Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
117 lines (99 loc) · 4.7 KB
/
Copy pathdocker-compose.yml
File metadata and controls
117 lines (99 loc) · 4.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
# Failover LB. One of these runs on every nginx box you have.
#
# No central server. Every node runs the same container and they form a
# trust group: one ACTIVE node takes writes, the rest are STANDBY and stay in
# sync. Losing any one node, even the active one, loses no config or certs.
#
# cp .env.example .env # then edit .env
# docker compose up -d
#
# Set up the first node and join the rest with ./install.sh. See the README.
services:
nginx-fleet-manager:
build:
context: .
dockerfile: Dockerfile
image: nginx-fleet-manager:${NFM_VERSION:-1.0.0}
container_name: nginx-fleet-manager
restart: unless-stopped
# Host networking is deliberate:
# 1. Health checks must reach backends from the same source address
# nginx uses; bridge NAT would make results differ from nginx's view.
# 2. Public IP detection needs the host's real route out. That decides
# which node requests the cert.
# 3. Peers talk to each other on the host's real addresses.
network_mode: host
environment:
# ---- who this node is ---------------------------------------------
NFM_NODE_NAME: ${NFM_NODE_NAME:?set NFM_NODE_NAME in .env}
NFM_NODE_ADDRESS: ${NFM_NODE_ADDRESS:?set NFM_NODE_ADDRESS in .env}
NFM_CLUSTER_PRIORITY: ${NFM_CLUSTER_PRIORITY:-100}
# ---- ports we listen on -------------------------------------------
NFM_GUI_PORT: ${NFM_GUI_PORT:-7443}
NFM_PEER_PORT: ${NFM_PEER_PORT:-7444}
NFM_BIND_ADDRESS: ${NFM_BIND_ADDRESS:-0.0.0.0}
# ---- security ------------------------------------------------------
# install.sh generates this. It encrypts the OIDC client secret, any DNS
# provider tokens, and the peer keys where they sit in the database.
NFM_SECRET_KEY: ${NFM_SECRET_KEY:?set NFM_SECRET_KEY in .env}
# Networks allowed to load the web GUI. Empty means anyone can, so set
# it before this is reachable from anywhere but a jump box.
NFM_ADMIN_ALLOWLIST: ${NFM_ADMIN_ALLOWLIST:-}
# Whose X-Forwarded-For to trust. Empty ignores the header and uses the
# peer address, which is right when the GUI is reached directly. Set it
# to the proxy's address only when you put one in front.
NFM_TRUSTED_PROXIES: ${NFM_TRUSTED_PROXIES:-}
# Path prefix when served behind a reverse proxy (e.g. /lb). Links,
# form actions and cookie paths are built from it.
NFM_ROOT_PATH: ${NFM_ROOT_PATH:-}
NFM_SESSION_TIMEOUT_MINUTES: ${NFM_SESSION_TIMEOUT_MINUTES:-60}
# ---- OIDC, optional. Local break glass logins always work. --------
NFM_OIDC_ENABLED: ${NFM_OIDC_ENABLED:-false}
NFM_OIDC_DISCOVERY_URL: ${NFM_OIDC_DISCOVERY_URL:-}
NFM_OIDC_CLIENT_ID: ${NFM_OIDC_CLIENT_ID:-}
NFM_OIDC_CLIENT_SECRET: ${NFM_OIDC_CLIENT_SECRET:-}
NFM_OIDC_REDIRECT_BASE: ${NFM_OIDC_REDIRECT_BASE:-}
NFM_OIDC_GROUPS_CLAIM: ${NFM_OIDC_GROUPS_CLAIM:-groups}
NFM_OIDC_ADMIN_GROUP: ${NFM_OIDC_ADMIN_GROUP:-nginx-admins}
NFM_OIDC_OPERATOR_GROUP: ${NFM_OIDC_OPERATOR_GROUP:-nginx-operators}
NFM_OIDC_VIEWER_GROUP: ${NFM_OIDC_VIEWER_GROUP:-nginx-viewers}
# ---- certificates ---------------------------------------------------
NFM_ACME_EMAIL: ${NFM_ACME_EMAIL:-}
NFM_ACME_STAGING: ${NFM_ACME_STAGING:-false}
# ---- day to day -----------------------------------------------------
NFM_LOG_LEVEL: ${NFM_LOG_LEVEL:-info}
NFM_AGENT_SOCKET: /run/nginxmgr/agent.sock
NFM_DATA_DIR: /data
volumes:
# The only way to reach the host. Everything that needs root (writing
# nginx config, reloads, certbot, reading certs) goes through it, and the
# agent checks each request against a verb list and a path allowlist.
- /run/nginxmgr:/run/nginxmgr
# Database, cluster CA, and this node's key pair. Back this up.
- nfm-data:/data
# Read-only view so the GUI can show what is really running and flag
# hand edits. Never written through.
- /etc/nginx:/host/etc/nginx:ro
- /etc/letsencrypt:/host/etc/letsencrypt:ro
- /etc/localtime:/etc/localtime:ro
# Nothing in here needs extra powers. We get to the agent socket by being
# in the right group, not by holding capabilities.
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
read_only: true
tmpfs:
- /tmp:rw,noexec,nosuid,size=64m
# The host's nginxmgr group (created by install.sh), which owns the agent
# socket. Without it the non-root user can't open the socket.
group_add:
- ${NFM_HOST_GID:-10001}
logging:
driver: json-file
options:
max-size: "20m"
max-file: "5"
volumes:
nfm-data:
driver: local