forked from coop-cloud/mediawiki
36feb5062d
Main issue is how to customise the virtual host configuration of the Mediawiki container to pass /simplesamlphp/ through to the right directory (or reverse proxy to the `simplesamlphp` container)
126 lines
3.9 KiB
YAML
126 lines
3.9 KiB
YAML
---
|
|
version: '3.8'
|
|
|
|
services:
|
|
mariadb:
|
|
image: 'mariadb:10.5'
|
|
environment:
|
|
- MYSQL_USER=mediawiki
|
|
- MYSQL_ROOT_PASSWORD_FILE=/run/secrets/db_root_password
|
|
- MYSQL_PASSWORD_FILE=/run/secrets/db_password
|
|
- MYSQL_DATABASE=mediawiki
|
|
volumes:
|
|
- 'mariadb:/var/lib/mysql'
|
|
secrets:
|
|
- db_root_password
|
|
- db_password
|
|
networks:
|
|
- internal
|
|
deploy:
|
|
restart_policy:
|
|
condition: on-failure
|
|
delay: "60s"
|
|
max_attempts: 3
|
|
window: 120s
|
|
mediawiki:
|
|
image: 'revianlabs/mediawiki-ve-bundle'
|
|
environment:
|
|
- DOMAIN=${DOMAIN}
|
|
- STACK_NAME=${STACK_NAME}
|
|
- MEDIAWIKI_EMAIL_CONTACT=${MEDIAWIKI_EMAIL_CONTACT}
|
|
- MEDIAWIKI_EMAIL_FROM=${MEDIAWIKI_EMAIL_FROM}
|
|
- MEDIAWIKI_SITENAME=${MEDIAWIKI_SITENAME}
|
|
- MEDIAWIKI_SITENAMESPACE=${MEDIAWIKI_SITENAMESPACE}
|
|
volumes:
|
|
- 'mediawiki_images:/var/www/html/images'
|
|
- 'parsoid:/usr/lib/parsoid'
|
|
- 'simplesaml:/var/www/html/simplesamlphp'
|
|
configs:
|
|
- source: LocalSettings_conf
|
|
target: /var/www/html/LocalSettings.php
|
|
- source: htaccess_conf
|
|
target: /var/www/html/.htaccess
|
|
- source: entrypoint2_conf
|
|
target: /docker-entrypoint2.sh
|
|
mode: 0555
|
|
depends_on:
|
|
- mariadb
|
|
secrets:
|
|
- db_password
|
|
- mediawiki_secret_key
|
|
networks:
|
|
- proxy
|
|
- internal
|
|
deploy:
|
|
update_config:
|
|
failure_action: rollback
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=80"
|
|
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`)"
|
|
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
|
|
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
|
entrypoint: /docker-entrypoint2.sh
|
|
simplesamlphp:
|
|
image: venatorfox/simplesamlphp:latest
|
|
environment:
|
|
- CONFIG_BASEURLPATH=${DOMAIN}/simplesamlphp
|
|
- CONFIG_AUTHADMINPASSWORD={SSHA256}MjJSiMlkQLa+fqI+CmQ1x1oUJ7OGucYpznKxBBHpgfC+Oh+7B9vgGw==
|
|
- CONFIG_SECRETSALT=exampleabcdefghijklmnopqrstuvwxy
|
|
- CONFIG_TECHNICALCONTACT_NAME=Adam W Zheng
|
|
- CONFIG_TECHNICALCONTACT_EMAIL=helo@autonomic.zone
|
|
- CONFIG_SHOWERRORS=true
|
|
- CONFIG_ERRORREPORTING=true
|
|
- CONFIG_ADMINPROTECTINDEXPAGE=true
|
|
- CONFIG_LOGGINGLEVEL=INFO
|
|
- CONFIG_ENABLESAML20IDP=true
|
|
#- CONFIG_STORETYPE=memcache
|
|
#- CONFIG_MEMCACHESTOREPREFIX=simplesamlphp
|
|
#- CONFIG_MEMCACHESTORESERVERS= 'memcache_store.servers' => [\n [\n ['hostname' => 'some-memcacheda01'],\n ['hostname' => 'some-memcacheda02'],\n ],\n [\n ['hostname' => 'some-memcachedb01'],\n ['hostname' => 'some-memcachedb02'],\n ],
|
|
- OPENLDAP_TLS_REQCERT=allow
|
|
- MTA_NULLCLIENT=false
|
|
- POSTFIX_MYHOSTNAME=${DOMAIN}
|
|
- POSTFIX_MYORIGIN=$$mydomain
|
|
- POSTFIX_INETINTERFACES=loopback-only
|
|
- DOCKER_REDIRECTLOGS=true
|
|
volumes:
|
|
- simplesaml:/var/simplesamlphp/
|
|
networks:
|
|
- internal
|
|
|
|
volumes:
|
|
mariadb:
|
|
mediawiki_images:
|
|
parsoid:
|
|
simplesaml:
|
|
|
|
networks:
|
|
proxy:
|
|
external: true
|
|
internal:
|
|
|
|
secrets:
|
|
db_root_password:
|
|
name: ${STACK_NAME}_db_root_password_${DB_ROOT_PASSWORD_VERSION}
|
|
external: true
|
|
db_password:
|
|
name: ${STACK_NAME}_db_password_${DB_PASSWORD_VERSION}
|
|
external: true
|
|
mediawiki_secret_key:
|
|
name: ${STACK_NAME}_mediawiki_secret_key_${MEDIAWIKI_SECRET_KEY_VERSION}
|
|
external: true
|
|
|
|
configs:
|
|
LocalSettings_conf:
|
|
name: ${STACK_NAME}_local_settings_${LOCAL_SETTINGS_CONF_VERSION}
|
|
file: LocalSettings.php.tmpl
|
|
template_driver: golang
|
|
htaccess_conf:
|
|
name: ${STACK_NAME}_htaccess_${HTACCESS_CONF_VERSION}
|
|
file: htaccess.tmpl
|
|
template_driver: golang
|
|
entrypoint2_conf:
|
|
name: ${STACK_NAME}_entrypoint2_${ENTRYPOINT_CONF_VERSION}
|
|
file: entrypoint.sh.tmpl
|
|
template_driver: golang
|