All checks were successful
Build and deploy / Validate source (push) Successful in 8s
Build and deploy / Integration suite on a real stack (push) Successful in 3m38s
Build and deploy / Secret scan and release gate (push) Successful in 7s
Build and deploy / Publish images (push) Successful in 1m2s
A backup service runs pg_dump every day at 03:00 Brasília, checks the archive, encrypts it with age to a public key and uploads it with a token for that bucket only. The server cannot read or delete backups: the private key stays with the owner, the bucket's lifecycle rule expires copies and its lock stops early deletion. Each run is recorded and shown on the Kanban's Integrations tab. tests/backup_test.py backs up, restores into a scratch database and compares the rows in CI. Setup and restore: docs/BACKUP.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
299 lines
11 KiB
YAML
299 lines
11 KiB
YAML
# Localhost development stack. Builds from source, uses MinIO, fake providers and
|
|
# disposable credentials. `docker-compose.yml` is the production/R2 stack and is
|
|
# NOT usable locally; the two are deliberately separate files.
|
|
#
|
|
# docker compose -f compose.local.yaml up --build
|
|
#
|
|
# Defaults here mirror `.env.example`; copy it to `.env` only to customise.
|
|
|
|
x-app: &app
|
|
build:
|
|
context: .
|
|
dockerfile: infra/Dockerfile
|
|
environment: &environment
|
|
APP_ENV: local
|
|
DATABASE_URL: postgresql://${APP_DB_USER:-dtf_app}:${APP_DB_PASSWORD:-local-app-database-only}@db:5432/${POSTGRES_DB:-dtf_local}
|
|
S3_ENDPOINT: http://storage:9000
|
|
S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:${STORAGE_PORT:-9000}}
|
|
S3_BUCKET: ${S3_BUCKET:-dtf-local-artwork}
|
|
AWS_ACCESS_KEY_ID: ${S3_APP_USER:-dtf_app}
|
|
AWS_SECRET_ACCESS_KEY: ${S3_APP_PASSWORD:-local-app-storage-only}
|
|
AWS_DEFAULT_REGION: us-east-1
|
|
OPERATOR_EMAIL: ${OPERATOR_EMAIL:-operator@example.test}
|
|
OPERATOR_PASSWORD: ${OPERATOR_PASSWORD:-local-operator-only}
|
|
# The browser reaches the API through the Site gateway, so the published
|
|
# Site/Kanban origins must be accepted or every write is rejected 403.
|
|
PUBLIC_ORIGIN: ${PUBLIC_ORIGIN:-http://localhost:${SITE_PORT:-8080}}
|
|
ALLOWED_HOSTS: ${ALLOWED_HOSTS:-localhost,127.0.0.1}
|
|
ALLOWED_ORIGINS: ${ALLOWED_ORIGINS:-http://localhost:${SITE_PORT:-8080},http://localhost:${KANBAN_PORT:-8081},http://127.0.0.1:${SITE_PORT:-8080},http://127.0.0.1:${KANBAN_PORT:-8081}}
|
|
COOKIE_SECURE: "false"
|
|
# Sandbox testing only: set PAYMENT_ADAPTER=mercadopago with the MP_* test
|
|
# credentials, or TINY_ADAPTER=tiny with a TINY_TOKEN, in .env. Never real
|
|
# production credentials on a developer machine.
|
|
PAYMENT_ADAPTER: ${PAYMENT_ADAPTER:-fake}
|
|
PAYMENT_WEBHOOK_SECRET: ${PAYMENT_WEBHOOK_SECRET:-local-webhook-secret}
|
|
MP_ACCESS_TOKEN: ${MP_ACCESS_TOKEN:-}
|
|
MP_WEBHOOK_SECRET: ${MP_WEBHOOK_SECRET:-}
|
|
MP_NOTIFICATION_URL: ${MP_NOTIFICATION_URL:-}
|
|
MP_PUBLIC_KEY: ${MP_PUBLIC_KEY:-}
|
|
FREIGHT_ADAPTER: ${FREIGHT_ADAPTER:-fake}
|
|
JADLOG_TOKEN: ${JADLOG_TOKEN:-}
|
|
JADLOG_CNPJ: ${JADLOG_CNPJ:-}
|
|
JADLOG_CONTA: ${JADLOG_CONTA:-}
|
|
JADLOG_CONTRATO: ${JADLOG_CONTRATO:-}
|
|
JADLOG_PESO_BASE_KG: ${JADLOG_PESO_BASE_KG:-}
|
|
JADLOG_PESO_POR_METRO_KG: ${JADLOG_PESO_POR_METRO_KG:-}
|
|
FREIGHT_PRODUCTION_DAYS: ${FREIGHT_PRODUCTION_DAYS:-0}
|
|
# Carts the Site priced are approved at checkout; larger ones wait for review.
|
|
QUOTE_AUTO_APPROVE: ${QUOTE_AUTO_APPROVE:-true}
|
|
QUOTE_AUTO_MAX_METRES: ${QUOTE_AUTO_MAX_METRES:-50}
|
|
TINY_ADAPTER: ${TINY_ADAPTER:-fake}
|
|
TINY_CLIENT_ID: ${TINY_CLIENT_ID:-}
|
|
TINY_CLIENT_SECRET: ${TINY_CLIENT_SECRET:-}
|
|
TINY_REDIRECT_URI: ${TINY_REDIRECT_URI:-}
|
|
TINY_PRODUCT_TEXTIL_FOLHA: ${TINY_PRODUCT_TEXTIL_FOLHA:-}
|
|
TINY_PRODUCT_TEXTIL_AVULSA: ${TINY_PRODUCT_TEXTIL_AVULSA:-}
|
|
TINY_PRODUCT_UV_FOLHA: ${TINY_PRODUCT_UV_FOLHA:-}
|
|
TINY_PRODUCT_UV_AVULSA: ${TINY_PRODUCT_UV_AVULSA:-}
|
|
TINY_ECOMMERCE_ID: ${TINY_ECOMMERCE_ID:-}
|
|
WHATSAPP_ADAPTER: fake
|
|
STORAGE_ADAPTER: s3-local
|
|
MOCK_FREIGHT_CENTS: ${MOCK_FREIGHT_CENTS:-1500}
|
|
MAX_UPLOAD_BYTES: ${MAX_UPLOAD_BYTES:-5368709120}
|
|
UPLOAD_PART_BYTES: ${UPLOAD_PART_BYTES:-8388608}
|
|
STORAGE_QUOTA_BYTES: ${STORAGE_QUOTA_BYTES:-53687091200}
|
|
OWNER_UPLOAD_QUOTA_BYTES: ${OWNER_UPLOAD_QUOTA_BYTES:-10737418240}
|
|
MAX_PENDING_UPLOADS: ${MAX_PENDING_UPLOADS:-10}
|
|
SCAN_MAX_BYTES: ${SCAN_MAX_BYTES:-2097152000}
|
|
networks: [local]
|
|
init: true
|
|
security_opt: [no-new-privileges:true]
|
|
cap_drop: [ALL]
|
|
read_only: true
|
|
tmpfs: [/tmp]
|
|
logging:
|
|
driver: json-file
|
|
options: {max-size: "10m", max-file: "3"}
|
|
|
|
services:
|
|
db:
|
|
image: postgres:17-alpine
|
|
environment:
|
|
POSTGRES_DB: ${POSTGRES_DB:-dtf_local}
|
|
POSTGRES_USER: ${POSTGRES_USER:-dtf_local}
|
|
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-local-database-only}
|
|
volumes: [postgres-data:/var/lib/postgresql/data]
|
|
networks: [local]
|
|
healthcheck:
|
|
test: [CMD-SHELL, 'pg_isready -U "$$POSTGRES_USER" -d "$$POSTGRES_DB"']
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 30
|
|
|
|
storage:
|
|
# MinIO stopped publishing public images: since September 2026 both
|
|
# Docker Hub (minio/minio) and quay.io answer anonymous pulls with 401,
|
|
# which breaks any machine or runner without a cached copy. Chainguard's
|
|
# build still pulls anonymously, ships sh and mc (the healthcheck and
|
|
# storage-init need both) and runs as a non-root user. Pinned by digest
|
|
# because Chainguard's free tier only publishes :latest. Override
|
|
# MINIO_IMAGE to use a mirror of your own.
|
|
image: ${MINIO_IMAGE:-cgr.dev/chainguard/minio@sha256:bd014394a80898e68c149f2311fdf8d5a2c2f3bb2c33b9327ae6d02b4b065ae1}
|
|
command: server /data --console-address :9001
|
|
environment:
|
|
MINIO_ROOT_USER: ${MINIO_ROOT_USER:-dtf_local}
|
|
MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-local-storage-only}
|
|
ports:
|
|
- "127.0.0.1:${STORAGE_PORT:-9000}:9000"
|
|
- "127.0.0.1:${STORAGE_CONSOLE_PORT:-9001}:9001"
|
|
volumes: [storage-data:/data]
|
|
networks: [local, edge]
|
|
healthcheck:
|
|
test: [CMD, mc, ready, local]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 30
|
|
|
|
db-init:
|
|
build:
|
|
context: .
|
|
dockerfile: infra/Dockerfile
|
|
command: python -m app.bootstrap
|
|
environment:
|
|
# Local only: the app role keeps a password distinct from the administrator.
|
|
DATABASE_ADMIN_URL: postgresql://${POSTGRES_USER:-dtf_local}:${POSTGRES_PASSWORD:-local-database-only}@db:5432/${POSTGRES_DB:-dtf_local}
|
|
APP_DB_USER: ${APP_DB_USER:-dtf_app}
|
|
APP_DB_PASSWORD: ${APP_DB_PASSWORD:-local-app-database-only}
|
|
# The migration job seeds the first operator account from these, so an
|
|
# existing deployment keeps its Kanban login after the accounts table
|
|
# lands. Without them there would be no account at all and login would
|
|
# fail closed with 503.
|
|
OPERATOR_EMAIL: ${OPERATOR_EMAIL:-operator@example.test}
|
|
OPERATOR_PASSWORD: ${OPERATOR_PASSWORD:-local-operator-only}
|
|
networks: [local]
|
|
depends_on:
|
|
db: {condition: service_healthy}
|
|
restart: on-failure
|
|
|
|
storage-init:
|
|
build:
|
|
context: .
|
|
dockerfile: infra/Dockerfile.storage-init
|
|
args:
|
|
MINIO_IMAGE: ${MINIO_IMAGE:-cgr.dev/chainguard/minio@sha256:bd014394a80898e68c149f2311fdf8d5a2c2f3bb2c33b9327ae6d02b4b065ae1}
|
|
entrypoint: [/bin/sh, /init.sh]
|
|
environment:
|
|
MINIO_ROOT_USER: ${MINIO_ROOT_USER:-dtf_local}
|
|
MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-local-storage-only}
|
|
S3_APP_USER: ${S3_APP_USER:-dtf_app}
|
|
S3_APP_PASSWORD: ${S3_APP_PASSWORD:-local-app-storage-only}
|
|
S3_BUCKET: ${S3_BUCKET:-dtf-local-artwork}
|
|
S3_BACKUP_BUCKET: dtf-local-backups
|
|
S3_BACKUP_USER: dtf_backup
|
|
S3_BACKUP_PASSWORD: local-backup-storage-only
|
|
networks: [local]
|
|
depends_on:
|
|
storage: {condition: service_healthy}
|
|
restart: on-failure
|
|
|
|
scanner:
|
|
# Built, not bind-mounted: see local/Dockerfile.scanner.
|
|
build:
|
|
context: .
|
|
dockerfile: infra/Dockerfile.scanner
|
|
args:
|
|
CLAMAV_IMAGE: ${CLAMAV_IMAGE:-clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4}
|
|
entrypoint: [clamd, --foreground=true, --config-file=/etc/clamav/clamd.conf]
|
|
networks: [local]
|
|
security_opt: [no-new-privileges:true]
|
|
healthcheck:
|
|
test: [CMD, clamdscan, --config-file=/etc/clamav/clamd.conf, --ping, "3"]
|
|
start_period: 60s
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 30
|
|
deploy:
|
|
resources:
|
|
limits: {memory: 3G}
|
|
|
|
api:
|
|
<<: *app
|
|
command: uvicorn app.app:app --host 0.0.0.0 --port 8000 --no-access-log
|
|
depends_on:
|
|
db-init: {condition: service_completed_successfully}
|
|
storage-init: {condition: service_completed_successfully}
|
|
healthcheck:
|
|
test: [CMD, python, -c, "import urllib.request; urllib.request.urlopen('http://localhost:8000/health')"]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 30
|
|
|
|
worker:
|
|
<<: *app
|
|
command: python -m app.worker
|
|
depends_on:
|
|
api: {condition: service_healthy}
|
|
scanner: {condition: service_healthy}
|
|
healthcheck:
|
|
test: [CMD, python, -c, "import urllib.request; urllib.request.urlopen('http://localhost:8002/health')"]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 12
|
|
|
|
# The daily database backup, against the local backup bucket. Idle until
|
|
# BACKUP_AGE_RECIPIENT is set; tests/backup_test.py runs it with a throwaway key.
|
|
backup:
|
|
build:
|
|
context: .
|
|
dockerfile: infra/Dockerfile
|
|
command: python -m ops.db_backup serve
|
|
environment:
|
|
DATABASE_ADMIN_URL: postgresql://${POSTGRES_USER:-dtf_local}:${POSTGRES_PASSWORD:-local-database-only}@db:5432/${POSTGRES_DB:-dtf_local}
|
|
BACKUP_S3_ENDPOINT: http://storage:9000
|
|
BACKUP_BUCKET: dtf-local-backups
|
|
BACKUP_ACCESS_KEY_ID: dtf_backup
|
|
BACKUP_SECRET_ACCESS_KEY: local-backup-storage-only
|
|
BACKUP_REGION: us-east-1
|
|
BACKUP_AGE_RECIPIENT: ${BACKUP_AGE_RECIPIENT:-}
|
|
networks: [local]
|
|
read_only: true
|
|
tmpfs: [/tmp]
|
|
depends_on:
|
|
db-init: {condition: service_completed_successfully}
|
|
storage-init: {condition: service_completed_successfully}
|
|
|
|
site:
|
|
build:
|
|
context: .
|
|
dockerfile: infra/Dockerfile.web
|
|
environment:
|
|
S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:${STORAGE_PORT:-9000}}
|
|
# Empty unless testing Mercado Pago's card form; see docs/LOCAL_SETUP.md.
|
|
PAYMENT_CSP_SOURCES: ${PAYMENT_CSP_SOURCES:-}
|
|
PAYMENT_CHALLENGE_SOURCES: ${PAYMENT_CHALLENGE_SOURCES:-}
|
|
ports:
|
|
# Published ports are host-wide even bound to loopback, so on a shared
|
|
# machine any of them can collide with something unrelated. CI overrides
|
|
# every one; see .gitea/workflows/deploy.yml.
|
|
- "127.0.0.1:${SITE_PORT:-8080}:80"
|
|
# Convenience only: the API through its own gateway. No test uses it.
|
|
- "127.0.0.1:${API_PORT:-8000}:81"
|
|
networks: [local, edge]
|
|
depends_on:
|
|
api: {condition: service_healthy}
|
|
healthcheck:
|
|
test: [CMD, wget, -q, -O, /dev/null, http://127.0.0.1/health]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 12
|
|
|
|
kanban:
|
|
build:
|
|
context: .
|
|
dockerfile: infra/Dockerfile.web
|
|
environment:
|
|
WEB_INDEX: kanban.html
|
|
S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:${STORAGE_PORT:-9000}}
|
|
PAYMENT_CSP_SOURCES: ""
|
|
PAYMENT_CHALLENGE_SOURCES: ""
|
|
ports: ["127.0.0.1:${KANBAN_PORT:-8081}:80"]
|
|
networks: [local, edge]
|
|
depends_on:
|
|
api: {condition: service_healthy}
|
|
healthcheck:
|
|
test: [CMD, wget, -q, -O, /dev/null, http://127.0.0.1/health]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 12
|
|
|
|
browser-tests:
|
|
profiles: [ci]
|
|
build:
|
|
context: .
|
|
dockerfile: infra/Dockerfile.browser-tests
|
|
environment:
|
|
CHROME_BIN: /usr/bin/chromium
|
|
CHROME_NO_SANDBOX: "1"
|
|
CHROME_TRUST_TEST_ORIGINS: "1"
|
|
SITE_BROWSER_ORIGIN: http://site
|
|
KANBAN_BROWSER_ORIGIN: http://kanban
|
|
OPERATOR_EMAIL: ${OPERATOR_EMAIL:-operator@example.test}
|
|
OPERATOR_PASSWORD: ${OPERATOR_PASSWORD:-local-operator-only}
|
|
shm_size: 1gb
|
|
networks: [local]
|
|
depends_on:
|
|
site: {condition: service_healthy}
|
|
kanban: {condition: service_healthy}
|
|
storage: {condition: service_healthy}
|
|
security_opt: [no-new-privileges:true]
|
|
cap_drop: [ALL]
|
|
|
|
volumes:
|
|
postgres-data:
|
|
storage-data:
|
|
|
|
networks:
|
|
local:
|
|
internal: true
|
|
edge:
|