services: db: image: postgres:16-alpine restart: unless-stopped env_file: .env environment: POSTGRES_USER: ${POSTGRES_USER} POSTGRES_PASSWORD: ${POSTGRES_PASSWORD} POSTGRES_DB: ${POSTGRES_DB} volumes: - postgres_data:/var/lib/postgresql/data healthcheck: test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER} -d ${POSTGRES_DB}"] interval: 5s timeout: 5s retries: 10 deploy: resources: limits: memory: 512M app: build: context: ./backend dockerfile: Dockerfile restart: unless-stopped env_file: .env environment: # Activates the production secret guard in config.rs — refuses to boot with # placeholder JWT_SECRET / ADMIN_PASSWORD_HASH. APP_ENV: production # The media volume is mounted at /media (below), so the app MUST write there. # Pin it here rather than trusting .env: if MEDIA_PATH in .env points elsewhere # (e.g. a host path used for running the backend natively) the container can't # create it and every upload 500s with EACCES. `environment` overrides `env_file`, # so this is authoritative for the container. MEDIA_PATH: /media depends_on: db: condition: service_healthy volumes: - media_data:/media # Export archives live OUTSIDE /media so the public media ServeDir can't # serve them — downloads go only through the ticket-gated handler. - exports_data:/exports expose: - "3000" healthcheck: # Use 127.0.0.1, NOT localhost: the app binds IPv4 (0.0.0.0) but `localhost` # resolves to ::1 (IPv6) first inside the container, so a localhost probe gets # "connection refused" and the container never turns healthy — which would leave # Caddy (gated on `condition: service_healthy` below) blocked forever on boot. test: ["CMD-SHELL", "wget -q -O- http://127.0.0.1:3000/health || exit 1"] interval: 10s timeout: 5s retries: 5 start_period: 20s deploy: resources: limits: # Bounds a runaway ffmpeg transcode (large uploads, 2 workers) so it can't # OOM the single box and take down Postgres. memory: 1G frontend: build: context: ./frontend dockerfile: Dockerfile restart: unless-stopped env_file: .env environment: # adapter-node behind Caddy TLS needs the public origin for CSRF checks on # POST form actions — without it they fail only in production. ORIGIN: "https://${DOMAIN}" depends_on: - app expose: - "3001" healthcheck: # 127.0.0.1, not localhost — see the app healthcheck note above (IPv4 bind vs # ::1 resolution would leave this container permanently unhealthy). test: ["CMD-SHELL", "wget -q -O- http://127.0.0.1:3001/ >/dev/null 2>&1 || exit 1"] interval: 10s timeout: 5s retries: 5 start_period: 15s deploy: resources: limits: memory: 256M caddy: image: caddy:2-alpine restart: unless-stopped environment: # The Caddyfile's site address is `{$DOMAIN}`, read from THIS container's env. # Without it, `{$DOMAIN}` expands to empty, the site block collapses, and Caddy # serves nothing / fails to obtain a TLS cert. `env_file` alone wouldn't help — # Caddy needs it in `environment`, and this keeps the Caddyfile the single source. DOMAIN: ${DOMAIN} ports: - "80:80" - "443:443" volumes: - ./Caddyfile:/etc/caddy/Caddyfile:ro - caddy_data:/data depends_on: app: condition: service_healthy frontend: condition: service_healthy deploy: resources: limits: memory: 256M volumes: postgres_data: media_data: exports_data: caddy_data: