1extends "../../config/Service.pkl"
2
3import "../../config/Service.pkl" as service
4import "../../config/OpenID.pkl" as sso
5import "../postgres/service.pkl" as postgres
6
7local dawarichImage = "docker.io/freikin/dawarich@sha256:76ec5fa62f414a5ca9e6dd71a9a5b09088c0011075c41644ba35bbb67627a943"
8
9local database = new postgres.Database {
10 name = "dawarich"
11 extensions { "postgis" }
12}
13
14local commonEnv: Mapping<String, String> = new {
15 ["RAILS_ENV"] = "production"
16 ["DATABASE_USERNAME"] = "${secret.database.username}"
17 ["DATABASE_PASSWORD"] = "${secret.database.password}"
18 ["DATABASE_NAME"] = "${secret.database.name}"
19 ["PGCONNECT_TIMEOUT"] = "10"
20 ["SECRET_KEY_BASE"] = "${secret.own.secret_key_base}"
21 ["APPLICATION_HOSTS"] = "localhost,127.0.0.1,\(module.containers["web"].http.hostname)"
22 ["APPLICATION_PROTOCOL"] = "https"
23 ["SELF_HOSTED"] = "true"
24 ["STORE_GEODATA"] = "true"
25 ["TIME_ZONE"] = "America/Los_Angeles"
26 ["PUID"] = "\(module.uid)"
27 ["PGID"] = "\(module.uid)"
28}
29
30local sharedVolumes: Mapping<String, service.Volume> = new {
31 ["/var/app/public"] {}
32 ["/var/app/storage"] {}
33 ["/var/app/tmp/imports/watched"] {}
34 ["/etc/ssl/certs/ca-certificates.crt"] {
35 src = "/var/lib/studio/ca-bundle.crt"
36 readOnly = true
37 }
38}
39
40local databaseEnv = """
41 {{ range nomadService 1 (env "NOMAD_ALLOC_ID") "postgres" }}DATABASE_HOST={{ .Address }}
42 DATABASE_PORT={{ .Port }}{{ end }}
43 {{ range nomadService 1 (env "NOMAD_ALLOC_ID") "\(module.id)-redis" }}REDIS_URL=redis://\(module.nomadHostPort){{ end }}
44 """
45
46meta { name = "Dawarich"; access = "infra-admin" }
47healthyDeadline = "20m"
48
49requirements {
50 database
51 new sso.Client {
52 clientId = module.id
53 name = module.meta.name
54 redirectUris { "https://\(module.containers["web"].http.hostname)/users/auth/openid_connect/callback" }
55 }
56}
57
58secrets {
59 ["secret_key_base"] { bytes = 64 }
60}
61
62containers {
63 ["migrate"] {
64 image = dawarichImage
65 entrypoint = "web-entrypoint.sh"
66 args { "ruby"; "-e"; "exit 0" }
67 imageUser = true
68 lifecycle = "prestart"
69 cpu = 200
70 memory = 1024
71 volumes = sharedVolumes
72 env = commonEnv
73 envTemplate = databaseEnv
74 }
75
76 ["web"] {
77 image = dawarichImage
78 extraHosts { "\(sso.hostname):host-gateway" }
79 entrypoint = "web-entrypoint.sh"
80 args { "bin/rails"; "server"; "-p"; "3000"; "-b"; "::" }
81 imageUser = true
82 cpu = 400
83 memory = 2048
84
85 http {
86 containerPort = 3000
87 subdomain = "dawarich"
88 checkPath = "/api/v1/health"
89 checkHeaders { ["X-Forwarded-Proto"] = "https" }
90 }
91
92 volumes = sharedVolumes
93 env = (commonEnv) {
94 ["DOMAIN"] = module.containers["web"].http.hostname
95 ["WEB_CONCURRENCY"] = "1"
96 ["OIDC_CLIENT_ID"] = "${secret.oidc.clientId}"
97 ["OIDC_CLIENT_SECRET"] = "${secret.oidc.clientSecret}"
98 ["OIDC_ISSUER"] = sso.issuer
99 ["OIDC_REDIRECT_URI"] = "https://\(module.containers["web"].http.hostname)/users/auth/openid_connect/callback"
100 ["ALLOW_EMAIL_PASSWORD_REGISTRATION"] = "false"
101 }
102 envTemplate = databaseEnv
103 }
104
105 ["worker"] {
106 image = dawarichImage
107 entrypoint = "sidekiq-entrypoint.sh"
108 args { "sidekiq" }
109 imageUser = true
110 cpu = 200
111 memory = 1024
112 volumes = sharedVolumes
113 env = (commonEnv) {
114 ["BACKGROUND_PROCESSING_CONCURRENCY"] = "3"
115 }
116 envTemplate = databaseEnv
117 }
118
119 ["redis"] {
120 image = "docker.io/library/redis@sha256:718f745deb7dfefeac6eed7041fc7ec9476b50e61b247932682457c41adafa0e"
121 lifecycle = "prestartSidecar"
122 args { "redis-server"; "--save"; "900"; "1"; "--appendonly"; "no" }
123 memory = 256
124 tcp {
125 name = "redis"
126 containerPort = 6379
127 loopback = false
128 }
129 volumes { ["/data"] {} }
130 }
131}