Frontend: - Multi-stage build: builder (node:22-alpine) → runner (nginx:alpine) replaces vite preview (400MB RAM) with nginx static serving (<20MB RAM) - New nginx-frontend.conf with gzip + long-term asset cache + SPA fallback Backend & Discord Gateway: - Add non-root user (USER app) for container security - chown app files to avoid permission issues - Add HEALTHCHECK: backend via /api/health, gateway via kill -0 1 Docker Compose: - Remove unnecessary backend→gateway depends_on - Add deploy.resources.limits.memory for all services - Add healthchecks for all services Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com
100 lines
2.6 KiB
YAML
100 lines
2.6 KiB
YAML
version: '3.8'
|
|
|
|
services:
|
|
# Nginx Reverse Proxy — handles /api and /ws routing behind Traefik
|
|
proxy:
|
|
image: ghcr.io/${OWNER:-mytheclipse}/bete-proxy:latest
|
|
container_name: imphenbot-proxy
|
|
restart: unless-stopped
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.imphenbot.rule=Host(`imphnen.asepharyana.my.id`)"
|
|
- "traefik.http.routers.imphenbot.entrypoints=websecure"
|
|
- "traefik.http.routers.imphenbot.tls=true"
|
|
- "traefik.http.services.imphenbot.loadbalancer.server.port=80"
|
|
depends_on:
|
|
- backend
|
|
healthcheck:
|
|
test: ["CMD", "nginx", "-t"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 64M
|
|
networks:
|
|
- app-shared-net
|
|
|
|
# Backend Service (REST API + WebSocket)
|
|
backend:
|
|
image: ghcr.io/${OWNER:-mytheclipse}/bete-backend:latest
|
|
container_name: imphenbot-backend
|
|
restart: unless-stopped
|
|
env_file:
|
|
- .env
|
|
environment:
|
|
NODE_ENV: production
|
|
WEBSERVER_PORT: 3000
|
|
# Backend talks to gateway via Redis+Postgres, not directly — no depends_on needed
|
|
healthcheck:
|
|
test: ["CMD", "wget", "-qO-", "http://localhost:3000/api/health"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
start_period: 15s
|
|
retries: 3
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 256M
|
|
networks:
|
|
- app-shared-net
|
|
|
|
# Discord Gateway Service (Event capture and processing — no HTTP)
|
|
discord-gateway:
|
|
image: ghcr.io/${OWNER:-mytheclipse}/bete-discord-gateway:latest
|
|
container_name: imphenbot-discord-gateway
|
|
restart: unless-stopped
|
|
env_file:
|
|
- .env
|
|
environment:
|
|
NODE_ENV: production
|
|
volumes:
|
|
- ./recordings:/app/recordings
|
|
# Gateway has no HTTP server — check if PID 1 (node) is alive
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "kill -0 1 || exit 1"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
start_period: 30s
|
|
retries: 3
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 512M
|
|
networks:
|
|
- app-shared-net
|
|
|
|
# Frontend Service (React Dashboard) — Nginx serving static files
|
|
frontend:
|
|
image: ghcr.io/${OWNER:-mytheclipse}/bete-frontend:latest
|
|
container_name: imphenbot-frontend
|
|
restart: unless-stopped
|
|
healthcheck:
|
|
test: ["CMD", "wget", "-qO-", "http://localhost:3000/"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
start_period: 5s
|
|
retries: 3
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 32M
|
|
networks:
|
|
- app-shared-net
|
|
|
|
networks:
|
|
app-shared-net:
|
|
name: app-shared-net
|
|
external: true
|