anvilsign in

collin/anvil

1# Local development only. `docker compose` merges this automatically when it
2# sits next to compose.yaml, and `hag` always passes `-f compose.yaml`
3# explicitly, so none of it reaches hagrid -- where Caddy fronts the container,
4# the SSO issuer is a public HTTPS URL with a normal CA, and there is
5# deliberately no Docker socket.
6#
7# The image carries a prebuilt binary, so stage one first (--debug compiles in
8# a fraction of the time a release build takes):
9#
10# ./deploy/build.sh --debug
11# docker compose up -d --build
12#
13# Then http://127.0.0.1:20640. `docker compose logs -f`, `docker compose down`.
14#
15# deploy/dev.sh remains the fuller path: it also generates deploy/dev-ca.crt
16# (mounted below), waits for /-/healthz, and points portless at the container.
17services:
18 anvil:
19 # A distinct tag, so a local build carrying the DEV config can never be
20 # mistaken for -- or pushed as -- the production image.
21 image: anvil-dev:latest
22 build:
23 args:
24 # Bakes deploy/anvil.dev.toml at /etc/anvil/anvil.toml instead of
25 # production's: local base_url, the login.localhost issuer, agent
26 # sessions on, and shorter periodic scans.
27 CONFIG: deploy/anvil.dev.toml
28 # Not `anvil`: that name belongs to deploy/dev.sh's container, and compose
29 # refuses to adopt a container it did not label.
30 container_name: anvil-dev
31
32 # !override, not a merge: `ports` is one of the keys compose CONCATENATES,
33 # so without it the production entry survives and the container tries to
34 # bind 165.232.162.167:22 on this machine.
35 ports: !override
36 # A stable, collision-resistant port for this project (`devport`), so it
37 # does not wander between runs.
38 - "127.0.0.1:${ANVIL_DEV_PORT:-20640}:3000"
39 # anvil.dev.toml advertises 20641 in SSH clone URLs; keep the two in step.
40 - "127.0.0.1:${ANVIL_DEV_SSH_PORT:-20641}:2222"
41
42 volumes: !override
43 # Separate from production's `anvil-data`, and the same volume dev.sh
44 # uses, so the two local paths share state. `docker volume rm
45 # anvil-dev-data` starts over.
46 - anvil-dev-data:/data
47
48 # Agent sessions (`[agent] enabled = true` in anvil.dev.toml) drive
49 # Docker directly, so they need the socket. CI does NOT -- that moved to
50 # anvil-worker, which is its own Docker client on its own machine.
51 #
52 # `label=disable` below rather than a `:z` relabel: :z would rewrite the
53 # SELinux label on the HOST's socket, which every other container on this
54 # machine also uses.
55 - /var/run/docker.sock:/var/run/docker.sock
56
57 # The SSO back channel calls https://login.localhost directly, and that
58 # certificate comes from the CA portless generated. anvild ships its own
59 # root store (rustls), so `portless trust` does not reach it -- hence a
60 # bundle of the host's roots plus that CA, which SSL_CERT_FILE points at.
61 # deploy/dev.sh writes this file; regenerate it by hand with:
62 # cat /etc/ssl/certs/ca-bundle.crt ~/.portless/ca.pem > deploy/dev-ca.crt
63 - ./deploy/dev-ca.crt:/etc/ssl/certs/anvil-dev-ca.crt:ro,z
64
65 # The gid owning /var/run/docker.sock on this host. `stat -c '%g'
66 # /var/run/docker.sock` if it differs on yours.
67 group_add:
68 - "${DOCKER_GID:-970}"
69 security_opt:
70 - label=disable
71
72 # Appended to production's host.docker.internal entry, not replacing it:
73 # login.localhost resolves to the container's own loopback otherwise,
74 # rather than the host's portless proxy.
75 extra_hosts:
76 - "login.localhost:host-gateway"
77
78 environment:
79 SSL_CERT_FILE: /etc/ssl/certs/anvil-dev-ca.crt
80 # Overrides anvil.dev.toml's baked base_url. Point it at
81 # http://127.0.0.1:20640 when testing websockets -- portless proxies
82 # them over HTTP/2, where they are currently broken -- but note that
83 # changing it also changes the OIDC redirect_uri, which the provider
84 # matches exactly.
85 ANVIL_BASE_URL: ${ANVIL_BASE_URL:-https://anvil.localhost}
86
87volumes:
88 anvil-dev-data:
89 name: anvil-dev-data
90 # Same expected "not created by Docker Compose" warning as production's
91 # volume: dev.sh made this one first, and compose adopts it.