Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
141 lines (134 loc) · 5.69 KB
/
Copy pathdocker-compose.yml
File metadata and controls
141 lines (134 loc) · 5.69 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
services:
backend:
build:
context: .
args:
EDITION: ${EDITION:-ce}
ports:
- "127.0.0.1:8000:8000"
volumes:
- egressdata:/app/data/network-egress
extra_hosts:
- "host.docker.internal:host-gateway"
env_file:
- path: .env
required: false
environment:
PROJECT_ROOT: /app
DATABASE_URL: postgresql://${POSTGRES_USER:?copy .env.example to .env and set POSTGRES_USER}:${POSTGRES_PASSWORD:?copy .env.example to .env and set POSTGRES_PASSWORD}@postgres:5432/${POSTGRES_DB:?copy .env.example to .env and set POSTGRES_DB}
DOCKER_HOST_ADDR: host.docker.internal
BROWSER_RUNTIME_ACCESS_MODE: ${BROWSER_RUNTIME_ACCESS_MODE:-published}
BROWSER_RUNTIME_BACKEND_URL: ${BROWSER_RUNTIME_BACKEND_URL:-http://host.docker.internal:8000}
BROWSER_RUNTIME_CONTROL_URL: http://runtime-worker:8001
BROWSER_RUNTIME_CONTROL_TOKEN: ${BROWSER_RUNTIME_CONTROL_TOKEN:?copy .env.example to .env and set BROWSER_RUNTIME_CONTROL_TOKEN}
CLOAK_BROWSER_IMAGE_NAME: ${CLOAK_BROWSER_IMAGE_NAME:-browser-pilot-cloak:latest}
BP_LEGACY_DOCKER_DOWNLOAD_WATCHER: ${BP_LEGACY_DOCKER_DOWNLOAD_WATCHER:-false}
NETWORK_EGRESS_DOCKER_NETWORK: ${NETWORK_EGRESS_DOCKER_NETWORK:-browser-pilot-net}
NETWORK_EGRESS_CONFIG_DIR: ${NETWORK_EGRESS_CONFIG_DIR:-/app/data/network-egress}
NETWORK_EGRESS_CLASH_IMAGE: ${NETWORK_EGRESS_CLASH_IMAGE:-ghcr.io/metacubex/mihomo:latest}
NETWORK_EGRESS_CLASH_PROXY_PORT: ${NETWORK_EGRESS_CLASH_PROXY_PORT:-7890}
NETWORK_EGRESS_OPENVPN_IMAGE: ${NETWORK_EGRESS_OPENVPN_IMAGE:-browser-pilot-openvpn-egress:latest}
NETWORK_EGRESS_OPENVPN_PROXY_PORT: ${NETWORK_EGRESS_OPENVPN_PROXY_PORT:-8888}
MINIO_STORAGE_BOOTSTRAP: "true"
MINIO_ROOT_USER: ${MINIO_ROOT_USER:?copy .env.example to .env and set MINIO_ROOT_USER}
MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:?copy .env.example to .env and set MINIO_ROOT_PASSWORD}
MINIO_BUCKET: ${MINIO_BUCKET:?copy .env.example to .env and set MINIO_BUCKET}
MINIO_ENDPOINT: http://minio:9000
MINIO_PUBLIC_ENDPOINT: ${MINIO_PUBLIC_ENDPOINT:-http://localhost:9000}
depends_on:
postgres:
condition: service_healthy
minio-init:
condition: service_completed_successfully
runtime-worker:
condition: service_healthy
runtime-worker:
build:
context: .
args:
EDITION: ${EDITION:-ce}
command: uvicorn app.runtime_worker:app --host 0.0.0.0 --port 8001
expose:
- "8001"
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- egressdata:/app/data/network-egress
extra_hosts:
- "host.docker.internal:host-gateway"
environment:
PROJECT_ROOT: /app
BROWSER_RUNTIME_CONTROL_TOKEN: ${BROWSER_RUNTIME_CONTROL_TOKEN:?copy .env.example to .env and set BROWSER_RUNTIME_CONTROL_TOKEN}
BROWSER_RUNTIME_COMMAND_MAX_TIMEOUT: ${BROWSER_RUNTIME_COMMAND_MAX_TIMEOUT:-3600}
NETWORK_EGRESS_CONFIG_DIR: ${NETWORK_EGRESS_CONFIG_DIR:-/app/data/network-egress}
NETWORK_EGRESS_DOCKER_NETWORK: ${NETWORK_EGRESS_DOCKER_NETWORK:-browser-pilot-net}
NETWORK_EGRESS_CLASH_IMAGE: ${NETWORK_EGRESS_CLASH_IMAGE:-ghcr.io/metacubex/mihomo:latest}
NETWORK_EGRESS_CLASH_PROXY_PORT: ${NETWORK_EGRESS_CLASH_PROXY_PORT:-7890}
NETWORK_EGRESS_OPENVPN_IMAGE: ${NETWORK_EGRESS_OPENVPN_IMAGE:-browser-pilot-openvpn-egress:latest}
NETWORK_EGRESS_OPENVPN_PROXY_PORT: ${NETWORK_EGRESS_OPENVPN_PROXY_PORT:-8888}
healthcheck:
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8001/healthz', timeout=2)"]
interval: 5s
timeout: 3s
retries: 10
postgres:
image: postgres:16-alpine
restart: unless-stopped
environment:
POSTGRES_USER: ${POSTGRES_USER:?copy .env.example to .env and set POSTGRES_USER}
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?copy .env.example to .env and set POSTGRES_PASSWORD}
POSTGRES_DB: ${POSTGRES_DB:?copy .env.example to .env and set POSTGRES_DB}
ports:
- "127.0.0.1:5432:5432"
volumes:
- pgdata:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U \"$${POSTGRES_USER}\""]
interval: 3s
timeout: 3s
retries: 5
minio:
image: minio/minio:latest
restart: unless-stopped
command: server /data
environment:
MINIO_ROOT_USER: ${MINIO_ROOT_USER:?copy .env.example to .env and set MINIO_ROOT_USER}
MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:?copy .env.example to .env and set MINIO_ROOT_PASSWORD}
expose:
- "9000"
ports:
- "127.0.0.1:9000:9000"
volumes:
- miniodata:/data
minio-init:
image: minio/mc:latest
restart: "no"
depends_on:
minio:
condition: service_started
environment:
MINIO_ROOT_USER: ${MINIO_ROOT_USER:?copy .env.example to .env and set MINIO_ROOT_USER}
MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:?copy .env.example to .env and set MINIO_ROOT_PASSWORD}
MINIO_BUCKET: ${MINIO_BUCKET:?copy .env.example to .env and set MINIO_BUCKET}
entrypoint: >
/bin/sh -c '
until mc alias set local http://minio:9000 "$$MINIO_ROOT_USER" "$$MINIO_ROOT_PASSWORD"; do
sleep 1;
done;
mc mb --ignore-existing "local/$$MINIO_BUCKET";
'
selenium:
build:
context: ./services/selenium-chrome
args:
BASE_IMAGE: ${SELENIUM_BASE_IMAGE:-selenium/standalone-chrome:latest}
image: ${SELENIUM_IMAGE_NAME:-browser-pilot-selenium}
profiles: ["build"]
cloak:
build:
context: ./services/cloak-chromium-runtime
image: ${CLOAK_BROWSER_IMAGE_NAME:-browser-pilot-cloak:latest}
profiles: ["build"]
volumes:
pgdata:
egressdata:
miniodata: