# ============================================================================= # Torrent Stack (infra) - DNS, management & monitoring # # Split from compose.yml on 2026-09-11 - verbatim service blocks. # Shared top-level networks:/volumes: are repeated in each subfile so it also # works standalone (docker compose -f infra.yml up -d). Identical copies merge # cleanly under compose.yml's `include:` with no change to the live config. # Keep ./ paths, container names and /mnt data as-is. # ============================================================================= networks: tdarr-net: driver: bridge default: name: portainer_network volumes: portainer_data: name: portainer_data services: # --------------------------------------------------------------------------- # Monitoring # --------------------------------------------------------------------------- # glances: # image: ${GLANCES_IMAGE} # container_name: glances # network_mode: host # volumes: # - /etc/os-release:/etc/os-release:ro # - /:/host:ro # #- /etc/localtime:/etc/localtime:ro # #- /etc/timezone:/etc/timezone:ro # environment: # - "GLANCES_OPT=-w --password ${GLANCES_PASSWORD}" # - PUID=${HOST_PUID:-1000} # - PGID=${HOST_PGID:-1000} # - TZ=${TIMEZONE} # healthcheck: # test: # ["CMD", "curl", "-f", "http://localhost:${GLANCES_PORT}/api/4/status"] # interval: 1m # timeout: 10s # retries: 3 # start_period: 60s # security_opt: # - no-new-privileges:true # mem_limit: 256m # cpus: 1.0 # devices: # - /dev/dri:/dev/dri # restart: unless-stopped # # Uncomment to protect Glances WebUI by a login/password (add --password to GLANCES_OPT) # secrets: # - source: glances_password # target: /root/.config/glances/.pwd # secrets: # glances_password: # file: ./secrets/glances_password autoheal: image: ${AUTOHEAL_IMAGE} container_name: autoheal volumes: - /var/run/docker.sock:/var/run/docker.sock environment: - AUTOHEAL_CONTAINER_LABEL=all - AUTOHEAL_INTERVAL=30 - AUTOHEAL_START_PERIOD=60 - TZ=${TIMEZONE} security_opt: - no-new-privileges:true read_only: true mem_limit: 64m cpus: 0.25 restart: unless-stopped scrutiny: image: ${SCRUTINY_IMAGE} container_name: scrutiny cap_add: - SYS_RAWIO ports: - ${SCRUTINY_PORT}:8080 - ${SCRUTINY_ADMIN_PORT}:8086 volumes: - /run/udev:/run/udev:ro - ./scrutiny/config:/opt/scrutiny/config - ./scrutiny/influxdb:/opt/scrutiny/influxdb environment: - TZ=${TIMEZONE} security_opt: - no-new-privileges:true mem_limit: 128m cpus: 0.25 devices: - /dev/nvme0n1 - /dev/sda restart: unless-stopped # --------------------------------------------------------------------------- # Infrastructure # --------------------------------------------------------------------------- pihole: image: ${PIHOLE_IMAGE} container_name: pihole cap_add: - NET_ADMIN # Allows managing network interfaces & sockets - NET_BIND_SERVICE # Allows non-root users to bind to ports < 1024 (port 53 & 123) - SYS_TIME # Resolves the NTP system time warning network_mode: host volumes: - ./etc-pihole:/etc/pihole - ./etc-dnsmasq.d:/etc/dnsmasq.d environment: - TZ=${TIMEZONE} - FTLCONF_misc_etc_dnsmasq_d=true - FTLCONF_webserver_port=${PIHOLE_PORT:-80} mem_limit: 256m cpus: 1.0 restart: unless-stopped portainer: image: ${PORTAINER_IMAGE} container_name: portainer ports: - ${PORTAINER_PORT}:${PORTAINER_PORT} volumes: - /var/run/docker.sock:/var/run/docker.sock - portainer_data:/data environment: - TZ=${TIMEZONE} security_opt: - no-new-privileges:true mem_limit: 256m cpus: 1.0 restart: unless-stopped