diff --git a/.docker/pdns-auth/pdns.conf b/.docker/pdns-auth/pdns.conf new file mode 100644 index 00000000..6bf15127 --- /dev/null +++ b/.docker/pdns-auth/pdns.conf @@ -0,0 +1,9 @@ +# Replaces the image default (gsqlite3). The API is configured by the image +# from PDNS_AUTH_API_KEY into pdns.d/_api.conf. +local-address=0.0.0.0,:: +include-dir=/etc/powerdns/pdns.d +launch=gpgsql +gpgsql-host=pdns-db +gpgsql-dbname=powerdns +gpgsql-user=powerdns +gpgsql-password=powerdns diff --git a/.docker/pdns-db/Dockerfile b/.docker/pdns-db/Dockerfile new file mode 100644 index 00000000..e828d44a --- /dev/null +++ b/.docker/pdns-db/Dockerfile @@ -0,0 +1,4 @@ +# PostgreSQL for pdns-auth, initialised with the schema shipped in the pdns image +FROM powerdns/pdns-auth-51:latest AS pdns +FROM postgres:17 +COPY --from=pdns /usr/local/share/doc/pdns/schema.pgsql.sql /docker-entrypoint-initdb.d/ diff --git a/docker-compose.yml b/docker-compose.yml index ebdadb67..bf181f6f 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -11,6 +11,9 @@ services: ports: - "127.0.0.1:5432:5432" command: "-c config_file=/etc/postgresql/postgres.conf" + healthcheck: + test: ["CMD-SHELL", "pg_isready -h 127.0.0.1 -U $$POSTGRES_USER -d $$POSTGRES_DB"] + interval: 5s web: build: .docker/web @@ -22,8 +25,47 @@ services: - "/code/.venv" ports: - "127.0.0.1:8000:8000" + healthcheck: + # -f without -L: the login redirect on / counts as healthy + test: ["CMD", "curl", "-fsS", "-o", "/dev/null", "http://127.0.0.1:8000/"] + interval: 10s depends_on: - - db + db: + condition: service_healthy + + # Optional PowerDNS for DNS integrations like serveradmin_powerdns, enable + # with COMPOSE_PROFILES=powerdns in .env. See docs/source/extending.rst. + pdns-db: + build: .docker/pdns-db + profiles: ["powerdns"] + environment: + - POSTGRES_DB=powerdns + - POSTGRES_USER=powerdns + - POSTGRES_PASSWORD=powerdns + volumes: + - pdns-data:/var/lib/postgresql/data + healthcheck: + test: ["CMD", "pg_isready", "-h", "127.0.0.1", "-U", "powerdns", "-d", "powerdns"] + interval: 2s + + pdns-auth: + image: "powerdns/pdns-auth-51:latest" + profiles: ["powerdns"] + volumes: + - ".docker/pdns-auth/pdns.conf:/etc/powerdns/pdns.conf:ro" + environment: + - PDNS_AUTH_API_KEY=0815passwd + ports: + - "127.0.0.1:1053:53" + - "127.0.0.1:1053:53/udp" + - "127.0.0.1:8081:8081" + healthcheck: + test: ["CMD", "pdns_control", "rping"] + interval: 5s + depends_on: + pdns-db: + condition: service_healthy volumes: postgres-data: + pdns-data: diff --git a/docs/source/extending.rst b/docs/source/extending.rst index e47f7d88..8b829c3e 100644 --- a/docs/source/extending.rst +++ b/docs/source/extending.rst @@ -40,6 +40,17 @@ host machines and run uv sync to have all modules available for your IDEs auto completion etc. +Optional: PowerDNS +^^^^^^^^^^^^^^^^^^ + +For DNS integrations such as ``serveradmin_powerdns`` the compose profile +``powerdns`` adds a PowerDNS Authoritative Server with its own PostgreSQL. +Enable it with ``COMPOSE_PROFILES=powerdns`` in your ``.env`` or run +``docker compose --profile powerdns up``. The HTTP API listens on +http://127.0.0.1:8081 (``http://pdns-auth:8081`` from ``web``), DNS on +``127.0.0.1:1053``. The API key is set in ``docker-compose.yml``. + + Database Dump -------------