feat: implement docker infrastructure (US-001)
- Add docker-compose.yml with postgres, redis, api, and web services - Add multi-stage Dockerfile for API (Python 3.11) - Add multi-stage Dockerfile for web (Node.js 20 + nginx) - Add Makefile with common development commands - Add .env.example with all required environment variables - Add placeholder pyproject.toml and package.json for builds - Configure health checks for all services - Setup persistent volumes for postgres, redis, and repos - Run services as non-root users
This commit is contained in:
+18
-36
@@ -1,42 +1,24 @@
|
||||
# App identity
|
||||
APP_NAME=Headquarter
|
||||
ROOT_DOMAIN=localhost
|
||||
TOOL_DOMAIN=tools.localhost
|
||||
|
||||
# API / Web URLs
|
||||
API_URL=http://localhost:8000
|
||||
WEB_URL=http://localhost:5173
|
||||
CORS_ORIGINS=http://localhost:5173
|
||||
|
||||
# Database (local development)
|
||||
POSTGRES_USER=postgres
|
||||
POSTGRES_PASSWORD=postgres
|
||||
# Database Configuration
|
||||
POSTGRES_USER=headquarter
|
||||
POSTGRES_PASSWORD=change-me-in-production
|
||||
POSTGRES_DB=headquarter
|
||||
# DATABASE_URL uses a literal value because Pydantic Settings does not expand
|
||||
# shell-style variable interpolation from .env files.
|
||||
DATABASE_URL=postgresql://postgres:postgres@localhost:5432/headquarter
|
||||
|
||||
# Authentik OIDC placeholders (wire in FN-004)
|
||||
AUTHENTIK_ISSUER_URL=https://auth.example.com/application/o/headquarter/
|
||||
AUTHENTIK_CLIENT_ID=your-client-id
|
||||
AUTHENTIK_CLIENT_SECRET=your-client-secret
|
||||
# Redis Configuration
|
||||
REDIS_URL=redis://redis:6379/0
|
||||
|
||||
# Traefik / deployment placeholders (wire in FN-006)
|
||||
TRAEFIK_NETWORK=traefik
|
||||
TRAEFIK_ENTRYPOINT=websecure
|
||||
TRAEFIK_CERT_RESOLVER=letsencrypt
|
||||
TRAEFIK_LOG_LEVEL=INFO
|
||||
TRAEFIK_ACME_EMAIL=admin@example.com
|
||||
TOOL_SUBDOMAIN_PATTERN={tool}-{project}-{user}.tools.localhost
|
||||
# JWT Configuration
|
||||
JWT_SECRET=change-me-in-production
|
||||
JWT_ALGORITHM=HS256
|
||||
JWT_EXPIRATION_HOURS=24
|
||||
|
||||
# Frontend build-time variables (passed to web container)
|
||||
# Application Configuration
|
||||
APP_ENV=development
|
||||
DEBUG=true
|
||||
LOG_LEVEL=info
|
||||
REPO_BASE_PATH=/data/repos
|
||||
|
||||
# Frontend Configuration
|
||||
VITE_API_URL=http://localhost:8000
|
||||
VITE_OIDC_ISSUER=https://auth.example.com/application/o/headquarter/
|
||||
VITE_OIDC_CLIENT_ID=your-client-id
|
||||
VITE_OIDC_REDIRECT_URI=https://headquarter.commumedia.org/callback
|
||||
|
||||
# Secrets (generate strong random values for production)
|
||||
SECRET_ENCRYPTION_KEY=change-me-in-production
|
||||
|
||||
# Auth dev bypass (local development only — NEVER enable in production)
|
||||
AUTH_DEV_BYPASS=false
|
||||
# Docker Configuration
|
||||
COMPOSE_PROJECT_NAME=headquarter
|
||||
|
||||
Reference in New Issue
Block a user