Files
torrent-stack/infra.yml
T

141 lines
3.9 KiB
YAML
Raw Normal View History

# =============================================================================
# Torrent Stack (infra) - DNS, management & monitoring
#
# Split from compose.yml on 2026-09-11 - verbatim service blocks.
# Shared top-level networks:/volumes: are repeated in each subfile so it also
# works standalone (docker compose -f infra.yml up -d). Identical copies merge
# cleanly under compose.yml's `include:` with no change to the live config.
# Keep ./ paths, container names and /mnt data as-is.
# =============================================================================
networks:
tdarr-net:
driver: bridge
default:
name: portainer_network
volumes:
portainer_data:
name: portainer_data
services:
# ---------------------------------------------------------------------------
# Monitoring
# ---------------------------------------------------------------------------
# glances:
# image: ${GLANCES_IMAGE}
# container_name: glances
# network_mode: host
# volumes:
# - /etc/os-release:/etc/os-release:ro
# - /:/host:ro
# #- /etc/localtime:/etc/localtime:ro
# #- /etc/timezone:/etc/timezone:ro
# environment:
# - "GLANCES_OPT=-w --password ${GLANCES_PASSWORD}"
# - PUID=${HOST_PUID:-1000}
# - PGID=${HOST_PGID:-1000}
# - TZ=${TIMEZONE}
# healthcheck:
# test:
# ["CMD", "curl", "-f", "http://localhost:${GLANCES_PORT}/api/4/status"]
# interval: 1m
# timeout: 10s
# retries: 3
# start_period: 60s
# security_opt:
# - no-new-privileges:true
# mem_limit: 256m
# cpus: 1.0
# devices:
# - /dev/dri:/dev/dri
# restart: unless-stopped
# # Uncomment to protect Glances WebUI by a login/password (add --password to GLANCES_OPT)
# secrets:
# - source: glances_password
# target: /root/.config/glances/<login>.pwd
# secrets:
# glances_password:
# file: ./secrets/glances_password
autoheal:
image: ${AUTOHEAL_IMAGE}
container_name: autoheal
volumes:
- /var/run/docker.sock:/var/run/docker.sock
environment:
- AUTOHEAL_CONTAINER_LABEL=all
- AUTOHEAL_INTERVAL=30
- AUTOHEAL_START_PERIOD=60
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
read_only: true
mem_limit: 64m
cpus: 0.25
restart: unless-stopped
scrutiny:
image: ${SCRUTINY_IMAGE}
container_name: scrutiny
cap_add:
- SYS_RAWIO
ports:
- ${SCRUTINY_PORT}:8080
- ${SCRUTINY_ADMIN_PORT}:8086
volumes:
- /run/udev:/run/udev:ro
- ./scrutiny/config:/opt/scrutiny/config
- ./scrutiny/influxdb:/opt/scrutiny/influxdb
environment:
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 128m
cpus: 0.25
devices:
- /dev/nvme0n1
- /dev/sda
restart: unless-stopped
# ---------------------------------------------------------------------------
# Infrastructure
# ---------------------------------------------------------------------------
pihole:
image: ${PIHOLE_IMAGE}
container_name: pihole
cap_add:
- NET_ADMIN # Allows managing network interfaces & sockets
- NET_BIND_SERVICE # Allows non-root users to bind to ports < 1024 (port 53 & 123)
- SYS_TIME # Resolves the NTP system time warning
network_mode: host
volumes:
- ./etc-pihole:/etc/pihole
- ./etc-dnsmasq.d:/etc/dnsmasq.d
environment:
- TZ=${TIMEZONE}
- FTLCONF_misc_etc_dnsmasq_d=true
- FTLCONF_webserver_port=${PIHOLE_PORT:-80}
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
portainer:
image: ${PORTAINER_IMAGE}
container_name: portainer
ports:
- ${PORTAINER_PORT}:${PORTAINER_PORT}
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- portainer_data:/data
environment:
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped