This repository was archived by the owner on Aug 19, 2025. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
126 lines (120 loc) · 3.51 KB
/
docker-compose.yml
File metadata and controls
126 lines (120 loc) · 3.51 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
services:
nginx:
image: nginx:latest
container_name: nginx
volumes:
- ./nginx.conf:/etc/nginx/nginx.conf:ro
- ./nginx_external_services.conf:/etc/nginx/conf.d/nginx_external_services.conf:ro
- certbot-etc:/etc/letsencrypt:ro
ports:
- "443:443"
- "80:80"
networks:
- imaginer-network
depends_on:
certbot:
condition: service_completed_successfully
keycloak:
condition: service_started
restart: always
certbot:
image: certbot/dns-cloudflare
container_name: certbot
volumes:
- certbot-etc:/etc/letsencrypt
- ./cloudflare.ini:/cloudflare.ini:ro
entrypoint: >
sh -c "
certbot certonly --dns-cloudflare
--dns-cloudflare-credentials /cloudflare.ini
--dns-cloudflare-propagation-seconds 30
--agree-tos
--email rodrigo.brocchi@gmail.com
-d imaginer.com.br
-d auth.imaginer.com.br
-d server.imaginer.com.br
-d gateway.imaginer.com.br
-d eureka.imaginer.com.br
--non-interactive &&
chmod -R 755 /etc/letsencrypt
"
restart: "no"
networks:
- imaginer-network
ofelia:
image: mcuadros/ofelia
container_name: ofelia
depends_on:
certbot:
condition: service_completed_successfully
volumes:
- /var/run/docker.sock:/var/run/docker.sock
command: daemon --docker
environment:
- TZ=America/Sao_Paulo
restart: always
labels:
- "ofelia.enabled=true"
- "ofelia.job-run.certbot.schedule=0 */12 * * *"
- "ofelia.job-run.certbot.container=certbot"
- "ofelia.job-run.certbot.command=certbot renew --dns-cloudflare --dns-cloudflare-credentials /cloudflare.ini --quiet && chmod -R 755 /etc/letsencrypt"
networks:
- imaginer-network
keycloak:
image: quay.io/keycloak/keycloak:latest
container_name: keycloak
command: start
ports:
- "9000:9000"
environment:
KC_DB: postgres
KC_DB_URL_HOST: keycloak-postgres
KC_DB_URL_PORT: 5432
KC_DB_USERNAME: ${POSTGRES_USER:-keycloak}
KC_DB_PASSWORD: ${POSTGRES_PASSWORD:-keycloak}
KC_HOSTNAME: auth.imaginer.com.br
KC_HOSTNAME_ADMIN_URL: https://auth.imaginer.com.br
KC_HTTP_ENABLED: false
KC_HTTPS_PORT: 9000
KC_HTTPS_CERTIFICATE_FILE: /etc/letsencrypt/live/imaginer.com.br/fullchain.pem
KC_HTTPS_CERTIFICATE_KEY_FILE: /etc/letsencrypt/live/imaginer.com.br/privkey.pem
KC_HOSTNAME_STRICT: true
KC_PROXY_MODE: "edge"
KC_PROXY: "edge"
KC_PROXY_HEADERS: "xforwarded"
PROXY_ADDRESS_FORWARDING: true
KEYCLOAK_ADMIN: ${KEYCLOAK_ADMIN:-admin}
KEYCLOAK_ADMIN_PASSWORD: ${KEYCLOAK_ADMIN_PASSWORD:-admin}
volumes:
- certbot-etc:/etc/letsencrypt:ro
depends_on:
certbot:
condition: service_completed_successfully
postgres:
condition: service_healthy
restart: unless-stopped
networks:
- imaginer-network
postgres:
image: postgres:17
container_name: keycloak-postgres
environment:
POSTGRES_USER: ${POSTGRES_USER:-keycloak}
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-keycloak}
POSTGRES_DB: ${POSTGRES_DB:-keycloak}
volumes:
- postgres_data:/var/lib/postgresql/data
networks:
- imaginer-network
restart: always
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-keycloak}"]
interval: 10s
timeout: 5s
retries: 5
volumes:
certbot-etc:
postgres_data:
networks:
imaginer-network:
driver: bridge