############################################################################### # Copyright (C) 2020 Simon Adlem, G7RZU # # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation; either version 3 of the License, or # (at your option) any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program; if not, write to the Free Software Foundation, # Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA ############################################################################### version: '2.4' services: freedmr: container_name: freedmr cpu_shares: 1024 mem_reservation: 600m volumes: - '/etc/freedmr/freedmr.cfg:/opt/freedmr/freedmr.cfg' - '/etc/freedmr/freedmr-bridge.cfg:/opt/freedmr/freedmr-bridge.cfg:ro' - '/etc/freedmr/rules-bridge.py:/opt/freedmr/rules.py:ro' #Write JSON files outside of container - '/etc/freedmr/json/:/opt/freedmr/json/' ports: - '62031:62031/udp' # Native Data Gateway worker ports; use other ports for external peers. - '62041-62045:62041-62045/udp' image: 'gitlab.hacknix.net:5050/hacknix/freedmr:latest' restart: "unless-stopped" networks: app_net: ipv4_address: 172.16.238.10 #Control parameters inside container environment: #IPV6 support - FDPROXY_IPV6=0 #Display connection stats in log - FDPROXY_STATS=1 #Display conneting client info in log - FDPROXY_CLIENTINFO=1 #Debug HBP session in log (lots of data!!) - FDPROXY_DEBUG=0 #Override proxy external port #- FDPROXY_LISTENPORT=62031 # Omitted HDSTACK uses host CPU count minus one, clamped to 1..5. # Set an explicit integer from 1 to 5 to override it. #- HDSTACK=5 # Aggregator ID. Workers use this value plus 1..HDSTACK. #- HDSTACK_BASEID=23400 # The separate bridge.py process is optional. - HDSTACK_BRIDGE=0 # Override these only when using different mounted files. #- HDSTACK_BRIDGE_CONFIG=/opt/freedmr/freedmr-bridge.cfg #- HDSTACK_BRIDGE_RULES=/opt/freedmr/rules.py tmpfs: /tmp read_only: "true" data-gateway: container_name: freedmr-data-gateway depends_on: - freedmr image: 'gitlab.hacknix.net:5050/freedmr/freedmr-data-gateway:latest' restart: "unless-stopped" read_only: true tmpfs: - /tmp:size=16m,mode=1777 cap_drop: - ALL security_opt: - no-new-privileges:true environment: FREEDMR_GATEWAY_INGRESS_MODE: fbp FREEDMR_GATEWAY_FBP_RELATIONSHIPS: '__FREEDMR_GATEWAY_FBP_RELATIONSHIPS__' FREEDMR_GATEWAY_RADIOID_PATH: /data/subscriber_ids.json FREEDMR_GATEWAY_APRS_HOST: rotate.aprs2.net FREEDMR_GATEWAY_APRS_PORT: '14580' FREEDMR_GATEWAY_APRS_LOGIN_CALL: '__FREEDMR_GATEWAY_APRS_LOGIN_CALL__' FREEDMR_GATEWAY_APRS_PASSCODE: '__FREEDMR_GATEWAY_APRS_PASSCODE__' FREEDMR_GATEWAY_LOG_LEVEL: INFO volumes: - '/etc/freedmr/json/:/data/:ro' networks: app_net: ipv4_address: 172.16.238.40 freedmrmonitor2: container_name: freedmrmonitor2 cpu_shares: 512 depends_on: - freedmr image: 'gitlab.hacknix.net:5050/freedmr/freedmrmonitor2/freedmrmonitor2:monitor-latest' restart: "unless-stopped" networks: app_net: ipv4_address: 172.16.238.20 read_only: "true" logging: driver: json-file freedmrmonpache: container_name: freedmrmonapache cpu_shares: 512 depends_on: - freedmrmonitor2 #where to store TLS certificates #and acme.sh files volumes: - '/etc/freedmr/certs/:/opt/apachecerts/' - '/etc/freedmr/acme.sh:/root/.acme.sh/' ports: - '80:80/tcp' - '443:443/tcp' image: 'gitlab.hacknix.net:5050/freedmr/freedmrmonitor2/freedmrmonitor2:apache-latest' restart: "unless-stopped" environment: #Set to 1 to enable TLS support #you'll need to actually generate the certtificates too #using these commands when the container is running: #docker exec -it freedmrmonapache gencert.sh #docker-compose restart freedmrmonapache #This only needs to be done once - unless the files in the volumes above are deleted. #The container will handle renewing the certificates every 60 days. #Note -the gencert.sh script only works when the webserver is available on the default port 80 #If it's on non-standard ports, you'll need to request the certificates manually. - 'USE_TLS=1' networks: app_net: ipv4_address: 172.16.238.30 logging: driver: json-file networks: app_net: driver: bridge ipam: driver: default config: - subnet: 172.16.238.0/24 gateway: 172.16.238.1