31 lines
1.3 KiB
YAML
31 lines
1.3 KiB
YAML
services:
|
||
traefik:
|
||
# Use hardened Traefik config in production (no staging CA, no tracing/metrics)
|
||
volumes:
|
||
- ./services/traefik/traefik.prod.yml:/etc/traefik/traefik.yml:ro
|
||
- ./services/traefik/dynamic.yml:/etc/traefik/dynamic.yml:ro
|
||
- ./services/traefik/acme.json:/acme.json
|
||
- ./services/traefik/acme-io.json:/acme-io.json
|
||
ports:
|
||
- "80:80"
|
||
- "443:443"
|
||
redis:
|
||
ports: []
|
||
healthcheck:
|
||
test: ["CMD", "redis-cli", "ping"]
|
||
interval: 10s
|
||
timeout: 5s
|
||
retries: 5
|
||
start_period: 10s
|
||
|
||
## Usage (examples):
|
||
## - With explicit files (recommended):
|
||
## docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d traefik caddy php1 php2 php3 php4 php5 db redis
|
||
##
|
||
## - Or set COMPOSE_FILE for the shell session (PowerShell on Windows):
|
||
## $env:COMPOSE_FILE = "docker-compose.yml;docker-compose.prod.yml"
|
||
## docker compose up -d traefik caddy php1 php2 php3 php4 php5 db redis
|
||
##
|
||
## Notes:
|
||
## - Traefik uses Let’s Encrypt production. Ensure DNS A/AAAA records for api.truckwash.dk, api.truckwash.io and traefik.truckwash.dk point to this host and ports 80/443 are reachable.
|
||
## - The dashboard is protected by basic auth and an IP allowlist (defined in dynamic.yml). Replace the bcrypt hash before enabling in production. |