anvilsign in

collin/mahjong

master / compose.yaml
1# 台灣麻將 on hagrid, deployed with `hag` -- the shared deploy tool for every
2# project on that host (build, push to the private registry, then pull and
3# recreate there). Both this machine and hagrid need
4# `docker login registry.vibe.richardscollin.com` once.
5#
6# IMAGE_TAG picks which build runs. hag sets it to the git sha it just pushed,
7# so `hag status` names the exact build, and rolling back on the host is
8# `IMAGE_TAG=<sha> docker compose up -d --no-build`.
9services:
10 mahjong:
11 image: registry.vibe.richardscollin.com/mahjong:${IMAGE_TAG:-latest}
12 build: .
13 # Caddy reverse-proxies to `mahjong:3000` by name, so this is load-bearing.
14 container_name: mahjong
15 restart: unless-stopped
16
17 # PUBLIC_URL above all -- see below. Optional so the container still starts
18 # on a host that has none.
19 env_file:
20 - path: .env
21 required: false
22
23 environment:
24 PORT: 3000
25 # Where the outside world reaches this game, and it matters more here
26 # than it looks: it is the origin every QR carries. The table's own
27 # address inside the container is a docker bridge address that nobody
28 # can reach, and the relay knows better than to hand that out (see
29 # `lanAddress` in server/rooms.ts), so without this there is simply no
30 # QR tile on the felt and the only way in is a link typed by hand.
31 #
32 # https, not http: a phone only gets fullscreen and the camera on a
33 # secure origin, and Caddy is already terminating TLS in front of this.
34 PUBLIC_URL: ${PUBLIC_URL:-}
35
36 networks:
37 - hagrid
38
39# Caddy runs on this network and reverse-proxies to the container by name, so
40# no host port is published. The hagrid repo owns the network's lifecycle.
41networks:
42 hagrid:
43 external: true