Files
anouma/docker-compose.yml
T
maroandClaude Sonnet 5 56b2a6497b Overhaul deployment to Gitea Actions CI/CD, remove update.sh
Production no longer builds from source or self-updates via cron/git pull:
setup.sh now only provisions the server once (Docker, /opt/anouma, a
restricted `anouma-deploy` SSH user whose key can only ever run
deploy.sh, generated secrets). All future deployments run through
.gitea/workflows/ci.yml (lint/typecheck/test/build on every push) and
release.yml (on a vX.Y.Z tag: build the image, push it to the Gitea
registry, then SSH-trigger deploy.sh on the server), which pulls,
migrates, restarts, healthchecks, backs up the database first, and
automatically rolls back the code on a failed healthcheck.

docker-compose.yml's app service now runs a registry image
(${ANOUMA_IMAGE}) instead of building locally.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-25 22:58:09 +02:00

60 lines
2.0 KiB
YAML

networks:
anouma-network:
name: ${DOCKER_NETWORK:-anouma-network}
volumes:
pgdata:
services:
postgres:
image: postgres:16-alpine
restart: unless-stopped
networks:
- anouma-network
environment:
POSTGRES_USER: ${POSTGRES_USER:-postgres}
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-postgres}
POSTGRES_DB: ${POSTGRES_DB:-anouma}
volumes:
- pgdata:/var/lib/postgresql/data
# Not published to the host by default — only reachable from other
# containers on anouma-network. Uncomment to reach it from the host too
# (e.g. with a GUI DB client) during development:
# ports:
# - "127.0.0.1:5432:5432"
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-postgres}"]
interval: 5s
timeout: 5s
retries: 20
app:
# Production never builds from source — the image is built once by
# Gitea Actions on release and pushed to the registry; this host only
# ever pulls a specific, already-tested tag (see deploy.sh, which is the
# only thing that ever changes ANOUMA_IMAGE in .env).
image: ${ANOUMA_IMAGE:-git.maro.run/maro/anouma:latest}
restart: unless-stopped
networks:
- anouma-network
env_file:
- .env
# DATABASE_URI in .env must point at the "postgres" service name, e.g.
# postgresql://postgres:<password>@postgres:5432/anouma — setup.sh sets
# this up for you automatically.
ports:
- "127.0.0.1:${APP_PORT:-3000}:3000"
volumes:
- ./media:/app/media
depends_on:
postgres:
condition: service_healthy
# Container-level healthcheck is inherited from the image's own
# HEALTHCHECK instruction (GET /api/health, which itself checks Postgres
# connectivity) — nothing to duplicate here.
# Optional external network to a reverse proxy (e.g. Nginx Proxy Manager)
# is attached via docker-compose.override.yml, generated by setup.sh only
# when such a network is actually detected — see DEPLOYMENT.md. Nothing
# here assumes NPM (or any reverse proxy) exists.