From 550d1d17414d47ad3710c2476578966e2d73b223 Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Fri, 14 Aug 2026 09:13:49 +0700 Subject: [PATCH] feat: add code-server service and repo scaffolding Set up the per-service layout: each service directory holds compose.yml with a committed .env.example and a gitignored .env. Add code-server as the first service, plus a README and CLAUDE.md documenting that these files target Coolify/Dokploy and deliberately omit ports and restart policies. --- .gitignore | 23 +++++++++++++ CLAUDE.md | 31 +++++++++++++++++ README.md | 72 +++++++++++++++++++++++++++++++++++++++- code-server/.env.example | 16 +++++++++ code-server/compose.yml | 24 ++++++++++++++ 5 files changed, 165 insertions(+), 1 deletion(-) create mode 100644 .gitignore create mode 100644 CLAUDE.md create mode 100644 code-server/.env.example create mode 100644 code-server/compose.yml diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..3620350 --- /dev/null +++ b/.gitignore @@ -0,0 +1,23 @@ +# Secrets: every service keeps its own .env next to its compose.yml +.env +*.env +!.env.example +!*.env.example + +# Compose override files are host-specific +compose.override.yml +compose.override.yaml +docker-compose.override.yml +docker-compose.override.yaml + +# Bind-mount data directories, if a service uses one instead of a named volume +data/ +*/data/ + +# OS / editor noise +.DS_Store +Thumbs.db +desktop.ini +*.swp +.idea/ +.vscode/ diff --git a/CLAUDE.md b/CLAUDE.md new file mode 100644 index 0000000..d20eaed --- /dev/null +++ b/CLAUDE.md @@ -0,0 +1,31 @@ +# composes + +Personal docker compose collection. One directory per service, each holding +`compose.yml`, a committed `.env.example`, and a gitignored `.env`. + +## Deployment target + +Services are deployed through Coolify and Dokploy, not plain `docker compose` +on a host. The platform owns the parts a standalone compose file would declare +itself. + +## Intentional omissions — do not "fix" these + +These are deliberate, not oversights. Do not flag them as defects or add them +unprompted: + +- **No `ports:`.** Coolify and Dokploy attach the container to their proxy + network and map a domain to the internal port. Publishing a port is redundant + and would additionally expose it on the host. +- **No `restart:` policy.** The platform manages the container lifecycle. +- **No `container_name:`.** Let Compose derive it from the directory. + +More generally: these files are tuned to one person's setup and are not meant +to be portable, standard, or turnkey. Prefer leaving a service minimal over +adding hardening or convention that the platform already provides. + +## Secrets + +Every service reads secrets from a sibling `.env`. Never commit one — the root +`.gitignore` covers `.env`/`*.env` and re-includes `.env.example`. Keep +`.env.example` in sync whenever a compose file gains or drops a variable. diff --git a/README.md b/README.md index d7599bf..42ac710 100644 --- a/README.md +++ b/README.md @@ -1,2 +1,72 @@ # composes -My docker compose collection + +My docker compose collection — one directory per service, each self-contained. + +These are tuned to my own setup, not written as general-purpose templates. They +are deployed through [Coolify](https://coolify.io) and +[Dokploy](https://dokploy.com), so they lean on the platform for things a +standalone compose file would normally declare: + +- **No published ports.** Both platforms attach the container to their proxy + network and map a domain directly to the internal port, so `ports:` is + unnecessary — and adding it would expose the host port as well. +- **No `restart:` policy.** The platform manages the container lifecycle. + +Treat them as working examples rather than drop-in configs. Running one with +plain `docker compose` means adding whatever your setup needs. + +## Layout + +``` +/ + compose.yml # the service definition + .env.example # required variables, committed + .env # real values, gitignored +``` + +Compose names the project after its directory, so `code-server/` comes up as +the `code-server` project with its own network and volumes. + +## Usage + +In Coolify or Dokploy, point a Docker Compose resource at the service directory +and set the environment variables from its `.env.example`. + +Locally, for a quick check: + +```sh +cd +cp .env.example .env # then fill it in +docker compose up -d +docker compose logs -f +docker compose down +``` + +`.env` is picked up automatically because it sits next to `compose.yml`. +Never commit it — the root `.gitignore` covers `.env`/`*.env` and re-includes +`.env.example`. + +## Services + +### code-server + +[VS Code in the browser](https://github.com/linuxserver/docker-code-server), +from the LinuxServer image, set up as a full remote dev box. + +Comes with Go, Node.js 24, Python 3, pnpm, and zsh via LinuxServer mods, plus +`gh`, `git`, `ffmpeg`, `imagemagick`, and other CLI tools through +`INSTALL_PACKAGES`. Git author/committer identity is injected from `.env`. + +Everything lives in the `code-server-config` named volume mounted at `/config`; +the default workspace is `/config/workspace`. Removing the volume wipes your +files, settings, and extensions. + +| Variable | Purpose | +| --- | --- | +| `PASSWORD` | Web UI login, also the in-container sudo password. **A blank value disables authentication entirely.** | +| `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity | +| `CODEX_ACCESS_TOKEN` | OpenAI Codex CLI auth; leave blank if unused | + +Generate a password with `openssl rand -base64 24`. + +Listens on `8443` — point the domain at that port in Coolify or Dokploy. diff --git a/code-server/.env.example b/code-server/.env.example new file mode 100644 index 0000000..141ab60 --- /dev/null +++ b/code-server/.env.example @@ -0,0 +1,16 @@ +# Copy to .env and fill in. Never commit .env. +# +# cp .env.example .env + +# Web UI login password. MUST NOT be blank -- the LinuxServer image serves +# code-server without authentication when PASSWORD is empty. +# Also used for SUDO_PASSWORD inside the container. +# Generate one with: openssl rand -base64 24 +PASSWORD= + +# Git identity baked into the container (author + committer). +GIT_NAME= +GIT_EMAIL= + +# OpenAI Codex CLI auth token. Leave blank if you don't use Codex. +CODEX_ACCESS_TOKEN= diff --git a/code-server/compose.yml b/code-server/compose.yml new file mode 100644 index 0000000..329cc74 --- /dev/null +++ b/code-server/compose.yml @@ -0,0 +1,24 @@ +services: + code-server: + image: 'lscr.io/linuxserver/code-server:latest' + hostname: miti99-cs + environment: + - PUID=1000 + - PGID=1000 + - TZ=Asia/Ho_Chi_Minh + - DEFAULT_WORKSPACE=/config/workspace + - PWA_APPNAME=code-server + - 'DOCKER_MODS=linuxserver/mods:universal-package-install|linuxserver/mods:universal-docker|linuxserver/mods:code-server-golang|linuxserver/mods:code-server-nodejs|linuxserver/mods:code-server-npmglobal|linuxserver/mods:code-server-pnpm|linuxserver/mods:code-server-python3|linuxserver/mods:code-server-zsh' + - INSTALL_PACKAGES=apache2-utils|bfs|ffmpeg|gh|git|imagemagick|librsvg2-bin|lsof|psmisc|ugrep|unzip|zip + - NODEJS_MOD_VERSION=24 + - PASSWORD=${PASSWORD} + - SUDO_PASSWORD=${PASSWORD} + - GIT_AUTHOR_NAME=${GIT_NAME} + - GIT_AUTHOR_EMAIL=${GIT_EMAIL} + - GIT_COMMITTER_NAME=${GIT_NAME} + - GIT_COMMITTER_EMAIL=${GIT_EMAIL} + - CODEX_ACCESS_TOKEN=${CODEX_ACCESS_TOKEN} + volumes: + - 'code-server-config:/config' +volumes: + code-server-config: