Make gateway-bound UIs reproducible
This commit is contained in:
1 parent
460a9f0207
commit
16ac177782
6 files changed
+42
-8
No files matched your search
@@ -50,6 +50,11 @@ services:
|
||||
- /tmp:size=16m,mode=1777
|
||||
volumes:
|
||||
- "${WIREGUARD_CONFIG_FILE:-/etc/mike-ai/wireguard/fritz-athena.conf}:/run/secrets/fritz-athena.conf:ro"
|
||||
# Namespace-sharing services cannot publish ports themselves. The owner
|
||||
# must keep these bindings so a gateway recreation cannot hide their UIs.
|
||||
ports:
|
||||
- "8099:8099"
|
||||
- "9443:9443"
|
||||
networks:
|
||||
frontend:
|
||||
ipv4_address: 172.30.10.254
|
||||
@@ -750,6 +755,20 @@ services:
|
||||
retries: 12
|
||||
start_period: 10s
|
||||
|
||||
portainer:
|
||||
image: ${PORTAINER_IMAGE:-portainer/portainer-ce@sha256:511f3f06c96fe3b993ebeaafde311c1959cae73a7ef825dba6397d51b450dffa}
|
||||
container_name: mike-ai-portainer
|
||||
restart: unless-stopped
|
||||
network_mode: "service:wireguard-gateway"
|
||||
command: [--no-setup-token]
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- portainer-data:/data
|
||||
depends_on:
|
||||
wireguard-gateway:
|
||||
condition: service_healthy
|
||||
security_opt: ["no-new-privileges:true"]
|
||||
|
||||
backup:
|
||||
image: ${BACKUP_IMAGE:-offen/docker-volume-backup@sha256:19102d8e59eb1d598cf8c647c2b21100abaadc5a1c808ac643fa612e323c3013}
|
||||
container_name: mike-ai-backup
|
||||
@@ -768,6 +787,7 @@ services:
|
||||
- piper-data:/backup/volumes/piper-data:ro
|
||||
- router-state:/backup/volumes/router-state:ro
|
||||
- router-images:/backup/volumes/router-images:ro
|
||||
- portainer-data:/backup/volumes/portainer-data:ro
|
||||
security_opt: ["no-new-privileges:true"]
|
||||
|
||||
networks:
|
||||
@@ -794,3 +814,5 @@ volumes:
|
||||
piper-data:
|
||||
router-state:
|
||||
router-images:
|
||||
portainer-data:
|
||||
name: portainer_data
|
||||
Reference in new issue
Block a user