synced 2026-10-11 17:28:05 +02:00
- Dockerfile: Go 1.26, npm ci, go mod verify, non-root user, alpine 3.22. - Compose: Postgres no longer published on the host, password and new security settings read from .env, GOMEMLIMIT. - README: document new environment variables and reading shortcuts. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
64 lines
2.0 KiB
YAML
64 lines
2.0 KiB
YAML
services:
|
|
app:
|
|
build:
|
|
context: .
|
|
dockerfile: Dockerfile
|
|
ports:
|
|
- "8080:8080"
|
|
environment:
|
|
- PORT=8080
|
|
# Set a strong password in a .env file next to this compose file.
|
|
# Note: POSTGRES_PASSWORD only applies when the volume is first created.
|
|
- DATABASE_URL=postgres://flowreader:${POSTGRES_PASSWORD:-flowreader}@db:5432/flowreader?sslmode=disable
|
|
# Close public sign-ups once your account exists (the first account is admin).
|
|
- REGISTRATION_ENABLED=${REGISTRATION_ENABLED:-true}
|
|
# Behind a reverse proxy (Traefik, NPM, Caddy…): its IP/CIDR, so rate
|
|
# limiting sees real client IPs. Leave empty when exposed directly.
|
|
- TRUSTED_PROXIES=${TRUSTED_PROXIES:-}
|
|
# Force Secure cookies when served over HTTPS behind a proxy.
|
|
- COOKIE_SECURE=${COOKIE_SECURE:-}
|
|
- GOMEMLIMIT=48MiB
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
restart: unless-stopped
|
|
healthcheck:
|
|
test: [ "CMD", "wget", "-q", "--spider", "http://localhost:8080/health" ]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 10s
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 64M
|
|
|
|
db:
|
|
image: postgres:16-alpine
|
|
environment:
|
|
- POSTGRES_USER=flowreader
|
|
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-flowreader}
|
|
- POSTGRES_DB=flowreader
|
|
volumes:
|
|
- postgres_data:/var/lib/postgresql/data
|
|
# Not published on the host: only the app container needs the database.
|
|
# Uncomment for local debugging only (and bind to 127.0.0.1).
|
|
# ports:
|
|
# - "127.0.0.1:5432:5432"
|
|
restart: unless-stopped
|
|
healthcheck:
|
|
test: [ "CMD-SHELL", "pg_isready -U flowreader -d flowreader" ]
|
|
interval: 5s
|
|
timeout: 5s
|
|
retries: 5
|
|
# RAM Optimization (from Architecture NFR1)
|
|
command: >
|
|
postgres -c shared_buffers=24MB -c max_connections=20 -c work_mem=2MB
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 80M
|
|
|
|
volumes:
|
|
postgres_data:
|