collin/anvil
7ddd780b72873d9441d2fef674cea14061aee161 / compose.override.yaml
| 1 | # Local development only. `docker compose` merges this automatically when it |
| 2 | # sits next to compose.yaml, and `hag` always passes `-f compose.yaml` |
| 3 | # explicitly, so none of it reaches hagrid -- where Caddy fronts the container, |
| 4 | # the SSO issuer is a public HTTPS URL with a normal CA, and there is |
| 5 | # deliberately no Docker socket. |
| 6 | # |
| 7 | # The image carries a prebuilt binary, so stage one first (--debug compiles in |
| 8 | # a fraction of the time a release build takes): |
| 9 | # |
| 10 | # ./deploy/build.sh --debug |
| 11 | # docker compose up -d --build |
| 12 | # |
| 13 | # Then http://127.0.0.1:20640. `docker compose logs -f`, `docker compose down`. |
| 14 | # |
| 15 | # deploy/dev.sh remains the fuller path: it also generates deploy/dev-ca.crt |
| 16 | # (mounted below), waits for /-/healthz, and points portless at the container. |
| 17 | services: |
| 18 | anvil: |
| 19 | # A distinct tag, so a local build carrying the DEV config can never be |
| 20 | # mistaken for -- or pushed as -- the production image. |
| 21 | image: anvil-dev:latest |
| 22 | build: |
| 23 | args: |
| 24 | # Bakes deploy/anvil.dev.toml at /etc/anvil/anvil.toml instead of |
| 25 | # production's: local base_url, the login.localhost issuer, agent |
| 26 | # sessions on, and shorter periodic scans. |
| 27 | CONFIG: deploy/anvil.dev.toml |
| 28 | # Not `anvil`: that name belongs to deploy/dev.sh's container, and compose |
| 29 | # refuses to adopt a container it did not label. |
| 30 | container_name: anvil-dev |
| 31 | |
| 32 | # !override, not a merge: `ports` is one of the keys compose CONCATENATES, |
| 33 | # so without it the production entry survives and the container tries to |
| 34 | # bind 165.232.162.167:22 on this machine. |
| 35 | ports: !override |
| 36 | # A stable, collision-resistant port for this project (`devport`), so it |
| 37 | # does not wander between runs. |
| 38 | - "127.0.0.1:${ANVIL_DEV_PORT:-20640}:3000" |
| 39 | # anvil.dev.toml advertises 20641 in SSH clone URLs; keep the two in step. |
| 40 | - "127.0.0.1:${ANVIL_DEV_SSH_PORT:-20641}:2222" |
| 41 | |
| 42 | volumes: !override |
| 43 | # Separate from production's `anvil-data`, and the same volume dev.sh |
| 44 | # uses, so the two local paths share state. `docker volume rm |
| 45 | # anvil-dev-data` starts over. |
| 46 | - anvil-dev-data:/data |
| 47 | |
| 48 | # Agent sessions (`[agent] enabled = true` in anvil.dev.toml) drive |
| 49 | # Docker directly, so they need the socket. CI does NOT -- that moved to |
| 50 | # anvil-worker, which is its own Docker client on its own machine. |
| 51 | # |
| 52 | # `label=disable` below rather than a `:z` relabel: :z would rewrite the |
| 53 | # SELinux label on the HOST's socket, which every other container on this |
| 54 | # machine also uses. |
| 55 | - /var/run/docker.sock:/var/run/docker.sock |
| 56 | |
| 57 | # The SSO back channel calls https://login.localhost directly, and that |
| 58 | # certificate comes from the CA portless generated. anvild ships its own |
| 59 | # root store (rustls), so `portless trust` does not reach it -- hence a |
| 60 | # bundle of the host's roots plus that CA, which SSL_CERT_FILE points at. |
| 61 | # deploy/dev.sh writes this file; regenerate it by hand with: |
| 62 | # cat /etc/ssl/certs/ca-bundle.crt ~/.portless/ca.pem > deploy/dev-ca.crt |
| 63 | - ./deploy/dev-ca.crt:/etc/ssl/certs/anvil-dev-ca.crt:ro,z |
| 64 | |
| 65 | # The gid owning /var/run/docker.sock on this host. `stat -c '%g' |
| 66 | # /var/run/docker.sock` if it differs on yours. |
| 67 | group_add: |
| 68 | - "${DOCKER_GID:-970}" |
| 69 | security_opt: |
| 70 | - label=disable |
| 71 | |
| 72 | # Appended to production's host.docker.internal entry, not replacing it: |
| 73 | # login.localhost resolves to the container's own loopback otherwise, |
| 74 | # rather than the host's portless proxy. |
| 75 | extra_hosts: |
| 76 | - "login.localhost:host-gateway" |
| 77 | |
| 78 | environment: |
| 79 | SSL_CERT_FILE: /etc/ssl/certs/anvil-dev-ca.crt |
| 80 | # Overrides anvil.dev.toml's baked base_url. Point it at |
| 81 | # http://127.0.0.1:20640 when testing websockets -- portless proxies |
| 82 | # them over HTTP/2, where they are currently broken -- but note that |
| 83 | # changing it also changes the OIDC redirect_uri, which the provider |
| 84 | # matches exactly. |
| 85 | ANVIL_BASE_URL: ${ANVIL_BASE_URL:-https://anvil.localhost} |
| 86 | |
| 87 | volumes: |
| 88 | anvil-dev-data: |
| 89 | name: anvil-dev-data |
| 90 | # Same expected "not created by Docker Compose" warning as production's |
| 91 | # volume: dev.sh made this one first, and compose adopts it. |