mirror of
https://github.com/ajisaacs/OpenNest.git
synced 2026-10-03 05:52:11 -04:00
- Run as the .NET image's non-root app user (UID 1654) with root-owned application files and an app-owned /app/data that fresh named volumes inherit. - Add a curl HEALTHCHECK on /healthz (30s/5s/10s/3, 2s start interval), keep the explicit 8090 URL and clear the base image's 8080 port default. - Parameterize VERSION/SOURCE_REVISION and base images; add OCI labels with development defaults. - Add an image-only Compose example (required image and bind address, named volume, cap_drop ALL, no-new-privileges) and an env template. - Document deployment, the upload limit, scoped ownership preparation, and checked backup/restore/upgrade functions that refuse existing destinations and verify the metadata list and every archive hash before switching volumes. - Extend the container smoke: image user/healthcheck/label contract, PID 1 UID, capabilities and writable paths, Docker-reported health, near-limit and oversized uploads, stopped-service backup restored into a second volume, and startup failure on read-only and root-owned data mounts.
24 lines
908 B
YAML
24 lines
908 B
YAML
# OpenNest.Server deployment example: one instance, one local data volume, LAN-only.
|
|
# Usage: docker compose --env-file <local-env> -f compose.server.yaml up -d
|
|
# Start from OpenNest.Server/server.env.example. See docs/nest-storage.md before deploying.
|
|
name: opennest-server
|
|
services:
|
|
opennest-server:
|
|
image: ${OPENNEST_SERVER_IMAGE:?Set a tested version or digest}
|
|
restart: unless-stopped
|
|
ports:
|
|
- "${OPENNEST_BIND_ADDRESS:?Set 127.0.0.1 for testing or a trusted LAN address}:${OPENNEST_HOST_PORT:-8090}:8090"
|
|
environment:
|
|
ASPNETCORE_URLS: http://+:8090
|
|
OPENNEST_DB: /app/data/nests.db
|
|
volumes:
|
|
- opennest-data:/app/data
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
cap_drop:
|
|
- ALL
|
|
volumes:
|
|
opennest-data:
|
|
# A restore switches to a separately verified volume instead of overwriting this one.
|
|
name: ${OPENNEST_DATA_VOLUME:-opennest-data}
|