g1t/deploy/self-host/docker-compose.yml

103 lines3,677 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Running g1t yourself: the design, a docker compose proof, and a guide to what works today1# Self-hosted g1t, phase 1: the core forge on your own machine.
2#
3# docker compose -f deploy/self-host/docker-compose.yml up --build
4#
5# Then open http://localhost:8787. Mail (the confirmation link at sign-up)
6# lands in Mailpit at http://localhost:8025.
7#
8# What runs: the site and every core service in one workerd (g1t), git
9# repositories as bare repos on a volume (gitstore), and Mailpit for mail.
10# Agents, deployments, context search and billing are off. See
11# docs/SELF_HOSTING.md.
12name: g1t
13
14services:
15 g1t:
16 build:
17 context: ../..
18 dockerfile: deploy/self-host/Dockerfile
19 ports:
20 - "${G1T_PORT:-8787}:8787"
21 environment:
22 # Where people reach this installation. Links in mail point here.
23 PUBLIC_URL: ${PUBLIC_URL:-http://localhost:8787}
24 GITSTORE_URL: http://gitstore:8080
25 GITSTORE_SECRET_FILE: /secrets/gitstore
26 MAIL_URL: ${MAIL_URL:-http://mailpit:8025}
27 MAIL_FROM: ${MAIL_FROM:-g1t <noreply@localhost>}
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look28 # Your own GitHub App, for "Continue with GitHub" and importing from
29 # GitHub. Leave these unset to have neither. See the self-hosting guide.
30 GITHUB_APP_ID: ${GITHUB_APP_ID:-}
31 GITHUB_APP_SLUG: ${GITHUB_APP_SLUG:-}
32 GITHUB_APP_CLIENT_ID: ${GITHUB_APP_CLIENT_ID:-}
33 GITHUB_APP_CLIENT_SECRET: ${GITHUB_APP_CLIENT_SECRET:-}
34 GITHUB_APP_PRIVATE_KEY: ${GITHUB_APP_PRIVATE_KEY:-}
35 GITHUB_APP_WEBHOOK_SECRET: ${GITHUB_APP_WEBHOOK_SECRET:-}
36 # open: anyone may register. invite: a new account needs an invite
37 # code, as on g1t.sh; the owners of INVITE_STAFF_WORKSPACES (slugs,
38 # comma separated) invite without limit, everyone else INVITES_PER_USER.
39 REGISTRATION_MODE: ${REGISTRATION_MODE:-open}
40 INVITE_STAFF_WORKSPACES: ${INVITE_STAFF_WORKSPACES:-}
41 INVITES_PER_USER: ${INVITES_PER_USER:-}
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas42 # Where summaries of new access requests go; empty sends none.
43 WAITLIST_NOTIFY_EMAIL: ${WAITLIST_NOTIFY_EMAIL:-}
Running g1t yourself: the design, a docker compose proof, and a guide to what works today44 volumes:
45 - g1t-data:/data
46 - g1t-secrets:/secrets:ro
47 depends_on:
48 gitstore:
49 condition: service_healthy
50 mailpit:
51 condition: service_started
52 restart: unless-stopped
53
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas54 # The status page, in a process of its own so it stays up when the site
55 # does not: http://localhost:8788. It checks the site every minute.
56 status:
57 build:
58 context: ../..
59 dockerfile: deploy/self-host/Dockerfile
60 command: ["bash", "deploy/self-host/status.sh"]
61 ports:
62 - "${STATUS_PORT:-8788}:8788"
63 environment:
64 PUBLIC_URL: ${PUBLIC_URL:-http://localhost:8787}
65 # How the status page reaches the site, from inside Compose.
66 STATUS_CHECK_URL: http://g1t:8787
67 # A public repository, `workspace/repo`, whose branches it lists as a
68 # clone would. Empty: git is not checked.
69 STATUS_PROBE_REPO: ${STATUS_PROBE_REPO:-}
70 volumes:
71 - g1t-status:/data
72 restart: unless-stopped
73
Running g1t yourself: the design, a docker compose proof, and a guide to what works today74 gitstore:
75 build:
76 context: ./gitstore
77 environment:
78 GITSTORE_URL: http://gitstore:8080
79 GITSTORE_SECRET_FILE: /secrets/gitstore
80 volumes:
81 - g1t-git:/data/git
82 - g1t-secrets:/secrets
83 # Not published: only the g1t container reaches it.
84 restart: unless-stopped
85
86 mailpit:
87 image: axllent/mailpit:latest
88 ports:
89 - "${MAILPIT_PORT:-8025}:8025"
90 # To deliver for real, relay through your SMTP server:
91 # environment:
92 # MP_SMTP_RELAY_HOST: smtp.example.com
93 # MP_SMTP_RELAY_PORT: "587"
94 # MP_SMTP_RELAY_USERNAME: ...
95 # MP_SMTP_RELAY_PASSWORD: ...
96 # MP_SMTP_RELAY_ALL: "true"
97 restart: unless-stopped
98
99volumes:
100 g1t-data:
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas101 g1t-status:
Running g1t yourself: the design, a docker compose proof, and a guide to what works today102 g1t-git:
103 g1t-secrets: