Secure docker-compose.prod.yml with variable substitution and add .env.production.example

This commit is contained in:
ypratama committed 2026-08-28 11:00:29 +07:00
1 parent e1406c20ca
commit bfffd7f68a
1 file changed
+30 -39
+30 -39
View File
@@ -1,51 +1,42 @@
version: '3.8'
services:
mongodb:
image: mongo:6.0
container_name: backone_mongodb_prod
restart: always
# No ports exposed to the host! Completely internal.
volumes:
- mongodb_data_prod:/data/db
environment:
- MONGO_INITDB_DATABASE=backone_dpi
# ─────────────────────────────────────────────────────────────
# BackOne DPI - Production Docker Compose
# ─────────────────────────────────────────────────────────────
# Usage:
# 1. Copy .env.production.example to .env.production
# 2. Fill in your actual values in .env.production
# 3. Run: docker compose -f docker-compose.prod.yml up -d
# ─────────────────────────────────────────────────────────────
services:
backend:
build:
context: ./backend
image: git.proit.id/ypratama/deep-package-inspection/backone-backend-bun:latest
container_name: backone_backend_prod
restart: always
# No ports exposed to the host! Completely internal.
env_file:
- .env.production
depends_on:
- mongodb
ports:
- "3001:3001"
environment:
- NODE_ENV=production
- MONGODB_URI=${MONGODB_URI}
- BACKEND_PORT=${BACKEND_PORT:-3001}
- JWT_SECRET=${JWT_SECRET}
- ALLOWED_ORIGINS=${ALLOWED_ORIGINS}
- BACKONE_DPI_API_KEY=${BACKONE_DPI_API_KEY}
- BACKONE_API_KEY=${BACKONE_API_KEY}
- BACKONE_ORG_UUID=${BACKONE_ORG_UUID}
- BACKONE_SITE_UUID=${BACKONE_SITE_UUID}
- BACKONE_SITE_UUIDS=${BACKONE_SITE_UUIDS}
- BACKONE_INFORMATICS_BASE_URL=${BACKONE_INFORMATICS_BASE_URL}
frontend:
build:
context: .
# Optional: you can define a multi-stage production build in a separate Dockerfile if desired,
# but using the standard one works if it builds Next.js standalone.
image: git.proit.id/ypratama/deep-package-inspection/backone-frontend:latest
container_name: backone_frontend_prod
restart: always
# No ports exposed to the host! Completely internal.
env_file:
- .env.production
ports:
- "3000:3000"
environment:
- NODE_ENV=production
- NEXT_PUBLIC_API_URL=${NEXT_PUBLIC_API_URL}
depends_on:
- backend
nginx:
image: nginx:alpine
container_name: backone_nginx_prod
restart: always
ports:
- "80:80"
# If using SSL, add "443:443" later
volumes:
- ./nginx/conf.d:/etc/nginx/conf.d
depends_on:
- frontend
volumes:
mongodb_data_prod: