docker-compose.yaml 1.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354
  1. {% set tpl = ix_lib.base.render.Render(values) %}
  2. {% set c1 = tpl.add_container(values.consts.kasm_container_name, "image") %}
  3. {% if values.ci %}
  4. {% do c1.healthcheck.set_test("curl", {"port": values.consts.setup_internal_port, "scheme": "https"}) %}
  5. {% else %}
  6. {% do c1.healthcheck.disable() %}
  7. {% endif %}
  8. {% do c1.set_privileged(true) %}
  9. {% do c1.remove_security_opt("no-new-privileges") %}
  10. {% do c1.add_caps([
  11. "CHOWN",
  12. "DAC_OVERRIDE",
  13. "FSETID",
  14. "FOWNER",
  15. "MKNOD",
  16. "NET_RAW",
  17. "SETGID",
  18. "SETUID",
  19. "SETFCAP",
  20. "SETPCAP",
  21. "NET_BIND_SERVICE",
  22. "SYS_CHROOT",
  23. "KILL",
  24. "AUDIT_WRITE",
  25. ]) %}
  26. {% if values.kasm.gamepad_support %}
  27. {% do c1.add_storage("/run/udev/data", {"type": "host_path", "read_only": true, "host_path_config": {"path": "/run/udev/data"}}) %}
  28. {% do c1.add_storage("/dev/input", {"type": "host_path", "read_only": true, "host_path_config": {"path": "/dev/input"}}) %}
  29. {% endif %}
  30. {% do c1.environment.add_env("KASM_PORT", values.network.web_port.port_number) %}
  31. {% do c1.environment.add_user_envs(values.kasm.additional_envs) %}
  32. {% if not values.network.host_network %}
  33. {% do c1.add_port(values.network.setup_port, {"container_port": values.consts.setup_internal_port}) %}
  34. {% do c1.add_port(values.network.web_port) %}
  35. {%endif %}
  36. {% do c1.add_storage("/opt", values.storage.opt) %}
  37. {% do c1.add_storage("/profiles", values.storage.profiles) %}
  38. {% for store in values.storage.additional_storage %}
  39. {% do c1.add_storage(store.mount_path, store) %}
  40. {% endfor %}
  41. {% do tpl.portals.add(values.network.web_port, {"scheme": "https"}) %}
  42. {% do tpl.portals.add(values.network.setup_port, {"name": "Setup", "scheme": "https", "port": values.consts.setup_internal_port if values.network.host_network else None}) %}
  43. {% do tpl.notes.set_body(values.consts.notes_body) %}
  44. {{ tpl.render() | tojson }}