g1t/deploy/self-host/docker-compose.yml

151 lines5,645 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Running g1t yourself: the design, a docker compose proof, and a guide to what works today1# Self-hosted g1t, phase 1: the core forge on your own machine.
2#
3# docker compose -f deploy/self-host/docker-compose.yml up --build
4#
5# Then open http://localhost:8787. Mail (the confirmation link at sign-up)
6# lands in Mailpit at http://localhost:8025.
7#
8# What runs: the site and every core service in one workerd (g1t), git
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member9# repositories as bare repos on a volume (gitstore), packages' files in
10# MinIO, and Mailpit for mail.
Running g1t yourself: the design, a docker compose proof, and a guide to what works today11# Agents, deployments, context search and billing are off. See
12# docs/SELF_HOSTING.md.
13name: g1t
14
15services:
16 g1t:
17 build:
18 context: ../..
19 dockerfile: deploy/self-host/Dockerfile
20 ports:
21 - "${G1T_PORT:-8787}:8787"
22 environment:
23 # Where people reach this installation. Links in mail point here.
24 PUBLIC_URL: ${PUBLIC_URL:-http://localhost:8787}
25 GITSTORE_URL: http://gitstore:8080
26 GITSTORE_SECRET_FILE: /secrets/gitstore
27 MAIL_URL: ${MAIL_URL:-http://mailpit:8025}
28 MAIL_FROM: ${MAIL_FROM:-g1t <noreply@localhost>}
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look29 # Your own GitHub App, for "Continue with GitHub" and importing from
30 # GitHub. Leave these unset to have neither. See the self-hosting guide.
31 GITHUB_APP_ID: ${GITHUB_APP_ID:-}
32 GITHUB_APP_SLUG: ${GITHUB_APP_SLUG:-}
33 GITHUB_APP_CLIENT_ID: ${GITHUB_APP_CLIENT_ID:-}
34 GITHUB_APP_CLIENT_SECRET: ${GITHUB_APP_CLIENT_SECRET:-}
35 GITHUB_APP_PRIVATE_KEY: ${GITHUB_APP_PRIVATE_KEY:-}
36 GITHUB_APP_WEBHOOK_SECRET: ${GITHUB_APP_WEBHOOK_SECRET:-}
37 # open: anyone may register. invite: a new account needs an invite
38 # code, as on g1t.sh; the owners of INVITE_STAFF_WORKSPACES (slugs,
39 # comma separated) invite without limit, everyone else INVITES_PER_USER.
40 REGISTRATION_MODE: ${REGISTRATION_MODE:-open}
41 INVITE_STAFF_WORKSPACES: ${INVITE_STAFF_WORKSPACES:-}
42 INVITES_PER_USER: ${INVITES_PER_USER:-}
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas43 # Where summaries of new access requests go; empty sends none.
44 WAITLIST_NOTIFY_EMAIL: ${WAITLIST_NOTIFY_EMAIL:-}
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member45 # Packages' files (container images and the rest), in MinIO below or
46 # any S3-compatible store. S3_PUBLIC_ENDPOINT, when clients can reach
47 # the store, sends large downloads there directly.
48 S3_ENDPOINT: ${S3_ENDPOINT:-http://minio:9000}
49 S3_BUCKET: ${S3_BUCKET:-g1t-packages}
50 S3_REGION: ${S3_REGION:-us-east-1}
51 S3_ACCESS_KEY_ID: ${S3_ACCESS_KEY_ID:-g1t}
52 S3_SECRET_ACCESS_KEY: ${S3_SECRET_ACCESS_KEY:-g1t-packages-secret}
53 S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-}
Self-hosted: backups go to a g1t-backups bucket on the compose file's MinIO54 # Nightly backups' bundles and manifests, in a bucket of their own on
55 # the same store (docs/SELF_HOSTING.md, "Backups").
56 BACKUP_S3_BUCKET: ${BACKUP_S3_BUCKET:-g1t-backups}
Running g1t yourself: the design, a docker compose proof, and a guide to what works today57 volumes:
58 - g1t-data:/data
59 - g1t-secrets:/secrets:ro
60 depends_on:
61 gitstore:
62 condition: service_healthy
63 mailpit:
64 condition: service_started
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member65 minio-setup:
66 condition: service_completed_successfully
Running g1t yourself: the design, a docker compose proof, and a guide to what works today67 restart: unless-stopped
68
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas69 # The status page, in a process of its own so it stays up when the site
70 # does not: http://localhost:8788. It checks the site every minute.
71 status:
72 build:
73 context: ../..
74 dockerfile: deploy/self-host/Dockerfile
75 command: ["bash", "deploy/self-host/status.sh"]
76 ports:
77 - "${STATUS_PORT:-8788}:8788"
78 environment:
79 PUBLIC_URL: ${PUBLIC_URL:-http://localhost:8787}
80 # How the status page reaches the site, from inside Compose.
81 STATUS_CHECK_URL: http://g1t:8787
82 # A public repository, `workspace/repo`, whose branches it lists as a
83 # clone would. Empty: git is not checked.
84 STATUS_PROBE_REPO: ${STATUS_PROBE_REPO:-}
85 volumes:
86 - g1t-status:/data
87 restart: unless-stopped
88
Running g1t yourself: the design, a docker compose proof, and a guide to what works today89 gitstore:
90 build:
91 context: ./gitstore
92 environment:
93 GITSTORE_URL: http://gitstore:8080
94 GITSTORE_SECRET_FILE: /secrets/gitstore
95 volumes:
96 - g1t-git:/data/git
97 - g1t-secrets:/secrets
98 # Not published: only the g1t container reaches it.
99 restart: unless-stopped
100
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member101 # Packages' files. Not published: only the g1t container reaches it,
102 # unless you publish 9000 and set S3_PUBLIC_ENDPOINT.
103 minio:
104 image: minio/minio:latest
105 command: ["server", "/data"]
106 environment:
107 MINIO_ROOT_USER: ${S3_ACCESS_KEY_ID:-g1t}
108 MINIO_ROOT_PASSWORD: ${S3_SECRET_ACCESS_KEY:-g1t-packages-secret}
109 volumes:
110 - g1t-packages:/data
111 healthcheck:
112 test: ["CMD", "mc", "ready", "local"]
113 interval: 5s
114 retries: 20
115 restart: unless-stopped
116
Self-hosted: backups go to a g1t-backups bucket on the compose file's MinIO117 # Makes the buckets once, then exits: packages' files, and backups.
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member118 minio-setup:
119 image: minio/mc:latest
120 depends_on:
121 minio:
122 condition: service_healthy
123 entrypoint:
124 - sh
125 - -c
Self-hosted: backups go to a g1t-backups bucket on the compose file's MinIO126 - mc alias set local http://minio:9000 "$$MINIO_ROOT_USER" "$$MINIO_ROOT_PASSWORD" && mc mb --ignore-existing "local/$$S3_BUCKET" && mc mb --ignore-existing "local/$$BACKUP_S3_BUCKET"
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member127 environment:
128 MINIO_ROOT_USER: ${S3_ACCESS_KEY_ID:-g1t}
129 MINIO_ROOT_PASSWORD: ${S3_SECRET_ACCESS_KEY:-g1t-packages-secret}
130 S3_BUCKET: ${S3_BUCKET:-g1t-packages}
Self-hosted: backups go to a g1t-backups bucket on the compose file's MinIO131 BACKUP_S3_BUCKET: ${BACKUP_S3_BUCKET:-g1t-backups}
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member132
Running g1t yourself: the design, a docker compose proof, and a guide to what works today133 mailpit:
134 image: axllent/mailpit:latest
135 ports:
136 - "${MAILPIT_PORT:-8025}:8025"
137 # To deliver for real, relay through your SMTP server:
138 # environment:
139 # MP_SMTP_RELAY_HOST: smtp.example.com
140 # MP_SMTP_RELAY_PORT: "587"
141 # MP_SMTP_RELAY_USERNAME: ...
142 # MP_SMTP_RELAY_PASSWORD: ...
143 # MP_SMTP_RELAY_ALL: "true"
144 restart: unless-stopped
145
146volumes:
147 g1t-data:
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member148 g1t-packages:
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas149 g1t-status:
Running g1t yourself: the design, a docker compose proof, and a guide to what works today150 g1t-git:
151 g1t-secrets: