-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.dokploy.yml
More file actions
84 lines (78 loc) · 3.49 KB
/
Copy pathdocker-compose.dokploy.yml
File metadata and controls
84 lines (78 loc) · 3.49 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
# Production compose for Dokploy (Compose + Traefik) on the Oracle Cloud ARM VM.
# The plain ./docker-compose.yml stays the local-dev file (so `docker compose up -d`
# from a clean clone still works); THIS file is what Dokploy's Compose service
# points at. See docs/deploy-dokploy.md for the full runbook.
#
# Secrets are interpolated from the Dokploy service's Environment settings —
# nothing sensitive lives in this file. Sourced from role inboxes
# (projects@monashcoding.com); no personal accounts anywhere.
services:
db:
image: postgres:16-alpine
restart: unless-stopped
# Convention: user = password = db = mac_hackathon. Not exposed to the host
# or the internet — only the app reaches it over the compose network.
environment:
POSTGRES_USER: mac_hackathon
POSTGRES_PASSWORD: mac_hackathon
POSTGRES_DB: mac_hackathon
volumes:
- db_data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U mac_hackathon -d mac_hackathon"]
interval: 5s
timeout: 5s
retries: 20
app:
build: .
restart: unless-stopped
depends_on:
db:
condition: service_healthy
# The entrypoint applies Drizzle migrations, then boots the server — so every
# deploy migrates automatically (idempotent).
environment:
DATABASE_URL: postgres://mac_hackathon:mac_hackathon@db:5432/mac_hackathon
NODE_ENV: production
PORT: "3000"
PUBLIC_URL: https://hackathons.monashcoding.com
# mac-auth (EdDSA JWTs verified locally via JWKS). Organiser access is by
# ROLE (committee/exec/admin from the token), not the informational `team`.
MAC_AUTH_URL: https://auth.monashcoding.com
MAC_AUTH_JWKS_URL: https://auth.monashcoding.com/api/auth/jwks
JWT_AUDIENCE: mac-suite
ORGANISER_ROLES: ${ORGANISER_ROLES:-committee,exec,admin}
# Humanitix (club-owned account, read-only). Regenerating the key in the
# Humanitix console invalidates the old one — update it here in Dokploy.
HUMANITIX_API_KEY: ${HUMANITIX_API_KEY:-}
HUMANITIX_API_BASE: https://api.humanitix.com/v1
FORCE_TICKET_SYNC: ${FORCE_TICKET_SYNC:-}
TICKET_SYNC_REVOKE_THRESHOLD: ${TICKET_SYNC_REVOKE_THRESHOLD:-0.20}
DISCORD_ALERT_WEBHOOK_URL: ${DISCORD_ALERT_WEBHOOK_URL:-}
# Notion content CMS.
NOTION_API_KEY: ${NOTION_API_KEY:-}
NOTION_EVENTS_DB_ID: ${NOTION_EVENTS_DB_ID:-}
NOTION_PRIZES_DB_ID: ${NOTION_PRIZES_DB_ID:-}
NOTION_JUDGES_DB_ID: ${NOTION_JUDGES_DB_ID:-}
NOTION_SCHEDULE_DB_ID: ${NOTION_SCHEDULE_DB_ID:-}
NOTION_SPONSORS_DB_ID: ${NOTION_SPONSORS_DB_ID:-}
NOTION_FAQ_DB_ID: ${NOTION_FAQ_DB_ID:-}
networks:
- default # reach the db
- dokploy-network # be reachable by Dokploy's Traefik
# Traefik ingress: route https://hackathons.monashcoding.com → app:3000.
# No published ports — Traefik terminates TLS and proxies over the network.
labels:
- traefik.enable=true
- traefik.docker.network=dokploy-network
- traefik.http.routers.mac-hackathon.rule=Host(`hackathons.monashcoding.com`)
- traefik.http.routers.mac-hackathon.entrypoints=websecure
- traefik.http.routers.mac-hackathon.tls.certresolver=letsencrypt
- traefik.http.services.mac-hackathon.loadbalancer.server.port=3000
# Dokploy's shared ingress network. Created by Dokploy; referenced as external
# so this file never tries to manage it.
networks:
dokploy-network:
external: true
volumes:
db_data: