refactor again

This commit is contained in:
2026-08-07 22:52:55 -07:00
parent 153ff43cf5
commit 3309f61d9c
14 changed files with 985 additions and 1380 deletions
+267 -111
View File
@@ -11,20 +11,20 @@ networks:
name: portainer_network
volumes:
meilisearch:
karakeep-data:
caddy_config:
caddy_data:
external: true
#caddy_config:
#caddy_data:
# external: true
myspeed:
external: true
portainer_data:
name: portainer_data
# =============================================================================
# Key ordering per service:
# image → container_name → env_file → networks/network_mode → cap_add
# → ports → volumes → environment → labels → healthcheck
# → extra_hosts → devices → pid → restart
# image → container_name → env_file → networks/network_mode
# → depends_on → cap_add → ports → volumes → environment
# → labels → healthcheck → security_opt → mem_limit → cpus
# → devices → restart
# =============================================================================
services:
@@ -35,6 +35,9 @@ services:
gluetun:
image: qmcgaw/gluetun:latest
container_name: gluetun
env_file:
- .env
- ./env/.gluetun.env
cap_add:
- NET_ADMIN
ports:
@@ -46,12 +49,12 @@ services:
- ${LIDARR_PORT}:${LIDARR_PORT}
volumes:
- ./gluetun-data:/tmp/gluetun:rw
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- VPN_SERVICE_PROVIDER=protonvpn
- VPN_TYPE=wireguard
- HTTP_CONTROL_SERVER=ON
- HTTP_CONTROL_SERVER_AUTH_DEFAULT_ROLE='{"auth":"apikey","apikey":"${GLUETUN_KEY}"}'
- WIREGUARD_PRIVATE_KEY=${VPN_PRIVATE_KEY}
- WIREGUARD_MTU=1280
- VPN_PORT_FORWARDING=on
- VPN_PORT_FORWARDING_PROVIDER=protonvpn
@@ -61,11 +64,15 @@ services:
- TZ=${TIMEZONE}
- DNS_UPSTREAM_RESOLVER_TYPE=doh
healthcheck:
test: wget --spider -q http://1.1.1.1 || exit 1
test: ["CMD-SHELL", "wget --spider -q http://1.1.1.1 || exit 1"]
interval: 30s
timeout: 15s
retries: 3
start_period: 1m
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
extra_hosts:
- "host.docker.internal:host-gateway"
devices:
@@ -84,8 +91,8 @@ services:
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- ./gluetun-data:/tmp/gluetun
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
@@ -94,11 +101,19 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "wget --spider -q https://1.1.1.1 || exit 1"]
test:
[
"CMD-SHELL",
"curl -sf http://localhost:${QBITTORRENT_PORT}/api/v2/app/version || exit 1",
]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 2.0
restart: unless-stopped
port-updater:
@@ -135,12 +150,19 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "curl -f https://1.1.1.1 || exit 1"]
test: ["CMD-SHELL", "curl -sf https://1.1.1.1 || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
restart: always
security_opt:
- no-new-privileges:true
read_only: true
tmpfs:
- /tmp
mem_limit: 64m
cpus: 0.25
restart: unless-stopped
# ---------------------------------------------------------------------------
# *arr Stack
@@ -156,8 +178,8 @@ services:
volumes:
- ./prowlarr:/config
- ./notify.sh:/notify.sh:ro
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
@@ -165,12 +187,20 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "wget --spider -q https://google.com || exit 1"]
interval: 5m
timeout: 60s
test:
[
"CMD-SHELL",
"curl -sf http://localhost:${PROWLARR_PORT}/ping || exit 1",
]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
restart: always
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
sonarr:
image: lscr.io/linuxserver/sonarr:latest
@@ -183,8 +213,8 @@ services:
- /var/lib/sonarr:/config
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
@@ -192,12 +222,17 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
interval: 5m
timeout: 60s
test:
["CMD-SHELL", "curl -sf http://localhost:${SONARR_PORT}/ping || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 60s
restart: always
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
radarr:
image: lscr.io/linuxserver/radarr:latest
@@ -210,8 +245,8 @@ services:
- /var/lib/radarr:/config
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
@@ -219,12 +254,17 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
test:
["CMD-SHELL", "curl -sf http://localhost:${RADARR_PORT}/ping || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
restart: always
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
lidarr:
image: lscr.io/linuxserver/lidarr:latest
@@ -238,8 +278,8 @@ services:
- /var/lib/lidarr:/config
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
@@ -247,11 +287,16 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
test:
["CMD-SHELL", "curl -sf http://localhost:${LIDARR_PORT}/ping || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
# ---------------------------------------------------------------------------
@@ -267,10 +312,16 @@ services:
- ${TAUTULLI_PORT}:${TAUTULLI_PORT}
volumes:
- ./tautulli:/config
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
tdarr:
@@ -287,12 +338,18 @@ services:
- ./tdarr/temp:/temp
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-100}
- PGID=${HOST_PGID:-1000}
- UMASK_SET=002
- serverIP=0.0.0.0
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 2.0
restart: unless-stopped
tdarr-node:
@@ -306,6 +363,8 @@ services:
- ./tdarr/temp:/temp
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
- PUID=${HOST_PUID:-1000}
@@ -314,8 +373,12 @@ services:
- nodeIP=0.0.0.0
- serverIP=tdarr
- serverPort=${TDARR_NODE_PORT}
security_opt:
- no-new-privileges:true
mem_limit: 2g
cpus: 4.0
devices:
- /dev/dri/:/dev/dri/
- /dev/dri:/dev/dri
restart: unless-stopped
seerr:
@@ -327,11 +390,11 @@ services:
- ${SEERR_PORT}:${SEERR_PORT}
volumes:
- ./seerr:/app/config
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- LOG_LEVEL=debug
- TZ=America/Los_Angeles
- LOG_LEVEL=info
- TZ=${TIMEZONE}
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
labels:
@@ -339,22 +402,35 @@ services:
init: true
working_dir: "/app"
healthcheck:
test: ["CMD-SHELL", "wget --spider -q http://1.1.1.1 || exit 1"]
test:
[
"CMD-SHELL",
"wget -qO- http://127.0.0.1:${SEERR_PORT}/api/v1/status || exit 1",
]
interval: 1m
timeout: 10s
retries: 3
start_period: 60s
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
seerr-anubis:
image: ghcr.io/techarohq/anubis:latest
container_name: seerr_anubis
networks:
- caddy_net
environment:
- BIND=:55055
- TARGET=http://seerr:${SEERR_PORT}
restart: unless-stopped
# Anubis anti-bot proxy for Seerr (uncomment to enable):
#seerr-anubis:
# image: ghcr.io/techarohq/anubis:latest
# container_name: seerr-anubis
# networks:
# - caddy_net
# environment:
# - BIND=:55055
# - TARGET=http://seerr:${SEERR_PORT}
# security_opt:
# - no-new-privileges:true
# mem_limit: 128m
# cpus: 0.5
# restart: unless-stopped
# ---------------------------------------------------------------------------
# Monitoring
@@ -363,6 +439,9 @@ services:
homepage:
image: ghcr.io/gethomepage/homepage:latest
container_name: homepage
env_file:
- .env
- ./env/.homepage.env
networks:
- caddy_net
ports:
@@ -372,8 +451,8 @@ services:
- ./homepage/images:/app/public/images
- /var/run/docker.sock:/var/run/docker.sock:ro
- ./gluetun-data:/tmp/gluetun:ro
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- "HOMEPAGE_ALLOWED_HOSTS=gethomepage.dev,${LOCAL_IPV4}:${HOMEPAGE_PORT},${SERVER_NAME}:${HOMEPAGE_PORT},${SERVER_NAME}.${TAILNET_NAME}:${HOMEPAGE_PORT}"
- "HOMEPAGE_VAR_DISK1=${DISK1}"
@@ -382,16 +461,6 @@ services:
- "HOMEPAGE_VAR_WEB_PROTOCOL=${WEB_PROTOCOL}"
- "HOMEPAGE_VAR_LOCAL_IPV4=${LOCAL_IPV4}"
- "HOMEPAGE_VAR_SERVER_NAME=${SERVER_NAME}"
- "HOMEPAGE_VAR_PLEX_KEY=${PLEX_KEY}"
- "HOMEPAGE_VAR_PROWLARR_KEY=${PROWLARR_KEY}"
- "HOMEPAGE_VAR_RADARR_KEY=${RADARR_KEY}"
- "HOMEPAGE_VAR_SONARR_KEY=${SONARR_KEY}"
- "HOMEPAGE_VAR_LIDARR_KEY=${LIDARR_KEY}"
- "HOMEPAGE_VAR_TAUTULLI_KEY=${TAUTULLI_KEY}"
- "HOMEPAGE_VAR_SEERR_KEY=${SEERR_KEY}"
- "HOMEPAGE_VAR_QBITTORRENT_KEY=${QBITTORRENT_KEY}"
- "HOMEPAGE_VAR_TAILSCALE_KEY=${TAILSCALE_KEY}"
- "HOMEPAGE_VAR_TAILSCALE_DEVICE_KEY=${TAILSCALE_DEVICE_KEY}"
- "HOMEPAGE_VAR_PLEX_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PLEX_PORT}"
- "HOMEPAGE_VAR_QBITTORRENT_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${QBITTORRENT_PORT}"
- "HOMEPAGE_VAR_PROWLARR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PROWLARR_PORT}"
@@ -404,8 +473,11 @@ services:
- "HOMEPAGE_VAR_GLANCES_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${GLANCES_PORT}"
- "HOMEPAGE_VAR_SEERR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${SEERR_PORT}"
- "HOMEPAGE_VAR_MYSPEED_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${MYSPEED_PORT}"
- "HOMEPAGE_VAR_TERMIX_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${TERMIX_PORT}"
- "HOMEPAGE_VAR_ODYSSEUS_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${ODYSSEUS_PORT}"
- "HOMEPAGE_VAR_PIHOLE_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PIHOLE_PORT}"
- "HOMEPAGE_VAR_PORTAINER_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PORTAINER_PORT}"
- "HOMEPAGE_VAR_SCRUTINY_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${SCRUTINY_PORT}"
- "HOMEPAGE_VAR_KARAKEEP_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${KARAKEEP_PORT}"
- "HOMEPAGE_VAR_PLEX_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PLEX_PORT}"
- "HOMEPAGE_VAR_QBITTORRENT_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${QBITTORRENT_PORT}"
- "HOMEPAGE_VAR_PROWLARR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PROWLARR_PORT}"
@@ -418,45 +490,74 @@ services:
- "HOMEPAGE_VAR_GLANCES_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${GLANCES_PORT}"
- "HOMEPAGE_VAR_SEERR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${SEERR_PORT}"
- "HOMEPAGE_VAR_MYSPEED_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${MYSPEED_PORT}"
- "HOMEPAGE_VAR_TERMIX_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${TERMIX_PORT}"
- "HOMEPAGE_VAR_ODYSSEUS_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${ODYSSEUS_PORT}"
- "HOMEPAGE_VAR_PIHOLE_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PIHOLE_PORT}"
- "HOMEPAGE_VAR_PORTAINER_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PORTAINER_PORT}"
- "HOMEPAGE_VAR_SCRUTINY_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${SCRUTINY_PORT}"
- "HOMEPAGE_VAR_KARAKEEP_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${KARAKEEP_PORT}"
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
extra_hosts:
- "host.docker.internal:host-gateway"
restart: always
glances:
image: nicolargo/glances:latest-full
container_name: glances
network_mode: host
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- /etc/os-release:/etc/os-release:ro
- /:/host:ro
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
environment:
- GLANCES_OPT=-w
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
- TZ=${TIMEZONE}
devices:
- /dev/dri:/dev/dri
pid: host
restart: unless-stopped
# glances:
# image: nicolargo/glances:latest-full
# container_name: glances
# network_mode: host
# volumes:
# - /etc/os-release:/etc/os-release:ro
# - /:/host:ro
# #- /etc/localtime:/etc/localtime:ro
# #- /etc/timezone:/etc/timezone:ro
# environment:
# - "GLANCES_OPT=-w --password ${GLANCES_PASSWORD}"
# - PUID=${HOST_PUID:-1000}
# - PGID=${HOST_PGID:-1000}
# - TZ=${TIMEZONE}
# healthcheck:
# test:
# ["CMD", "curl", "-f", "http://localhost:${GLANCES_PORT}/api/4/status"]
# interval: 1m
# timeout: 10s
# retries: 3
# start_period: 60s
# security_opt:
# - no-new-privileges:true
# mem_limit: 256m
# cpus: 1.0
# devices:
# - /dev/dri:/dev/dri
# restart: unless-stopped
# # Uncomment to protect Glances WebUI by a login/password (add --password to GLANCES_OPT)
# secrets:
# - source: glances_password
# target: /root/.config/glances/<login>.pwd
# secrets:
# glances_password:
# file: ./secrets/glances_password
autoheal:
image: willfarrell/autoheal:latest
container_name: autoheal
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- AUTOHEAL_CONTAINER_LABEL=all
- AUTOHEAL_INTERVAL=30
- AUTOHEAL_START_PERIOD=60
restart: always
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
read_only: true
mem_limit: 64m
cpus: 0.25
restart: unless-stopped
myspeed:
image: germannewsmaker/myspeed
@@ -465,10 +566,14 @@ services:
- ${MYSPEED_PORT}:${MYSPEED_PORT}/tcp
volumes:
- myspeed:/myspeed/data
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
scrutiny:
@@ -477,12 +582,20 @@ services:
cap_add:
- SYS_RAWIO
ports:
- ${SCRUTINY_PORT:-54321}:8080
- ${SCRUTINY_ADMIN_PORT:-12345}:8086
- ${SCRUTINY_PORT}:8080
- ${SCRUTINY_ADMIN_PORT}:8086
volumes:
- /run/udev:/run/udev:ro
- ./config:/opt/scrutiny/config
- ./influxdb:/opt/scrutiny/influxdb
- ./scrutiny/config:/opt/scrutiny/config
- ./scrutiny/influxdb:/opt/scrutiny/influxdb
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 1.0
devices:
- /dev/nvme0n1
- /dev/sda
@@ -496,28 +609,40 @@ services:
image: pihole/pihole:latest
container_name: pihole
cap_add:
- NET_ADMIN
- NET_ADMIN # Allows managing network interfaces & sockets
- NET_BIND_SERVICE # Allows non-root users to bind to ports < 1024 (port 53 & 123)
- SYS_TIME # Resolves the NTP system time warning
network_mode: host
ports:
- 53:53/tcp
- 53:53/udp
- 67:67/udp
- 6060:6060/tcp
- ${PIHOLE_PORT}:${PIHOLE_PORT}/tcp
volumes:
- ./etc-pihole:/etc/pihole
- ./etc-dnsmasq.d:/etc/dnsmasq.d
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=America/Los_Angeles
- WEBPASSWORD=password123
- TZ=${TIMEZONE}
- FTLCONF_misc_etc_dnsmasq_d=true
# security_opt:
# - no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
cloudflared:
image: cloudflare/cloudflared:latest
container_name: cloudflared
command: tunnel --no-autoupdate run --token ${CLOUDFLARED_KEY}
env_file:
- ./env/.cloudflared.env
command: tunnel --no-autoupdate run # --token ${CLOUDFLARED_KEY}
security_opt:
- no-new-privileges:true
read_only: true
mem_limit: 128m
cpus: 0.5
restart: always
portainer:
@@ -528,7 +653,15 @@ services:
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- portainer_data:/data
restart: always
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
caddy:
image: caddy:latest
@@ -539,11 +672,18 @@ services:
- 80:80
- 443:443
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./caddy/Caddyfile:/etc/caddy/Caddyfile
- ./caddy/site:/srv
- ./caddy/caddy_data:/data
- ./caddy/caddy_config:/config
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 128m
cpus: 0.5
restart: unless-stopped
# ---------------------------------------------------------------------------
@@ -554,15 +694,21 @@ services:
image: ghcr.io/karakeep-app/karakeep:${KARAKEEP_VERSION:-release}
container_name: karakeep
env_file:
- .env
- ./env/.karakeep.env
ports:
- 4621:3000
- ${KARAKEEP_PORT}:3000 # must be 3000 as per the dev
volumes:
- karakeep-data:/data
- ./karakeep-data:/data
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- MEILI_ADDR=http://meilisearch:7700
- BROWSER_WEB_URL=http://chrome:9222
- MEILI_ADDR=http://meilisearch:${MEILI_PORT}
- BROWSER_WEB_URL=http://chrome:${KARAKEEP_CHROME_PORT}
- DATA_DIR=/data
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 2.0
restart: unless-stopped
chrome:
@@ -573,10 +719,14 @@ services:
- --disable-gpu
- --disable-dev-shm-usage
- --remote-debugging-address=0.0.0.0
- --remote-debugging-port=9222
- --remote-debugging-port=${KARAKEEP_CHROME_PORT}
- --hide-scrollbars
- --disable-blink-features=AutomationControlled
- --window-size=1440,900
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 1.0
restart: unless-stopped
meilisearch:
@@ -585,7 +735,13 @@ services:
env_file:
- .env
volumes:
- meilisearch:/meili_data
- ./meilisearch:/meili_data
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- MEILI_NO_ANALYTICS="true"
- MEILI_NO_ANALYTICS=true
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 1.0
restart: unless-stopped