forked from Synapse-bridgez/synapse-core
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
85 lines (81 loc) · 2.7 KB
/
Copy pathdocker-compose.yml
File metadata and controls
85 lines (81 loc) · 2.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
services:
postgres:
image: postgres:14-alpine
container_name: synapse-postgres
environment:
POSTGRES_USER: synapse
POSTGRES_PASSWORD: synapse
POSTGRES_DB: synapse
POSTGRES_INITDB_ARGS: "-c wal_level=replica -c max_wal_senders=3 -c max_replication_slots=3"
ports:
- "5432:5432"
volumes:
- postgres_data:/var/lib/postgresql/data
- postgres_wal:/var/lib/postgresql/wal_archive
# Provisions the restricted synapse_app role (NOBYPASSRLS) the app
# connects as below. Only runs on first init of an empty data volume —
# `docker compose down -v` before `up` if the role needs (re)creating
# on an existing volume.
- ./scripts/db-init:/docker-entrypoint-initdb.d:ro
healthcheck:
test: ["CMD-SHELL", "pg_isready -U synapse"]
interval: 5s
timeout: 5s
retries: 5
redis:
image: redis:7-alpine
container_name: synapse-redis
ports:
- "6379:6379"
volumes:
- redis_data:/data
healthcheck:
test: ["CMD", "redis-cli", "ping"]
interval: 5s
timeout: 5s
retries: 5
vault:
image: hashicorp/vault:latest
container_name: synapse-vault
ports:
- "8200:8200"
environment:
VAULT_DEV_ROOT_TOKEN_ID: "root"
VAULT_DEV_LISTEN_ADDRESS: "0.0.0.0:8200"
cap_add:
- IPC_LOCK
command: server -dev
app:
build: .
container_name: synapse-app
depends_on:
postgres:
condition: service_healthy
redis:
condition: service_healthy
environment:
SERVER_PORT: 3000
# Restricted, non-superuser role — see scripts/db-init/01-create-app-role.sql.
# Do not point this at the bootstrap `synapse` superuser: that role has
# BYPASSRLS and silently defeats every RLS policy in migrations/.
DATABASE_URL: postgres://synapse_app:synapse_app@postgres:5432/synapse
DATABASE_URL_TEMPLATE: postgres://synapse_app:{password}@postgres:5432/synapse
# pg_dump refuses to dump FORCE ROW LEVEL SECURITY tables (transactions,
# settlements) under synapse_app's NOBYPASSRLS role — BackupService
# needs its own, separately-privileged connection. See
# Config::backup_database_url and docs/postmortem-cross-tenant-leak.md.
BACKUP_DATABASE_URL: postgres://synapse:synapse@postgres:5432/synapse
STELLAR_HORIZON_URL: https://horizon-testnet.stellar.org
VAULT_ADDR: http://vault:8200
VAULT_ROLE_ID: ""
VAULT_SECRET_ID: ""
REDIS_URL: redis://redis:6379
ports:
- "3000:3000"
volumes:
- ./migrations:/app/migrations # optional: for live migration updates
command: ["/app/synapse-core"]
volumes:
postgres_data:
postgres_wal:
redis_data: