-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
64 lines (63 loc) · 2.67 KB
/
Copy pathdocker-compose.yml
File metadata and controls
64 lines (63 loc) · 2.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
services:
pec-server:
build:
context: .
dockerfile: Dockerfile
image: pec-proxy-extension-corp:latest
container_name: pec-proxy-server
restart: unless-stopped
ports:
- "${PORT:-3000}:3000"
environment:
- NODE_ENV=production
- PORT=3000
- HOST=0.0.0.0
- EXT_SHARED_TOKEN=${EXT_SHARED_TOKEN:?Set EXT_SHARED_TOKEN in .env (see .env.example)}
- ADMIN_TOKEN=${ADMIN_TOKEN:?Set ADMIN_TOKEN in .env (a long random value, distinct from EXT_SHARED_TOKEN)}
# All persistent state lives in /app/data (mounted volume below) so
# profiles, rotation config and instance metadata survive redeploys.
- DATA_DIR=/app/data
- PROXIES_STORE_PATH=/app/data/proxies.json
- CREDS_STORE=/app/data/current_creds.json
- DASHBOARD_AUTH_PATH=/app/data/dashboard_auth.json
- PROXY_CONFIG_PATH=/app/data/proxy_config.json
- ROUTING_PROFILES_PATH=/app/data/routing_profiles.json
- ROUTING_PRESETS_PATH=/app/data/routing_presets.json
- INSTANCES_META_PATH=/app/data/instances_meta.json
- ROTATION_CONFIG_PATH=/app/data/rotation_config.json
- ROTATION_HISTORY_PATH=/app/data/rotation_history.json
- BUILDER_CONFIG=/app/data/extension_build_config.json
# Behind the compose-provided nginx (docker-compose.prod.yml) set to 1;
# for this direct-exposure setup keep disabled unless another proxy sits
# in front. Enables correct client IPs for rate limiting and audit.
- TRUST_PROXY=${TRUST_PROXY:-false}
# Public URL used in updates.xml / GPO artifacts (prevents Host-header
# poisoning). Set it to the URL your fleet uses to reach this server.
- PUBLIC_BASE_URL=${PUBLIC_BASE_URL:-}
# 3x-ui panel integration (credential rotation) - without these the
# container cannot reach the panel and .env values are ignored.
- XUI_PANEL_URL=${XUI_PANEL_URL:-}
- XUI_ADMIN_USER=${XUI_ADMIN_USER:-}
- XUI_ADMIN_PASS=${XUI_ADMIN_PASS:-}
- XUI_INBOUND_REMARK=${XUI_INBOUND_REMARK:-squid-in}
- ROTATION_INTERVAL_MIN=${ROTATION_INTERVAL_MIN:-1440}
volumes:
# Runtime state: survives rebuilds (creds, profiles, rotation, meta).
- pec_data:/app/data
# The CRX signing key lives here - a stable key means a stable
# extension ID (GPO forcelists break when the ID changes).
- pec_extension:/app/extension
- pec_updates:/app/dist/updates
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:3000/healthz"]
interval: 30s
timeout: 5s
retries: 3
start_period: 10s
volumes:
pec_data:
driver: local
pec_extension:
driver: local
pec_updates:
driver: local