Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
95 lines (91 loc) · 4.37 KB
/
Copy pathdocker-compose.yml
File metadata and controls
95 lines (91 loc) · 4.37 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
name: openflows
services:
redis:
image: redis:7-alpine
ports:
- "6379:6379"
volumes:
- redis_data:/data
command: redis-server --appendonly yes
restart: unless-stopped
coder-db:
image: postgres:16-alpine
environment:
POSTGRES_USER: coder
POSTGRES_PASSWORD: ${CODER_PG_PASSWORD:-coder}
POSTGRES_DB: coder
volumes:
- coder_db_data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U coder"]
interval: 5s
timeout: 3s
retries: 10
restart: unless-stopped
coder:
image: ghcr.io/coder/coder:${CODER_IMAGE_TAG:-v2.37.3}
user: "0:0"
ports:
- "${CODER_PORT:-7080}:${CODER_INTERNAL_PORT:-7080}"
environment:
CODER_PG_CONNECTION_URL: postgres://coder:${CODER_PG_PASSWORD:-coder}@coder-db:5432/coder?sslmode=disable
CODER_ACCESS_URL: ${CODER_ACCESS_URL:-http://localhost:${CODER_PORT:-7080}}
CODER_HTTP_ADDRESS: "0.0.0.0:${CODER_INTERNAL_PORT:-7080}"
CODER_PROVISIONER_DAEMONS: "1"
CODER_PROVISIONER_DAEMON_TYPE: "docker"
# Shared Terraform provider cache so workspace builds reuse downloaded
# providers instead of re-fetching them from GitHub on every build (which
# intermittently 504s). Persisted on the tf_plugin_cache volume.
TF_PLUGIN_CACHE_DIR: /root/.terraform.d/plugin-cache
DOCKER_HOST: unix:///var/run/docker.sock
REDIS_URL: ${REDIS_URL:-redis://redis:6379}
CODER_URL: ${CODER_URL:-http://localhost:${CODER_PORT:-7080}}
CODER_OAUTH2_GITHUB_ALLOW_SIGNUPS: ${CODER_OAUTH2_GITHUB_ALLOW_SIGNUPS:-true}
# GitHub external auth (Git App) — lets agents push/pull against PRIVATE
# repos via OIDC. Values come from .env (see quick_start.md Step 2).
# IMPORTANT: `coder server` fails to start if client_id/client_secret are
# EMPTY, so these MUST be populated in .env BEFORE `docker compose up -d`.
# A fresh setup is covered by `.env.example` (which ships these populated
# with placeholders) + quick_start Step 2. If your existing `.env` predates
# this block, add the CODER_EXTERNAL_AUTH_0_* vars (or start from
# `.env.example`) or Coder will not come up.
# Callback URL: ${CODER_ACCESS_URL}/external-auth/primary-github/callback
CODER_EXTERNAL_AUTH_0_ID: ${CODER_EXTERNAL_AUTH_0_ID:-primary-github}
CODER_EXTERNAL_AUTH_0_TYPE: ${CODER_EXTERNAL_AUTH_0_TYPE:-github}
CODER_EXTERNAL_AUTH_0_CLIENT_ID: ${CODER_EXTERNAL_AUTH_0_CLIENT_ID:-}
CODER_EXTERNAL_AUTH_0_CLIENT_SECRET: ${CODER_EXTERNAL_AUTH_0_CLIENT_SECRET:-}
CODER_EXTERNAL_AUTH_0_SCOPES: ${CODER_EXTERNAL_AUTH_0_SCOPES:-repo}
CODER_EXTERNAL_AUTH_0_APP_INSTALL_URL: ${CODER_EXTERNAL_AUTH_0_APP_INSTALL_URL:-}
# Agent lifecycle hooks are wired by OpenFlows. Operators do not need to
# configure Coder's raw hook URL/experiment flags for the bundled stack.
# OPENFLOWS_HOOK_URL is the single source of truth for the hook endpoint:
# it is forwarded to Coder (here) and to the Nexus consumer via bootstrap,
# so Coder's CODER_CHAT_HOOK_URL and the consumer's expected JWT `aud`
# stay in lockstep (prevents hook JWT InvalidAudience failures).
CODER_EXPERIMENTS: ${CODER_EXPERIMENTS:-agent-lifecycle-hooks}
CODER_CHAT_HOOK_URL: ${OPENFLOWS_HOOK_URL:-http://openflows-nexus:3001/experimental/hooks/chat}
CODER_CHAT_HOOK_SECRET: ${CODER_CHAT_HOOK_SECRET:?Set CODER_CHAT_HOOK_SECRET to 32+ random bytes before enabling lifecycle hooks}
# Dev-only: allow the plain-http hook URL above.
CODER_CHAT_HOOK_ALLOW_INSECURE: ${CODER_CHAT_HOOK_ALLOW_INSECURE:-true}
extra_hosts:
# Keep host-gateway available for local integrations that need the host.
- "host.docker.internal:host-gateway"
volumes:
- /var/run/docker.sock:/var/run/docker.sock
# TEMPORARY: Mount local openflows binary for testing (remove when using GitHub releases)
- ./.dev-binaries:/opt/openflows-dev:ro
# Persist the Terraform provider cache across restarts.
- tf_plugin_cache:/root/.terraform.d/plugin-cache
depends_on:
coder-db:
condition: service_healthy
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:${CODER_INTERNAL_PORT:-7080}/api/v2/buildinfo"]
interval: 5s
timeout: 3s
retries: 15
restart: unless-stopped
volumes:
redis_data:
coder_db_data:
tf_plugin_cache: