read.markets/docker-compose.prod.yml
Giorgio Gilestro 411094d7b8 admin: internal-only superadmin console (users, payments, DB stats)
New independent `admin` service (admin.main:app) on the same image, reusing
app.db/app.models read-only. Never runs migrations or the scheduler; issues
SELECTs only.

- Password-gated (ADMIN_CONSOLE_PASSWORD) with a 12h signed cookie; closed by
  default when the password is empty.
- Bound to 127.0.0.1:8091 (SSH-tunnel access); off the intranet/NPM network.
- Pages: overview stats, user list + search, per-user history/payment detail,
  DB usage (information_schema size + row estimates).
- Compose: base `admin` service (+prod DB-host override, test mount); Dockerfile
  bakes admin/ into runtime + test stages.
- Tests: tests/test_admin_console.py (auth, queries, page wiring) — 12 passing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-01 16:08:20 +02:00

57 lines
2.7 KiB
YAML

# Production overlay. Applied on the VPS with:
#
# docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d
#
# Drops the host port binding entirely and joins the `intranet` external
# Docker network so a front-side proxy (Nginx Proxy Manager) on the same
# network can reach the container directly. The app listens on port 80
# inside the container so NPM upstreams are uniform across services
# (always `<container-name>:80`).
#
# The local-dev compose (just `docker-compose.yml` alone) still binds to
# the host port from `.env` / CASSANDRA_PORT — unchanged.
services:
app:
# --proxy-headers makes Starlette honour X-Forwarded-Proto / -For from
# NPM, so request.url_for() generates https:// URLs (otherwise static
# asset links render as http://… and browsers block as mixed content).
# --forwarded-allow-ips=* is safe here: the container has no host port,
# only the intranet bridge reaches it.
command: ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "80",
"--workers", "1", "--proxy-headers", "--forwarded-allow-ips=*"]
expose:
- "80"
networks:
- default
- intranet
# The shared `intranet` network has many other containers aliased as
# `db` and `redis`; Docker's embedded DNS would pick one of those
# before ours. Use the project-prefixed container names instead —
# those are globally unique on the daemon.
environment:
DATABASE_URL: mysql+aiomysql://${MARIADB_USER:-cassandra}:${MARIADB_PASSWORD:-changeme}@readmarkets-db-1:3306/${MARIADB_DATABASE:-cassandra}
REDIS_URL: redis://readmarkets-redis-1:6379/0
scheduler:
# Scheduler isn't fronted by NPM, so it doesn't need intranet — but
# it does share the same DNS-collision problem on `default` (it only
# joins `default`, where our `db` alias would normally win… except
# the scheduler too is multi-network if you ever decide to expose
# its health endpoint via NPM). Future-proofing: use the explicit
# container names here too.
environment:
DATABASE_URL: mysql+aiomysql://${MARIADB_USER:-cassandra}:${MARIADB_PASSWORD:-changeme}@readmarkets-db-1:3306/${MARIADB_DATABASE:-cassandra}
REDIS_URL: redis://readmarkets-redis-1:6379/0
admin:
# Same DNS-collision reasoning as app/scheduler: use the project-prefixed
# container name for the DB. The console stays OFF the intranet network —
# it is internal-only (127.0.0.1:8091 host port from the base file), so it
# never needs to be reachable by NPM.
environment:
DATABASE_URL: mysql+aiomysql://${MARIADB_USER:-cassandra}:${MARIADB_PASSWORD:-changeme}@readmarkets-db-1:3306/${MARIADB_DATABASE:-cassandra}
networks:
intranet:
external: true