refactor again

This commit is contained in:
2026-08-07 22:52:55 -07:00
parent 153ff43cf5
commit 3309f61d9c
14 changed files with 985 additions and 1380 deletions
+97
View File
@@ -0,0 +1,97 @@
# =============================================================================
# Torrent Stack - Environment Variables
# Copy this file to .env and fill in your values.
# NEVER commit .env to version control.
# =============================================================================
# ----- Time & Location -----
TIMEZONE=America/Los_Angeles
# ----- Host -----
LOCAL_IPV4=192.168.50.0 # of your device
EXTERNAL_IPV4=123.156.178.190
SERVER_NAME=your-server # most likely, set this to be the same as your local ipv4, unless you use tailscale or any sort of mDNS on your machine. homepage relies on this for hyperlinks, but not api calls.
WEB_NAME=your-server.com
TAILNET_NAME=tasty-food.ts.net
WEB_PROTOCOL=http
# ----- Storage -----
DISK1=/mnt/media
DISK2=/mnt/11tb_ext
DISK3=/mnt/shaimpy
# ----- Gluetun (VPN) -----
GLUETUN_KEY=YHotvxxNsRHa4YLu2j6ENL
VPN_PRIVATE_KEY="kGfvaULQs1KBWJ4KXD1LiX8sHNZ7hnCm/W45uBj4P1k="
# ----- Service Ports -----
PLEX_PORT=32400
PLEX_PFWD_PORT=32401 # PLEX PORT FORWARDED PORT. only if you manually specified
TAUTULLI_PORT=8181
HOMEPAGE_PORT=3000
GLANCES_PORT=61208 # this is hardcoded, please do not change
SEERR_PORT=5055
MYSPEED_PORT=5216
PROWLARR_PORT=9696
SONARR_PORT=8989
RADARR_PORT=7878
LIDARR_PORT=8686
QBITTORRENT_PORT=2161
TDARR_PORT=8265
TDARR_NODE_PORT=8266
ODYSSEUS_PORT=7001
PORTAINER_PORT=9443
SCRUTINY_PORT=4545
SCRUTINY_ADMIN_PORT=4646
PIHOLE_PORT=6060
KARAKEEP_PORT=4621
KARAKEEP_CHROME_PORT=9222
MEILI_PORT=7700
LLAMA_PORT=8079
TDARR_NODE_ID=ShaanNode
# ----- API Keys (for homepage widgets & service integrations) -----
PLEX_KEY=
PROWLARR_KEY=
RADARR_KEY=
SONARR_KEY=
LIDARR_KEY=
TAUTULLI_KEY=
SEERR_KEY=
QBITTORRENT_KEY=
TAILSCALE_KEY=
TAILSCALE_DEVICE_KEY=
CLOUDFLARED_KEY=
# ----- Cloudflare (for homepage widget) -----
CLOUDFLARED_ACCOUNT_ID=
CLOUDFLARED_TUNNEL_ID=
CLOUDFLARED_API_KEY=
# ----- Portainer (for homepage widget) -----
PORTAINER_API_KEY=
# ----- Pi-hole -----
PIHOLE_WEBPASSWORD=
# ----- Glances -----
GLANCES_USERNAME=
GLANCES_PASSWORD=
# ----- Karakeep -----
# KARAKEEP
DATA_DIR=/karakeep-data
MEILI_ADDR=http://127.0.0.1:${MEILI_PORT}
MEILI_MASTER_KEY=
NEXTAUTH_URL=http://localhost:3001
NEXTAUTH_SECRET=
OPENAI_API_KEY=ollama
OPENAI_BASE_URL=http://${LOCAL_IPV4}:${LLAMA_PORT}/v1
INFERENCE_TEXT_MODEL=Qwen3.6
INFERENCE_IMAGE_MODEL=Qwen3.6
EMBEDDING_TEXT_MODEL=Qwen3-Embedding
EMBEDDING_DIMENSIONS=2048
EMBEDDING_CONTEXT_LENGTH=4096
EMBEDDING_ENABLE_AUTO_INDEXING=true
+7
View File
@@ -1,5 +1,6 @@
# Ignore the environment file containing secrets
.env*
!.env.example
*.bak
*.log
@@ -20,6 +21,12 @@ config/
conf/
torrents.csv
torrents-csv-data/
env/*
meilisearch/
portainer-data/
scrutiny
karakeep-data
SECURITY.md
init-database.*
etc*
!odysseus/.*
+12 -1
View File
@@ -1,7 +1,18 @@
# Caddy reverse proxy for Seerr
# When Anubis is enabled (uncomment seerr-anubis in compose.yml),
# change the proxy target to http://seerr-anubis:55055
seerr.shaan-server, seerr.shaan-server.cc {
tls internal
reverse_proxy http://anubis-seerr:55055 {
reverse_proxy http://seerr:5055 {
header_up X-Real-Ip {remote_host}
header_up X-Http-Version {http.request.proto}
}
header {
# Security headers
X-Content-Type-Options nosniff
X-Frame-Options DENY
Referrer-Policy no-referrer
-Server
}
}
+267 -111
View File
@@ -11,20 +11,20 @@ networks:
name: portainer_network
volumes:
meilisearch:
karakeep-data:
caddy_config:
caddy_data:
external: true
#caddy_config:
#caddy_data:
# external: true
myspeed:
external: true
portainer_data:
name: portainer_data
# =============================================================================
# Key ordering per service:
# image → container_name → env_file → networks/network_mode → cap_add
# → ports → volumes → environment → labels → healthcheck
# → extra_hosts → devices → pid → restart
# image → container_name → env_file → networks/network_mode
# → depends_on → cap_add → ports → volumes → environment
# → labels → healthcheck → security_opt → mem_limit → cpus
# → devices → restart
# =============================================================================
services:
@@ -35,6 +35,9 @@ services:
gluetun:
image: qmcgaw/gluetun:latest
container_name: gluetun
env_file:
- .env
- ./env/.gluetun.env
cap_add:
- NET_ADMIN
ports:
@@ -46,12 +49,12 @@ services:
- ${LIDARR_PORT}:${LIDARR_PORT}
volumes:
- ./gluetun-data:/tmp/gluetun:rw
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- VPN_SERVICE_PROVIDER=protonvpn
- VPN_TYPE=wireguard
- HTTP_CONTROL_SERVER=ON
- HTTP_CONTROL_SERVER_AUTH_DEFAULT_ROLE='{"auth":"apikey","apikey":"${GLUETUN_KEY}"}'
- WIREGUARD_PRIVATE_KEY=${VPN_PRIVATE_KEY}
- WIREGUARD_MTU=1280
- VPN_PORT_FORWARDING=on
- VPN_PORT_FORWARDING_PROVIDER=protonvpn
@@ -61,11 +64,15 @@ services:
- TZ=${TIMEZONE}
- DNS_UPSTREAM_RESOLVER_TYPE=doh
healthcheck:
test: wget --spider -q http://1.1.1.1 || exit 1
test: ["CMD-SHELL", "wget --spider -q http://1.1.1.1 || exit 1"]
interval: 30s
timeout: 15s
retries: 3
start_period: 1m
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
extra_hosts:
- "host.docker.internal:host-gateway"
devices:
@@ -84,8 +91,8 @@ services:
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- ./gluetun-data:/tmp/gluetun
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
@@ -94,11 +101,19 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "wget --spider -q https://1.1.1.1 || exit 1"]
test:
[
"CMD-SHELL",
"curl -sf http://localhost:${QBITTORRENT_PORT}/api/v2/app/version || exit 1",
]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 2.0
restart: unless-stopped
port-updater:
@@ -135,12 +150,19 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "curl -f https://1.1.1.1 || exit 1"]
test: ["CMD-SHELL", "curl -sf https://1.1.1.1 || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
restart: always
security_opt:
- no-new-privileges:true
read_only: true
tmpfs:
- /tmp
mem_limit: 64m
cpus: 0.25
restart: unless-stopped
# ---------------------------------------------------------------------------
# *arr Stack
@@ -156,8 +178,8 @@ services:
volumes:
- ./prowlarr:/config
- ./notify.sh:/notify.sh:ro
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
@@ -165,12 +187,20 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "wget --spider -q https://google.com || exit 1"]
interval: 5m
timeout: 60s
test:
[
"CMD-SHELL",
"curl -sf http://localhost:${PROWLARR_PORT}/ping || exit 1",
]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
restart: always
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
sonarr:
image: lscr.io/linuxserver/sonarr:latest
@@ -183,8 +213,8 @@ services:
- /var/lib/sonarr:/config
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
@@ -192,12 +222,17 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
interval: 5m
timeout: 60s
test:
["CMD-SHELL", "curl -sf http://localhost:${SONARR_PORT}/ping || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 60s
restart: always
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
radarr:
image: lscr.io/linuxserver/radarr:latest
@@ -210,8 +245,8 @@ services:
- /var/lib/radarr:/config
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
@@ -219,12 +254,17 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
test:
["CMD-SHELL", "curl -sf http://localhost:${RADARR_PORT}/ping || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
restart: always
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
lidarr:
image: lscr.io/linuxserver/lidarr:latest
@@ -238,8 +278,8 @@ services:
- /var/lib/lidarr:/config
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
@@ -247,11 +287,16 @@ services:
labels:
- "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
test:
["CMD-SHELL", "curl -sf http://localhost:${LIDARR_PORT}/ping || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
# ---------------------------------------------------------------------------
@@ -267,10 +312,16 @@ services:
- ${TAUTULLI_PORT}:${TAUTULLI_PORT}
volumes:
- ./tautulli:/config
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
tdarr:
@@ -287,12 +338,18 @@ services:
- ./tdarr/temp:/temp
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-100}
- PGID=${HOST_PGID:-1000}
- UMASK_SET=002
- serverIP=0.0.0.0
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 2.0
restart: unless-stopped
tdarr-node:
@@ -306,6 +363,8 @@ services:
- ./tdarr/temp:/temp
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
- PUID=${HOST_PUID:-1000}
@@ -314,8 +373,12 @@ services:
- nodeIP=0.0.0.0
- serverIP=tdarr
- serverPort=${TDARR_NODE_PORT}
security_opt:
- no-new-privileges:true
mem_limit: 2g
cpus: 4.0
devices:
- /dev/dri/:/dev/dri/
- /dev/dri:/dev/dri
restart: unless-stopped
seerr:
@@ -327,11 +390,11 @@ services:
- ${SEERR_PORT}:${SEERR_PORT}
volumes:
- ./seerr:/app/config
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- LOG_LEVEL=debug
- TZ=America/Los_Angeles
- LOG_LEVEL=info
- TZ=${TIMEZONE}
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
labels:
@@ -339,22 +402,35 @@ services:
init: true
working_dir: "/app"
healthcheck:
test: ["CMD-SHELL", "wget --spider -q http://1.1.1.1 || exit 1"]
test:
[
"CMD-SHELL",
"wget -qO- http://127.0.0.1:${SEERR_PORT}/api/v1/status || exit 1",
]
interval: 1m
timeout: 10s
retries: 3
start_period: 60s
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
seerr-anubis:
image: ghcr.io/techarohq/anubis:latest
container_name: seerr_anubis
networks:
- caddy_net
environment:
- BIND=:55055
- TARGET=http://seerr:${SEERR_PORT}
restart: unless-stopped
# Anubis anti-bot proxy for Seerr (uncomment to enable):
#seerr-anubis:
# image: ghcr.io/techarohq/anubis:latest
# container_name: seerr-anubis
# networks:
# - caddy_net
# environment:
# - BIND=:55055
# - TARGET=http://seerr:${SEERR_PORT}
# security_opt:
# - no-new-privileges:true
# mem_limit: 128m
# cpus: 0.5
# restart: unless-stopped
# ---------------------------------------------------------------------------
# Monitoring
@@ -363,6 +439,9 @@ services:
homepage:
image: ghcr.io/gethomepage/homepage:latest
container_name: homepage
env_file:
- .env
- ./env/.homepage.env
networks:
- caddy_net
ports:
@@ -372,8 +451,8 @@ services:
- ./homepage/images:/app/public/images
- /var/run/docker.sock:/var/run/docker.sock:ro
- ./gluetun-data:/tmp/gluetun:ro
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- "HOMEPAGE_ALLOWED_HOSTS=gethomepage.dev,${LOCAL_IPV4}:${HOMEPAGE_PORT},${SERVER_NAME}:${HOMEPAGE_PORT},${SERVER_NAME}.${TAILNET_NAME}:${HOMEPAGE_PORT}"
- "HOMEPAGE_VAR_DISK1=${DISK1}"
@@ -382,16 +461,6 @@ services:
- "HOMEPAGE_VAR_WEB_PROTOCOL=${WEB_PROTOCOL}"
- "HOMEPAGE_VAR_LOCAL_IPV4=${LOCAL_IPV4}"
- "HOMEPAGE_VAR_SERVER_NAME=${SERVER_NAME}"
- "HOMEPAGE_VAR_PLEX_KEY=${PLEX_KEY}"
- "HOMEPAGE_VAR_PROWLARR_KEY=${PROWLARR_KEY}"
- "HOMEPAGE_VAR_RADARR_KEY=${RADARR_KEY}"
- "HOMEPAGE_VAR_SONARR_KEY=${SONARR_KEY}"
- "HOMEPAGE_VAR_LIDARR_KEY=${LIDARR_KEY}"
- "HOMEPAGE_VAR_TAUTULLI_KEY=${TAUTULLI_KEY}"
- "HOMEPAGE_VAR_SEERR_KEY=${SEERR_KEY}"
- "HOMEPAGE_VAR_QBITTORRENT_KEY=${QBITTORRENT_KEY}"
- "HOMEPAGE_VAR_TAILSCALE_KEY=${TAILSCALE_KEY}"
- "HOMEPAGE_VAR_TAILSCALE_DEVICE_KEY=${TAILSCALE_DEVICE_KEY}"
- "HOMEPAGE_VAR_PLEX_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PLEX_PORT}"
- "HOMEPAGE_VAR_QBITTORRENT_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${QBITTORRENT_PORT}"
- "HOMEPAGE_VAR_PROWLARR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PROWLARR_PORT}"
@@ -404,8 +473,11 @@ services:
- "HOMEPAGE_VAR_GLANCES_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${GLANCES_PORT}"
- "HOMEPAGE_VAR_SEERR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${SEERR_PORT}"
- "HOMEPAGE_VAR_MYSPEED_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${MYSPEED_PORT}"
- "HOMEPAGE_VAR_TERMIX_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${TERMIX_PORT}"
- "HOMEPAGE_VAR_ODYSSEUS_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${ODYSSEUS_PORT}"
- "HOMEPAGE_VAR_PIHOLE_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PIHOLE_PORT}"
- "HOMEPAGE_VAR_PORTAINER_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PORTAINER_PORT}"
- "HOMEPAGE_VAR_SCRUTINY_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${SCRUTINY_PORT}"
- "HOMEPAGE_VAR_KARAKEEP_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${KARAKEEP_PORT}"
- "HOMEPAGE_VAR_PLEX_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PLEX_PORT}"
- "HOMEPAGE_VAR_QBITTORRENT_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${QBITTORRENT_PORT}"
- "HOMEPAGE_VAR_PROWLARR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PROWLARR_PORT}"
@@ -418,45 +490,74 @@ services:
- "HOMEPAGE_VAR_GLANCES_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${GLANCES_PORT}"
- "HOMEPAGE_VAR_SEERR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${SEERR_PORT}"
- "HOMEPAGE_VAR_MYSPEED_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${MYSPEED_PORT}"
- "HOMEPAGE_VAR_TERMIX_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${TERMIX_PORT}"
- "HOMEPAGE_VAR_ODYSSEUS_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${ODYSSEUS_PORT}"
- "HOMEPAGE_VAR_PIHOLE_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PIHOLE_PORT}"
- "HOMEPAGE_VAR_PORTAINER_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PORTAINER_PORT}"
- "HOMEPAGE_VAR_SCRUTINY_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${SCRUTINY_PORT}"
- "HOMEPAGE_VAR_KARAKEEP_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${KARAKEEP_PORT}"
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
extra_hosts:
- "host.docker.internal:host-gateway"
restart: always
glances:
image: nicolargo/glances:latest-full
container_name: glances
network_mode: host
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- /etc/os-release:/etc/os-release:ro
- /:/host:ro
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
environment:
- GLANCES_OPT=-w
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
- TZ=${TIMEZONE}
devices:
- /dev/dri:/dev/dri
pid: host
restart: unless-stopped
# glances:
# image: nicolargo/glances:latest-full
# container_name: glances
# network_mode: host
# volumes:
# - /etc/os-release:/etc/os-release:ro
# - /:/host:ro
# #- /etc/localtime:/etc/localtime:ro
# #- /etc/timezone:/etc/timezone:ro
# environment:
# - "GLANCES_OPT=-w --password ${GLANCES_PASSWORD}"
# - PUID=${HOST_PUID:-1000}
# - PGID=${HOST_PGID:-1000}
# - TZ=${TIMEZONE}
# healthcheck:
# test:
# ["CMD", "curl", "-f", "http://localhost:${GLANCES_PORT}/api/4/status"]
# interval: 1m
# timeout: 10s
# retries: 3
# start_period: 60s
# security_opt:
# - no-new-privileges:true
# mem_limit: 256m
# cpus: 1.0
# devices:
# - /dev/dri:/dev/dri
# restart: unless-stopped
# # Uncomment to protect Glances WebUI by a login/password (add --password to GLANCES_OPT)
# secrets:
# - source: glances_password
# target: /root/.config/glances/<login>.pwd
# secrets:
# glances_password:
# file: ./secrets/glances_password
autoheal:
image: willfarrell/autoheal:latest
container_name: autoheal
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- AUTOHEAL_CONTAINER_LABEL=all
- AUTOHEAL_INTERVAL=30
- AUTOHEAL_START_PERIOD=60
restart: always
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
read_only: true
mem_limit: 64m
cpus: 0.25
restart: unless-stopped
myspeed:
image: germannewsmaker/myspeed
@@ -465,10 +566,14 @@ services:
- ${MYSPEED_PORT}:${MYSPEED_PORT}/tcp
volumes:
- myspeed:/myspeed/data
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
scrutiny:
@@ -477,12 +582,20 @@ services:
cap_add:
- SYS_RAWIO
ports:
- ${SCRUTINY_PORT:-54321}:8080
- ${SCRUTINY_ADMIN_PORT:-12345}:8086
- ${SCRUTINY_PORT}:8080
- ${SCRUTINY_ADMIN_PORT}:8086
volumes:
- /run/udev:/run/udev:ro
- ./config:/opt/scrutiny/config
- ./influxdb:/opt/scrutiny/influxdb
- ./scrutiny/config:/opt/scrutiny/config
- ./scrutiny/influxdb:/opt/scrutiny/influxdb
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 1.0
devices:
- /dev/nvme0n1
- /dev/sda
@@ -496,28 +609,40 @@ services:
image: pihole/pihole:latest
container_name: pihole
cap_add:
- NET_ADMIN
- NET_ADMIN # Allows managing network interfaces & sockets
- NET_BIND_SERVICE # Allows non-root users to bind to ports < 1024 (port 53 & 123)
- SYS_TIME # Resolves the NTP system time warning
network_mode: host
ports:
- 53:53/tcp
- 53:53/udp
- 67:67/udp
- 6060:6060/tcp
- ${PIHOLE_PORT}:${PIHOLE_PORT}/tcp
volumes:
- ./etc-pihole:/etc/pihole
- ./etc-dnsmasq.d:/etc/dnsmasq.d
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=America/Los_Angeles
- WEBPASSWORD=password123
- TZ=${TIMEZONE}
- FTLCONF_misc_etc_dnsmasq_d=true
# security_opt:
# - no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
cloudflared:
image: cloudflare/cloudflared:latest
container_name: cloudflared
command: tunnel --no-autoupdate run --token ${CLOUDFLARED_KEY}
env_file:
- ./env/.cloudflared.env
command: tunnel --no-autoupdate run # --token ${CLOUDFLARED_KEY}
security_opt:
- no-new-privileges:true
read_only: true
mem_limit: 128m
cpus: 0.5
restart: always
portainer:
@@ -528,7 +653,15 @@ services:
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- portainer_data:/data
restart: always
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 256m
cpus: 1.0
restart: unless-stopped
caddy:
image: caddy:latest
@@ -539,11 +672,18 @@ services:
- 80:80
- 443:443
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./caddy/Caddyfile:/etc/caddy/Caddyfile
- ./caddy/site:/srv
- ./caddy/caddy_data:/data
- ./caddy/caddy_config:/config
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- TZ=${TIMEZONE}
security_opt:
- no-new-privileges:true
mem_limit: 128m
cpus: 0.5
restart: unless-stopped
# ---------------------------------------------------------------------------
@@ -554,15 +694,21 @@ services:
image: ghcr.io/karakeep-app/karakeep:${KARAKEEP_VERSION:-release}
container_name: karakeep
env_file:
- .env
- ./env/.karakeep.env
ports:
- 4621:3000
- ${KARAKEEP_PORT}:3000 # must be 3000 as per the dev
volumes:
- karakeep-data:/data
- ./karakeep-data:/data
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- MEILI_ADDR=http://meilisearch:7700
- BROWSER_WEB_URL=http://chrome:9222
- MEILI_ADDR=http://meilisearch:${MEILI_PORT}
- BROWSER_WEB_URL=http://chrome:${KARAKEEP_CHROME_PORT}
- DATA_DIR=/data
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 2.0
restart: unless-stopped
chrome:
@@ -573,10 +719,14 @@ services:
- --disable-gpu
- --disable-dev-shm-usage
- --remote-debugging-address=0.0.0.0
- --remote-debugging-port=9222
- --remote-debugging-port=${KARAKEEP_CHROME_PORT}
- --hide-scrollbars
- --disable-blink-features=AutomationControlled
- --window-size=1440,900
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 1.0
restart: unless-stopped
meilisearch:
@@ -585,7 +735,13 @@ services:
env_file:
- .env
volumes:
- meilisearch:/meili_data
- ./meilisearch:/meili_data
#- /etc/localtime:/etc/localtime:ro
#- /etc/timezone:/etc/timezone:ro
environment:
- MEILI_NO_ANALYTICS="true"
- MEILI_NO_ANALYTICS=true
security_opt:
- no-new-privileges:true
mem_limit: 512m
cpus: 1.0
restart: unless-stopped
-604
View File
@@ -1,604 +0,0 @@
services:
gluetun:
image: qmcgaw/gluetun:latest
container_name: gluetun
cap_add:
- NET_ADMIN
devices:
- /dev/net/tun:/dev/net/tun
environment:
- VPN_SERVICE_PROVIDER=protonvpn # Or mullvad, protonvpn, surfshark, etc.
- VPN_TYPE=wireguard # WireGuard, openvpn
- HTTP_CONTROL_SERVER=ON
- HTTP_CONTROL_SERVER_AUTH_DEFAULT_ROLE='{"auth":"apikey","apikey":"${GLUETUN_KEY}"}' # generate by running `docker run --rm qmcgaw/gluetun genkey`, then adding this to your `.env` file
- WIREGUARD_PRIVATE_KEY=${VPN_PRIVATE_KEY}
- WIREGUARD_MTU=1280
- VPN_PORT_FORWARDING=on
- VPN_PORT_FORWARDING_PROVIDER=protonvpn
#- OPENVPN_USER=user
#- OPENVPN_PASSWORD=password
- SERVER_COUNTRIES=Netherlands # choose fast P2P friendly countries
- NETWORK_LOCAL_ADDRESSES=192.168.50.0/24,172.16.0.0/12
- FIREWALL_OUTBOUND_SUBNETS=192.168.50.0/24
- TZ=${TIMEZONE}
- DNS_UPSTREAM_RESOLVER_TYPE=doh # DNS over TLS is an extra layer of security so your isp can not look at what you're doing through your DNS requests, even if your using a vpn (very vague, I don't know how this syustem works with a vpn).
ports: # YOU MUST SPECIFY A PORT PER SERVICE ROUTED THROUGH GLUETUN!
- 8888:8000/tcp # gluetun control server, i dont think you should change this
- ${QBITTORRENT_PORT}:${QBITTORRENT_PORT} # qBittorrent Web UI
- ${PROWLARR_PORT}:${PROWLARR_PORT} # Prowlarr
- ${SONARR_PORT}:${SONARR_PORT} # Sonarr
- ${RADARR_PORT}:${RADARR_PORT} # Radarr
- ${LIDARR_PORT}:${LIDARR_PORT} # Lidarr
#- ${SEERR_PORT}:${SEERR_PORT}/tcp # Seerr # took this out of gluetun, as it could cause issues with starting the container, and it was unecessary
healthcheck:
test: wget --spider -q http://1.1.1.1 || exit 1
interval: 30s
timeout: 15s
retries: 3
start_period: 1m
volumes:
- ./gluetun-data:/tmp/gluetun:rw
extra_hosts:
- "host.docker.internal:host-gateway" # host-gateway is a docker variable that automatically grabs the 172.XX.0.1 address, this is to be used by prowlarr to communicate with sonarr and radarr.
restart: always
qbittorrent:
image: lscr.io/linuxserver/qbittorrent:latest
container_name: qbittorrent
network_mode: "container:gluetun" # vpn bunker
environment:
- PUID=1000
- PGID=1000
- TZ=${TIMEZONE}
- WEBUI_PORT=${QBITTORRENT_PORT}
volumes:
- ./qbittorrent:/config
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- ./gluetun-data:/tmp/gluetun
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
labels:
- "autoheal=true"
depends_on:
gluetun:
condition: service_healthy
healthcheck: # if gluetun is slow to start, it's over
test: ["CMD-SHELL", wget --spider -q https://1.1.1.1 || exit 1] # use 1.1.1.1, we don't need dns around here
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
restart: unless-stopped
port-updater:
# use an image that already has curl/wget to skip the 'apk add' step
image: curlimages/curl:latest
container_name: port-updater
volumes:
- ./gluetun-data:/tmp/gluetun:ro
# using 'exec' format and 'trap' allows the container to stop instantly
entrypoint: ["/bin/sh", "-c"]
command: # loololloloolol gemini did this for me
- |
trap 'exit 0' SIGTERM;
while true; do
# 1. Wait for Gluetun to actually create the file with a number
while [ ! -s /tmp/gluetun/forwarded_port ]; do
echo "Waiting for Gluetun to provide a port..."
sleep 5
done
# 2. Read and clean the port
read -r PORT_VAL < /tmp/gluetun/forwarded_port;
CLEAN_PORT=$$(echo "$$PORT_VAL" | tr -d '\r\n ');
# 3. Only update if the port isn't empty
if [ -n "$$CLEAN_PORT" ]; then
echo "Updating qBit to port: $$CLEAN_PORT";
sleep 10;
echo "Updated to $$CLEAN_PORT"
curl -s -X POST -d "json={\"listen_port\":$$CLEAN_PORT}" http://localhost:${QBITTORRENT_PORT}/api/v2/app/setPreferences;
# 4. Success! Now sleep for a long time (e.g., 1 hour)
sleep 3600 & wait $$!;
else
# If for some reason it's still blank, retry quickly
sleep 10
fi
done
labels:
- "autoheal=true"
network_mode: "container:gluetun"
depends_on:
gluetun:
condition: service_healthy
healthcheck:
test: ["CMD-SHELL", "curl -f https://1.1.1.1 || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
restart: always
prowlarr:
image: lscr.io/linuxserver/prowlarr:latest
container_name: prowlarr
environment:
- PUID=1000
- PGID=1000
- TZ=${TIMEZONE}
volumes:
- ./prowlarr:/config
- ./notify.sh:/notify.sh:ro
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
labels:
- "autoheal=true"
network_mode: "container:gluetun"
depends_on:
gluetun:
condition: service_healthy
healthcheck:
test: ["CMD-SHELL", wget --spider -q https://google.com || exit 1] # needs DNS
interval: 5m
timeout: 60s
retries: 3
start_period: 30s
restart: always
sonarr:
image: lscr.io/linuxserver/sonarr:latest
container_name: sonarr
environment:
- PUID=1000
- PGID=1000
- TZ=${TIMEZONE}
volumes:
- /var/lib/sonarr:/config # had migrated into docker compose
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
labels:
- "autoheal=true"
network_mode: "container:gluetun"
depends_on:
gluetun:
condition: service_healthy
healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
interval: 5m
timeout: 60s
retries: 3
start_period: 60s
restart: always
radarr:
image: lscr.io/linuxserver/radarr:latest
container_name: radarr
environment:
- PUID=1000
- PGID=1000
- TZ=${TIMEZONE}
volumes:
- /var/lib/radarr:/config # had migrated into docker compose
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
labels:
- "autoheal=true"
network_mode: "container:gluetun"
depends_on:
gluetun:
condition: service_healthy
healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
restart: always
lidarr:
image: lscr.io/linuxserver/lidarr:latest
container_name: lidarr
environment:
- PUID=1000
- PGID=1000
- TZ=${TIMEZONE}
volumes:
- /home/shaan/torrent-stack/lidarr:/music
- /var/lib/lidarr:/config
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
labels:
- "autoheal=true"
network_mode: "container:gluetun"
depends_on:
gluetun:
condition: service_healthy
healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 30s
restart: unless-stopped
tautulli: # has no network bridge between containers. this is fine, as it only needs to get from plex, which is outside this container
image: ghcr.io/tautulli/tautulli
container_name: tautulli
volumes:
#- /mnt/media/media:/config
- ./tautulli:/config
environment:
- PUID=1000
- PGID=1000
- TZ=${TIMEZONE}
ports:
- ${TAUTULLI_PORT}:${TAUTULLI_PORT}
networks:
- caddy_net
restart: always
tdarr:
container_name: tdarr
image: haveagitgat/tdarr:latest
networks:
- tdarr-net
ports:
- ${TDARR_PORT}:${TDARR_PORT} # WebUI
- ${TDARR_NODE_PORT}:${TDARR_NODE_PORT} # local tdarr-node
environment:
- TZ=${TIMEZONE}
- PUID=1000
- PGID=1000
- UMASK_SET=002
- serverIP=0.0.0.0
volumes:
- ./tdarr/server:/app/server
- ./tdarr/configs:/app/configs
- ./tdarr/temp:/temp
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
# dont put temp files onto a HARD DISK DRIVE! > - ${DISK1}/tdarr-temp:/temp
devices:
- /dev/dri:/dev/dri # Intel UHD Graphics 710
restart: always
tdarr-node:
container_name: tdarr-node
image: haveagitgat/tdarr_node:latest
networks:
- tdarr-net
environment:
- TZ=${TIMEZONE}
- PUID=1000
- PGID=1000
- nodeID=${TDARR_NODE_ID}
- nodeIP=0.0.0.0
- serverIP=tdarr # Points to the server container
- serverPort=${TDARR_NODE_PORT}
volumes:
- ./tdarr/configs:/app/configs
- ./tdarr/logs:/app/logs
- /home/shaan/torrent-stack/tdarr/temp:/temp
- ${DISK1}:${DISK1}
- ${DISK2}:${DISK2}
devices:
- /dev/dri:/dev/dri # only works if user 'shaan' is a part of the 'video' or 'render' group.
restart: always
homepage:
image: ghcr.io/gethomepage/homepage:latest
container_name: homepage
ports:
- ${HOMEPAGE_PORT}:${HOMEPAGE_PORT}
volumes:
- ./homepage:/app/config
- ./homepage/images:/app/public/images
- /var/run/docker.sock:/var/run/docker.sock:ro # (optional) For docker integrations
- ./gluetun-data:/tmp/gluetun:ro # get the port from port-updater
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
environment:
#- "HOMEPAGE_ALLOWED_HOSTS=gethomepage.dev,${LOCAL_IPV4}:${HOMEPAGE_PORT},${SERVER_NAME}:${HOMEPAGE_PORT},100.76.249.110:${HOMEPAGE_PORT},${SERVER_NAME}.tail:${HOMEPAGE_PORT},${EXTERNAL_IPV4}:${HOMEPAGE_PORT},${WEB_NAME}:${HOMEPAGE_PORT},${WEB_NAME},172.17.0.1:${HOMEPAGE_PORT},${SERVER_NAME}:80,${SERVER_NAME}:443,shaan-server:443" # required, may need port. See gethomepage.dev/installation/#homepage_allowed_hosts
- "HOMEPAGE_ALLOWED_HOSTS=*"
- "HOMEPAGE_VAR_DISK1=${DISK1}"
- "HOMEPAGE_VAR_DISK2=${DISK2}"
- "HOMEPAGE_VAR_DISK3=${DISK3}"
- "HOMEPAGE_VAR_WEB_PROTOCOL=${WEB_PROTOCOL}"
- "HOMEPAGE_VAR_LOCAL_IPV4=${LOCAL_IPV4}"
- "HOMEPAGE_VAR_SERVER_NAME=${SERVER_NAME}"
- "HOMEPAGE_VAR_PLEX_KEY=${PLEX_KEY}"
- "HOMEPAGE_VAR_PROWLARR_KEY=${PROWLARR_KEY}"
- "HOMEPAGE_VAR_RADARR_KEY=${RADARR_KEY}"
- "HOMEPAGE_VAR_SONARR_KEY=${SONARR_KEY}"
- "HOMEPAGE_VAR_LIDARR_KEY=${LIDARR_KEY}"
- "HOMEPAGE_VAR_TAUTULLI_KEY=${TAUTULLI_KEY}"
- "HOMEPAGE_VAR_SEERR_KEY=${SEERR_KEY}"
- "HOMEPAGE_VAR_QBITTORRENT_KEY=${QBITTORRENT_KEY}"
- "HOMEPAGE_VAR_TAILSCALE_KEY=${TAILSCALE_KEY}"
- "HOMEPAGE_VAR_TAILSCALE_DEVICE_KEY=${TAILSCALE_DEVICE_KEY}"
- "HOMEPAGE_VAR_PLEX_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PLEX_PORT}"
- "HOMEPAGE_VAR_QBITTORRENT_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${QBITTORRENT_PORT}"
- "HOMEPAGE_VAR_PROWLARR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PROWLARR_PORT}"
- "HOMEPAGE_VAR_SONARR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${SONARR_PORT}"
- "HOMEPAGE_VAR_RADARR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${RADARR_PORT}"
- "HOMEPAGE_VAR_LIDARR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${LIDARR_PORT}"
- "HOMEPAGE_VAR_TAUTULLI_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${TAUTULLI_PORT}"
- "HOMEPAGE_VAR_TDARR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${TDARR_PORT}"
- "HOMEPAGE_VAR_HOMEPAGE_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${HOMEPAGE_PORT}"
- "HOMEPAGE_VAR_GLANCES_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${GLANCES_PORT}"
- "HOMEPAGE_VAR_SEERR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${SEERR_PORT}"
- "HOMEPAGE_VAR_MYSPEED_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${MYSPEED_PORT}"
- "HOMEPAGE_VAR_TERMIX_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${TERMIX_PORT}"
- "HOMEPAGE_VAR_ODYSSEUS_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${ODYSSEUS_PORT}"
- "HOMEPAGE_VAR_PLEX_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PLEX_PORT}"
- "HOMEPAGE_VAR_QBITTORRENT_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${QBITTORRENT_PORT}"
- "HOMEPAGE_VAR_PROWLARR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PROWLARR_PORT}"
- "HOMEPAGE_VAR_SONARR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${SONARR_PORT}"
- "HOMEPAGE_VAR_RADARR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${RADARR_PORT}"
- "HOMEPAGE_VAR_LIDARR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${LIDARR_PORT}"
- "HOMEPAGE_VAR_TAUTULLI_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${TAUTULLI_PORT}"
- "HOMEPAGE_VAR_TDARR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${TDARR_PORT}"
- "HOMEPAGE_VAR_HOMEPAGE_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${HOMEPAGE_PORT}"
- "HOMEPAGE_VAR_GLANCES_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${GLANCES_PORT}"
- "HOMEPAGE_VAR_SEERR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${SEERR_PORT}"
- "HOMEPAGE_VAR_MYSPEED_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${MYSPEED_PORT}"
- "HOMEPAGE_VAR_TERMIX_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${TERMIX_PORT}"
- "HOMEPAGE_VAR_ODYSSEUS_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${ODYSSEUS_PORT}"
- TZ=${TIMEZONE}
extra_hosts:
- "host.docker.internal:host-gateway"
networks:
- caddy_net
restart: always
glances:
image: nicolargo/glances:latest-full
container_name: glances
pid: host
network_mode: host
devices:
- /dev/dri:/dev/dri
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- /etc/os-release:/etc/os-release:ro
- /:/host:ro
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
environment:
- GLANCES_OPT=-w
- PUID=1000
- PGID=1000
- TZ=${TIMEZONE}
restart: unless-stopped
autoheal:
image: willfarrell/autoheal:latest
container_name: autoheal
environment:
- AUTOHEAL_CONTAINER_LABEL=all
- AUTOHEAL_INTERVAL=30
- AUTOHEAL_START_PERIOD=60
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
restart: always
seerr:
image: ghcr.io/seerr-team/seerr:latest
init: true
container_name: seerr
ports:
- ${SEERR_PORT}:${SEERR_PORT}
environment:
- LOG_LEVEL=debug
- TZ=America/Los_Angeles
- PUID=1000
- PGID=1000
volumes:
- "./seerr:/app/config"
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
working_dir: "/app"
labels:
- "autoheal=true"
networks:
- caddy_net
healthcheck:
test: ["CMD-SHELL", "wget --spider -q http://1.1.1.1 || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 60s
restart: unless-stopped
anubis-seerr:
image: ghcr.io/techarohq/anubis:latest
environment:
BIND: ":55055"
TARGET: http://seerr:${SEERR_PORT}
networks:
- caddy_net
restart: unless-stopped
MySpeed:
command:
- "node"
- "server"
container_name: "MySpeed"
entrypoint:
- "docker-entrypoint.sh"
environment:
- "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
- "NODE_VERSION=18.20.3"
- "YARN_VERSION=1.22.19"
- "NODE_ENV=production"
- TZ=${TIMEZONE}
hostname: "4b5e3178fcc4"
image: "germannewsmaker/myspeed"
ipc: "private"
logging:
driver: "json-file"
options: {}
mac_address: "02:42:ac:11:00:03"
network_mode: "bridge"
ports:
- "${MYSPEED_PORT}:${MYSPEED_PORT}/tcp"
volumes:
- "myspeed:/myspeed/data"
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
working_dir: "/myspeed"
restart: unless-stopped
termix:
image: ghcr.io/lukegus/termix:latest
container_name: termix
cap_add:
- NET_ADMIN
- SYS_ADMIN
ports:
- "${TERMIX_PORT}:${TERMIX_PORT}"
volumes:
- termix-data:/app/data
environment:
- "PORT: ${TERMIX_PORT}"
- "TZ: {TIMEZONE}"
networks:
- termix-net
restart: unless-stopped
pihole:
container_name: pihole
image: pihole/pihole:latest
network_mode: "host"
ports:
- "53:53/tcp"
- "53:53/udp"
- "67:67/udp"
- "6060:6060/tcp"
environment:
TZ: "America/Los_Angeles"
WEBPASSWORD: "password123"
FTLCONF_misc_etc_dnsmasq_d: "true"
volumes:
- "./etc-pihole:/etc/pihole"
- "./etc-dnsmasq.d:/etc/dnsmasq.d"
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
cap_add:
- NET_ADMIN
restart: unless-stopped
cloudflared:
container_name: cloudflared-tunnel
image: cloudflare/cloudflared:latest
restart: always
command: tunnel --no-autoupdate run --token ${CLOUDFLARED_KEY}
torrents-csv:
image: dessalines/torrents-csv-server:latest
restart: unless-stopped
ports:
- "8902:8902"
environment:
TORRENTS_CSV_DB_HOST: "postgres://postgres:password@db"
TORRENTS_CSV_FRONT_END_DIR: /app/dist
RUST_LOG: DEBUG
TIMEZONE: ${TIMEZONE}
depends_on:
- db # search at 'http://shaan-server:8902/service/search?q={SEARCH_TERM'
db:
image: pgautoupgrade/pgautoupgrade:17-alpine
shm_size: 1gb
volumes:
- ./init-database.sh:/docker-entrypoint-initdb.d/init-database.sh
- ./init-database.sql:/var/lib/postgresql/init-database.sql
- ./torrents.csv:/var/lib/postgresql/torrents.csv
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
ports:
- "127.0.0.1:5433:5432"
environment:
POSTGRES_PASSWORD: password
POSTGRES_USER: postgres
TIMEZONE: ${TIMEZONE}
restart: unless-stopped
portainer:
container_name: portainer
image: portainer/portainer-ce:lts
restart: always
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- portainer_data:/data
ports:
- ${PORTAINER_PORT}:${PORTAINER_PORT}
caddy:
image: caddy:latest
restart: unless-stopped
container_name: caddy
ports:
- 80:80
- 443:443
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- /home/shaan/torrent-stack/caddy/Caddyfile:/etc/caddy/Caddyfile
- /home/shaan/torrent-stack/caddy/site:/srv
- /home/shaan/torrent-stack/caddy/caddy_data:/data
- /home/shaan/torrent-stack/caddy/caddy_config:/config
networks:
- caddy_net
scrutiny:
restart: unless-stopped
container_name: scrutiny
image: ghcr.io/analogj/scrutiny:nightly-omnibus
cap_add:
- SYS_RAWIO
ports:
- "${SCRUTINY_PORT:-54321}:8080" # webapp
- "${SCRUTINY_ADMIN_PORT:-12345}:8086" # influxDB admin
volumes:
- /run/udev:/run/udev:ro
- ./config:/opt/scrutiny/config
- ./influxdb:/opt/scrutiny/influxdb
devices:
- "/dev/nvme0n1"
- "/dev/sda"
- "/dev/sdb"
networks:
caddy_net:
external: true
tdarr-net:
driver: bridge
termix-net:
driver: bridge
staticaddress:
ipam:
config:
- subnet: "172.200.0.0/16"
default:
name: portainer_network
volumes:
caddy_data:
external: true
caddy_config:
myspeed:
external: true # docker compose will fail creating myspeed if the volume hasn't been manually created, which we have done. unless you deleted it...
termix-data:
driver: local
portainer_data:
name: portainer_data
+30 -28
View File
@@ -2,13 +2,21 @@
# For configuration options and examples, please see:
# https://gethomepage.dev/configs/bookmarks
- "Apps":
- "User":
- "Plex":
- icon: si-plex-#EBAF00
href: "{{HOMEPAGE_VAR_PLEX_HOST}}"
- "Seerr":
- icon: sh-seerr
href: "{{HOMEPAGE_VAR_SEERR_HOST}}"
- "Odysseus":
- icon: http://shaan-server:7001/static/icons/icon-192.png
href: https://shaan-server.cc
- "Karakeep":
- icon: sh-karakeep-light
href: "{{HOMEPAGE_VAR_KARAKEEP_HOST}}"
- "Admin":
- "Sonarr":
- icon: sh-sonarr
href: "{{HOMEPAGE_VAR_SONARR_HOST}}"
@@ -18,6 +26,9 @@
- "Lidarr":
- icon: sh-lidarr
href: "{{HOMEPAGE_VAR_LIDARR_HOST}}"
- "Prowlarr":
- icon: sh-prowlarr
href: "{{HOMEPAGE_VAR_PROWLARR_HOST}}"
- "Tautulli":
- icon: sh-tautulli
href: "{{HOMEPAGE_VAR_TAUTULLI_HOST}}"
@@ -26,37 +37,31 @@
href: "{{HOMEPAGE_VAR_TDARR_HOST}}"
- "qBittorrent":
- icon: sh-qbittorrent
href: http://shaan-server:2161
- "Seerr":
- icon: sh-seerr
href: "{{HOMEPAGE_VAR_SEERR_HOST}}"
- "Prowlarr":
- icon: sh-prowlarr
href: "{{HOMEPAGE_VAR_PROWLARR_HOST}}"
- "Portainer":
- icon: sh-portainer-light
href: https://shaan-server:9443
- "Pi-Hole":
- icon: sh-pi-hole
href: http://shaan-server:6060/admin
- "Router Gateway":
- icon: "http://192.168.50.1/images/favicon.png"
href: http://192.168.50.1
- "llama.cpp":
- icon: sh-llama-cpp
href: http://192.168.50.6:5078
- "Tailscale":
- icon: sh-tailscale-light
href: https://login.tailscale.com
href: "{{HOMEPAGE_VAR_QBITTORRENT_HOST}}"
- "Speedtest":
- icon: sh-speedtest-light
href: "{{HOMEPAGE_VAR_MYSPEED_HOST}}"
- "Scrutiny":
- icon: sh-scrutiny-light
href: http://shaan-server:54321
href: "{{HOMEPAGE_VAR_SCRUTINY_HOST}}"
- "Router Gateway":
- icon: "http://192.168.50.1/images/favicon.png"
href: http://192.168.50.1
- "Tailscale":
- icon: sh-tailscale-light
href: https://login.tailscale.com
- "Portainer":
- icon: sh-portainer-light
href: "{{HOMEPAGE_VAR_PORTAINER_HOST}}"
- "Pi-Hole":
- icon: sh-pi-hole
href: "{{HOMEPAGE_VAR_PIHOLE_HOST}}/admin"
- "Cloudflare":
- icon: sh-cloudflare
href: https://dash.cloudflare.com
- Monitorix:
- icon: "{{HOMEPAGE_VAR_WEB_PROTOCOL}}://{{HOMEPAGE_VAR_LOCAL_IPV4}}:4000/monitorix/monitorixico.png"
href: http://{{HOMEPAGE_VAR_SERVER_NAME}}:4000/monitorix
- Bookmarks:
- "Youtube":
@@ -74,7 +79,4 @@
# href: "{{HOMEPAGE_VAR_TERMIX_HOST}}"
# description: Terminal emulator in your web browser
#
# - Monitorix:
# - icon: "{{HOMEPAGE_VAR_WEB_PROTOCOL}}://{{HOMEPAGE_VAR_LOCAL_IPV4}}:4000/monitorix/monitorixico.png"
# href: http://{{HOMEPAGE_VAR_SERVER_NAME}}:4000/monitorix
# description: Generate and review system reports
#
+34 -74
View File
@@ -7,13 +7,13 @@
icon: sh-cloudflare
href: "https://dash.cloudflare.com/"
server: my-docker
container: cloudflared-tunnel
container: cloudflared
description:
widget:
type: cloudflared
accountid: 252f471fd316e89626f13c25c6012bc7 # from zero trust dashboard url e.g. https://one.dash.cloudflare.com/<accountid>/home/quick-start
tunnelid: 5aa02e6a-4166-4a2d-95c9-0af0f7237b23 # found in tunnels dashboard under the tunnel name
key: cfut_2i9bGXfbFuu0XkDEcCClXvVu0x1wYuwn7sTztLLGd5469df7
accountid: "{{HOMEPAGE_VAR_CLOUDFLARED_ACCOUNT_ID}}"
tunnelid: "{{HOMEPAGE_VAR_CLOUDFLARED_TUNNEL_ID}}"
key: "{{HOMEPAGE_VAR_CLOUDFLARED_API_KEY}}"
- "VPN Address >":
icon: sh-gluetun
href: "{{HOMEPAGE_VAR_QBITTORRENT_HOST}}"
@@ -39,38 +39,23 @@
icon: sh-speedtest-light
href: "{{HOMEPAGE_VAR_MYSPEED_HOST}}"
server: my-docker
container: MySpeed
container: myspeed
widget:
type: myspeed
url: "{{HOMEPAGE_VAR_MYSPEED_ADDRESS}}"
fields: [download, upload]
- "Media":
- "Media_1":
- "llama.cpp (shaan-pc)":
icon: sh-llama-cpp
href: "http://192.168.50.6:5078"
#siteMonitor: http://192.168.50.6:5078/v1/health
description: 32GB VRAM + 64GB RAM
- "Odysseus":
icon: sh-ollama
icon: "{{HOMEPAGE_VAR_ODYSSEUS_HOST}}/static/icons/icon-192.png"
href: "{{HOMEPAGE_VAR_ODYSSEUS_HOST}}"
siteMonitor: "{{HOMEPAGE_VAR_ODYSSEUS_HOST}}"
description: Local AI Models
- "Github":
icon: sh-github-light
href: https://github.com/dhaan7/torrent-stack
description: Repository
- "Port Updater":
icon: sh-docker
description: Shell
server: my-docker
container: port-updater
- "Termix":
icon: "{{HOMEPAGE_VAR_TERMIX_ADDRESS}}/favicon.ico"
href: "{{HOMEPAGE_VAR_TERMIX_HOST}}"
description: Terminal
server: my-docker
container: termix
- "Monitorix":
icon: "{{HOMEPAGE_VAR_WEB_PROTOCOL}}://{{HOMEPAGE_VAR_LOCAL_IPV4}}:4000/monitorix/monitorixico.png"
href: http://{{HOMEPAGE_VAR_SERVER_NAME}}:4000/monitorix
@@ -200,11 +185,15 @@
- level: warn
when: gt
value: 0
- "Media_Bottom":
- "Tdarr Node (Intel Arc Pro B70)":
icon: sh-tdarr
server: my-docker
container: tdarr-node
- "Tdarr Node (Intel Graphics UHD 710)":
icon: sh-tdarr
server: my-docker
container: tdarr-node
- "Media_Bottom":
- "Tdarr >":
icon: sh-tdarr
href: "{{HOMEPAGE_VAR_TDARR_HOST}}"
@@ -226,11 +215,7 @@
- level: danger
when: gt
value: 0
# - "Media_Tdarr_Nodes":
# - "Intel UHD 710":
# icon: sh-tdarr
# server: my-docker
# container: tdarr-node
- "Network":
- "Network_1":
- "Portainer":
@@ -243,7 +228,7 @@
type: portainer
url: https://shaan-server:9443
env: 3
key: ptr_dR3wQa568otBJzfZz5FET+IQKXee7K6O+VO301iY6x4=
key: "{{HOMEPAGE_VAR_PORTAINER_KEY}}"
- "Pi-Hole Adblocker":
icon: sh-pi-hole
href: "http://192.168.50.2:6060/admin/login"
@@ -254,7 +239,27 @@
type: pihole
url: http://shaan-server:6060
version: 6 # required if running v6 or higher, defaults to 5
key: password # optional, in v6 can be your password or app password
key: "{{HOMEPAGE_VAR_PIHOLE_PASSWORD}}"
- "Network_2":
- "Scrutiny":
icon: sh-scrutiny
href: http://192.168.50.2:4545 #"{{HOMEPAGE_VAR_SCRUTINY_ADDRESS}}""
description: S.M.A.R.T.
server: my-docker
container: scrutiny
widget:
type: scrutiny
url: http://192.168.50.2:4545 #"{{HOMEPAGE_VAR_SCRUTINY_ADDRESS}}"
- "Karakeep":
icon: sh-karakeep-light
href: http://192.168.50.2:4545 #"{{HOMEPAGE_VAR_SCRUTINY_ADDRESS}}""
description: Bookmarks
server: my-docker
container: karakeep
widget:
type: karakeep
url: http://shaan-server:4621
key: ak2_bfee1806ec533a9557bd_940feeb8fbe798d465ab6f90a3562c43
- "Network_qbit":
- "Prowlarr >":
icon: sh-prowlarr
@@ -406,58 +411,13 @@
format: bytes
scale: 0.862
highlight:
#"T. Down":
# numeric:
# - level: good
# when: gt
# value: 0
"Down":
numeric:
- level: good
when: gt
value: 0
#"T. Up":
# numeric:
# - level: good
# when: gt
# value: 0
"Up":
numeric:
- level: good
when: gt
value: 0
# - "Minecraft":
# icon: sh-minecraft-creeper
# description: Game Server Instance
# server: my-docker
# container: mc
# #siteMonitor: "udp://localhost:25575"
# widget:
# type: minecraft
# url: http://localhost:25565
# highlight:
# status:
# valueOnly: true
# string:
# - level: good
# when: equals
# value: "connected"
# - level: warn
# when: equals
# value: "connected"
# negate: true
# players:
# numeric:
# - level: warn
# when: lte
# value: 0
- "Network_2":
- "Scrutiny":
icon: sh-scrutiny
href: http://192.168.50.2:4545 #"{{HOMEPAGE_VAR_SCRUTINY_ADDRESS}}""
description: S.M.A.R.T.
server: my-docker
container: scrutiny
widget:
type: scrutiny
url: http://192.168.50.2:4545 #"{{HOMEPAGE_VAR_SCRUTINY_ADDRESS}}"
+14 -7
View File
@@ -40,13 +40,26 @@ headerStyle: boxed #underlined
useEqualHeights: true
layout:
"Apps":
"User":
tab: Apps
iconsOnly: false
header: true
disableCollapse: true
style: row
columns: 3
"Admin":
tab: Apps
iconsOnly: false
header: true
disableCollapse: true
style: row
columns: 3
"Bookmarks":
tab: Apps
header: true
initiallyCollapsed: true
style: row
columns: 3
"Top":
tab: Detailed
header: false
@@ -92,9 +105,3 @@ layout:
header: false
style: row
columns: 2
"Bookmarks":
tab: Apps
header: true
initiallyCollapsed: true
style: row
columns: 3
+32 -19
View File
@@ -20,26 +20,39 @@
longitude: -121.49
units: imperial # Uses Fahrenheit and mph for Roseville
- glances:
url: http://host.docker.internal:61208
href: "{{HOMEPAGE_VAR_GLANCES_HOST}}"
username: user # optional if auth enabled in Glances
password: pass # optional if auth enabled in Glances
version: 4 # required only if running glances v4 or higher, defaults to 3
cpu: true # optional, enabled by default, disable by setting to false
cputemp: false # disabled by default
mem: true # optional, enabled by default, disable by setting to false
cpuSensorLabel: Package id # optional additional cputemp sensor label prefix
unit: imperial # optional for temp, default is metric
uptime: true # disabled by default
disk: # disabled by default, use mount point of disk(s) in glances. Can also be a list (see below)
- /
- "/host{{HOMEPAGE_VAR_DISK1}}"
- "/host{{HOMEPAGE_VAR_DISK2}}"
- "/host{{HOMEPAGE_VAR_DISK3}}"
- resources:
cpu: true
memory: true
#disk: {{HOMEPAGE_VAR_DISK1}}
cputemp: true
tempmin: 0 # optional, minimum cpu temp
tempmax: 100 # optional, maximum cpu temp
uptime: true
units: metric # only used by cpu temp, options: 'imperial' or 'metric'
refresh: 2000 # optional, in ms
diskUnits: bytes # optional, bytes (default) or bbytes. Only applies to disk
expanded: true # show the expanded view
#label: MyMachine # optional
network: false # optional, uses 'default' if true or specify a network interface name
# - glances:
# url: http://host.docker.internal:61208
# href: "{{HOMEPAGE_VAR_GLANCES_HOST}}"
# username: "{{HOMEPAGE_VAR_GLANCES_USERNAME}}"
# password: "{{HOMEPAGE_VAR_GLANCES_PASSWORD}}"
# version: 4 # required only if running glances v4 or higher, defaults to 3
# cpu: true # optional, enabled by default, disable by setting to false
# cputemp: false # disabled by default
# mem: true # optional, enabled by default, disable by setting to false
# cpuSensorLabel: Package id # optional additional cputemp sensor label prefix
# unit: imperial # optional for temp, default is metric
# uptime: true # disabled by default
# disk: # disabled by default, use mount point of disk(s) in glances. Can also be a list (see below)
# - /
# - "/host{{HOMEPAGE_VAR_DISK1}}"
# - "/host{{HOMEPAGE_VAR_DISK2}}"
# - "/host{{HOMEPAGE_VAR_DISK3}}"
# diskUnits: bytes # optional, bytes (default) or bbytes. Only applies to disk
# expanded: true # show the expanded view
# #label: MyMachine # optional
- search:
provider: google
-4
View File
@@ -1,4 +0,0 @@
#!/bin/bash
set -e
psql -v ON_ERROR_STOP=1 -U postgres -f init-database.sql
-38
View File
@@ -1,38 +0,0 @@
-- Create a temp table
CREATE TABLE torrent_tmp (
infohash text NOT NULL,
name text NOT NULL,
size_bytes bigint NOT NULL,
created_unix bigint NOT NULL,
seeders integer NOT NULL,
leechers integer NOT NULL,
completed integer NOT NULL,
scraped_date bigint NOT NULL,
published bigint NOT NULL
);
-- Copy from csv
COPY torrent_tmp
FROM
'../torrents.csv' WITH (
FORMAT csv,
HEADER);
-- default sort by seeders
CREATE TABLE torrent AS
SELECT
*
FROM
torrent_tmp
ORDER BY
seeders DESC;
-- Add the identity column
ALTER TABLE torrent
ADD COLUMN id int GENERATED ALWAYS AS IDENTITY,
ADD COLUMN name_search tsvector GENERATED ALWAYS AS (to_tsvector('english', name)) STORED;
CREATE INDEX idx_name ON torrent USING gin (name_search);
DROP TABLE torrent_tmp;
View File
Submodule torrents-csv-data deleted from a48af42e1f
-1
View File
@@ -1 +0,0 @@
torrents-csv-data/torrents.csv
1 torrents-csv-data/torrents.csv