Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
210 lines (195 loc) · 6.2 KB
/
Copy pathdocker-compose.yml
File metadata and controls
210 lines (195 loc) · 6.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
services:
# Database needed to store the test data
icat_mariadb:
restart: always
# note: the latest version does not support the SQL connector needed by icat
image: mariadb:10.10
container_name: icat_mariadb_container
# note: in the case that something else is already running on 3306 locally,
# this can be changed or removed without affecting the tests which connect
# directly to the icat_mariadb service without using port forwarding
# ports:
# - "3308:3306"
environment:
MYSQL_ROOT_PASSWORD: pw
MARIADB_DATABASE: icatdb
MARIADB_USER: icatdbuser
MARIADB_PASSWORD: icatdbuserpw
# the health check will tell us when data is in the DB
healthcheck:
test: '/usr/bin/mysql --database=$$MARIADB_DATABASE --user=$$MARIADB_USER --password=$$MARIADB_PASSWORD --execute "SHOW TABLES;"'
interval: 10s
timeout: 2s
retries: 10
networks:
- dg_network
profiles: [dependencies, tests, full]
# The ICAT server, available at https://localhost:18181/icat/version
icat_payara:
restart: always
# This image was built manually from https://github.com/icatproject-contrib/icat-cloud-native-migration/blob/main/icat/Dockerfile.
# This was necessary because the image needs anon/anon included in rootUserNames.
image: harbor.stfc.ac.uk/icat/icat_6:dg-api
container_name: icat_payara_container
depends_on:
icat_mariadb:
condition: service_healthy
auth_anon:
condition: service_started
auth_simple:
condition: service_started
ports:
- "14747:4848" # payara port
- "18181:8181" # https port
- "18080:8080" # https port
volumes:
- ./icat/post-boot-commands.asadmin:/config/post-boot-commands.asadmin
environment:
- POSTBOOT_COMMANDS=/config/post-boot-commands.asadmin
healthcheck:
test: curl --fail http://localhost:8080/icat/version || exit 1
interval: 10s
timeout: 2s
retries: 10
networks:
- dg_network
profiles: [dependencies, tests, full]
auth_simple:
restart: unless-stopped
image: harbor.stfc.ac.uk/icat/icat_auth_simple:latest
container_name: auth_simple_container
ports:
- "28181:8181"
- "24747:4848"
networks:
- dg_network
profiles: [dependencies, tests, full]
auth_anon:
restart: unless-stopped
image: harbor.stfc.ac.uk/icat/icat_auth_anon:latest
container_name: auth_anon_container
ports:
- "29181:8181"
- "25747:4848"
networks:
- dg_network
profiles: [dependencies, tests, full]
testdata:
container_name: dg_api_testdata
build:
context: .
target: test
depends_on:
icat_payara:
condition: service_healthy
volumes:
- ./util:/datagateway-api-run/util
command: uv run python -m util.icat_db_generator
restart: "no"
networks:
- dg_network
profiles: [dependencies, tests, full]
format:
container_name: dg_api_format
build:
context: .
target: test
volumes:
- ./datagateway_api:/datagateway-api-run/datagateway_api
- ./test:/datagateway-api-run/test
- ./util:/datagateway-api-run/util
command: uv run black datagateway_api test util
profiles: [format, checks]
lint:
container_name: dg_api_lint
build:
context: .
target: test
volumes:
- ./datagateway_api:/datagateway-api-run/datagateway_api
- ./test:/datagateway-api-run/test
- ./util:/datagateway-api-run/util
command: uv run flake8 datagateway_api test util
profiles: [lint, checks]
unit-tests:
container_name: dg_api_unit_tests
build:
context: .
target: test
volumes:
# use for local development
# - ./datagateway_api:/datagateway-api-run/datagateway_api
# - ./test:/datagateway-api-run/test
- ./coverage.xml:/datagateway-api-run/coverage.xml
command: uv run pytest test/unit --cov=datagateway_api --cov-report=xml
profiles: [tests]
integration-tests:
container_name: dg_api_integration-tests
build:
context: .
target: test
depends_on:
icat_payara:
condition: service_healthy
auth_simple:
condition: service_started
auth_anon:
condition: service_started
testdata:
condition: service_completed_successfully
volumes:
# use for local development
# - ./datagateway_api:/datagateway-api-run/datagateway_api
# - ./test:/datagateway-api-run/test
- ./coverage.xml:/datagateway-api-run/coverage.xml
command: uv run pytest test/integration --cov=datagateway_api --cov-report=xml
networks:
- dg_network
profiles: [tests]
# Build the api from the local docker image
# available at http://localhost:5000/docs
dg_api:
build:
context: .
target: dev
container_name: dg_api_container
depends_on:
icat_payara:
condition: service_healthy
volumes:
- ./datagateway_api:/datagateway-api-run/datagateway_api
- ./.env:/datagateway-api-run/.env
- ./logging.ini:/datagateway-api-run/logging.ini
ports:
- "5000:8000"
networks:
- dg_network
profiles: [full]
# Builds and tags the production image so the trivy service has something to scan
prod_image:
image: datagateway-api:scan
container_name: dg_api_prod_image
build:
context: .
target: prod
# the image only needs building, it is never run, so do nothing and exit
command: /bin/true
restart: "no"
profiles: [scan]
# Scans the production image with the same options as the gate in the
# Docker Image Vulnerability Scan job in .github/workflows/ci-build.yml
trivy:
image: aquasec/trivy:latest
container_name: dg_api_trivy
depends_on:
prod_image:
condition: service_completed_successfully
volumes:
# the socket gives trivy access to the image built by the prod_image service
- /var/run/docker.sock:/var/run/docker.sock
- ./.trivyignore:/.trivyignore
command: image --scanners vuln --severity HIGH,CRITICAL --ignore-unfixed --ignorefile /.trivyignore --table-mode detailed --exit-code 1 datagateway-api:scan
restart: "no"
profiles: [scan]
networks:
dg_network: