mirror of
https://github.com/tiennm99/composes.git
synced 2026-10-11 12:09:25 +00:00
Data encrypted under one secret is unreadable under another, so the secrets must move with the data instead of being regenerated by the image.
57 lines
1.5 KiB
YAML
57 lines
1.5 KiB
YAML
services:
|
|
db:
|
|
image: postgres:16-alpine
|
|
restart: unless-stopped
|
|
environment:
|
|
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-gitea}
|
|
POSTGRES_USER: gitea
|
|
POSTGRES_DB: gitea
|
|
volumes:
|
|
- db-data:/var/lib/postgresql/data
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U gitea -d gitea"]
|
|
interval: 5s
|
|
timeout: 5s
|
|
retries: 10
|
|
|
|
gitea:
|
|
image: gitea/gitea:28
|
|
restart: unless-stopped
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
environment:
|
|
GITEA__database__PASSWD: ${POSTGRES_PASSWORD:-gitea}
|
|
GITEA__database__DB_TYPE: postgres
|
|
GITEA__database__HOST: db:5432
|
|
GITEA__database__NAME: gitea
|
|
GITEA__database__USER: gitea
|
|
GITEA__server__ROOT_URL: ${GITEA_ROOT_URL:?required}
|
|
GITEA__server__DISABLE_SSH: "true"
|
|
volumes:
|
|
- gitea-data:/data
|
|
healthcheck:
|
|
test: ["CMD", "curl", "-fsS", "http://localhost:3000/api/healthz"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 5
|
|
start_period: 30s
|
|
|
|
gitea-mirror:
|
|
image: ghcr.io/raylabshq/gitea-mirror:latest
|
|
restart: unless-stopped
|
|
pull_policy: always
|
|
environment:
|
|
BETTER_AUTH_SECRET: ${BETTER_AUTH_SECRET:?required}
|
|
ENCRYPTION_SECRET: ${ENCRYPTION_SECRET:?required}
|
|
BETTER_AUTH_URL: ${GITEA_MIRROR_URL:?required}
|
|
PUBLIC_BETTER_AUTH_URL: ${GITEA_MIRROR_URL:?required}
|
|
BETTER_AUTH_TRUSTED_ORIGINS: ${GITEA_MIRROR_URL:?required}
|
|
volumes:
|
|
- gitea-mirror-data:/app/data
|
|
|
|
volumes:
|
|
db-data:
|
|
gitea-data:
|
|
gitea-mirror-data:
|