109 lines
2.9 KiB
YAML
109 lines
2.9 KiB
YAML
---
|
|
version: "3.8"
|
|
|
|
services:
|
|
app:
|
|
image: nginx:1.20.0-alpine
|
|
networks:
|
|
- proxy
|
|
- internal
|
|
environment:
|
|
- DOMAIN
|
|
- STACK_NAME
|
|
configs:
|
|
- source: nginx_config
|
|
target: /etc/nginx/nginx.conf
|
|
- source: htpasswd_conf
|
|
target: /etc/nginx/conf.d/.htpasswd
|
|
secrets:
|
|
- nginx_htpasswd
|
|
deploy:
|
|
restart_policy:
|
|
condition: on-failure
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.services.${STACK_NAME}-web.loadbalancer.server.port=80"
|
|
- "traefik.http.routers.${STACK_NAME}-web.rule=Host(`${DOMAIN}`)"
|
|
- "traefik.http.routers.${STACK_NAME}-web.entrypoints=web-secure"
|
|
- "traefik.http.routers.${STACK_NAME}-web.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
|
|
|
node_exporter:
|
|
image: prom/node-exporter:v1.0.1
|
|
user: root
|
|
environment:
|
|
- NODE_ID={{.Node.ID}}
|
|
volumes:
|
|
- /proc:/host/proc:ro
|
|
- /sys:/host/sys:ro
|
|
- /:/rootfs:ro
|
|
- /etc/hostname:/etc/nodename:ro
|
|
command:
|
|
- "--path.sysfs=/host/sys"
|
|
- "--path.procfs=/host/proc"
|
|
- "--path.rootfs=/rootfs"
|
|
- "--collector.textfile.directory=/etc/node-exporter/"
|
|
- "--collector.filesystem.ignored-mount-points=^/(sys|proc|dev|host|etc)($$|/)"
|
|
- "--no-collector.ipvs"
|
|
configs:
|
|
- source: node_exporter_entrypoint_sh
|
|
target: /entrypoint.sh
|
|
networks:
|
|
- internal
|
|
entrypoint: ["/bin/sh", "-e", "/entrypoint.sh"]
|
|
|
|
cadvisor:
|
|
image: google/cadvisor:v0.33.0
|
|
command: -logtostderr -docker_only
|
|
volumes:
|
|
- /var/lib/docker/:/var/lib/docker:ro
|
|
- /dev/disk/:/dev/disk:ro
|
|
- /sys:/sys:ro
|
|
- /var/run:/var/run:ro
|
|
- /:/rootfs:ro
|
|
networks:
|
|
- internal
|
|
|
|
promtail:
|
|
image: grafana/promtail:2.0.0
|
|
volumes:
|
|
- /var/log:/var/log:ro
|
|
- /var/lib/docker/containers:/var/lib/docker/containers:ro
|
|
command: -config.file=/etc/promtail/config.yml
|
|
configs:
|
|
- source: promtail_yml
|
|
target: /etc/promtail/config.yml
|
|
networks:
|
|
- internal
|
|
secrets:
|
|
- loki_admin_password
|
|
|
|
configs:
|
|
promtail_yml:
|
|
name: ${STACK_NAME}_promtail_yml_${PROMTAIL_YML_VERSION}
|
|
file: promtail.yml.tmpl
|
|
template_driver: golang
|
|
node_exporter_entrypoint_sh:
|
|
name: ${STACK_NAME}_node_exporter_entrypoint_${NODE_EXPORTER_ENTRYPOINT_VERSION}
|
|
file: node-exporter-entrypoint.sh
|
|
nginx_config:
|
|
template_driver: golang
|
|
name: ${STACK_NAME}_nginx_config_${NGINX_CONFIG_VERSION}
|
|
file: nginx.conf.tmpl
|
|
htpasswd_conf:
|
|
template_driver: golang
|
|
name: ${STACK_NAME}_htpasswd_${HTPASSWD_CONFIG_VERSION}
|
|
file: htpasswd.tmpl
|
|
|
|
networks:
|
|
internal:
|
|
proxy:
|
|
external: true
|
|
|
|
secrets:
|
|
nginx_htpasswd:
|
|
external: true
|
|
name: ${STACK_NAME}_nginx_htpasswd_${SECRET_NGINX_HTPASSWD_VERSION}
|
|
loki_admin_password:
|
|
external: true
|
|
name: ${STACK_NAME}_loki_admin_password_${SECRET_LOKI_ADMIN_PASSWORD_VERSION}
|