version: '3.8' # Configuration Docker Compose pour PRODUCTION RegisFlow services: # Base de données PostgreSQL (Production) regisflow-db: image: postgres:15-alpine container_name: regisflow-db environment: POSTGRES_DB: regisflow POSTGRES_USER: regisflow POSTGRES_PASSWORD: ${POSTGRES_PASSWORD} # Optimisations PostgreSQL pour production POSTGRES_INITDB_ARGS: "--auth-host=md5 --auth-local=peer" volumes: - postgres_data:/var/lib/postgresql/data - ./init.sql:/docker-entrypoint-initdb.d/init.sql:ro - ./postgres-prod.conf:/etc/postgresql/postgresql.conf:ro ports: - "5433:5432" restart: unless-stopped healthcheck: test: ["CMD-SHELL", "pg_isready -U regisflow -d regisflow"] interval: 30s timeout: 10s retries: 5 start_period: 30s # Limites de ressources pour production deploy: resources: limits: memory: 512M reservations: memory: 256M # Configuration réseau sécurisée networks: - regisflow-internal # Application RegisFlow (Production) regisflow: build: context: . target: production container_name: regisflow-app depends_on: regisflow-db: condition: service_healthy environment: NODE_ENV: production PORT: 5000 DATABASE_URL: postgresql://regisflow:${POSTGRES_PASSWORD}@regisflow-db:5432/regisflow SESSION_SECRET: ${SESSION_SECRET} TZ: ${TZ:-Europe/Paris} # Configuration sécurité production SECURE_COOKIES: ${SECURE_COOKIES:-true} DATA_RETENTION_MONTHS: ${DATA_RETENTION_MONTHS:-19} BACKUP_RETENTION_DAYS: ${BACKUP_RETENTION_DAYS:-90} MAX_BACKUP_COUNT: ${MAX_BACKUP_COUNT:-20} volumes: - backup_data:/app/backups - logs_data:/app/logs ports: - "5000:5000" restart: unless-stopped healthcheck: test: ["CMD-SHELL", "wget --no-verbose --tries=1 --spider http://localhost:5000/health || exit 1"] interval: 30s timeout: 15s retries: 3 start_period: 90s # Limites de ressources pour production deploy: resources: limits: memory: 1G reservations: memory: 512M # Configuration réseau sécurisée networks: - regisflow-internal # Sécurité container security_opt: - no-new-privileges:true read_only: false tmpfs: - /tmp # Volumes persistants pour production volumes: postgres_data: driver: local driver_opts: type: none o: bind device: ${PWD}/data/postgres backup_data: driver: local driver_opts: type: none o: bind device: ${PWD}/data/backups logs_data: driver: local driver_opts: type: none o: bind device: ${PWD}/data/logs # Réseau interne sécurisé networks: regisflow-internal: driver: bridge internal: false ipam: driver: default config: - subnet: 172.20.0.0/24