docker-compose.yaml 2.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354
  1. {% set tpl = ix_lib.base.render.Render(values) %}
  2. {% set c1 = tpl.add_container(values.consts.scrutiny_container_name, "image") %}
  3. {% do c1.set_user(0,0) %}
  4. {% do c1.set_privileged(true) %}
  5. {% do c1.add_caps([
  6. "CHOWN",
  7. "DAC_OVERRIDE",
  8. "FSETID",
  9. "FOWNER",
  10. "MKNOD",
  11. "NET_RAW",
  12. "SETGID",
  13. "SETUID",
  14. "SETFCAP",
  15. "SETPCAP",
  16. "NET_BIND_SERVICE",
  17. "SYS_CHROOT",
  18. "KILL",
  19. "AUDIT_WRITE",
  20. ]) %}
  21. {% do c1.add_storage("/run/udev", {"type": "host_path", "read_only": True, "host_path_config": {"path": "/run/udev"}}) %}
  22. {% do c1.add_storage("/dev", {"type": "host_path", "read_only": True, "host_path_config": {"path": "/dev"}}) %}
  23. {% do c1.add_storage(values.consts.config_dir, values.storage.config) %}
  24. {% do c1.add_storage("/opt/scrutiny/influxdb", values.storage.influxdb) %}
  25. {% for store in values.storage.additional_storage %}
  26. {% do c1.add_storage(store.mount_path, store) %}
  27. {% endfor %}
  28. {% if not values.network.host_network %}
  29. {% do c1.add_port(values.network.web_port, {"container_port": values.consts.internal_web_port}) %}
  30. {% do c1.add_port(values.network.influxdb_port, {"container_port": values.consts.internal_influxdb_port}) %}
  31. {% endif %}
  32. {% do c1.environment.add_user_envs(values.scrutiny.additional_envs) %}
  33. {% do c1.environment.add_env("SCRUTINY_WEB_LISTEN_HOST", "0.0.0.0") %}
  34. {# Collector has an init script that has hardcoded 8080 port, so we cannot change that #}
  35. {% do c1.environment.add_env("SCRUTINY_WEB_LISTEN_PORT", values.consts.internal_web_port) %}
  36. {% do c1.environment.add_env("SCRUTINY_WEB_INFLUXDB_HOST", "127.0.0.1") %}
  37. {% do c1.environment.add_env("SCRUTINY_WEB_INFLUXDB_PORT", values.consts.internal_influxdb_port) %}
  38. {% do c1.environment.add_env("SCRUTINY_WEB_DATABASE_LOCATION", "%s/scrutiny.db"|format(values.consts.config_dir)) %}
  39. {% do c1.environment.add_env("COLLECTOR_API_ENDPOINT", "http://127.0.0.1:%d"|format(values.consts.internal_web_port)) %}
  40. {% do c1.healthcheck.set_test("curl", {"port": values.consts.internal_web_port, "path": "/api/health"}) %}
  41. {% do tpl.portals.add(values.network.web_port, {"port": values.consts.internal_web_port if values.network.host_network else None}) %}
  42. {% do tpl.portals.add(values.network.influxdb_port, {"name": "InfluxDB", "port": values.consts.internal_influxdb_port if values.network.host_network else None}) %}
  43. {% do tpl.notes.set_body(values.consts.notes_body) %}
  44. {{ tpl.render() | tojson }}