| 1 | extends "../../config/Service.pkl" |
| 2 | |
| 3 | import "../../config/Service.pkl" as service |
| 4 | import "../../config/OpenID.pkl" as sso |
| 5 | import "../postgres/service.pkl" as postgres |
| 6 | |
| 7 | local dawarichImage = "docker.io/freikin/dawarich@sha256:76ec5fa62f414a5ca9e6dd71a9a5b09088c0011075c41644ba35bbb67627a943" |
| 8 | |
| 9 | local database = new postgres.Database { |
| 10 | name = "dawarich" |
| 11 | extensions { "postgis" } |
| 12 | } |
| 13 | |
| 14 | local commonEnv: Mapping<String, String> = new { |
| 15 | ["RAILS_ENV"] = "production" |
| 16 | ["DATABASE_USERNAME"] = "${secret.database.username}" |
| 17 | ["DATABASE_PASSWORD"] = "${secret.database.password}" |
| 18 | ["DATABASE_NAME"] = "${secret.database.name}" |
| 19 | ["PGCONNECT_TIMEOUT"] = "10" |
| 20 | ["SECRET_KEY_BASE"] = "${secret.own.secret_key_base}" |
| 21 | ["APPLICATION_HOSTS"] = "localhost,127.0.0.1,\(module.containers["web"].http.hostname)" |
| 22 | ["APPLICATION_PROTOCOL"] = "https" |
| 23 | ["SELF_HOSTED"] = "true" |
| 24 | ["STORE_GEODATA"] = "true" |
| 25 | ["TIME_ZONE"] = "America/Los_Angeles" |
| 26 | ["PUID"] = "\(module.uid)" |
| 27 | ["PGID"] = "\(module.uid)" |
| 28 | } |
| 29 | |
| 30 | local sharedVolumes: Mapping<String, service.Volume> = new { |
| 31 | ["/var/app/public"] {} |
| 32 | ["/var/app/storage"] {} |
| 33 | ["/var/app/tmp/imports/watched"] {} |
| 34 | ["/etc/ssl/certs/ca-certificates.crt"] { |
| 35 | src = "/var/lib/studio/ca-bundle.crt" |
| 36 | readOnly = true |
| 37 | } |
| 38 | } |
| 39 | |
| 40 | local databaseEnv = """ |
| 41 | {{ range nomadService 1 (env "NOMAD_ALLOC_ID") "postgres" }}DATABASE_HOST={{ .Address }} |
| 42 | DATABASE_PORT={{ .Port }}{{ end }} |
| 43 | {{ range nomadService 1 (env "NOMAD_ALLOC_ID") "\(module.id)-redis" }}REDIS_URL=redis://\(module.nomadHostPort){{ end }} |
| 44 | """ |
| 45 | |
| 46 | meta { name = "Dawarich"; access = "infra-admin" } |
| 47 | healthyDeadline = "20m" |
| 48 | |
| 49 | requirements { |
| 50 | database |
| 51 | new sso.Client { |
| 52 | clientId = module.id |
| 53 | name = module.meta.name |
| 54 | redirectUris { "https://\(module.containers["web"].http.hostname)/users/auth/openid_connect/callback" } |
| 55 | } |
| 56 | } |
| 57 | |
| 58 | secrets { |
| 59 | ["secret_key_base"] { bytes = 64 } |
| 60 | } |
| 61 | |
| 62 | containers { |
| 63 | ["migrate"] { |
| 64 | image = dawarichImage |
| 65 | entrypoint = "web-entrypoint.sh" |
| 66 | args { "ruby"; "-e"; "exit 0" } |
| 67 | imageUser = true |
| 68 | lifecycle = "prestart" |
| 69 | cpu = 200 |
| 70 | memory = 1024 |
| 71 | volumes = sharedVolumes |
| 72 | env = commonEnv |
| 73 | envTemplate = databaseEnv |
| 74 | } |
| 75 | |
| 76 | ["web"] { |
| 77 | image = dawarichImage |
| 78 | extraHosts { "\(sso.hostname):host-gateway" } |
| 79 | entrypoint = "web-entrypoint.sh" |
| 80 | args { "bin/rails"; "server"; "-p"; "3000"; "-b"; "::" } |
| 81 | imageUser = true |
| 82 | cpu = 400 |
| 83 | memory = 2048 |
| 84 | |
| 85 | http { |
| 86 | containerPort = 3000 |
| 87 | subdomain = "dawarich" |
| 88 | checkPath = "/api/v1/health" |
| 89 | checkHeaders { ["X-Forwarded-Proto"] = "https" } |
| 90 | } |
| 91 | |
| 92 | volumes = sharedVolumes |
| 93 | env = (commonEnv) { |
| 94 | ["DOMAIN"] = module.containers["web"].http.hostname |
| 95 | ["WEB_CONCURRENCY"] = "1" |
| 96 | ["OIDC_CLIENT_ID"] = "${secret.oidc.clientId}" |
| 97 | ["OIDC_CLIENT_SECRET"] = "${secret.oidc.clientSecret}" |
| 98 | ["OIDC_ISSUER"] = sso.issuer |
| 99 | ["OIDC_REDIRECT_URI"] = "https://\(module.containers["web"].http.hostname)/users/auth/openid_connect/callback" |
| 100 | ["ALLOW_EMAIL_PASSWORD_REGISTRATION"] = "false" |
| 101 | } |
| 102 | envTemplate = databaseEnv |
| 103 | } |
| 104 | |
| 105 | ["worker"] { |
| 106 | image = dawarichImage |
| 107 | entrypoint = "sidekiq-entrypoint.sh" |
| 108 | args { "sidekiq" } |
| 109 | imageUser = true |
| 110 | cpu = 200 |
| 111 | memory = 1024 |
| 112 | volumes = sharedVolumes |
| 113 | env = (commonEnv) { |
| 114 | ["BACKGROUND_PROCESSING_CONCURRENCY"] = "3" |
| 115 | } |
| 116 | envTemplate = databaseEnv |
| 117 | } |
| 118 | |
| 119 | ["redis"] { |
| 120 | image = "docker.io/library/redis@sha256:718f745deb7dfefeac6eed7041fc7ec9476b50e61b247932682457c41adafa0e" |
| 121 | lifecycle = "prestartSidecar" |
| 122 | args { "redis-server"; "--save"; "900"; "1"; "--appendonly"; "no" } |
| 123 | memory = 256 |
| 124 | tcp { |
| 125 | name = "redis" |
| 126 | containerPort = 6379 |
| 127 | loopback = false |
| 128 | } |
| 129 | volumes { ["/data"] {} } |
| 130 | } |
| 131 | } |