Files
ngit-grasp/compose.yaml
T
DanConwayDev 37d81f3713 feat(deploy): add portable container contract
Production deployment previously depended on an illustrative Docker snippet and did not define which state or identity must survive replacement.

Add a non-root runtime image, loopback-only Compose service, optional Caddy TLS overlay, shared /data layout, bounded public verifier, and an identity-persistence container test. Document backup, proxy, single-writer, upgrade, and rollback requirements as the contract for every environment.

This assumes one ngit-grasp writer per state directory and a reverse proxy or platform edge for public TLS. Image publication and provider-specific control-plane setup are deliberately left to separate changes.

Validated with sh -n, ShellCheck 0.11.0, locked Cargo metadata, YAML parsing, Docker Hub tag lookups, local input-failure checks, and git diff --check. Docker/Podman is unavailable in this VM, so the included end-to-end container test was not run here.
2026-08-20 19:38:04 +00:00

47 lines
1.2 KiB
YAML

name: ngit-grasp
services:
ngit-grasp:
build:
context: .
args:
NGIT_BUILD_REVISION: "${NGIT_BUILD_REVISION:-unknown}"
NGIT_IMAGE_REVISION: "${NGIT_IMAGE_REVISION:-unknown}"
NGIT_IMAGE_VERSION: "${NGIT_IMAGE_VERSION:-dev}"
image: "${NGIT_IMAGE:-ngit-grasp:local}"
restart: unless-stopped
env_file:
- path: ./.env
required: false
environment:
NGIT_DOMAIN: "${NGIT_DOMAIN:?copy deploy.env.example to .env and set NGIT_DOMAIN}"
NGIT_BASE_PATH: "${NGIT_BASE_PATH:-/}"
NGIT_LOG_LEVEL: "${NGIT_LOG_LEVEL:-info}"
ports:
- "127.0.0.1:${NGIT_HOST_PORT:-7334}:7334"
volumes:
- ngit-grasp-data:/data
networks:
- backend
stop_grace_period: 5m
healthcheck:
test:
- CMD-SHELL
- >-
curl --fail --silent --show-error
--header 'Accept: application/nostr+json'
"http://127.0.0.1:7334$${NGIT_BASE_PATH:-/}" >/dev/null
interval: 30s
timeout: 5s
retries: 10
start_period: 30s
volumes:
ngit-grasp-data:
networks:
backend:
ipam:
config:
- subnet: "${NGIT_COMPOSE_SUBNET:-172.30.73.0/24}"