-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
52 lines (49 loc) · 2.26 KB
/
Copy pathdocker-compose.yml
File metadata and controls
52 lines (49 loc) · 2.26 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
# Run birdy in a container, on the same host as BIRD.
#
# birdy talks to BIRD over its control socket, so the socket has to be shared
# into the container. This example runs it as a viewer (--read-only), which needs
# nothing but the socket. To let it APPLY config, see the notes at the bottom.
#
# One-time setup — create the database and admin account:
#
# docker compose run --rm birdy init --asn 64496 --router-id 192.0.2.1 --label rtr1
#
# (add --password to avoid the prompt; it will land in your shell history).
# Then bring up the server:
#
# docker compose up -d
#
# This compose file publishes the port to the host's loopback only, so reach the
# UI over an SSH tunnel:
# ssh -L 8080:127.0.0.1:8080 router
# then open http://127.0.0.1:8080. To reach it directly instead, publish on
# "8080:8080" and set the IP allow-list under Settings -> Access control as soon
# as you log in: birdy has no TLS.
services:
birdy:
build: .
# Or pull a published image instead of building:
# image: ghcr.io/floreabogdan/birdy:latest
restart: unless-stopped
command: ["server", "--read-only", "--listen", "0.0.0.0:8080"]
# Publish ONLY to the host's loopback — birdy has no TLS. Tunnel in over SSH.
ports:
- "127.0.0.1:8080:8080"
volumes:
# birdy's database and snapshots. Holds BGP MD5 passwords in the clear
# once you configure peers, so treat this volume as a secret.
- birdy-data:/var/lib/birdy
# BIRD's control socket. Read-only is enough for a viewer; drop ":ro" if
# you enable apply (birdy sends "configure" over this socket).
- /run/bird:/run/bird:ro
# ── To enable apply (drop the viewer mode) ───────────────────────────────
# 1. Drop --read-only from `command`, and make the socket mount writable
# (remove the ":ro" above).
# 2. Mount BIRD's config so birdy can write it, and make sure --bird-conf
# matches the path BIRD was started with (bird -c):
# - /etc/bird:/etc/bird
# then add `--bird-conf /etc/bird/bird.conf` to the command.
# 3. The container already ships the `bird` binary for "bird -p" syntax
# checks; pin it to the host's version if you need an exact match.
volumes:
birdy-data: