Fester Wert statt gerechnetem Platzhalter, vorerst 4G. Als command-Eintrag, nicht als eigene Konfigurationsdatei: Der Entrypoint stellt mariadbd davor und prueft die Option beim Start, ein Tippfehler faellt also sofort auf. Ohne die Zeile waeren es 128 MB. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
133 lines
4.0 KiB
YAML
133 lines
4.0 KiB
YAML
# Stand fuer Ring 0 (intern). Einziger kundenspezifischer Wert: __FQDN__.
|
|
# espo-compose-rendern <fqdn> <ring> setzt ihn ein und schreibt /srv/espo/docker-compose.yml.
|
|
# Aenderungen ausschliesslich hier im Repository, nie auf der VM.
|
|
# Freigabe in den naechsten Ring = diese Datei in dessen Ordner kopieren.
|
|
name: espocrm
|
|
|
|
services:
|
|
|
|
espocrm-db:
|
|
image: mariadb:12.3
|
|
container_name: espocrm-db
|
|
# Server-Option statt eigener Konfigurationsdatei; der Entrypoint stellt mariadbd davor
|
|
# und prueft die Option beim Start. Ohne diese Zeile waeren es 128 MB.
|
|
command: ["--innodb-buffer-pool-size=4G"]
|
|
restart: unless-stopped
|
|
stop_grace_period: 120s
|
|
security_opt: ["no-new-privileges:true"]
|
|
environment:
|
|
MARIADB_ROOT_PASSWORD_FILE: /run/secrets/db_root_password
|
|
MARIADB_DATABASE: espocrm
|
|
MARIADB_USER: espocrm
|
|
MARIADB_PASSWORD_FILE: /run/secrets/db_password
|
|
MARIADB_AUTO_UPGRADE: "1"
|
|
TZ: Europe/Berlin
|
|
secrets: [db_root_password, db_password]
|
|
volumes:
|
|
- /srv/espo/mariadb:/var/lib/mysql
|
|
healthcheck:
|
|
test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
|
|
interval: 20s
|
|
start_period: 60s
|
|
timeout: 10s
|
|
retries: 3
|
|
|
|
espocrm:
|
|
image: espocrm:10.0.8
|
|
container_name: espocrm
|
|
restart: unless-stopped
|
|
stop_grace_period: 30s
|
|
security_opt: ["no-new-privileges:true"]
|
|
depends_on:
|
|
espocrm-db:
|
|
condition: service_healthy
|
|
environment:
|
|
ESPOCRM_DATABASE_PLATFORM: Mysql
|
|
ESPOCRM_DATABASE_HOST: espocrm-db
|
|
ESPOCRM_DATABASE_NAME: espocrm
|
|
ESPOCRM_DATABASE_USER: espocrm
|
|
ESPOCRM_DATABASE_PASSWORD_FILE: /run/secrets/db_password
|
|
ESPOCRM_ADMIN_USERNAME: admin
|
|
ESPOCRM_ADMIN_PASSWORD: admin
|
|
ESPOCRM_SITE_URL: https://__FQDN__
|
|
ESPOCRM_CONFIG_SITE_URL: https://__FQDN__
|
|
ESPOCRM_CONFIG_ADMIN_UPGRADE_DISABLED: "true"
|
|
ESPOCRM_CONFIG_USE_WEB_SOCKET: "true"
|
|
ESPOCRM_CONFIG_WEB_SOCKET_URL: wss://__FQDN__/wss
|
|
ESPOCRM_CONFIG_WEB_SOCKET_ZERO_M_Q_SUBSCRIBER_DSN: "tcp://*:7777"
|
|
ESPOCRM_CONFIG_WEB_SOCKET_ZERO_M_Q_SUBMISSION_DSN: tcp://espocrm-websocket:7777
|
|
TZ: Europe/Berlin
|
|
secrets: [db_password]
|
|
configs:
|
|
- source: recordId
|
|
target: /var/www/html/custom/Espo/Custom/Resources/metadata/app/recordId.json
|
|
volumes:
|
|
- /srv/espo/data:/var/www/html/data
|
|
- /srv/espo/custom:/var/www/html/custom
|
|
- /srv/espo/client-custom:/var/www/html/client/custom
|
|
ports:
|
|
- 8080:80
|
|
healthcheck:
|
|
test: ["CMD", "bin/command", "app-check"]
|
|
start_period: 300s
|
|
interval: 60s
|
|
timeout: 20s
|
|
retries: 3
|
|
|
|
espocrm-daemon:
|
|
image: espocrm:10.0.8
|
|
container_name: espocrm-daemon
|
|
restart: unless-stopped
|
|
entrypoint: docker-daemon.sh
|
|
security_opt: ["no-new-privileges:true"]
|
|
environment:
|
|
TZ: Europe/Berlin
|
|
volumes_from: [espocrm]
|
|
configs:
|
|
- source: recordId
|
|
target: /var/www/html/custom/Espo/Custom/Resources/metadata/app/recordId.json
|
|
depends_on:
|
|
espocrm:
|
|
condition: service_healthy
|
|
healthcheck:
|
|
test: ["CMD", "bin/command", "app-check"]
|
|
start_period: 60s
|
|
interval: 180s
|
|
timeout: 20s
|
|
retries: 3
|
|
|
|
espocrm-websocket:
|
|
image: espocrm:10.0.8
|
|
container_name: espocrm-websocket
|
|
restart: unless-stopped
|
|
entrypoint: docker-websocket.sh
|
|
security_opt: ["no-new-privileges:true"]
|
|
environment:
|
|
TZ: Europe/Berlin
|
|
volumes_from: [espocrm]
|
|
configs:
|
|
- source: recordId
|
|
target: /var/www/html/custom/Espo/Custom/Resources/metadata/app/recordId.json
|
|
depends_on:
|
|
espocrm:
|
|
condition: service_healthy
|
|
ports:
|
|
- 8081:8080
|
|
healthcheck:
|
|
test: ["CMD", "bin/command", "app-check"]
|
|
start_period: 60s
|
|
interval: 180s
|
|
timeout: 20s
|
|
retries: 3
|
|
|
|
secrets:
|
|
db_root_password:
|
|
file: /srv/espo/secrets/db_root_password
|
|
db_password:
|
|
file: /srv/espo/secrets/db_password
|
|
|
|
configs:
|
|
recordId:
|
|
content: |
|
|
{"type": "uuid4", "length": 36}
|