Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
69 lines (59 loc) · 2.01 KB
/
Copy pathdocker-compose.yml
File metadata and controls
69 lines (59 loc) · 2.01 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
version: '3.8'
services:
web:
image: ghcr.io/vreshch/vreshch.com:latest
restart: unless-stopped
env_file:
- .env
networks:
- traefik-public
deploy:
replicas: 1
update_config:
order: start-first
failure_action: rollback
delay: 10s
restart_policy:
condition: on-failure
delay: 5s
max_attempts: 3
labels:
# Enable Traefik
- traefik.enable=true
- traefik.docker.network=traefik-public
- traefik.constraint-label=traefik-public
# HTTP Router (redirect to HTTPS, but allow ACME challenges)
- traefik.http.routers.vreshch-http.rule=Host(`vreshch.com`) || Host(`www.vreshch.com`)
- traefik.http.routers.vreshch-http.entrypoints=http
- traefik.http.routers.vreshch-http.middlewares=https-redirect
# Create HTTPS redirect middleware that allows ACME challenges
- traefik.http.middlewares.https-redirect.redirectscheme.scheme=https
- traefik.http.middlewares.https-redirect.redirectscheme.permanent=true
# HTTPS Router
- traefik.http.routers.vreshch-https.rule=Host(`vreshch.com`) || Host(`www.vreshch.com`)
- traefik.http.routers.vreshch-https.entrypoints=https
- traefik.http.routers.vreshch-https.tls=true
- traefik.http.routers.vreshch-https.tls.certresolver=letsencrypt
# Service configuration
- traefik.http.services.vreshch.loadbalancer.server.port=3000
resources:
limits:
cpus: '0.5'
memory: 256M
reservations:
cpus: '0.25'
memory: 128M
healthcheck:
test: ['CMD', 'wget', '--quiet', '--tries=1', '--spider', 'http://127.0.0.1:3000/health']
interval: 30s
timeout: 10s
retries: 3
start_period: 40s
volumes:
# optimized-image cache must survive deploys/restarts (p95 latency SLA)
- next-image-cache:/app/.next/cache
volumes:
next-image-cache:
networks:
traefik-public:
external: true