Compare commits
75 Commits
0877334a4b
...
dev
| Author | SHA1 | Date | |
|---|---|---|---|
| 090b437186 | |||
|
|
f6371f8813 | ||
| 62e301ec5b | |||
|
|
1af2cfa4e2 | ||
|
|
975ae0cedc | ||
| 9fad7dd21a | |||
|
|
0ba70d2e60 | ||
|
|
5a7d51e253 | ||
|
|
e4670693cd | ||
|
|
90b875752b | ||
| 1324c6f0a3 | |||
| 05523cd797 | |||
| f0a258a422 | |||
| 8bdb1f6a17 | |||
| 02b3f3c740 | |||
| 04acdbf72b | |||
| a24c79752d | |||
| ce89f22545 | |||
| e00d0b63e7 | |||
| 223b6ac8a1 | |||
| df0fdfe2e4 | |||
| e968457afa | |||
| 2c2920d7b5 | |||
| 15b05eb4cf | |||
| cd2e02bb82 | |||
| 7e4b38e9da | |||
| 97ac924c22 | |||
| f342e38fea | |||
| b4bf02cb14 | |||
| 0e3d0395d7 | |||
| 2da700990b | |||
| b3d731fb5e | |||
| c04cad9712 | |||
| fd030ea07e | |||
| 3adc86e8eb | |||
| 47fc79299e | |||
| a8018d7e37 | |||
| a721ab2f4f | |||
| ce85345584 | |||
| 2dea0a941c | |||
| 6f5594ade5 | |||
| 91007c85d8 | |||
| 34217290c1 | |||
| 07f05e7e94 | |||
| 462bcd7cce | |||
| 11b9cdcf02 | |||
| 59f1a17e53 | |||
| e3292ccd60 | |||
| 838e83cfc2 | |||
| 0f18439790 | |||
| 62606adab9 | |||
| b21186d2e9 | |||
| 69d4bde07e | |||
| 500d894e91 | |||
| 05571ceb34 | |||
| e0e7929741 | |||
| afb455dc28 | |||
| 3ebead084f | |||
| 674fb16aea | |||
| fbed4fb5b0 | |||
| 72ee47c543 | |||
| 9e05d2080a | |||
| e5c4f0104e | |||
| fbf7ba5ad8 | |||
| 2a19abe3bf | |||
| d7cfb08e57 | |||
| 94ae009b29 | |||
| 13d3ec50e9 | |||
| 7b5b62f46e | |||
| d07aaeb565 | |||
| 8a3ca5ea11 | |||
| 32e63e705c | |||
| 56bfb333e9 | |||
| 7c9041cf43 | |||
| 96de98c362 |
@@ -7,6 +7,7 @@ services:
|
|||||||
networks:
|
networks:
|
||||||
- common-infra-nginx-development
|
- common-infra-nginx-development
|
||||||
- configurator
|
- configurator
|
||||||
|
- minio-development
|
||||||
environment:
|
environment:
|
||||||
MINIO_SECRET_KEY: $MINIO_SECRET_KEY_DEV
|
MINIO_SECRET_KEY: $MINIO_SECRET_KEY_DEV
|
||||||
ports:
|
ports:
|
||||||
@@ -48,6 +49,8 @@ services:
|
|||||||
|
|
||||||
postgres:
|
postgres:
|
||||||
image: postgres:14-alpine3.19
|
image: postgres:14-alpine3.19
|
||||||
|
networks:
|
||||||
|
- postgres-development
|
||||||
volumes:
|
volumes:
|
||||||
- /sprint-data/postgres-data:/var/lib/postgresql/data
|
- /sprint-data/postgres-data:/var/lib/postgresql/data
|
||||||
environment:
|
environment:
|
||||||
@@ -74,6 +77,8 @@ services:
|
|||||||
|
|
||||||
mongo:
|
mongo:
|
||||||
image: mongo:6.0.2
|
image: mongo:6.0.2
|
||||||
|
networks:
|
||||||
|
- mongo-development
|
||||||
volumes:
|
volumes:
|
||||||
- /sprint-data/mongo:/data/db
|
- /sprint-data/mongo:/data/db
|
||||||
environment:
|
environment:
|
||||||
@@ -93,29 +98,6 @@ services:
|
|||||||
parallelism: 1
|
parallelism: 1
|
||||||
order: start-first
|
order: start-first
|
||||||
|
|
||||||
rabbitmq:
|
|
||||||
image: rabbitmq:3.10.7-management
|
|
||||||
volumes:
|
|
||||||
- /sprint-data/rabbitmq:/var/lib/rabbitmq
|
|
||||||
ports:
|
|
||||||
- published: 5672
|
|
||||||
target: 5672
|
|
||||||
mode: host
|
|
||||||
- published: 15672
|
|
||||||
target: 15672
|
|
||||||
mode: host
|
|
||||||
environment:
|
|
||||||
RABBITMQ_DEFAULT_PASS: $RABBITMQ_PASSWORD_DEV
|
|
||||||
deploy:
|
|
||||||
mode: replicated
|
|
||||||
restart_policy:
|
|
||||||
condition: any
|
|
||||||
placement:
|
|
||||||
constraints: [node.labels.stage == development]
|
|
||||||
update_config:
|
|
||||||
parallelism: 1
|
|
||||||
order: start-first
|
|
||||||
|
|
||||||
redis:
|
redis:
|
||||||
image: redis:alpine3.16
|
image: redis:alpine3.16
|
||||||
volumes:
|
volumes:
|
||||||
@@ -137,6 +119,8 @@ services:
|
|||||||
|
|
||||||
minio:
|
minio:
|
||||||
image: bitnami/minio:2022.10.8
|
image: bitnami/minio:2022.10.8
|
||||||
|
networks:
|
||||||
|
- minio-development
|
||||||
volumes:
|
volumes:
|
||||||
- minio_data:/data
|
- minio_data:/data
|
||||||
environment:
|
environment:
|
||||||
@@ -165,7 +149,7 @@ services:
|
|||||||
- /var/run/docker.sock:/var/run/docker.sock
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
- /sprint-data:/sprint-data
|
- /sprint-data:/sprint-data
|
||||||
environment:
|
environment:
|
||||||
GITEA_INSTANCE_URL: https://gitea.sprinthub.ru/
|
GITEA_INSTANCE_URL: https://gitea.chocomarsh.com/
|
||||||
GITEA_RUNNER_REGISTRATION_TOKEN: $REGISTRATION_TOKEN
|
GITEA_RUNNER_REGISTRATION_TOKEN: $REGISTRATION_TOKEN
|
||||||
GITEA_RUNNER_NAME: dev
|
GITEA_RUNNER_NAME: dev
|
||||||
GITEA_RUNNER_LABELS: dev
|
GITEA_RUNNER_LABELS: dev
|
||||||
@@ -190,3 +174,9 @@ networks:
|
|||||||
external: true
|
external: true
|
||||||
clickhouse-development:
|
clickhouse-development:
|
||||||
external: true
|
external: true
|
||||||
|
postgres-development:
|
||||||
|
external: true
|
||||||
|
mongo-development:
|
||||||
|
external: true
|
||||||
|
minio-development:
|
||||||
|
external: true
|
||||||
@@ -7,6 +7,7 @@ services:
|
|||||||
networks:
|
networks:
|
||||||
- common-infra-nginx
|
- common-infra-nginx
|
||||||
- configurator
|
- configurator
|
||||||
|
- minio
|
||||||
environment:
|
environment:
|
||||||
MINIO_SECRET_KEY: $MINIO_SECRET_KEY_PROD
|
MINIO_SECRET_KEY: $MINIO_SECRET_KEY_PROD
|
||||||
ports:
|
ports:
|
||||||
@@ -26,57 +27,6 @@ services:
|
|||||||
update_config:
|
update_config:
|
||||||
parallelism: 1
|
parallelism: 1
|
||||||
# order: start-first
|
# order: start-first
|
||||||
|
|
||||||
zitadel:
|
|
||||||
image: ghcr.io/zitadel/zitadel:latest
|
|
||||||
networks:
|
|
||||||
- common-infra-nginx
|
|
||||||
command: 'start-from-init --masterkey "MasterkeyNeedsToHave32Characters" --tlsMode disabled'
|
|
||||||
environment:
|
|
||||||
ZITADEL_DATABASE_POSTGRES_HOST: pg.sprinthub.ru
|
|
||||||
ZITADEL_DATABASE_POSTGRES_PORT: 5432
|
|
||||||
ZITADEL_DATABASE_POSTGRES_DATABASE: zitadel
|
|
||||||
ZITADEL_DATABASE_POSTGRES_USER_USERNAME: postgres
|
|
||||||
ZITADEL_DATABASE_POSTGRES_USER_PASSWORD: $DB_PASSWORD_PROD
|
|
||||||
ZITADEL_DATABASE_POSTGRES_USER_SSL_MODE: disable
|
|
||||||
ZITADEL_DATABASE_POSTGRES_ADMIN_USERNAME: postgres
|
|
||||||
ZITADEL_DATABASE_POSTGRES_ADMIN_PASSWORD: $DB_PASSWORD_PROD
|
|
||||||
ZITADEL_DATABASE_POSTGRES_ADMIN_SSL_MODE: disable
|
|
||||||
ZITADEL_EXTERNALSECURE: "false"
|
|
||||||
ZITADEL_EXTERNALDOMAIN: zitadel.chocomarsh.com
|
|
||||||
deploy:
|
|
||||||
mode: replicated
|
|
||||||
replicas: 1
|
|
||||||
restart_policy:
|
|
||||||
condition: any
|
|
||||||
update_config:
|
|
||||||
parallelism: 1
|
|
||||||
|
|
||||||
# authelia:
|
|
||||||
# image: mathwave/sprint-repo:authelia
|
|
||||||
# networks:
|
|
||||||
# - common-infra-nginx
|
|
||||||
# environment:
|
|
||||||
# AUTHELIA_JWT_SECRET: $AUTHTHELIA_JWT_SECRET
|
|
||||||
# AUTHELIA_SESSION_SECRET: $AUTHTHELIA_SESSION_SECRET
|
|
||||||
# AUTHELIA_STORAGE_ENCRYPTION_KEY: $AUTHELIA_STORAGE_ENCRYPTION_KEY
|
|
||||||
# AUTHELIA_STORAGE_POSTGRES_PORT: "5432"
|
|
||||||
# AUTHELIA_STORAGE_POSTGRES_DATABASE: "authelia"
|
|
||||||
# AUTHELIA_STORAGE_POSTGRES_USERNAME: "postgres"
|
|
||||||
# AUTHELIA_STORAGE_POSTGRES_PASSWORD: $DB_PASSWORD_PROD
|
|
||||||
# AUTHELIA_ACCESS_CONTROL_DEFAULT_POLICY: "one_factor"
|
|
||||||
# AUTHELIA_NOTIFIER_SMTP_ENABLED: "false"
|
|
||||||
# volumes:
|
|
||||||
# - /sprint-data/authelia/data:/var/lib/authelia
|
|
||||||
# deploy:
|
|
||||||
# mode: replicated
|
|
||||||
# replicas: 1
|
|
||||||
# restart_policy:
|
|
||||||
# condition: any
|
|
||||||
# placement:
|
|
||||||
# constraints: [node.labels.stage == production]
|
|
||||||
# update_config:
|
|
||||||
# parallelism: 1
|
|
||||||
|
|
||||||
grafana:
|
grafana:
|
||||||
image: grafana/grafana
|
image: grafana/grafana
|
||||||
@@ -128,6 +78,8 @@ services:
|
|||||||
|
|
||||||
postgres:
|
postgres:
|
||||||
image: postgres:14-alpine3.19
|
image: postgres:14-alpine3.19
|
||||||
|
networks:
|
||||||
|
- postgres
|
||||||
volumes:
|
volumes:
|
||||||
- /sprint-data/postgres-data:/var/lib/postgresql/data
|
- /sprint-data/postgres-data:/var/lib/postgresql/data
|
||||||
environment:
|
environment:
|
||||||
@@ -159,6 +111,8 @@ services:
|
|||||||
|
|
||||||
mongo:
|
mongo:
|
||||||
image: mongo:6.0.2
|
image: mongo:6.0.2
|
||||||
|
networks:
|
||||||
|
- mongo
|
||||||
volumes:
|
volumes:
|
||||||
- /sprint-data/mongo:/data/db
|
- /sprint-data/mongo:/data/db
|
||||||
environment:
|
environment:
|
||||||
@@ -199,6 +153,8 @@ services:
|
|||||||
|
|
||||||
minio:
|
minio:
|
||||||
image: bitnami/minio:2022.10.8
|
image: bitnami/minio:2022.10.8
|
||||||
|
networks:
|
||||||
|
- minio
|
||||||
volumes:
|
volumes:
|
||||||
- minio_data:/data
|
- minio_data:/data
|
||||||
environment:
|
environment:
|
||||||
@@ -234,7 +190,7 @@ services:
|
|||||||
USER_UID: 1000
|
USER_UID: 1000
|
||||||
USER_GID: 1000
|
USER_GID: 1000
|
||||||
GITEA__database__DB_TYPE: postgres
|
GITEA__database__DB_TYPE: postgres
|
||||||
GITEA__database__HOST: pg.sprinthub.ru:5432
|
GITEA__database__HOST: pg.chocomarsh.com:5432
|
||||||
GITEA__database__NAME: gitea
|
GITEA__database__NAME: gitea
|
||||||
GITEA__database__USER: postgres
|
GITEA__database__USER: postgres
|
||||||
GITEA__database__PASSWD: $DB_PASSWORD_PROD
|
GITEA__database__PASSWD: $DB_PASSWORD_PROD
|
||||||
@@ -254,7 +210,7 @@ services:
|
|||||||
- /var/run/docker.sock:/var/run/docker.sock
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
- /sprint-data:/sprint-data
|
- /sprint-data:/sprint-data
|
||||||
environment:
|
environment:
|
||||||
GITEA_INSTANCE_URL: https://gitea.sprinthub.ru/
|
GITEA_INSTANCE_URL: https://gitea.chocomarsh.com/
|
||||||
GITEA_RUNNER_REGISTRATION_TOKEN: $REGISTRATION_TOKEN
|
GITEA_RUNNER_REGISTRATION_TOKEN: $REGISTRATION_TOKEN
|
||||||
GITEA_RUNNER_NAME: prod
|
GITEA_RUNNER_NAME: prod
|
||||||
GITEA_RUNNER_LABELS: prod
|
GITEA_RUNNER_LABELS: prod
|
||||||
@@ -283,3 +239,9 @@ networks:
|
|||||||
external: true
|
external: true
|
||||||
clickhouse:
|
clickhouse:
|
||||||
external: true
|
external: true
|
||||||
|
postgres:
|
||||||
|
external: true
|
||||||
|
mongo:
|
||||||
|
external: true
|
||||||
|
minio:
|
||||||
|
external: true
|
||||||
|
|||||||
@@ -19,8 +19,6 @@ jobs:
|
|||||||
ref: dev
|
ref: dev
|
||||||
- name: build nginx dev
|
- name: build nginx dev
|
||||||
run: docker build -t mathwave/sprint-repo:sprint-infra-nginx-dev nginx/nginx-dev
|
run: docker build -t mathwave/sprint-repo:sprint-infra-nginx-dev nginx/nginx-dev
|
||||||
- name: build gitea runner
|
|
||||||
run: docker build -t mathwave/sprint-repo:gitea-runner gitea-runner
|
|
||||||
push:
|
push:
|
||||||
name: Push
|
name: Push
|
||||||
runs-on: [ prod ]
|
runs-on: [ prod ]
|
||||||
|
|||||||
@@ -21,8 +21,6 @@ jobs:
|
|||||||
run: docker build -t mathwave/sprint-repo:sprint-infra-nginx-prod nginx/nginx-prod
|
run: docker build -t mathwave/sprint-repo:sprint-infra-nginx-prod nginx/nginx-prod
|
||||||
- name: build gitea runner
|
- name: build gitea runner
|
||||||
run: docker build -t mathwave/sprint-repo:gitea-runner gitea-runner
|
run: docker build -t mathwave/sprint-repo:gitea-runner gitea-runner
|
||||||
- name: build authelia
|
|
||||||
run: docker build -t mathwave/sprint-repo:authelia authelia
|
|
||||||
push:
|
push:
|
||||||
name: Push
|
name: Push
|
||||||
runs-on: [ prod ]
|
runs-on: [ prod ]
|
||||||
@@ -32,8 +30,6 @@ jobs:
|
|||||||
run: docker push mathwave/sprint-repo:sprint-infra-nginx-prod
|
run: docker push mathwave/sprint-repo:sprint-infra-nginx-prod
|
||||||
- name: push gitea runner
|
- name: push gitea runner
|
||||||
run: docker push mathwave/sprint-repo:gitea-runner
|
run: docker push mathwave/sprint-repo:gitea-runner
|
||||||
- name: push authelia
|
|
||||||
run: docker push mathwave/sprint-repo:authelia
|
|
||||||
prepare:
|
prepare:
|
||||||
name: prepare
|
name: prepare
|
||||||
runs-on: [prod]
|
runs-on: [prod]
|
||||||
@@ -58,8 +54,6 @@ jobs:
|
|||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
ref: prod
|
ref: prod
|
||||||
- name: deploy swarmpit
|
|
||||||
run: docker stack deploy --with-registry-auth -c ./.deploy-swarmpit/deploy-prod.yaml swarmpit
|
|
||||||
- name: deploy portainer
|
- name: deploy portainer
|
||||||
run: docker stack deploy --with-registry-auth -c ./.deploy-portainer/deploy-prod.yaml portainer
|
run: docker stack deploy --with-registry-auth -c ./.deploy-portainer/deploy-prod.yaml portainer
|
||||||
- name: deploy infra
|
- name: deploy infra
|
||||||
|
|||||||
@@ -1,3 +0,0 @@
|
|||||||
FROM authelia/authelia
|
|
||||||
COPY configuration.yml /config/configuration.yml
|
|
||||||
COPY users.yml /config/users.yml
|
|
||||||
@@ -1,44 +0,0 @@
|
|||||||
theme: dark
|
|
||||||
|
|
||||||
jwt_secret: secret-jwt-will-be-overridden-by-env
|
|
||||||
|
|
||||||
server:
|
|
||||||
host: 0.0.0.0
|
|
||||||
port: 9091
|
|
||||||
|
|
||||||
log:
|
|
||||||
level: info
|
|
||||||
|
|
||||||
authentication_backend:
|
|
||||||
file:
|
|
||||||
path: /config/users.yml
|
|
||||||
|
|
||||||
access_control:
|
|
||||||
default_policy: one_factor
|
|
||||||
rules:
|
|
||||||
- domain: "*.chocomarsh.com"
|
|
||||||
policy: one_factor
|
|
||||||
|
|
||||||
session:
|
|
||||||
name: authelia_session
|
|
||||||
expiration: 1h
|
|
||||||
inactivity: 5m
|
|
||||||
remember_me_duration: 1w
|
|
||||||
cookies:
|
|
||||||
- domain: chocomarsh.com
|
|
||||||
authelia_url: https://auth.chocomarsh.com
|
|
||||||
default_redirection_url: https://login.chocomarsh.com
|
|
||||||
|
|
||||||
storage:
|
|
||||||
encryption_key: "a_very_long_secret_32_characters_minimum"
|
|
||||||
postgres:
|
|
||||||
host: pg.sprinthub.ru
|
|
||||||
port: 5432
|
|
||||||
database: authelia
|
|
||||||
schema: public
|
|
||||||
username: postgres
|
|
||||||
password: autheliapass # also override with env if preferred
|
|
||||||
|
|
||||||
notifier:
|
|
||||||
filesystem:
|
|
||||||
filename: /config/notification.txt
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
users:
|
|
||||||
emmatveev:
|
|
||||||
password: "$argon2id$v=19$m=65536,t=1,p=4$CixMXaAilVof3yk1rtghwg$V/kcl1HNDWeybrV3SrVjjdI00D1lFtuvLldkwAklSOE"
|
|
||||||
displayname: "Egor Matveev"
|
|
||||||
email: emmtvv@gmail.com
|
|
||||||
@@ -6,7 +6,7 @@ from json import loads
|
|||||||
|
|
||||||
|
|
||||||
minio_client = Minio(
|
minio_client = Minio(
|
||||||
"minio.dev.chocomarsh.com:9000",
|
"minio:9000",
|
||||||
access_key="serviceminioadmin",
|
access_key="serviceminioadmin",
|
||||||
secret_key=os.getenv("MINIO_SECRET_KEY", "minioadmin"),
|
secret_key=os.getenv("MINIO_SECRET_KEY", "minioadmin"),
|
||||||
secure=False,
|
secure=False,
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ from json import loads
|
|||||||
|
|
||||||
|
|
||||||
minio_client = Minio(
|
minio_client = Minio(
|
||||||
"minio.chocomarsh.com:9000",
|
"minio:9000",
|
||||||
access_key="serviceminioadmin",
|
access_key="serviceminioadmin",
|
||||||
secret_key=os.getenv("MINIO_SECRET_KEY", "minioadmin"),
|
secret_key=os.getenv("MINIO_SECRET_KEY", "minioadmin"),
|
||||||
secure=False,
|
secure=False,
|
||||||
|
|||||||
@@ -8,10 +8,15 @@ docker network create -d overlay --attachable configurator || true
|
|||||||
docker network create -d overlay --attachable monitoring || true
|
docker network create -d overlay --attachable monitoring || true
|
||||||
docker network create -d overlay --attachable configurator-development || true
|
docker network create -d overlay --attachable configurator-development || true
|
||||||
docker network create -d overlay --attachable clickhouse || true
|
docker network create -d overlay --attachable clickhouse || true
|
||||||
docker network create -d overlay --attachable clickhouse-development || true
|
docker network create -d overlay --attachable postgres || true
|
||||||
|
docker network create -d overlay --attachable postgres-development || true
|
||||||
|
docker network create -d overlay --attachable mongo || true
|
||||||
|
docker network create -d overlay --attachable mongo-development || true
|
||||||
|
docker network create -d overlay --attachable minio || true
|
||||||
|
docker network create -d overlay --attachable minio-development || true
|
||||||
|
|
||||||
mkdir /sprint-data/mongo || true
|
mkdir /sprint-data/mongo || true
|
||||||
mkdir /sprint-data/redis || true
|
mkdir /sprint-data/redis || true
|
||||||
mkdir /sprint-data/rabbitmq || true
|
|
||||||
mkdir /sprint-data/certs || true
|
mkdir /sprint-data/certs || true
|
||||||
mkdir /sprint-data/gitea || true
|
mkdir /sprint-data/gitea || true
|
||||||
mkdir /sprint-data/clickhouse || true
|
mkdir /sprint-data/clickhouse || true
|
||||||
|
|||||||
Reference in New Issue
Block a user