add herald + upgrade gitea and woodpecker
This commit is contained in:
@@ -1,11 +1,12 @@
|
|||||||
{
|
{
|
||||||
"workspaceFolder": "/workspace",
|
"workspaceFolder": "/workspace",
|
||||||
"workspaceMount": "source=${localWorkspaceFolder},target=/workspace,type=bind,Z",
|
"workspaceMount": "source=${localWorkspaceFolder},target=/workspace,type=bind,Z",
|
||||||
|
"runArgs": ["--userns=keep-id", "--security-opt", "label=disable"],
|
||||||
"mounts": [
|
"mounts": [
|
||||||
"source=${localEnv:HOME}/.ssh,target=/home/vscode/.ssh,type=bind,readonly"
|
"source=${localEnv:HOME}/.ssh,target=/root/.ssh,type=bind,readonly"
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"dockerfile": "Dockerfile"
|
"dockerfile": "Dockerfile"
|
||||||
},
|
},
|
||||||
"postAttachCommand": "docker context create prod --docker \"host=ssh://user@62.210.212.10\""
|
"postAttachCommand": "docker context create prod --docker \"host=ssh://user@62.210.212.10\""
|
||||||
}
|
}
|
||||||
|
|||||||
+163
-124
@@ -1,142 +1,181 @@
|
|||||||
version: "3"
|
version: "3"
|
||||||
|
|
||||||
services:
|
services:
|
||||||
reverse_caddy:
|
reverse_caddy:
|
||||||
image: caddy:2.11-alpine
|
image: caddy:2.11-alpine
|
||||||
ports:
|
ports:
|
||||||
- "80:80"
|
- "80:80"
|
||||||
- "443:443"
|
- "443:443"
|
||||||
- "443:443/udp"
|
- "443:443/udp"
|
||||||
configs:
|
configs:
|
||||||
- source: caddy_config
|
- source: caddy_config
|
||||||
target: /etc/caddy/Caddyfile
|
target: /etc/caddy/Caddyfile
|
||||||
volumes:
|
volumes:
|
||||||
- reversecaddydata:/data
|
- reversecaddydata:/data
|
||||||
- reversecaddyconfig:/config
|
- reversecaddyconfig:/config
|
||||||
networks:
|
networks:
|
||||||
- reverse_network
|
- reverse_network
|
||||||
- prometheus_network
|
- prometheus_network
|
||||||
|
|
||||||
woodpecker_server:
|
woodpecker_server:
|
||||||
image: woodpeckerci/woodpecker-server:v3.13.0-alpine
|
image: woodpeckerci/woodpecker-server:v3.15-alpine
|
||||||
volumes:
|
volumes:
|
||||||
- woodpeckerdata:/var/lib/woodpecker/
|
- woodpeckerdata:/var/lib/woodpecker/
|
||||||
entrypoint: /bin/sh -c "export WOODPECKER_GITEA_CLIENT=$$(cat /run/secrets/woodpecker_gitea_client) && export WOODPECKER_GITEA_SECRET=$$(cat /run/secrets/woodpecker_gitea_secret) && export WOODPECKER_AGENT_SECRET=$$(cat /run/secrets/woodpecker_agent_secret) && /bin/woodpecker-server"
|
entrypoint: /bin/sh -c "export WOODPECKER_GITEA_CLIENT=$$(cat /run/secrets/woodpecker_gitea_client) && export WOODPECKER_GITEA_SECRET=$$(cat /run/secrets/woodpecker_gitea_secret) && export WOODPECKER_AGENT_SECRET=$$(cat /run/secrets/woodpecker_agent_secret) && /bin/woodpecker-server"
|
||||||
environment:
|
environment:
|
||||||
WOODPECKER_ADMIN: qpismont
|
WOODPECKER_ADMIN: qpismont
|
||||||
WOODPECKER_HOST: https://woodpecker.qpismont.fr
|
WOODPECKER_HOST: https://woodpecker.qpismont.fr
|
||||||
WOODPECKER_GITEA: "true"
|
WOODPECKER_GITEA: "true"
|
||||||
WOODPECKER_GITEA_URL: https://gitea.qpismont.fr
|
WOODPECKER_GITEA_URL: https://gitea.qpismont.fr
|
||||||
networks:
|
networks:
|
||||||
- reverse_network
|
- reverse_network
|
||||||
secrets:
|
secrets:
|
||||||
- woodpecker_agent_secret
|
- woodpecker_agent_secret
|
||||||
- woodpecker_gitea_client
|
- woodpecker_gitea_client
|
||||||
- woodpecker_gitea_secret
|
- woodpecker_gitea_secret
|
||||||
|
|
||||||
woodpecker_agent:
|
woodpecker_agent:
|
||||||
image: woodpeckerci/woodpecker-agent:v3.13.0-alpine
|
image: woodpeckerci/woodpecker-agent:v3.15-alpine
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
entrypoint: /bin/sh -c "export WOODPECKER_AGENT_SECRET=$$(cat /run/secrets/woodpecker_agent_secret) && /bin/woodpecker-agent"
|
entrypoint: /bin/sh -c "export WOODPECKER_AGENT_SECRET=$$(cat /run/secrets/woodpecker_agent_secret) && /bin/woodpecker-agent"
|
||||||
environment:
|
environment:
|
||||||
WOODPECKER_SERVER: woodpecker_server:9000
|
WOODPECKER_SERVER: woodpecker_server:9000
|
||||||
WOODPECKER_MAX_WORKFLOWS: 1
|
WOODPECKER_MAX_WORKFLOWS: 1
|
||||||
WOODPECKER_LIMIT_CPU_SET: 1
|
WOODPECKER_LIMIT_CPU_SET: 1
|
||||||
networks:
|
networks:
|
||||||
- reverse_network
|
- reverse_network
|
||||||
secrets:
|
secrets:
|
||||||
- woodpecker_agent_secret
|
- woodpecker_agent_secret
|
||||||
|
|
||||||
gitea:
|
gitea:
|
||||||
image: docker.gitea.com/gitea:1.25.2
|
image: docker.gitea.com/gitea:1.26.2
|
||||||
environment:
|
environment:
|
||||||
- USER_UID=1000
|
- USER_UID=1000
|
||||||
- USER_GID=1000
|
- USER_GID=1000
|
||||||
restart: always
|
restart: always
|
||||||
volumes:
|
volumes:
|
||||||
- giteadata:/data
|
- giteadata:/data
|
||||||
- /etc/timezone:/etc/timezone:ro
|
- /etc/timezone:/etc/timezone:ro
|
||||||
- /etc/localtime:/etc/localtime:ro
|
- /etc/localtime:/etc/localtime:ro
|
||||||
networks:
|
networks:
|
||||||
- reverse_network
|
- reverse_network
|
||||||
|
|
||||||
wireguard_server:
|
wireguard_server:
|
||||||
image: linuxserver/wireguard
|
image: linuxserver/wireguard
|
||||||
cap_add:
|
cap_add:
|
||||||
- NET_ADMIN
|
- NET_ADMIN
|
||||||
- SYS_MODULE
|
- SYS_MODULE
|
||||||
environment:
|
environment:
|
||||||
PUID: 1000
|
PUID: 1000
|
||||||
PGID: 1000
|
PGID: 1000
|
||||||
TZ: Europe/Paris
|
TZ: Europe/Paris
|
||||||
SERVEURURL: wireguard.qpismont.fr
|
SERVEURURL: wireguard.qpismont.fr
|
||||||
SERVERPORT: 51820
|
SERVERPORT: 51820
|
||||||
PEERS: 1
|
PEERS: 1
|
||||||
PEERDNS: auto
|
PEERDNS: auto
|
||||||
volumes:
|
volumes:
|
||||||
- /home/user/wireguard-config:/config
|
- /home/user/wireguard-config:/config
|
||||||
- /lib/modules:/lib/modules
|
- /lib/modules:/lib/modules
|
||||||
ports:
|
ports:
|
||||||
- 51820:51820/udp
|
- 51820:51820/udp
|
||||||
sysctls:
|
sysctls:
|
||||||
- net.ipv4.conf.all.src_valid_mark=1
|
- net.ipv4.conf.all.src_valid_mark=1
|
||||||
networks:
|
networks:
|
||||||
- wireguard_network
|
- wireguard_network
|
||||||
|
|
||||||
perses:
|
perses:
|
||||||
image: persesdev/perses:latest
|
image: persesdev/perses:latest
|
||||||
networks:
|
networks:
|
||||||
- wireguard_network
|
- wireguard_network
|
||||||
- prometheus_network
|
- prometheus_network
|
||||||
|
|
||||||
prometheus:
|
prometheus:
|
||||||
image: prom/prometheus:v3.9.1
|
image: prom/prometheus:v3.9.1
|
||||||
configs:
|
configs:
|
||||||
- source: prometheus_config
|
- source: prometheus_config
|
||||||
target: /etc/prometheus/prometheus.yml
|
target: /etc/prometheus/prometheus.yml
|
||||||
networks:
|
networks:
|
||||||
- prometheus_network
|
- prometheus_network
|
||||||
|
|
||||||
cadvisor:
|
cadvisor:
|
||||||
image: gcr.io/cadvisor/cadvisor:latest
|
image: gcr.io/cadvisor/cadvisor:latest
|
||||||
volumes:
|
volumes:
|
||||||
- /:/rootfs:ro
|
- /:/rootfs:ro
|
||||||
- /var/run:/var/run:rw
|
- /var/run:/var/run:rw
|
||||||
- /sys:/sys:ro
|
- /sys:/sys:ro
|
||||||
- /var/lib/docker/:/var/lib/docker:ro
|
- /var/lib/docker/:/var/lib/docker:ro
|
||||||
networks:
|
networks:
|
||||||
- prometheus_network
|
- prometheus_network
|
||||||
|
|
||||||
|
herald:
|
||||||
|
image: tintounn/herald:1.0
|
||||||
|
entrypoint:
|
||||||
|
- /bin/sh
|
||||||
|
- -c
|
||||||
|
- >-
|
||||||
|
export GITEA_TOKEN=$$(cat /run/secrets/herald_gitea_token) &&
|
||||||
|
export OPEN_ROUTER_API_KEY=$$(cat /run/secrets/herald_openrouter_token) &&
|
||||||
|
export WEBHOOK_SIG_HEADER_SECRET=$$(cat /run/secrets/herald_gitea_header_secret) &&
|
||||||
|
export SENTRY_DSN=$$(cat /run/secrets/herald_sentry_dsn) &&
|
||||||
|
/app/herald
|
||||||
|
networks:
|
||||||
|
- reverse_network
|
||||||
|
secrets:
|
||||||
|
- herald_gitea_token
|
||||||
|
- herald_openrouter_token
|
||||||
|
- herald_gitea_header_secret
|
||||||
|
- herald_sentry_dsn
|
||||||
|
environment:
|
||||||
|
HTTP_PORT: 3000
|
||||||
|
BOT_NAME: Herald
|
||||||
|
BOT_MAX_CONCURRENT: 5
|
||||||
|
GITEA_URL: http://gitea:3000
|
||||||
|
GITEA_TIMEOUT: 60
|
||||||
|
OPEN_ROUTER_MODEL: deepseek/deepseek-v4-flash
|
||||||
|
OPEN_ROUTER_TIMEOUT: 600
|
||||||
|
|
||||||
secrets:
|
secrets:
|
||||||
woodpecker_agent_secret:
|
woodpecker_agent_secret:
|
||||||
name: woodpecker_agent_secret_${DATETIME}
|
name: woodpecker_agent_secret_${DATETIME}
|
||||||
file: ./secrets/woodpecker_agent_secret
|
file: ./secrets/woodpecker_agent_secret
|
||||||
woodpecker_gitea_secret:
|
woodpecker_gitea_secret:
|
||||||
name: woodpecker_gitea_secret_${DATETIME}
|
name: woodpecker_gitea_secret_${DATETIME}
|
||||||
file: ./secrets/woodpecker_gitea_secret
|
file: ./secrets/woodpecker_gitea_secret
|
||||||
woodpecker_gitea_client:
|
woodpecker_gitea_client:
|
||||||
name: woodpecker_gitea_client_${DATETIME}
|
name: woodpecker_gitea_client_${DATETIME}
|
||||||
file: ./secrets/woodpecker_gitea_client
|
file: ./secrets/woodpecker_gitea_client
|
||||||
|
herald_gitea_token:
|
||||||
|
name: herald_gitea_token_${DATETIME}
|
||||||
|
file: ./secrets/herald/herald_gitea_token
|
||||||
|
herald_openrouter_token:
|
||||||
|
name: herald_openrouter_token_${DATETIME}
|
||||||
|
file: ./secrets/herald/herald_openrouter_token
|
||||||
|
herald_gitea_header_secret:
|
||||||
|
name: herald_gitea_header_secret_${DATETIME}
|
||||||
|
file: ./secrets/herald/herald_gitea_header_secret
|
||||||
|
herald_sentry_dsn:
|
||||||
|
name: herald_sentry_dsn_${DATETIME}
|
||||||
|
file: ./secrets/herald/herald_sentry_dsn
|
||||||
|
|
||||||
configs:
|
configs:
|
||||||
caddy_config:
|
caddy_config:
|
||||||
name: caddy_config_${DATETIME}
|
name: caddy_config_${DATETIME}
|
||||||
file: ./Caddyfile
|
file: ./Caddyfile
|
||||||
prometheus_config:
|
prometheus_config:
|
||||||
name: prometheus_config_${DATETIME}
|
name: prometheus_config_${DATETIME}
|
||||||
file: ./prometheus.yml
|
file: ./prometheus.yml
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
giteadata:
|
giteadata:
|
||||||
woodpeckerdata:
|
woodpeckerdata:
|
||||||
reversecaddyconfig:
|
reversecaddyconfig:
|
||||||
reversecaddydata:
|
reversecaddydata:
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
reverse_network:
|
reverse_network:
|
||||||
external: true
|
external: true
|
||||||
wireguard_network:
|
wireguard_network:
|
||||||
external: true
|
external: true
|
||||||
prometheus_network:
|
prometheus_network:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
Reference in New Issue
Block a user