name: ccn-platform # Production base configuration. # Deploys a pre-built image pulled from a registry — no build step. # # docker compose -f docker-compose.yml pull # docker compose -f docker-compose.yml up -d # # The `-f docker-compose.yml` flag is important in production: it skips the docker-compose.override.yml file, which # Compose would otherwise merge in automatically for local development. services: website: image: ${HOST_CONTAINER}/${HOST_OWNER}/${IMAGE_NAME}:${IMAGE_TAG:-latest} platform: ${IMAGE_PLATFORM:-linux/amd64} container_name: ${HOST_OWNER}-${IMAGE_NAME} restart: unless-stopped ports: - "${HOST_PORT:-8080}:8080" environment: LOG_LEVEL: ${LOG_LEVEL:-info} HTTP_SERVER_NAME: ${HTTP_SERVER_NAME:-CCNWebsite} SECURITY_STRICT_TRANSPORT_SECURITY: "${SECURITY_STRICT_TRANSPORT_SECURITY:-max-age=31536000; includeSubDomains}" # Falls back to the policy the app ships with; set it in `.env` to allow the analytics origin, # which must match `String.Analytics.origin`. SECURITY_CONTENT_SECURITY_POLICY: "${SECURITY_CONTENT_SECURITY_POLICY:-default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'}" # Persistence: a managed PostgreSQL database. Provide the password via the environment or a secret — never # commit it. DATABASE_DRIVER: ${DATABASE_DRIVER:-postgres} DATABASE_HOST: ${DATABASE_HOST:?DATABASE_HOST is required} DATABASE_PORT: ${DATABASE_PORT:-5432} DATABASE_NAME: ${DATABASE_NAME:-ccn} DATABASE_USERNAME: ${DATABASE_USERNAME:-ccn} DATABASE_PASSWORD: ${DATABASE_PASSWORD:?DATABASE_PASSWORD is required} DATABASE_TLS: ${DATABASE_TLS:-require} DATABASE_POOL_MAX_PER_EVENT_LOOP: ${DATABASE_POOL_MAX_PER_EVENT_LOOP:-4} healthcheck: test: ["CMD", "curl", "--fail", "--silent", "--show-error", "http://127.0.0.1:8080/health"] interval: 30s timeout: 5s retries: 3 start_period: 10s