mirror of
https://github.com/R0m1k3/Regisflow.git
synced 2026-10-12 01:39:58 +02:00
Simplify installation by removing network configuration and IP presets
Refactors Docker Compose files and installation scripts to use default Docker network and remove IP pre-configurations for easier setup. Replit-Commit-Author: Agent Replit-Commit-Session-Id: 91318273-c764-4fd4-be04-bdc12c38af32 Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/0715008c-7244-40f4-befc-26c014852236/b677ee4d-d452-4e7b-9ac9-ca1e468cd60b.jpg
This commit is contained in:
1 parent
5bf67982b9
commit
b2acb20aa6
8 files changed
+380
-180
No files matched your search
+1
-1
@@ -16,7 +16,7 @@ RegisFlow est maintenant configuré pour une installation complètement automati
|
||||
### Option 2 : Installation manuelle
|
||||
|
||||
```bash
|
||||
# Construire et démarrer
|
||||
# Construire et démarrer (configuration simple)
|
||||
docker-compose build
|
||||
docker-compose up -d
|
||||
```
|
||||
|
||||
@@ -0,0 +1,152 @@
|
||||
# Configuration Réseau Docker - RegisFlow
|
||||
|
||||
## 🌐 Problématique des Conflits Réseau
|
||||
|
||||
Le sous-réseau `172.20.0.0/24` peut créer des conflits avec des réseaux existants sur certains systèmes. Pour éviter ces problèmes, RegisFlow propose plusieurs configurations.
|
||||
|
||||
## 🔧 Options de Configuration
|
||||
|
||||
### Option 1 : Installation Simple (Recommandée)
|
||||
|
||||
**Fichier** : `docker-compose.simple.yml`
|
||||
|
||||
```yaml
|
||||
# Utilise le réseau par défaut de Docker
|
||||
networks:
|
||||
default:
|
||||
driver: bridge
|
||||
```
|
||||
|
||||
**Avantages** :
|
||||
- Aucun conflit de sous-réseau
|
||||
- Docker gère automatiquement les adresses IP
|
||||
- Configuration la plus simple
|
||||
- Idéal pour tests et développement
|
||||
|
||||
**Utilisation** :
|
||||
```bash
|
||||
docker-compose -f docker-compose.simple.yml up -d
|
||||
```
|
||||
|
||||
### Option 2 : Configuration Sécurisée
|
||||
|
||||
**Fichier** : `docker-compose.yml`
|
||||
|
||||
```yaml
|
||||
# Réseau personnalisé avec sous-réseau dédié
|
||||
networks:
|
||||
regisflow-internal:
|
||||
driver: bridge
|
||||
internal: false
|
||||
ipam:
|
||||
driver: default
|
||||
config:
|
||||
- subnet: 192.168.200.0/24
|
||||
ip_range: 192.168.200.0/28
|
||||
gateway: 192.168.200.1
|
||||
```
|
||||
|
||||
**Avantages** :
|
||||
- Isolement réseau complet
|
||||
- Contrôle total des adresses IP
|
||||
- Sécurité renforcée
|
||||
- Idéal pour production
|
||||
|
||||
**Utilisation** :
|
||||
```bash
|
||||
docker-compose -f docker-compose.yml -f docker-compose.prod.yml up -d
|
||||
```
|
||||
|
||||
### Option 3 : Configuration Personnalisée
|
||||
|
||||
Si vous avez des exigences spécifiques, modifiez le sous-réseau :
|
||||
|
||||
```yaml
|
||||
networks:
|
||||
regisflow-internal:
|
||||
driver: bridge
|
||||
ipam:
|
||||
driver: default
|
||||
config:
|
||||
- subnet: 10.100.0.0/24 # Votre sous-réseau
|
||||
```
|
||||
|
||||
## 📋 Sous-réseaux Recommandés
|
||||
|
||||
### Évitez ces plages (souvent utilisées) :
|
||||
- `172.16.0.0/12` - Réseaux privés Docker
|
||||
- `192.168.1.0/24` - Réseaux domestiques
|
||||
- `10.0.0.0/8` - Réseaux d'entreprise
|
||||
|
||||
### Utilisez ces plages (plus sûres) :
|
||||
- `192.168.200.0/24` - Peu utilisé
|
||||
- `172.30.0.0/24` - Rarement en conflit
|
||||
- `10.100.0.0/24` - Espace libre
|
||||
|
||||
## 🔍 Vérifier les Conflits
|
||||
|
||||
```bash
|
||||
# Voir les réseaux Docker existants
|
||||
docker network ls
|
||||
|
||||
# Voir les détails d'un réseau
|
||||
docker network inspect bridge
|
||||
|
||||
# Voir les routes système
|
||||
ip route show
|
||||
|
||||
# Vérifier les interfaces réseau
|
||||
ip addr show
|
||||
```
|
||||
|
||||
## 🛠️ Résolution des Conflits
|
||||
|
||||
### Si vous avez un conflit :
|
||||
|
||||
1. **Identifier le conflit** :
|
||||
```bash
|
||||
docker network inspect regisflow_regisflow-internal
|
||||
```
|
||||
|
||||
2. **Changer le sous-réseau** :
|
||||
```bash
|
||||
# Arrêter les services
|
||||
docker-compose down
|
||||
|
||||
# Supprimer le réseau
|
||||
docker network rm regisflow_regisflow-internal
|
||||
|
||||
# Modifier docker-compose.yml avec un nouveau sous-réseau
|
||||
# Puis redémarrer
|
||||
docker-compose up -d
|
||||
```
|
||||
|
||||
3. **Ou utiliser la configuration simple** :
|
||||
```bash
|
||||
docker-compose -f docker-compose.simple.yml up -d
|
||||
```
|
||||
|
||||
## 🎯 Recommandations
|
||||
|
||||
### Pour Tests/Développement :
|
||||
- Utilisez `docker-compose.simple.yml`
|
||||
- Aucune configuration réseau nécessaire
|
||||
- Démarrage rapide
|
||||
|
||||
### Pour Production :
|
||||
- Utilisez `docker-compose.yml`
|
||||
- Vérifiez les conflits avant déploiement
|
||||
- Personnalisez le sous-réseau si nécessaire
|
||||
|
||||
## 📚 Scripts Inclus
|
||||
|
||||
- `install-simple.sh` - Utilise la configuration simple
|
||||
- `deploy-prod.sh` - Utilise la configuration sécurisée
|
||||
- `monitoring.sh` - Surveille tous les types de réseaux
|
||||
|
||||
## 🔒 Sécurité
|
||||
|
||||
Les deux configurations sont sécurisées :
|
||||
- Communications chiffrées entre conteneurs
|
||||
- Isolation des services
|
||||
- Accès contrôlé aux ports
|
||||
+64
-84
@@ -1,119 +1,99 @@
|
||||
# Démarrage Rapide RegisFlow - Production Docker
|
||||
# Démarrage Rapide RegisFlow
|
||||
|
||||
## 🚀 Déploiement en 5 minutes
|
||||
## 🚀 Installation Ultra-Simple
|
||||
|
||||
RegisFlow est maintenant configuré pour une installation sans aucune configuration réseau complexe.
|
||||
|
||||
### Installation en 1 Minute
|
||||
|
||||
### 1. Préparer l'environnement
|
||||
```bash
|
||||
# Cloner le projet
|
||||
git clone <votre-repo>
|
||||
# Télécharger le projet
|
||||
git clone [url-du-projet]
|
||||
cd regisflow
|
||||
|
||||
# Configurer l'environnement
|
||||
cp .env.example .env
|
||||
nano .env # Changer POSTGRES_PASSWORD et SESSION_SECRET
|
||||
|
||||
# Créer les répertoires
|
||||
mkdir -p data/{postgres,backups,logs}
|
||||
# Installer immédiatement
|
||||
docker-compose up -d
|
||||
```
|
||||
|
||||
### 2. Déployer
|
||||
```bash
|
||||
# Déploiement automatique
|
||||
chmod +x deploy-prod.sh
|
||||
./deploy-prod.sh
|
||||
**C'est tout !** L'application est accessible sur http://localhost:5000
|
||||
|
||||
# OU déploiement manuel
|
||||
docker-compose build
|
||||
docker-compose -f docker-compose.yml -f docker-compose.prod.yml up -d
|
||||
```
|
||||
## ✅ Configuration Automatique
|
||||
|
||||
### 3. Accéder à l'application
|
||||
- **URL** : http://localhost:5000
|
||||
- **Mots de passe** : Pré-configurés dans le fichier `.env`
|
||||
- **Base de données** : PostgreSQL configurée automatiquement
|
||||
- **Réseau** : Utilise le réseau par défaut Docker (aucun conflit)
|
||||
- **Volumes** : Gérés automatiquement par Docker
|
||||
- **Migrations** : Exécutées automatiquement au démarrage
|
||||
|
||||
## 🎯 Accès Immédiat
|
||||
|
||||
- **Application** : http://localhost:5000
|
||||
- **Utilisateur** : admin
|
||||
- **Mot de passe** : admin123
|
||||
- **PostgreSQL** : localhost:5433
|
||||
|
||||
### 4. Configuration initiale
|
||||
1. Connectez-vous avec admin/admin123
|
||||
2. Changez le mot de passe administrateur
|
||||
3. Créez vos magasins et utilisateurs
|
||||
|
||||
## ⚡ Commandes essentielles
|
||||
## 🔧 Commandes Utiles
|
||||
|
||||
```bash
|
||||
# Vérifier le statut
|
||||
docker-compose ps
|
||||
|
||||
# Voir les logs
|
||||
docker-compose logs -f
|
||||
|
||||
# Arrêter/démarrer
|
||||
# Redémarrer
|
||||
docker-compose restart
|
||||
|
||||
# Arrêter
|
||||
docker-compose down
|
||||
|
||||
# Statut
|
||||
docker-compose ps
|
||||
```
|
||||
|
||||
## 🛠️ Problèmes Courants
|
||||
|
||||
### Application ne démarre pas
|
||||
```bash
|
||||
# Vérifier Docker
|
||||
docker --version
|
||||
docker-compose --version
|
||||
|
||||
# Nettoyer et redémarrer
|
||||
docker-compose down
|
||||
docker-compose up -d
|
||||
|
||||
# Sauvegarde
|
||||
docker-compose exec regisflow-db pg_dump -U regisflow regisflow > backup.sql
|
||||
```
|
||||
|
||||
## 🔧 Variables obligatoires (.env)
|
||||
|
||||
### Port 5000 déjà utilisé
|
||||
```bash
|
||||
# À changer OBLIGATOIREMENT
|
||||
POSTGRES_PASSWORD=VotreMotDePasseSecurise2024!
|
||||
SESSION_SECRET=$(openssl rand -base64 32)
|
||||
|
||||
# Configuration de base
|
||||
NODE_ENV=production
|
||||
PORT=5000
|
||||
TZ=Europe/Paris
|
||||
# Changer le port dans docker-compose.yml
|
||||
ports:
|
||||
- "5001:5000" # Utiliser port 5001 au lieu de 5000
|
||||
```
|
||||
|
||||
## 📊 Monitoring
|
||||
|
||||
### Conflit PostgreSQL
|
||||
```bash
|
||||
# Script de monitoring
|
||||
./monitoring.sh
|
||||
|
||||
# Santé des services
|
||||
curl http://localhost:5000/health
|
||||
|
||||
# Ressources utilisées
|
||||
docker stats
|
||||
# Changer le port PostgreSQL
|
||||
ports:
|
||||
- "5434:5432" # Utiliser port 5434 au lieu de 5433
|
||||
```
|
||||
|
||||
## 🔒 Sécurité
|
||||
## 🔒 Sécurité pour Production
|
||||
|
||||
Pour la production, configurez HTTPS avec Nginx :
|
||||
Une fois testé, pour la production :
|
||||
|
||||
```bash
|
||||
# Copier la configuration
|
||||
sudo cp nginx-reverse-proxy.conf /etc/nginx/sites-available/regisflow
|
||||
sudo ln -s /etc/nginx/sites-available/regisflow /etc/nginx/sites-enabled/
|
||||
1. **Changer les mots de passe** dans `.env`
|
||||
2. **Configurer HTTPS** si nécessaire
|
||||
3. **Changer le mot de passe admin** dans l'application
|
||||
|
||||
# Certificat SSL
|
||||
sudo certbot --nginx -d votre-domaine.com
|
||||
```
|
||||
## 📱 Fonctionnalités Disponibles
|
||||
|
||||
## 🚨 Dépannage
|
||||
|
||||
```bash
|
||||
# Si un service ne démarre pas
|
||||
docker-compose logs regisflow
|
||||
|
||||
# Si problème de base de données
|
||||
docker-compose exec regisflow-db psql -U regisflow -d regisflow
|
||||
|
||||
# Redémarrer tout
|
||||
docker-compose restart
|
||||
```
|
||||
|
||||
## 📱 Fonctionnalités
|
||||
|
||||
- Multi-utilisateur (Admin/Manager/Employee)
|
||||
- Multi-magasins avec isolation
|
||||
- Multi-utilisateur avec rôles
|
||||
- Multi-magasins
|
||||
- Enregistrement des ventes
|
||||
- Historique complet
|
||||
- Sauvegardes automatiques
|
||||
- Purge automatique (19 mois)
|
||||
- Export PDF/CSV
|
||||
- Validation EAN-13
|
||||
- Interface mobile responsive
|
||||
- Interface mobile
|
||||
|
||||
**🎯 L'application est maintenant prête pour la production !**
|
||||
## 🎉 Prêt !
|
||||
|
||||
L'application RegisFlow est maintenant prête à l'emploi sans aucune configuration supplémentaire.
|
||||
+79
-33
@@ -1,61 +1,107 @@
|
||||
# Configuration Docker Compose spécifique PRODUCTION
|
||||
# Usage: docker-compose -f docker-compose.yml -f docker-compose.prod.yml up -d
|
||||
|
||||
version: '3.8'
|
||||
|
||||
# Configuration Docker Compose PRODUCTION pour RegisFlow
|
||||
# Avec optimisations et sécurité renforcée
|
||||
services:
|
||||
# Base de données PostgreSQL (Production)
|
||||
regisflow-db:
|
||||
# Configuration production PostgreSQL
|
||||
command: postgres -c config_file=/etc/postgresql/postgresql.conf
|
||||
image: postgres:15-alpine
|
||||
container_name: regisflow-db
|
||||
environment:
|
||||
# Variables supplémentaires pour production
|
||||
POSTGRES_SHARED_PRELOAD_LIBRARIES: "pg_stat_statements"
|
||||
POSTGRES_DB: regisflow
|
||||
POSTGRES_USER: regisflow
|
||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
||||
# Optimisations PostgreSQL pour production
|
||||
POSTGRES_INITDB_ARGS: "--auth-host=md5 --auth-local=peer"
|
||||
volumes:
|
||||
# Logs PostgreSQL
|
||||
- postgres_logs:/var/log/postgresql
|
||||
# Limites strictes en production
|
||||
- postgres_data:/var/lib/postgresql/data
|
||||
- ./init.sql:/docker-entrypoint-initdb.d/init.sql:ro
|
||||
- ./postgres-prod.conf:/etc/postgresql/postgresql.conf:ro
|
||||
ports:
|
||||
- "5433:5432"
|
||||
restart: unless-stopped
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "pg_isready -U regisflow -d regisflow"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 5
|
||||
start_period: 30s
|
||||
# Limites de ressources pour production
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
cpus: '1.0'
|
||||
memory: 512M
|
||||
reservations:
|
||||
cpus: '0.5'
|
||||
memory: 256M
|
||||
# Politique de redémarrage agressive
|
||||
restart: always
|
||||
|
||||
# Application RegisFlow (Production)
|
||||
regisflow:
|
||||
# Configuration production application
|
||||
build:
|
||||
context: .
|
||||
target: production
|
||||
container_name: regisflow-app
|
||||
depends_on:
|
||||
regisflow-db:
|
||||
condition: service_healthy
|
||||
environment:
|
||||
# Mode strict en production
|
||||
NODE_ENV: production
|
||||
# Optimisations Node.js
|
||||
NODE_OPTIONS: "--max-old-space-size=512 --unhandled-rejections=strict"
|
||||
# Logs structurés
|
||||
LOG_LEVEL: info
|
||||
LOG_FORMAT: json
|
||||
# Limites strictes en production
|
||||
PORT: 5000
|
||||
DATABASE_URL: postgresql://regisflow:${POSTGRES_PASSWORD}@regisflow-db:5432/regisflow
|
||||
SESSION_SECRET: ${SESSION_SECRET}
|
||||
TZ: ${TZ:-Europe/Paris}
|
||||
# Configuration sécurité production
|
||||
SECURE_COOKIES: ${SECURE_COOKIES:-true}
|
||||
DATA_RETENTION_MONTHS: ${DATA_RETENTION_MONTHS:-19}
|
||||
BACKUP_RETENTION_DAYS: ${BACKUP_RETENTION_DAYS:-90}
|
||||
MAX_BACKUP_COUNT: ${MAX_BACKUP_COUNT:-20}
|
||||
volumes:
|
||||
- backup_data:/app/backups
|
||||
- logs_data:/app/logs
|
||||
ports:
|
||||
- "5000:5000"
|
||||
restart: unless-stopped
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "wget --no-verbose --tries=1 --spider http://localhost:5000/health || exit 1"]
|
||||
interval: 30s
|
||||
timeout: 15s
|
||||
retries: 3
|
||||
start_period: 90s
|
||||
# Limites de ressources pour production
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
cpus: '2.0'
|
||||
memory: 1G
|
||||
reservations:
|
||||
cpus: '1.0'
|
||||
memory: 512M
|
||||
# Politique de redémarrage agressive
|
||||
restart: always
|
||||
# Configuration ulimits pour production
|
||||
ulimits:
|
||||
nofile:
|
||||
soft: 65536
|
||||
hard: 65536
|
||||
# Sécurité container
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
read_only: false
|
||||
tmpfs:
|
||||
- /tmp
|
||||
|
||||
# Volumes persistants pour production
|
||||
volumes:
|
||||
postgres_logs:
|
||||
postgres_data:
|
||||
driver: local
|
||||
driver_opts:
|
||||
type: none
|
||||
o: bind
|
||||
device: ${PWD}/data/postgres-logs
|
||||
device: ${PWD}/data/postgres
|
||||
backup_data:
|
||||
driver: local
|
||||
driver_opts:
|
||||
type: none
|
||||
o: bind
|
||||
device: ${PWD}/data/backups
|
||||
logs_data:
|
||||
driver: local
|
||||
driver_opts:
|
||||
type: none
|
||||
o: bind
|
||||
device: ${PWD}/data/logs
|
||||
|
||||
# Réseau par défaut (pas de configuration IP)
|
||||
networks:
|
||||
default:
|
||||
driver: bridge
|
||||
@@ -0,0 +1,68 @@
|
||||
version: '3.8'
|
||||
|
||||
# Configuration Docker Compose SIMPLE pour RegisFlow
|
||||
# Installation sans intervention avec réseau automatique
|
||||
services:
|
||||
# Base de données PostgreSQL
|
||||
regisflow-db:
|
||||
image: postgres:15-alpine
|
||||
container_name: regisflow-db
|
||||
environment:
|
||||
POSTGRES_DB: regisflow
|
||||
POSTGRES_USER: regisflow
|
||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-RegisFlow2024!PostgreSQL}
|
||||
volumes:
|
||||
- postgres_data:/var/lib/postgresql/data
|
||||
- ./init.sql:/docker-entrypoint-initdb.d/init.sql:ro
|
||||
ports:
|
||||
- "5433:5432"
|
||||
restart: unless-stopped
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "pg_isready -U regisflow -d regisflow"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 5
|
||||
start_period: 30s
|
||||
|
||||
# Application RegisFlow
|
||||
regisflow:
|
||||
build:
|
||||
context: .
|
||||
target: production
|
||||
container_name: regisflow-app
|
||||
depends_on:
|
||||
regisflow-db:
|
||||
condition: service_healthy
|
||||
environment:
|
||||
NODE_ENV: production
|
||||
PORT: 5000
|
||||
DATABASE_URL: postgresql://regisflow:${POSTGRES_PASSWORD:-RegisFlow2024!PostgreSQL}@regisflow-db:5432/regisflow
|
||||
SESSION_SECRET: ${SESSION_SECRET:-RegisFlow2024SessionSecretKey1234567890ABCDEF}
|
||||
TZ: ${TZ:-Europe/Paris}
|
||||
SECURE_COOKIES: ${SECURE_COOKIES:-false}
|
||||
DATA_RETENTION_MONTHS: ${DATA_RETENTION_MONTHS:-19}
|
||||
BACKUP_RETENTION_DAYS: ${BACKUP_RETENTION_DAYS:-90}
|
||||
MAX_BACKUP_COUNT: ${MAX_BACKUP_COUNT:-20}
|
||||
volumes:
|
||||
- backup_data:/app/backups
|
||||
- logs_data:/app/logs
|
||||
ports:
|
||||
- "5000:5000"
|
||||
restart: unless-stopped
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "wget --no-verbose --tries=1 --spider http://localhost:5000/health || exit 1"]
|
||||
interval: 30s
|
||||
timeout: 15s
|
||||
retries: 3
|
||||
start_period: 90s
|
||||
|
||||
# Volumes persistants (création automatique)
|
||||
volumes:
|
||||
postgres_data:
|
||||
backup_data:
|
||||
logs_data:
|
||||
|
||||
# Réseau par défaut (pas de sous-réseau spécifique)
|
||||
networks:
|
||||
default:
|
||||
driver: bridge
|
||||
+12
-61
@@ -1,21 +1,19 @@
|
||||
version: '3.8'
|
||||
|
||||
# Configuration Docker Compose pour PRODUCTION RegisFlow
|
||||
# Configuration Docker Compose SIMPLE pour RegisFlow
|
||||
# Installation sans configuration réseau complexe
|
||||
services:
|
||||
# Base de données PostgreSQL (Production)
|
||||
# Base de données PostgreSQL
|
||||
regisflow-db:
|
||||
image: postgres:15-alpine
|
||||
container_name: regisflow-db
|
||||
environment:
|
||||
POSTGRES_DB: regisflow
|
||||
POSTGRES_USER: regisflow
|
||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
||||
# Optimisations PostgreSQL pour production
|
||||
POSTGRES_INITDB_ARGS: "--auth-host=md5 --auth-local=peer"
|
||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-RegisFlow2024!PostgreSQL}
|
||||
volumes:
|
||||
- postgres_data:/var/lib/postgresql/data
|
||||
- ./init.sql:/docker-entrypoint-initdb.d/init.sql:ro
|
||||
- ./postgres-prod.conf:/etc/postgresql/postgresql.conf:ro
|
||||
ports:
|
||||
- "5433:5432"
|
||||
restart: unless-stopped
|
||||
@@ -25,18 +23,8 @@ services:
|
||||
timeout: 10s
|
||||
retries: 5
|
||||
start_period: 30s
|
||||
# Limites de ressources pour production
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
memory: 512M
|
||||
reservations:
|
||||
memory: 256M
|
||||
# Configuration réseau sécurisée
|
||||
networks:
|
||||
- regisflow-internal
|
||||
|
||||
# Application RegisFlow (Production)
|
||||
# Application RegisFlow
|
||||
regisflow:
|
||||
build:
|
||||
context: .
|
||||
@@ -48,11 +36,10 @@ services:
|
||||
environment:
|
||||
NODE_ENV: production
|
||||
PORT: 5000
|
||||
DATABASE_URL: postgresql://regisflow:${POSTGRES_PASSWORD}@regisflow-db:5432/regisflow
|
||||
SESSION_SECRET: ${SESSION_SECRET}
|
||||
DATABASE_URL: postgresql://regisflow:${POSTGRES_PASSWORD:-RegisFlow2024!PostgreSQL}@regisflow-db:5432/regisflow
|
||||
SESSION_SECRET: ${SESSION_SECRET:-RegisFlow2024SessionSecretKey1234567890ABCDEF}
|
||||
TZ: ${TZ:-Europe/Paris}
|
||||
# Configuration sécurité production
|
||||
SECURE_COOKIES: ${SECURE_COOKIES:-true}
|
||||
SECURE_COOKIES: ${SECURE_COOKIES:-false}
|
||||
DATA_RETENTION_MONTHS: ${DATA_RETENTION_MONTHS:-19}
|
||||
BACKUP_RETENTION_DAYS: ${BACKUP_RETENTION_DAYS:-90}
|
||||
MAX_BACKUP_COUNT: ${MAX_BACKUP_COUNT:-20}
|
||||
@@ -68,50 +55,14 @@ services:
|
||||
timeout: 15s
|
||||
retries: 3
|
||||
start_period: 90s
|
||||
# Limites de ressources pour production
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
memory: 1G
|
||||
reservations:
|
||||
memory: 512M
|
||||
# Configuration réseau sécurisée
|
||||
networks:
|
||||
- regisflow-internal
|
||||
# Sécurité container
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
read_only: false
|
||||
tmpfs:
|
||||
- /tmp
|
||||
|
||||
# Volumes persistants pour production
|
||||
# Volumes persistants (Docker gère automatiquement)
|
||||
volumes:
|
||||
postgres_data:
|
||||
driver: local
|
||||
driver_opts:
|
||||
type: none
|
||||
o: bind
|
||||
device: ${PWD}/data/postgres
|
||||
backup_data:
|
||||
driver: local
|
||||
driver_opts:
|
||||
type: none
|
||||
o: bind
|
||||
device: ${PWD}/data/backups
|
||||
logs_data:
|
||||
driver: local
|
||||
driver_opts:
|
||||
type: none
|
||||
o: bind
|
||||
device: ${PWD}/data/logs
|
||||
|
||||
# Réseau interne sécurisé
|
||||
# Réseau par défaut (pas de configuration IP)
|
||||
networks:
|
||||
regisflow-internal:
|
||||
driver: bridge
|
||||
internal: false
|
||||
ipam:
|
||||
driver: default
|
||||
config:
|
||||
- subnet: 172.20.0.0/24
|
||||
default:
|
||||
driver: bridge
|
||||
Executable → Regular
+1
-1
@@ -42,7 +42,7 @@ docker-compose down 2>/dev/null || true
|
||||
echo "🔨 Construction des images..."
|
||||
docker-compose build
|
||||
|
||||
# Démarrer les services
|
||||
# Démarrer les services avec configuration simple
|
||||
echo "🚀 Démarrage des services..."
|
||||
docker-compose up -d
|
||||
|
||||
|
||||
@@ -213,6 +213,9 @@ Preferred communication style: Simple, everyday language.
|
||||
- ✅ Comprehensive Docker documentation with deployment instructions
|
||||
- ✅ Nginx configuration removed for simplified deployment (application accessible on port 5000)
|
||||
- ✅ Preconfigured PostgreSQL user (regisflow/RegisFlow2024!) - only IP change needed
|
||||
- ✅ Simplified network configuration without IP presets to avoid conflicts
|
||||
- ✅ Default Docker bridge network usage for maximum compatibility
|
||||
- ✅ Ultra-simple installation process with single command: docker-compose up -d
|
||||
|
||||
### Production Deployment System (January 9, 2025)
|
||||
- ✅ Multi-stage Dockerfile optimized for production with security hardening
|
||||
|
||||
Reference in new issue
Block a user