2
0

docker-compose.yml 6.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195
  1. version: "3.4"
  2. services:
  3. netmaker:
  4. container_name: netmaker
  5. image: gravitl/netmaker:v0.16.0
  6. cap_add:
  7. - NET_ADMIN
  8. - NET_RAW
  9. - SYS_MODULE
  10. sysctls:
  11. - net.ipv4.ip_forward=1
  12. - net.ipv4.conf.all.src_valid_mark=1
  13. - net.ipv6.conf.all.disable_ipv6=0
  14. - net.ipv6.conf.all.forwarding=1
  15. restart: always
  16. volumes:
  17. - dnsconfig:/root/config/dnsconfig
  18. - sqldata:/root/data
  19. - shared_certs:/etc/netmaker
  20. environment:
  21. SERVER_NAME: "broker.NETMAKER_BASE_DOMAIN"
  22. SERVER_HOST: "SERVER_PUBLIC_IP"
  23. SERVER_API_CONN_STRING: "api.NETMAKER_BASE_DOMAIN:443"
  24. COREDNS_ADDR: "SERVER_PUBLIC_IP"
  25. DNS_MODE: "on"
  26. SERVER_HTTP_HOST: "api.NETMAKER_BASE_DOMAIN"
  27. API_PORT: "8081"
  28. CLIENT_MODE: "on"
  29. MASTER_KEY: "REPLACE_MASTER_KEY"
  30. CORS_ALLOWED_ORIGIN: "*"
  31. DISPLAY_KEYS: "on"
  32. DATABASE: "sqlite"
  33. NODE_ID: "netmaker-server-1"
  34. MQ_HOST: "mq"
  35. MQ_PORT: "443"
  36. MQ_SERVER_PORT: "1883"
  37. HOST_NETWORK: "off"
  38. VERBOSITY: "1"
  39. MANAGE_IPTABLES: "on"
  40. PORT_FORWARD_SERVICES: "dns"
  41. METRICS_EXPORTER: "on"
  42. ports:
  43. - "51821-51830:51821-51830/udp"
  44. expose:
  45. - "8081"
  46. labels:
  47. - traefik.enable=true
  48. - traefik.http.routers.netmaker-api.entrypoints=websecure
  49. - traefik.http.routers.netmaker-api.rule=Host(`api.NETMAKER_BASE_DOMAIN`)
  50. - traefik.http.routers.netmaker-api.service=netmaker-api
  51. - traefik.http.services.netmaker-api.loadbalancer.server.port=8081
  52. netmaker-ui:
  53. container_name: netmaker-ui
  54. image: gravitl/netmaker-ui:v0.16.0
  55. depends_on:
  56. - netmaker
  57. links:
  58. - "netmaker:api"
  59. restart: always
  60. environment:
  61. BACKEND_URL: "https://api.NETMAKER_BASE_DOMAIN"
  62. expose:
  63. - "80"
  64. labels:
  65. - traefik.enable=true
  66. - traefik.http.middlewares.nmui-security.headers.accessControlAllowOriginList=*.NETMAKER_BASE_DOMAIN
  67. - traefik.http.middlewares.nmui-security.headers.stsSeconds=31536000
  68. - traefik.http.middlewares.nmui-security.headers.browserXssFilter=true
  69. - traefik.http.middlewares.nmui-security.headers.customFrameOptionsValue=SAMEORIGIN
  70. - traefik.http.middlewares.nmui-security.headers.customResponseHeaders.X-Robots-Tag=none
  71. - traefik.http.middlewares.nmui-security.headers.customResponseHeaders.Server= # Remove the server name
  72. - traefik.http.routers.netmaker-ui.entrypoints=websecure
  73. - traefik.http.routers.netmaker-ui.middlewares=nmui-security@docker
  74. - traefik.http.routers.netmaker-ui.rule=Host(`dashboard.NETMAKER_BASE_DOMAIN`)
  75. - traefik.http.routers.netmaker-ui.service=netmaker-ui
  76. - traefik.http.services.netmaker-ui.loadbalancer.server.port=80
  77. coredns:
  78. container_name: coredns
  79. image: coredns/coredns
  80. command: -conf /root/dnsconfig/Corefile
  81. depends_on:
  82. - netmaker
  83. restart: always
  84. volumes:
  85. - dnsconfig:/root/dnsconfig
  86. traefik:
  87. image: traefik:v2.6
  88. container_name: traefik
  89. command:
  90. - "--certificatesresolvers.http.acme.email=YOUR_EMAIL"
  91. - "--certificatesresolvers.http.acme.storage=/letsencrypt/acme.json"
  92. - "--certificatesresolvers.http.acme.tlschallenge=true"
  93. - "--entrypoints.websecure.address=:443"
  94. - "--entrypoints.websecure.http.tls=true"
  95. - "--entrypoints.websecure.http.tls.certResolver=http"
  96. - "--log.level=INFO"
  97. - "--providers.docker=true"
  98. - "--providers.docker.exposedByDefault=false"
  99. - "--serverstransport.insecureskipverify=true"
  100. restart: always
  101. volumes:
  102. - /var/run/docker.sock:/var/run/docker.sock:ro
  103. - traefik_certs:/letsencrypt
  104. ports:
  105. - "443:443"
  106. mq:
  107. container_name: mq
  108. image: eclipse-mosquitto:2.0.11-openssl
  109. depends_on:
  110. - netmaker
  111. restart: unless-stopped
  112. volumes:
  113. - /root/mosquitto.conf:/mosquitto/config/mosquitto.conf
  114. - /root/mosquitto.passwords:/etc/mosquitto.passwords
  115. - mosquitto_data:/mosquitto/data
  116. - mosquitto_logs:/mosquitto/log
  117. - shared_certs:/mosquitto/certs
  118. expose:
  119. - "8883"
  120. labels:
  121. - traefik.enable=true
  122. - traefik.tcp.routers.mqtts.rule=HostSNI(`broker.NETMAKER_BASE_DOMAIN`)
  123. - traefik.tcp.routers.mqtts.tls.passthrough=true
  124. - traefik.tcp.services.mqtts-svc.loadbalancer.server.port=8883
  125. - traefik.tcp.routers.mqtts.service=mqtts-svc
  126. - traefik.tcp.routers.mqtts.entrypoints=websecure
  127. prometheus:
  128. container_name: prometheus
  129. image: gravitl/netmaker-prometheus:latest
  130. environment:
  131. NETMAKER_METRICS_TARGET: "netmaker-exporter.NETMAKER_BASE_DOMAIN"
  132. labels:
  133. - traefik.enable=true
  134. - traefik.http.routers.prometheus.entrypoints=websecure
  135. - traefik.http.routers.prometheus.rule=Host(`prometheus.NETMAKER_BASE_DOMAIN`)
  136. - traefik.http.services.prometheus.loadbalancer.server.port=9090
  137. - traefik.http.routers.prometheus.service=prometheus
  138. restart: always
  139. volumes:
  140. - prometheus_data:/prometheus
  141. depends_on:
  142. - netmaker
  143. ports:
  144. - 9090:9090
  145. grafana:
  146. container_name: grafana
  147. image: gravitl/netmaker-grafana:latest
  148. labels:
  149. - traefik.enable=true
  150. - traefik.http.routers.grafana.entrypoints=websecure
  151. - traefik.http.routers.grafana.rule=Host(`grafana.NETMAKER_BASE_DOMAIN`)
  152. - traefik.http.services.grafana.loadbalancer.server.port=3000
  153. - traefik.http.routers.grafana.service=grafana
  154. environment:
  155. PROMETHEUS_HOST: "prometheus.NETMAKER_BASE_DOMAIN"
  156. NETMAKER_METRICS_TARGET: "netmaker-exporter.NETMAKER_BASE_DOMAIN"
  157. ports:
  158. - 3000:3000
  159. restart: always
  160. links:
  161. - prometheus
  162. depends_on:
  163. - prometheus
  164. - netmaker
  165. netmaker-exporter:
  166. container_name: netmaker-exporter
  167. image: gravitl/netmaker-exporter:latest
  168. labels:
  169. - traefik.enable=true
  170. - traefik.http.routers.netmaker-exporter.entrypoints=websecure
  171. - traefik.http.routers.netmaker-exporter.rule=Host(`netmaker-exporter.NETMAKER_BASE_DOMAIN`)
  172. - traefik.http.services.netmaker-exporter.loadbalancer.server.port=8085
  173. - traefik.http.routers.netmaker-exporter.service=netmaker-exporter
  174. restart: always
  175. depends_on:
  176. - netmaker
  177. environment:
  178. MQ_HOST: "mq"
  179. MQ_PORT: "443"
  180. MQ_SERVER_PORT: "1884"
  181. PROMETHEUS: "on"
  182. VERBOSITY: "1"
  183. API_PORT: "8085"
  184. PROMETHEUS_HOST: https://prometheus.NETMAKER_BASE_DOMAIN
  185. expose:
  186. - "8085"
  187. volumes:
  188. traefik_certs: {}
  189. shared_certs: {}
  190. sqldata: {}
  191. dnsconfig: {}
  192. mosquitto_data: {}
  193. mosquitto_logs: {}
  194. prometheus_data: {}