Monorepo for Tangled
tangled.org
1services:
2 redis:
3 image: redis:7-alpine
4 restart: unless-stopped
5 networks: [tngl]
6
7 postgres:
8 image: postgres:14-alpine
9 restart: unless-stopped
10 environment:
11 POSTGRES_USER: tnglr
12 POSTGRES_PASSWORD: tnglr
13 volumes:
14 - postgres-data:/var/lib/postgresql/data
15 - ./localinfra/postgres-init.sql:/docker-entrypoint-initdb.d/init.sql
16 healthcheck:
17 test: ["CMD-SHELL", "pg_isready -U tnglr -d plc"]
18 interval: 2s
19 timeout: 2s
20 retries: 30
21 start_period: 5s
22 networks: [tngl]
23
24 pds:
25 image: ghcr.io/bluesky-social/pds:0.4.219
26 restart: unless-stopped
27 env_file: localinfra/pds.env
28 environment:
29 PDS_DID_PLC_URL: http://plc:8080
30 NODE_EXTRA_CA_CERTS: /caddy-ca/root.crt
31 volumes:
32 - pds-data:/pds
33 - ./localinfra/certs/root.crt:/caddy-ca/root.crt:ro
34 healthcheck:
35 test: ["CMD", "wget", "-qO-", "http://localhost:3000/xrpc/_health"]
36 interval: 2s
37 timeout: 2s
38 retries: 30
39 start_period: 5s
40 depends_on:
41 plc:
42 condition: service_started
43 networks: [tngl]
44
45 init-accounts:
46 image: alpine:3.22
47 restart: "no"
48 env_file: localinfra/pds.env
49 environment:
50 PDS_URL: http://pds:3000
51 OWNER_USER: alice
52 KNOT_HOSTNAME: knot.tngl.boltless.dev
53 SPINDLE_HOSTNAME: spindle.tngl.boltless.dev
54 volumes:
55 - ./localinfra/scripts/init-accounts.sh:/init.sh:ro
56 - init-state:/shared
57 command: sh -c "apk add --no-cache curl jq >/dev/null && sh /init.sh"
58 depends_on:
59 pds:
60 condition: service_healthy
61 networks: [tngl]
62
63 plc:
64 platform: linux/amd64
65 image: ghcr.io/bluesky-social/did-method-plc:plc-f2ab7516bac5bc0f3f86842fa94e996bd1b3815b
66 restart: unless-stopped
67 environment:
68 DEBUG_MODE: "1"
69 LOG_ENABLED: "true"
70 LOG_LEVEL: debug
71 LOG_DESTINATION: "1"
72 PLC_VERSION: 0.0.1
73 PORT: "8080"
74 DB_CREDS_JSON: &DB_CREDS_JSON '{"username":"tnglr","password":"tnglr","host":"postgres","port":5432}'
75 DB_MIGRATE_CREDS_JSON: *DB_CREDS_JSON
76 depends_on: [postgres]
77 networks: [tngl]
78
79 jetstream:
80 platform: linux/amd64
81 image: ghcr.io/bluesky-social/jetstream:sha-d5a3b62
82 restart: unless-stopped
83 environment:
84 JETSTREAM_DATA_DIR: /data
85 JETSTREAM_LIVENESS_TTL: 300s
86 JETSTREAM_WS_URL: wss://pds.tngl.boltless.dev/xrpc/com.atproto.sync.subscribeRepos
87 volumes:
88 - jetstream-data:/data
89 - ./localinfra/certs/root.crt:/etc/ssl/certs/ca-certificates.crt:ro
90 depends_on:
91 pds:
92 condition: service_healthy
93 networks: [tngl]
94
95 knot:
96 build:
97 context: .
98 dockerfile: localinfra/knot.Dockerfile
99 restart: unless-stopped
100 environment:
101 KNOT_SERVER_HOSTNAME: knot.tngl.boltless.dev
102 KNOT_SERVER_LISTEN_ADDR: 0.0.0.0:5555
103 KNOT_SERVER_INTERNAL_LISTEN_ADDR: 127.0.0.1:5444
104 KNOT_SERVER_DB_PATH: /home/git/knotserver.db
105 KNOT_SERVER_PLC_URL: https://plc.tngl.boltless.dev
106 KNOT_SERVER_JETSTREAM_ENDPOINT: wss://jetstream.tngl.boltless.dev/subscribe
107 KNOT_SERVER_DEV: "false"
108 KNOT_REPO_SCAN_PATH: /home/git/repositories
109 APPVIEW_ENDPOINT: https://tangled.org
110 KNOT_MIRRORS: https://mirror.tngl.boltless.dev
111 ports:
112 - "2222:22"
113 volumes:
114 - knot-data:/home/git
115 - knot-ssh-keys:/etc/ssh/keys
116 - init-state:/shared:ro
117 - ./localinfra/certs/root.crt:/usr/local/share/ca-certificates/caddy.crt:ro
118 healthcheck:
119 test: ["CMD", "wget", "-qO-", "http://localhost:5555/"]
120 interval: 2s
121 timeout: 2s
122 retries: 60
123 start_period: 30s
124 depends_on:
125 plc:
126 condition: service_started
127 jetstream:
128 condition: service_started
129 knotmirror:
130 condition: service_healthy
131 init-accounts:
132 condition: service_completed_successfully
133 networks: [tngl]
134
135 spindle:
136 build:
137 context: .
138 dockerfile: localinfra/spindle.Dockerfile
139 restart: unless-stopped
140 environment:
141 SPINDLE_SERVER_HOSTNAME: spindle.tngl.boltless.dev
142 SPINDLE_SERVER_LISTEN_ADDR: 0.0.0.0:6555
143 SPINDLE_SERVER_DB_PATH: /var/lib/spindle/spindle.db
144 SPINDLE_SERVER_PLC_URL: https://plc.tngl.boltless.dev
145 SPINDLE_SERVER_JETSTREAM_ENDPOINT: wss://jetstream.tngl.boltless.dev/subscribe
146 SPINDLE_SERVER_DEV: "true"
147 SPINDLE_SERVER_DEV_EXTRA_HOSTS: knot.tngl.boltless.dev,mirror.tngl.boltless.dev
148 SPINDLE_SERVER_TAP_DB_PATH: /var/lib/spindle/tap.db
149 SPINDLE_SERVER_TAP_RELAY_URL: https://pds.tngl.boltless.dev
150 SPINDLE_MICROVM_PIPELINES_IMAGE_DIR: /var/lib/spindle/images
151 SPINDLE_MICROVM_PIPELINES_OVERLAY_DIR: /var/lib/spindle/overlays
152 SPINDLE_MICROVM_PIPELINES_AGENT_PORT: "11240"
153 SPINDLE_S3_LOG_BUCKET: ""
154 SPINDLE_MICROVM_PIPELINES_ENABLE_CGROUPS: "false"
155 SPINDLE_MICROVM_PIPELINES_DEBUG_SSH_ENABLED: true
156 SPINDLE_MICROVM_PIPELINES_DEBUG_SSH_LISTEN_ADDR: 0.0.0.0:2223
157 SPINDLE_MICROVM_PIPELINES_DEBUG_SSH_GRACE_PERIOD: 10m
158 # these two are required for cgroups, uncomment if testing
159 # privileged: true
160 # cgroup: host
161 devices:
162 - /dev/vsock:/dev/vsock
163 - /dev/kvm:/dev/kvm
164 - /dev/vhost-vsock:/dev/vhost-vsock
165 - /dev/net/tun:/dev/net/tun
166 cap_add:
167 - NET_ADMIN
168 - SYS_ADMIN
169 security_opt:
170 - label=disable
171 - seccomp=unconfined
172 ports:
173 - "2223:2223"
174 volumes:
175 - spindle-data:/var/lib/spindle
176 - spindle-logs:/var/log/spindle
177 - ./out/localinfra-spindle-images:/var/lib/spindle/images:ro
178 - init-state:/shared:ro
179 - ./localinfra/certs/root.crt:/usr/local/share/ca-certificates/caddy.crt:ro
180 healthcheck:
181 test: ["CMD", "wget", "-qO-", "http://localhost:6555/"]
182 interval: 2s
183 timeout: 2s
184 retries: 30
185 start_period: 5s
186 depends_on:
187 plc:
188 condition: service_started
189 jetstream:
190 condition: service_started
191 init-accounts:
192 condition: service_completed_successfully
193 networks: [tngl]
194
195 knotmirror-tap:
196 image: ghcr.io/bluesky-social/indigo/tap:sha-4f47add43060c27e8a37d9d76482ecddf001fcd8 # 0.1.10
197 restart: unless-stopped
198 environment:
199 TAP_BIND: ":2480"
200 TAP_PLC_URL: https://plc.tngl.boltless.dev
201 TAP_RELAY_URL: https://pds.tngl.boltless.dev # PDS can be used as basic relay without collectiondir.
202 TAP_DATABASE_URL: postgres://tnglr:tnglr@postgres:5432/mirror_tap?sslmode=disable
203 TAP_COLLECTION_FILTERS: sh.tangled.repo
204 TAP_SIGNAL_COLLECTION: sh.tangled.repo
205 TAP_RESYNC_PARALLELISM: "10"
206 TAP_RETRY_TIMEOUT: 60s
207 volumes:
208 - ./localinfra/certs/root.crt:/etc/ssl/certs/ca-certificates.crt:ro
209 depends_on:
210 postgres:
211 condition: service_started
212 pds:
213 condition: service_healthy
214 networks: [tngl]
215
216 knotmirror:
217 build:
218 context: .
219 dockerfile: localinfra/knotmirror.Dockerfile
220 restart: unless-stopped
221 environment:
222 MIRROR_LISTEN: 0.0.0.0:7000
223 MIRROR_ADMIN_LISTEN: 0.0.0.0:7200
224 MIRROR_HOSTNAME: mirror.tngl.boltless.dev
225 MIRROR_TAP_URL: http://knotmirror-tap:2480
226 MIRROR_DB_URL: postgres://tnglr:tnglr@postgres:5432/mirror?sslmode=disable
227 MIRROR_REDIS_ADDR: redis:6379
228 MIRROR_PLC_URL: https://plc.tngl.boltless.dev
229 MIRROR_GIT_BASEPATH: /data/repos
230 MIRROR_KNOT_USE_SSL: "true"
231 MIRROR_KNOT_SSRF: "true"
232 MIRROR_RESYNC_PARALLELISM: "4"
233 volumes:
234 - knotmirror-data:/data
235 - ./localinfra/certs/root.crt:/usr/local/share/ca-certificates/caddy.crt:ro
236 healthcheck:
237 test: ["CMD", "wget", "-qO-", "http://localhost:7000/"]
238 interval: 2s
239 timeout: 2s
240 retries: 30
241 start_period: 5s
242 ports:
243 - "7201:7200"
244 depends_on:
245 postgres:
246 condition: service_started
247 knotmirror-tap:
248 condition: service_started
249 networks: [tngl]
250
251 tailwind:
252 image: d3fk/tailwindcss:v3
253 restart: unless-stopped
254 working_dir: /build
255 init: true
256 environment:
257 BROWSERSLIST_IGNORE_OLD_DATA: "true"
258 volumes:
259 - ./tailwind.config.js:/build/tailwind.config.js:ro
260 - ./input.css:/build/input.css:ro
261 - ./appview/pages/templates:/build/appview/pages/templates:ro
262 - ./docs:/build/docs:ro
263 - ./blog/templates:/build/blog/templates:ro
264 - ./blog/posts:/build/blog/posts:ro
265 - ./appview/pages/static:/build/appview/pages/static
266 command:
267 ["-i", "input.css", "-o", "appview/pages/static/tw.css", "--watch=always"]
268 network_mode: none
269
270 appview:
271 build:
272 context: .
273 dockerfile: localinfra/appview.Dockerfile
274 restart: unless-stopped
275 environment:
276 TANGLED_DEV: "true"
277 TANGLED_APPVIEW_HOST: 127.0.0.1:3000
278 TANGLED_DB_PATH: /var/lib/appview/appview.db
279 TANGLED_PLC_URL: https://plc.tngl.boltless.dev
280 TANGLED_JETSTREAM_ENDPOINT: wss://jetstream.tngl.boltless.dev/subscribe
281 TANGLED_REDIS_ADDR: redis:6379
282 TANGLED_KNOTMIRROR_URL: https://mirror.tngl.boltless.dev
283 ports:
284 - "3000:3000"
285 volumes:
286 - .:/src:cached
287 - go-cache:/go/cache
288 - go-mod-cache:/go/mod
289 - appview-data:/var/lib/appview
290 - init-state:/shared:ro
291 - ./localinfra/certs/root.crt:/usr/local/share/ca-certificates/caddy.crt:ro
292 depends_on:
293 redis:
294 condition: service_started
295 pds:
296 condition: service_healthy
297 init-accounts:
298 condition: service_completed_successfully
299 networks: [tngl]
300
301 caddy:
302 image: caddy:2-alpine
303 restart: unless-stopped
304 ports:
305 - "80:80"
306 - "443:443"
307 volumes:
308 - ./localinfra/Caddyfile:/etc/caddy/Caddyfile
309 - ./localinfra/certs:/etc/caddy/certs:ro
310 - caddy-data:/data
311 networks:
312 tngl:
313 aliases:
314 - plc.tngl.boltless.dev
315 - pds.tngl.boltless.dev
316 - alice.pds.tngl.boltless.dev
317 - bob.pds.tngl.boltless.dev
318 - jetstream.tngl.boltless.dev
319 - knot.tngl.boltless.dev
320 - spindle.tngl.boltless.dev
321 - tngl.boltless.dev
322 - mirror.tngl.boltless.dev
323
324volumes:
325 caddy-data:
326 postgres-data:
327 pds-data:
328 jetstream-data:
329 knot-data:
330 knot-ssh-keys:
331 knotmirror-data:
332 spindle-data:
333 spindle-logs:
334 init-state:
335 go-cache:
336 go-mod-cache:
337 appview-data:
338
339networks:
340 tngl:
341 driver: bridge
342 # Public-looking subnet so SSRF checks see container IPs as "public".
343 # RFC1918 + doc/benchmark ranges are blocklisted; 11.x is unrouted on
344 # the public internet, so it passes the check and won't collide.
345 ipam:
346 config:
347 - subnet: 11.0.0.0/24