-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
66 lines (65 loc) 路 2.75 KB
/
Copy pathdocker-compose.yml
File metadata and controls
66 lines (65 loc) 路 2.75 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
name: devbox
services:
# -- Remote development container -------------------------------------------
# Unprivileged sshd owned by the `dev` user; the published port is the entire
# network boundary (see docs/networking.md).
devbox:
container_name: devbox
build:
context: .
args:
HOST_UID: '${HOST_UID}'
HOST_GID: '${HOST_GID}'
init: true
restart: unless-stopped
user: '${HOST_UID}:${HOST_GID}'
hostname: devbox
# No identity here: who this box is lives in
# ~/.config/devbox/identities.conf on the bind mount, read by
# devbox-identities (docs/git.md). An enumeration of per-account variables
# is what that file replaced - a new account used to need a line here, one
# in .env and a branch in bootstrap.
environment:
TZ: '${TZ}'
DEVBOX_GITHUB_USER: '${DEVBOX_GITHUB_USER}'
DEVBOX_EXTRA_AUTHORIZED_KEYS: '${DEVBOX_EXTRA_AUTHORIZED_KEYS}'
ports:
- '${BIND_ADDR}:${DEVBOX_SSH_PORT}:2222'
- '127.0.0.1:${DEVBOX_SSH_PORT}:2222'
# docker0 is this container's own gateway (see network_mode below), so
# `host-gateway` resolves to the address the project daemon publishes on.
extra_hosts:
- 'host.docker.internal:host-gateway'
volumes:
- '${DEVBOX_DATA_DIR}:/home/dev'
- './container:/opt/devbox/container:ro'
- './home:/opt/devbox/home:ro'
# The *directory*, not the socket file: rootlesskit recreates the socket
# inode on every daemon restart and a file bind mount would pin the old
# one. This is a sibling rootless daemon owned by the unprivileged `dev`
# host user - never the host's root /var/run/docker.sock.
#
# Defaulted so an .env written before `sudo ./bin/rootless-docker` ran
# still parses; an unset variable would make every compose command fail
# with "empty section between colons". Docker creates the directory
# root-owned if it is missing, which the tmpfiles.d rule then re-owns -
# until then the socket is simply absent and `docker` says so.
- '${DEVBOX_DOCKER_SOCKET_DIR:-/run/devbox}:/run/devbox'
tmpfs:
- '/tmp:mode=1777'
cap_drop:
- ALL
security_opt:
- 'no-new-privileges:true'
healthcheck:
test: [ 'CMD-SHELL', 'ss -ltn | grep -q ":2222"' ]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
# The default bridge, deliberately: docker0 exists whenever the host docker
# daemon does, while a compose-managed bridge disappears on `down` and is
# recreated on `up`. The rootless project daemon publishes onto this
# gateway, so a vanishing interface would leave project containers unable to
# bind their ports (docs/docker.md). One service, no compose DNS needed.
network_mode: bridge