-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
135 lines (121 loc) · 3.93 KB
/
Copy pathdocker-compose.yml
File metadata and controls
135 lines (121 loc) · 3.93 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
services:
# PostgreSQL database
postgres:
image: postgres:16-alpine
container_name: cudly-postgres
environment:
POSTGRES_DB: cudly
POSTGRES_USER: cudly
POSTGRES_PASSWORD: cudly_local_dev
POSTGRES_INITDB_ARGS: "-E UTF8 --locale=C"
ports:
- "5432:5432"
volumes:
- postgres_data:/var/lib/postgresql/data
# Note: Migrations are handled by the app via golang-migrate (DB_AUTO_MIGRATE=true)
# Do NOT mount to docker-entrypoint-initdb.d as it conflicts with golang-migrate
healthcheck:
test: ["CMD-SHELL", "pg_isready -U cudly"]
interval: 5s
timeout: 5s
retries: 5
networks:
- cudly-network
# CUDly application (development mode)
app:
build:
context: .
dockerfile: Dockerfile.dev
container_name: cudly-app
depends_on:
postgres:
condition: service_healthy
environment:
# Database configuration
DB_HOST: postgres
DB_PORT: 5432
DB_NAME: cudly
DB_USER: cudly
DB_PASSWORD: cudly_local_dev
DB_SSL_MODE: disable
DB_AUTO_MIGRATE: "true"
DB_MIGRATIONS_PATH: /app/internal/database/postgres/migrations
# Secret provider — "env" reads secrets from env vars (local-dev only).
# Production uses "aws" / "azure" / "gcp" with real Secrets Manager.
SECRET_PROVIDER: env
# Admin password secret: the EnvResolver looks up the env var whose
# NAME equals ADMIN_PASSWORD_SECRET. Here it points at ADMIN_PASSWORD_DEV.
ADMIN_PASSWORD_SECRET: ADMIN_PASSWORD_DEV
ADMIN_PASSWORD_DEV: "LocalDev!Pass123"
ADMIN_EMAIL: [email protected]
# API-key secret: same pattern — name → env var that holds the value.
# Frontend asks for this in the admin-setup modal.
API_KEY_SECRET_ARN: ADMIN_API_KEY_DEV
ADMIN_API_KEY_DEV: "cudly-local-dev-api-key-not-for-prod"
# Credential encryption: dev key (all-zero) is gated behind this flag.
CREDENTIAL_ENCRYPTION_ALLOW_DEV_KEY: "1"
# Email disabled for local development (no SNS topic / SES creds)
EMAIL_ENABLED: "false"
# Scheduled-task auth: OIDC for prod, disabled for local dev so the
# internal /api/scheduled/* endpoints don't require Google ID tokens.
SCHEDULED_TASK_AUTH_MODE: disabled
# Application settings
ENVIRONMENT: development
LOG_LEVEL: debug
CORS_ALLOWED_ORIGIN: http://localhost:3001
# Optional: set initial admin password (skips password reset)
# ADMIN_PASSWORD: "YourSecureP@ss1"
# AWS configuration (if needed for testing)
AWS_REGION: us-east-1
# AWS_PROFILE: default # Uncomment if using AWS profiles
ports:
- "8080:8080"
volumes:
# Mount source code for hot reload
- .:/app
# Cache Go modules
- go_modules:/go/pkg/mod
networks:
- cudly-network
command: air # Use Air for hot reload in development
# Frontend (nginx with reverse proxy to backend)
frontend:
image: nginx:alpine
container_name: cudly-frontend
depends_on:
- app
ports:
- "3001:80"
volumes:
- ./frontend/dist:/usr/share/nginx/html:ro
- ./scripts/nginx.conf:/etc/nginx/conf.d/default.conf:ro
networks:
- cudly-network
# pgAdmin for database management (local development only — do not expose in production)
pgadmin:
image: dpage/pgadmin4:9.2
container_name: cudly-pgadmin
environment:
PGADMIN_DEFAULT_EMAIL: ${PGADMIN_EMAIL}
PGADMIN_DEFAULT_PASSWORD: ${PGADMIN_PASSWORD}
PGADMIN_CONFIG_SERVER_MODE: 'False'
ports:
- "5050:80"
volumes:
- pgadmin_data:/var/lib/pgadmin
networks:
- cudly-network
depends_on:
- postgres
profiles:
- tools # Only start with: docker-compose --profile tools up
volumes:
postgres_data:
driver: local
pgadmin_data:
driver: local
go_modules:
driver: local
networks:
cudly-network:
driver: bridge