compose.yaml / compose.override.yaml:
- container_name is now ${STACK_NAME:-escapepage}-* (STACK_NAME is a plain var,
not COMPOSE_PROJECT_NAME, so prod keeps its escapepage-* names with no config change)
- every published host port is ${*_PORT:-<current default>}, so prod is unchanged
and a second stack can bind its own (localhost-only) ports
- nginx joins the external nginx_default network so Nginx Proxy Manager can
forward to <stack>-nginx by name
restart.sh:
- scoped to STACK_NAME / COMPOSE_PROJECT_NAME read from docker/.env, so running it
from the test checkout can't touch the prod stack
- host-wide `docker system prune` / `docker builder prune` moved behind --prune-all
Adds docker/.env.test.example and doc/test-environment.md (separate checkout,
env layers, NPM proxy host + Access List IP allowlist, Mercure on test).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
201 lines
6.2 KiB
YAML
201 lines
6.2 KiB
YAML
version: '3.7'
|
|
|
|
# This stack can run more than once on the same host (e.g. production + a
|
|
# test.escapepage.com staging copy). Everything that must be unique per instance
|
|
# comes from docker/.env:
|
|
# STACK_NAME -> container name prefix (default: escapepage)
|
|
# COMPOSE_PROJECT_NAME -> compose project / network namespace
|
|
# NGINX_HTTP_PORT etc. -> published host ports
|
|
# With no docker/.env overrides it behaves exactly as before: containers
|
|
# escapepage-*, ports 8080/8443/3306/8090/8025.
|
|
|
|
services:
|
|
php:
|
|
build:
|
|
context: ..
|
|
dockerfile: docker/php/Dockerfile
|
|
args:
|
|
USER_ID: ${USER_ID}
|
|
GROUP_ID: ${GROUP_ID}
|
|
container_name: ${STACK_NAME:-escapepage}-php
|
|
volumes:
|
|
- ../:/var/www/html:delegated
|
|
- /etc/hosts:/etc/hosts:ro
|
|
environment:
|
|
APP_ENV: ${APP_ENV}
|
|
SITE_BASE_URL: ${SITE_BASE_URL}
|
|
MAILER_DSN: ${MAILER_DSN}
|
|
MAILER_FROM: ${MAILER_FROM}
|
|
DATABASE_URL: ${DATABASE_URL}
|
|
MERCURE_URL: ${MERCURE_URL}
|
|
MERCURE_PUBLIC_URL: ${MERCURE_PUBLIC_URL}
|
|
MERCURE_JWT_SECRET: ${MERCURE_JWT_SECRET}
|
|
MERCURE_CORS_ALLOWED_ORIGINS: ${MERCURE_CORS_ALLOWED_ORIGINS}
|
|
MERCURE_TOPIC_BASE: ${MERCURE_TOPIC_BASE}
|
|
RECAPTCHA3_KEY: ${RECAPTCHA3_KEY}
|
|
RECAPTCHA3_SECRET: ${RECAPTCHA3_SECRET}
|
|
depends_on:
|
|
- database
|
|
- mercure
|
|
# networks:
|
|
# backend:
|
|
# ipv4_address: 172.23.0.10
|
|
restart: unless-stopped
|
|
|
|
php-worker:
|
|
build:
|
|
context: ..
|
|
dockerfile: docker/php/Dockerfile
|
|
args:
|
|
USER_ID: ${USER_ID}
|
|
GROUP_ID: ${GROUP_ID}
|
|
container_name: ${STACK_NAME:-escapepage}-php-worker
|
|
volumes:
|
|
- ../:/var/www/html:delegated
|
|
- /etc/hosts:/etc/hosts:ro
|
|
environment:
|
|
APP_ENV: ${APP_ENV}
|
|
SITE_BASE_URL: ${SITE_BASE_URL}
|
|
MAILER_DSN: ${MAILER_DSN}
|
|
MAILER_FROM: ${MAILER_FROM}
|
|
DATABASE_URL: ${DATABASE_URL}
|
|
MERCURE_URL: ${MERCURE_URL}
|
|
MERCURE_PUBLIC_URL: ${MERCURE_PUBLIC_URL}
|
|
MERCURE_JWT_SECRET: ${MERCURE_JWT_SECRET}
|
|
MERCURE_CORS_ALLOWED_ORIGINS: ${MERCURE_CORS_ALLOWED_ORIGINS}
|
|
MERCURE_TOPIC_BASE: ${MERCURE_TOPIC_BASE}
|
|
RECAPTCHA3_KEY: ${RECAPTCHA3_KEY}
|
|
RECAPTCHA3_SECRET: ${RECAPTCHA3_SECRET}
|
|
depends_on:
|
|
- database
|
|
- mercure
|
|
command: ["php", "bin/console", "messenger:consume", "async", "-vv"]
|
|
# networks:
|
|
# backend:
|
|
# ipv4_address: 172.23.0.11
|
|
restart: unless-stopped
|
|
|
|
php-cron:
|
|
build:
|
|
context: ..
|
|
dockerfile: docker/php/Dockerfile
|
|
args:
|
|
USER_ID: ${USER_ID}
|
|
GROUP_ID: ${GROUP_ID}
|
|
container_name: ${STACK_NAME:-escapepage}-php-cron
|
|
volumes:
|
|
- ../:/var/www/html:delegated
|
|
- /etc/hosts:/etc/hosts:ro
|
|
environment:
|
|
APP_ENV: ${APP_ENV}
|
|
SITE_BASE_URL: ${SITE_BASE_URL}
|
|
MAILER_DSN: ${MAILER_DSN}
|
|
MAILER_FROM: ${MAILER_FROM}
|
|
DATABASE_URL: ${DATABASE_URL}
|
|
MERCURE_URL: ${MERCURE_URL}
|
|
MERCURE_PUBLIC_URL: ${MERCURE_PUBLIC_URL}
|
|
MERCURE_JWT_SECRET: ${MERCURE_JWT_SECRET}
|
|
MERCURE_CORS_ALLOWED_ORIGINS: ${MERCURE_CORS_ALLOWED_ORIGINS}
|
|
MERCURE_TOPIC_BASE: ${MERCURE_TOPIC_BASE}
|
|
RECAPTCHA3_KEY: ${RECAPTCHA3_KEY}
|
|
RECAPTCHA3_SECRET: ${RECAPTCHA3_SECRET}
|
|
depends_on:
|
|
- database
|
|
- mercure
|
|
command: ["crond", "-f", "-l", "2"]
|
|
# networks:
|
|
# backend:
|
|
# ipv4_address: 172.23.0.16
|
|
restart: unless-stopped
|
|
|
|
nginx:
|
|
image: nginx:1.29.4-alpine
|
|
container_name: ${STACK_NAME:-escapepage}-nginx
|
|
ports:
|
|
- "${NGINX_HTTP_PORT:-8080}:80"
|
|
- "${NGINX_HTTPS_PORT:-8443}:443"
|
|
volumes:
|
|
- ../:/var/www/html:ro
|
|
- ./nginx/default.conf:/etc/nginx/conf.d/default.conf:ro
|
|
- ./nginx/ssl:/etc/nginx/ssl:ro
|
|
- /etc/hosts:/etc/hosts:ro
|
|
depends_on:
|
|
- php
|
|
# Joined to the Nginx Proxy Manager network so NPM can forward straight to
|
|
# "<project>-nginx" without going back out to a published host port.
|
|
networks:
|
|
- default
|
|
- nginx_proxy
|
|
restart: unless-stopped
|
|
|
|
mailer:
|
|
image: axllent/mailpit:latest
|
|
container_name: ${STACK_NAME:-escapepage}-mailer
|
|
ports:
|
|
- "${MAILPIT_UI_PORT:-8025}:8025"
|
|
volumes:
|
|
- /etc/hosts:/etc/hosts:ro
|
|
networks:
|
|
- default
|
|
- nginx_proxy
|
|
restart: unless-stopped
|
|
|
|
mercure:
|
|
image: dunglas/mercure:v0.21
|
|
container_name: ${STACK_NAME:-escapepage}-mercure
|
|
environment:
|
|
SERVER_NAME: "http://:80"
|
|
MERCURE_PUBLISHER_JWT_KEY: ${MERCURE_JWT_SECRET}
|
|
MERCURE_SUBSCRIBER_JWT_KEY: ${MERCURE_JWT_SECRET}
|
|
MERCURE_CORS_ALLOWED_ORIGINS: ${MERCURE_CORS_ALLOWED_ORIGINS}
|
|
MERCURE_PUBLISH_ALLOWED_ORIGINS: ${MERCURE_CORS_ALLOWED_ORIGINS}
|
|
MERCURE_EXTRA_DIRECTIVES: |
|
|
cors_origins ${MERCURE_CORS_ALLOWED_ORIGINS}
|
|
publish_origins ${MERCURE_CORS_ALLOWED_ORIGINS}
|
|
anonymous
|
|
ports:
|
|
- "${MERCURE_HTTP_PORT:-8090}:80"
|
|
volumes:
|
|
- /etc/hosts:/etc/hosts:ro
|
|
networks:
|
|
- default
|
|
- nginx_proxy
|
|
restart: unless-stopped
|
|
|
|
###> doctrine/doctrine-bundle ###
|
|
database:
|
|
image: mysql:8.0
|
|
container_name: ${STACK_NAME:-escapepage}-db
|
|
environment:
|
|
MYSQL_DATABASE: ${DB_NAME}
|
|
MYSQL_USER: ${DB_USER}
|
|
MYSQL_PASSWORD: ${DB_PASSWORD}
|
|
MYSQL_ROOT_PASSWORD: ${MYSQL_ROOT_PASSWORD}
|
|
healthcheck:
|
|
test: ["CMD", "mysqladmin", "ping", "-h", "127.0.0.1", "-uroot", "-p${MYSQL_ROOT_PASSWORD}"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 10
|
|
start_period: 30s
|
|
command: ["--default-authentication-plugin=mysql_native_password", "--character-set-server=utf8mb4", "--collation-server=utf8mb4_unicode_ci", "--lower-case-table-names=1", "--innodb-use-native-aio=0"]
|
|
volumes:
|
|
- ../var/volumes/db:/var/lib/mysql:rw
|
|
- ./mysql/init:/docker-entrypoint-initdb.d:ro
|
|
- /etc/hosts:/etc/hosts:ro
|
|
# Uncomment the two lines below if you need to access MySQL from your host (workbench, etc.)
|
|
ports:
|
|
- "${DB_HOST_PORT:-3306}:3306"
|
|
# networks:
|
|
# backend:
|
|
# ipv4_address: 172.23.0.15
|
|
restart: unless-stopped
|
|
###< doctrine/doctrine-bundle ###
|
|
|
|
###> doctrine/doctrine-bundle ###
|
|
###< doctrine/doctrine-bundle ###
|
|
|
|
networks:
|
|
nginx_proxy:
|
|
external: true
|
|
name: nginx_default
|