Перенесены секреты из .env в SM
This commit is contained in:
@@ -4,17 +4,18 @@ services:
|
||||
context: .
|
||||
image: han-chat-redis:${RELEASE_VERSION:-local}
|
||||
environment:
|
||||
REDIS_API_PASSWORD: ${REDIS_API_PASSWORD}
|
||||
REDIS_SAFETY_PASSWORD: ${REDIS_SAFETY_PASSWORD}
|
||||
REDIS_HEALTH_PASSWORD: ${REDIS_HEALTH_PASSWORD}
|
||||
REDIS_MAXMEMORY: ${REDIS_MAXMEMORY:-384mb}
|
||||
REDIS_EVICTION_POLICY: ${REDIS_EVICTION_POLICY:-volatile-lru}
|
||||
secrets:
|
||||
- redis_api_password
|
||||
- redis_safety_password
|
||||
- redis_health_password
|
||||
expose: ["6379"]
|
||||
volumes:
|
||||
- redis-data:/data
|
||||
networks: [backend]
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "redis-cli --no-auth-warning --user ops_health --pass \"$$REDIS_HEALTH_PASSWORD\" PING | grep -qx PONG"]
|
||||
test: ["CMD-SHELL", "REDISCLI_AUTH=\"$$(cat /run/secrets/redis_health_password)\" redis-cli --user ops_health PING | grep -qx PONG"]
|
||||
interval: 10s
|
||||
timeout: 3s
|
||||
retries: 10
|
||||
@@ -28,7 +29,16 @@ services:
|
||||
cap_drop: ["ALL"]
|
||||
mem_limit: 512m
|
||||
ulimits:
|
||||
core: {soft: 0, hard: 0}
|
||||
nofile: {soft: 65536, hard: 65536}
|
||||
logging:
|
||||
driver: json-file
|
||||
options: {max-size: "50m", max-file: "5"}
|
||||
|
||||
secrets:
|
||||
redis_api_password:
|
||||
file: ${HAN_SECRETS_DIR:-/run/han-chat/secrets}/REDIS_API_PASSWORD
|
||||
redis_safety_password:
|
||||
file: ${HAN_SECRETS_DIR:-/run/han-chat/secrets}/REDIS_SAFETY_PASSWORD
|
||||
redis_health_password:
|
||||
file: ${HAN_SECRETS_DIR:-/run/han-chat/secrets}/REDIS_HEALTH_PASSWORD
|
||||
|
||||
Reference in New Issue
Block a user