1extends "../../config/Service.pkl"
2
3import "../../config/Service.pkl" as service
4import "../keycloak/service.pkl" as keycloak
5import "../postgres/service.pkl" as postgres
6
7local dawarichImage = "docker.io/freikin/dawarich@sha256:76ec5fa62f414a5ca9e6dd71a9a5b09088c0011075c41644ba35bbb67627a943"
8
9local database = new postgres.Database {
10 name = "dawarich"
11 extensions { "postgis" }
12}
13
14local commonEnv: Mapping<String, String> = new {
15 ["RAILS_ENV"] = "production"
16 ["DATABASE_USERNAME"] = "${secret.database.username}"
17 ["DATABASE_PASSWORD"] = "${secret.database.password}"
18 ["DATABASE_NAME"] = "${secret.database.name}"
19 ["PGCONNECT_TIMEOUT"] = "10"
20 ["SECRET_KEY_BASE"] = "${secret.own.secret_key_base}"
21 ["APPLICATION_HOSTS"] = "localhost,127.0.0.1,\(module.containers["web"].http.hostname)"
22 ["APPLICATION_PROTOCOL"] = "https"
23 ["SELF_HOSTED"] = "true"
24 ["STORE_GEODATA"] = "true"
25 ["TIME_ZONE"] = "America/Los_Angeles"
26 ["PUID"] = "\(module.uid)"
27 ["PGID"] = "\(module.uid)"
28}
29
30local sharedVolumes: Mapping<String, service.Volume> = new {
31 ["/var/app/public"] {}
32 ["/var/app/storage"] {}
33 ["/var/app/tmp/imports/watched"] {}
34 ["/etc/ssl/certs/ca-certificates.crt"] {
35 src = "/var/lib/studio/ca-bundle.crt"
36 readOnly = true
37 }
38}
39
40local databaseEnv = """
41 {{ range nomadService 1 (env "NOMAD_ALLOC_ID") "postgres" }}DATABASE_HOST={{ .Address }}
42 DATABASE_PORT={{ .Port }}{{ end }}
43 {{ range nomadService 1 (env "NOMAD_ALLOC_ID") "\(module.id)-redis" }}REDIS_URL=redis://\(module.nomadHostPort){{ end }}
44 """
45
46meta { name = "Dawarich"; access = "infra-admin" }
47healthyDeadline = "20m"
48
49requirements {
50 database
51 new keycloak.OpenIDClient {
52 clientId = module.id
53 name = module.meta.name
54 }
55}
56
57secrets {
58 ["secret_key_base"] { bytes = 64 }
59}
60
61containers {
62 ["migrate"] {
63 image = dawarichImage
64 entrypoint = "web-entrypoint.sh"
65 args { "ruby"; "-e"; "exit 0" }
66 imageUser = true
67 lifecycle = "prestart"
68 cpu = 200
69 memory = 1024
70 volumes = sharedVolumes
71 env = commonEnv
72 envTemplate = databaseEnv
73 }
74
75 ["web"] {
76 image = dawarichImage
77 extraHosts { "\(keycloak.container.http.hostname):host-gateway" }
78 entrypoint = "web-entrypoint.sh"
79 args { "bin/rails"; "server"; "-p"; "3000"; "-b"; "::" }
80 imageUser = true
81 cpu = 400
82 memory = 2048
83
84 http {
85 containerPort = 3000
86 subdomain = "dawarich"
87 checkPath = "/api/v1/health"
88 checkHeaders { ["X-Forwarded-Proto"] = "https" }
89 }
90
91 volumes = sharedVolumes
92 env = (commonEnv) {
93 ["DOMAIN"] = module.containers["web"].http.hostname
94 ["WEB_CONCURRENCY"] = "1"
95 ["OIDC_CLIENT_ID"] = "${secret.oidc.clientId}"
96 ["OIDC_CLIENT_SECRET"] = "${secret.oidc.clientSecret}"
97 ["OIDC_ISSUER"] = "https://\(keycloak.container.http.hostname)/realms/master"
98 ["OIDC_REDIRECT_URI"] = "https://\(module.containers["web"].http.hostname)/users/auth/openid_connect/callback"
99 ["ALLOW_EMAIL_PASSWORD_REGISTRATION"] = "false"
100 }
101 envTemplate = databaseEnv
102 }
103
104 ["worker"] {
105 image = dawarichImage
106 entrypoint = "sidekiq-entrypoint.sh"
107 args { "sidekiq" }
108 imageUser = true
109 cpu = 200
110 memory = 1024
111 volumes = sharedVolumes
112 env = (commonEnv) {
113 ["BACKGROUND_PROCESSING_CONCURRENCY"] = "3"
114 }
115 envTemplate = databaseEnv
116 }
117
118 ["redis"] {
119 image = "docker.io/library/redis@sha256:718f745deb7dfefeac6eed7041fc7ec9476b50e61b247932682457c41adafa0e"
120 lifecycle = "prestartSidecar"
121 args { "redis-server"; "--save"; "900"; "1"; "--appendonly"; "no" }
122 memory = 256
123 tcp {
124 name = "redis"
125 containerPort = 6379
126 loopback = false
127 }
128 volumes { ["/data"] {} }
129 }
130}