refactoring: Env-Dateien und Docker-Dateien
This commit is contained in:
+119
-58
@@ -1,87 +1,69 @@
|
||||
name: meldestelle-hardcoded
|
||||
name: ${COMPOSE_PROJECT_NAME:-meldestelle}
|
||||
|
||||
services:
|
||||
# --- DATENBANK ---
|
||||
# ==========================================
|
||||
# CORE INFRASTRUCTURE
|
||||
# ==========================================
|
||||
postgres:
|
||||
image: postgres:16-alpine
|
||||
container_name: meldestelle-postgres
|
||||
container_name: ${COMPOSE_PROJECT_NAME}-postgres
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "5432:5432"
|
||||
- "${POSTGRES_PORT}"
|
||||
environment:
|
||||
POSTGRES_USER: pg-user
|
||||
POSTGRES_PASSWORD: pg-password
|
||||
POSTGRES_DB: meldestelle
|
||||
POSTGRES_USER: ${POSTGRES_USER}
|
||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
||||
POSTGRES_DB: ${POSTGRES_DB}
|
||||
volumes:
|
||||
- postgres-data:/var/lib/postgresql/data
|
||||
# Falls du Init-Scripte hast, lassen wir die erstmal weg,
|
||||
# um Fehlerquellen zu reduzieren, oder lassen den Pfad, falls er existiert:
|
||||
- ./docker/core/postgres:/docker-entrypoint-initdb.d:Z
|
||||
healthcheck:
|
||||
test: [ "CMD-SHELL", "pg_isready -U pg-user -d meldestelle" ]
|
||||
interval: 1s
|
||||
test: [ "CMD-SHELL", "pg_isready -U ${POSTGRES_USER} -d ${POSTGRES_DB}" ]
|
||||
interval: 5s
|
||||
timeout: 5s
|
||||
retries: 3
|
||||
start_period: 30s
|
||||
retries: 5
|
||||
start_period: 10s
|
||||
networks:
|
||||
- meldestelle-network
|
||||
|
||||
# --- DATENBANK-MANAGEMENT-TOOL ---
|
||||
pgadmin:
|
||||
image: dpage/pgadmin4:8
|
||||
container_name: pgadmin4_container
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "8888:80"
|
||||
environment:
|
||||
PGADMIN_DEFAULT_EMAIL: user@domain.com
|
||||
PGADMIN_DEFAULT_PASSWORD: strong-password
|
||||
volumes:
|
||||
- pgadmin-data:/var/lib/pgadmin
|
||||
healthcheck:
|
||||
test: [ "CMD-SHELL", "wget --spider -q http://localhost:80/ || exit 1" ]
|
||||
interval: 1s
|
||||
timeout: 5s
|
||||
retries: 3
|
||||
start_period: 30s
|
||||
networks:
|
||||
- meldestelle-network
|
||||
|
||||
# --- CACHE ---
|
||||
redis:
|
||||
image: redis:7-alpine
|
||||
container_name: meldestelle-redis
|
||||
container_name: ${COMPOSE_PROJECT_NAME}-redis
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "6379:6379"
|
||||
- "${REDIS_PORT}"
|
||||
volumes:
|
||||
- redis-data:/data
|
||||
command: redis-server --appendonly yes
|
||||
healthcheck:
|
||||
test: [ "CMD", "redis-cli" ]
|
||||
interval: 1s
|
||||
interval: 5s
|
||||
timeout: 5s
|
||||
retries: 3
|
||||
networks:
|
||||
- meldestelle-network
|
||||
|
||||
# --- IDENTITY PROVIDER (Wartet auf Postgres) ---
|
||||
# ==========================================
|
||||
# SECURITY
|
||||
# ==========================================
|
||||
keycloak:
|
||||
image: quay.io/keycloak/keycloak:26.4
|
||||
container_name: meldestelle-keycloak
|
||||
container_name: ${COMPOSE_PROJECT_NAME}-keycloak
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
KC_HEALTH_ENABLED: true
|
||||
KC_METRICS_ENABLED: true
|
||||
KC_BOOTSTRAP_ADMIN_USERNAME: kc-admin
|
||||
KC_BOOTSTRAP_ADMIN_PASSWORD: kc-password
|
||||
# Admin Credentials aus .env
|
||||
KC_BOOTSTRAP_ADMIN_USERNAME: ${KC_ADMIN_USER}
|
||||
KC_BOOTSTRAP_ADMIN_PASSWORD: ${KC_ADMIN_PASSWORD}
|
||||
# DB Verbindung (Nutzt interne Docker-Namen, daher fest 'postgres')
|
||||
KC_DB: postgres
|
||||
KC_DB_URL: jdbc:postgresql://postgres:5432/meldestelle
|
||||
KC_DB_USERNAME: pg-user
|
||||
KC_DB_PASSWORD: pg-password
|
||||
KC_HOSTNAME: localhost
|
||||
KC_DB_URL: jdbc:postgresql://postgres:5432/${POSTGRES_DB}
|
||||
KC_DB_USERNAME: ${POSTGRES_USER}
|
||||
KC_DB_PASSWORD: ${POSTGRES_PASSWORD}
|
||||
KC_HOSTNAME: ${KC_HOSTNAME}
|
||||
ports:
|
||||
- "8180:8080"
|
||||
- "${KC_PORT}"
|
||||
depends_on:
|
||||
postgres:
|
||||
condition: service_healthy
|
||||
@@ -90,20 +72,36 @@ services:
|
||||
command: start-dev --import-realm
|
||||
healthcheck:
|
||||
test: [ "CMD-SHELL", "exec 3<>/dev/tcp/127.0.0.1/9000" ]
|
||||
interval: 20s
|
||||
timeout: 10s
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
start_period: 60s
|
||||
networks:
|
||||
- meldestelle-network
|
||||
|
||||
# --- MONITORING ---
|
||||
prometheus:
|
||||
image: prom/prometheus:v2.54.1
|
||||
container_name: meldestelle-prometheus
|
||||
# ==========================================
|
||||
# MONITORING & TOOLS
|
||||
# ==========================================
|
||||
pgadmin:
|
||||
image: dpage/pgadmin4:8
|
||||
container_name: ${COMPOSE_PROJECT_NAME}-pgadmin
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "9090:9090"
|
||||
- "${PGADMIN_PORT:-8888:80}"
|
||||
environment:
|
||||
PGADMIN_DEFAULT_EMAIL: ${PGADMIN_EMAIL}
|
||||
PGADMIN_DEFAULT_PASSWORD: ${PGADMIN_PASSWORD}
|
||||
volumes:
|
||||
- pgadmin-data:/var/lib/pgadmin
|
||||
networks:
|
||||
- meldestelle-network
|
||||
|
||||
prometheus:
|
||||
image: prom/prometheus:v2.54.1
|
||||
container_name: ${COMPOSE_PROJECT_NAME}-prometheus
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "${PROMETHEUS_PORT}"
|
||||
volumes:
|
||||
- prometheus-data:/prometheus
|
||||
- ./docker/monitoring/prometheus:/etc/prometheus:Z
|
||||
@@ -121,12 +119,13 @@ services:
|
||||
|
||||
grafana:
|
||||
image: grafana/grafana:11.3.0
|
||||
container_name: meldestelle-grafana
|
||||
container_name: ${COMPOSE_PROJECT_NAME}-grafana
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
GF_SECURITY_ADMIN_USER: gf-admin
|
||||
GF_SECURITY_ADMIN_PASSWORD: gf-password
|
||||
GF_SECURITY_ADMIN_USER: ${GF_ADMIN_USER}
|
||||
GF_SECURITY_ADMIN_PASSWORD: ${GF_ADMIN_PASSWORD}
|
||||
ports:
|
||||
- "3000:3000"
|
||||
- "${GF_PORT}"
|
||||
volumes:
|
||||
- grafana-data:/var/lib/grafana
|
||||
- ./docker/monitoring/grafana:/etc/grafana/provisioning:Z
|
||||
@@ -141,6 +140,68 @@ services:
|
||||
networks:
|
||||
- meldestelle-network
|
||||
|
||||
# ==========================================
|
||||
# APPLICATION GATEWAY
|
||||
# ==========================================
|
||||
|
||||
consul:
|
||||
image: hashicorp/consul:1.15
|
||||
container_name: ${COMPOSE_PROJECT_NAME}-consul
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "${CONSUL_PORT}"
|
||||
command: agent -server -bind=0.0.0.0 -client=0.0.0.0 -bootstrap-expect=1 -ui
|
||||
healthcheck:
|
||||
test: [ "CMD", "curl", "-f", "http://localhost:8500/v1/status/leader" ]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 3
|
||||
networks:
|
||||
- meldestelle-network
|
||||
|
||||
api-gateway:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: dockerfiles/infrastructure/gateway/Dockerfile
|
||||
args:
|
||||
# Build-Args aus deinen .env Dateien (werden hier statisch benötigt für den Build)
|
||||
GRADLE_VERSION: 9.1.0
|
||||
JAVA_VERSION: 21
|
||||
VERSION: 1.0.0
|
||||
BUILD_DATE: "2025-11-20"
|
||||
container_name: ${COMPOSE_PROJECT_NAME}-gateway
|
||||
restart: no
|
||||
ports:
|
||||
- "${GATEWAY_PORT}"
|
||||
- "${GATEWAY_DEBUG_PORT}" # Für Remote Debugging
|
||||
environment:
|
||||
SPRING_PROFILES_ACTIVE: docker
|
||||
DEBUG: "true"
|
||||
# --- VERBINDUNGEN ---
|
||||
# Keycloak URL (INTERN im Docker Netzwerk!)
|
||||
# Beachte: http://container-name:8080 (nicht localhost, nicht 8180)
|
||||
SPRING_SECURITY_OAUTH2_RESOURCESERVER_JWT_ISSUER_URI: http://${COMPOSE_PROJECT_NAME}-keycloak:8080/realms/meldestelle
|
||||
SPRING_CLOUD_CONSUL_HOST: consul
|
||||
SPRING_CLOUD_CONSUL_PORT: 8500
|
||||
# WICHTIG: Das Gateway muss wissen, wie es von anderen Containern erreicht wird (nicht localhost!)
|
||||
SPRING_CLOUD_CONSUL_DISCOVERY_HOSTNAME: api-gateway
|
||||
# Postgres Verbindung (für Routes/Session, falls nötig)
|
||||
SPRING_DATASOURCE_URL: jdbc:postgresql://${COMPOSE_PROJECT_NAME}-postgres:5432/${POSTGRES_DB}
|
||||
SPRING_DATASOURCE_USERNAME: ${POSTGRES_USER}
|
||||
SPRING_DATASOURCE_PASSWORD: ${POSTGRES_PASSWORD}
|
||||
# Logging
|
||||
LOGGING_LEVEL_ORG_SPRINGFRAMEWORK_CLOUD_GATEWAY: DEBUG
|
||||
LOGGING_LEVEL_ORG_SPRINGFRAMEWORK_SECURITY: DEBUG
|
||||
depends_on:
|
||||
consul:
|
||||
condition: service_healthy
|
||||
postgres:
|
||||
condition: service_healthy
|
||||
keycloak:
|
||||
condition: service_healthy
|
||||
networks:
|
||||
- meldestelle-network
|
||||
|
||||
volumes:
|
||||
postgres-data:
|
||||
pgadmin-data:
|
||||
|
||||
Reference in New Issue
Block a user