-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
95 lines (92 loc) · 3.51 KB
/
Copy pathdocker-compose.yml
File metadata and controls
95 lines (92 loc) · 3.51 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
services:
backend:
build:
context: ./backend
dockerfile: Dockerfile
container_name: raventag-backend
restart: unless-stopped
environment:
NODE_ENV: production
PORT: 3001
DB_PATH: /data/raventag.db
RVN_RPC_HOST: ${RVN_RPC_HOST:-localhost}
RVN_RPC_PORT: ${RVN_RPC_PORT:-8766}
# Secrets loaded from mounted files (./secrets/ in standalone, Docker Swarm secrets in production).
ADMIN_KEY_FILE: /run/secrets/admin_key
OPERATOR_KEY_FILE: /run/secrets/operator_key
BRAND_MASTER_KEY_FILE: /run/secrets/brand_master_key
BRAND_SALT_FILE: /run/secrets/brand_salt
# Optional: set only if connecting to a local Ravencoin node with auth
RVN_RPC_USER: ${RVN_RPC_USER:-}
RVN_RPC_PASS: ${RVN_RPC_PASS:-}
RVN_PUBLIC_RPC_URL: ${RVN_PUBLIC_RPC_URL:-https://rvn-rpc.publicnode.com}
ALLOWED_ORIGINS: ${ALLOWED_ORIGINS:-https://raventag.com}
# RT108-SEC-205: set true only when behind a reverse proxy that appends
# the real client IP to X-Forwarded-For (e.g. the documented nginx setup).
TRUST_PROXY: ${TRUST_PROXY:-false}
CACHE_TTL_ASSET: ${CACHE_TTL_ASSET:-300}
CACHE_TTL_IPFS: ${CACHE_TTL_IPFS:-3600}
IPFS_GATEWAY: ${IPFS_GATEWAY:-https://ipfs.io/ipfs/}
# RTSL-1.0 LICENSE REQUIREMENT: RavenTag Verify fingerprint MUST be included
ANDROID_APP_FINGERPRINT: ${ANDROID_APP_FINGERPRINT:-3EA5B9F375631A4E1DE95DE1DA9C2245141E4AD8FA7A63787D6AB98196B4A3BE}
secrets:
- admin_key
- operator_key
- brand_master_key
- brand_salt
volumes:
- raventag_data:/data
ports:
- "127.0.0.1:3001:3001"
healthcheck:
test: ["CMD", "wget", "-qO-", "http://localhost:3001/health"]
interval: 30s
timeout: 10s
retries: 3
# SQLite backup: runs every 24 hours, keeps the 7 newest successful encrypted backups.
# To decrypt: openssl enc -d -aes-256-cbc -pbkdf2 -iter 100000 \
# -pass file:/path/to/backup_encryption_key -in raventag_TIMESTAMP.db.enc -out raventag.db
backup:
image: alpine:3.19
container_name: raventag-backup
restart: unless-stopped
volumes:
- raventag_data:/data:ro
- raventag_backups:/backups
secrets:
- backup_encryption_key
command: >
sh -c "apk add --no-cache openssl sqlite > /dev/null 2>&1;
while true; do
TIMESTAMP=$$(date +%Y%m%d_%H%M%S);
sqlite3 /data/raventag.db \".backup /tmp/raventag_snap.db\";
openssl enc -aes-256-cbc -pbkdf2 -iter 100000 \
-pass file:/run/secrets/backup_encryption_key \
-in /tmp/raventag_snap.db \
-out /backups/raventag_$${TIMESTAMP}.db.enc 2>/dev/null \
&& echo \"[Backup] raventag_$${TIMESTAMP}.db.enc (encrypted)\";
rm -f /tmp/raventag_snap.db;
ls -t /backups/raventag_*.db.enc 2>/dev/null | tail -n +8 | xargs rm -f;
sleep 86400;
done"
depends_on:
backend:
condition: service_healthy
# Docker secrets: in compose dev mode, create ./secrets/<name> files with the secret value.
# In Swarm mode, create secrets with: docker secret create <name> - <<< "value"
secrets:
backup_encryption_key:
file: ${BACKUP_ENCRYPTION_KEY_FILE:-./secrets/backup_encryption_key.txt}
admin_key:
file: ./secrets/admin_key
operator_key:
file: ./secrets/operator_key
brand_master_key:
file: ./secrets/brand_master_key
brand_salt:
file: ./secrets/brand_salt
volumes:
raventag_data:
driver: local
raventag_backups:
driver: local