Docker: full Dockerized deployment (volumes, host networking, multi-package-manager build)
- docker-compose.yml: network_mode host so 127.0.0.1 refs (.env) keep working; mounts /var/www/Gamedata + write volumes; /api/health healthcheck; mem_limit - Dockerfile: package-manager detection (pnpm/yarn/npm) + PACKAGE_MANAGER arg; runs as www-data (UID/GID 33) so gamedata is writable; .env loaded only for the build (no secrets baked in); build runs on the host network - .dockerignore: .env stays in the build context (needed for NEXT_PUBLIC_*) - README: Docker deployment section (paths, volumes, chown, migrations on host)
This commit is contained in:
1 parent
58c35a2920
commit
cb927db78d
4 files changed
+377
-411
No files matched your search
+52
-9
@@ -1,20 +1,63 @@
|
||||
version: "3.8"
|
||||
|
||||
services:
|
||||
cms:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
# The host disables Docker iptables (daemon.json: "iptables": false), so
|
||||
# build containers on the bridge network have no outbound NAT/DNS. Build on
|
||||
# the host network instead so pnpm/npm/yarn can reach the registry.
|
||||
network: host
|
||||
args:
|
||||
# Run as the host owner (www-data = UID/GID 33, already present in the
|
||||
# node base image) of /var/www/Gamedata so the container can read + write
|
||||
# the shared gamedata directory.
|
||||
RUN_USER: "www-data"
|
||||
container_name: epicnext-cms
|
||||
ports:
|
||||
# Host port -> container port (container always listens on 3002)
|
||||
- "3002:3002"
|
||||
# Runs on the host network so existing 127.0.0.1 refs in .env keep working:
|
||||
# MariaDB (3306), DragonflyDB/Redis (6379), emulator RCON (3003) + API (3001),
|
||||
# and the imaging renderer (8082). The container then listens directly on the
|
||||
# host's 3002 (the same port the current host-side CMS uses).
|
||||
# NOTE: stop the host CMS (next-server on 3002) first, otherwise the port is taken.
|
||||
network_mode: host
|
||||
restart: unless-stopped
|
||||
env_file:
|
||||
- .env
|
||||
volumes:
|
||||
# ~3GB client assets live on the host; mount them read-only into the container
|
||||
- ./public/nitro-assets:/app/public/nitro-assets:ro
|
||||
- ./public/swf:/app/public/swf:ro
|
||||
# Runtime uploaded media (persistent on the host)
|
||||
# ── Write targets (runtime imports/uploads, persistent on the host) ──
|
||||
# The CMS writes imported furni/figures/pets/effects here (see
|
||||
# src/lib/services/furni-asset-dirs.ts). These must be RW, and owned by
|
||||
# UID/GID 33 (www-data) on the host so the container user can write to them:
|
||||
# sudo chown -R 33:33 ./public/nitro-assets ./public/swf ./storage
|
||||
- ./public/nitro-assets:/app/public/nitro-assets
|
||||
- ./public/swf:/app/public/swf
|
||||
# Runtime uploaded media (persistent on the host).
|
||||
- ./storage:/app/storage
|
||||
|
||||
# ── Shared gamedata (absolute path the CMS hardcodes & writes to) ──
|
||||
# src/lib/services/furni-asset-dirs.ts: `DEFAULT_GAMEDATA_ROOT =
|
||||
# /var/www/Gamedata`. nginx on the host also serves /gamedata/ from this
|
||||
# same directory, so mount it into the container at the same absolute path.
|
||||
# Must be RW so furniture/badge imports can write mirrors to it.
|
||||
- /var/www/Gamedata:/var/www/Gamedata
|
||||
|
||||
healthcheck:
|
||||
test: ["CMD", "node", "-e", "fetch('http://localhost:3002/api/health').then(r=>{if(!r.ok)process.exit(1)}).catch(()=>process.exit(1))"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
start_period: 40s
|
||||
mem_limit: 2g
|
||||
|
||||
# ── Opt-in: Octane-Renderer (Habbo avatar imager) ──
|
||||
# Serves /imaging on port 3030 (the CMS proxies /imaging to it). Renders
|
||||
# avatars into /var/www/Gamedata/habbo-imaging, so it needs RW access.
|
||||
# Disabled by default — uncomment to run the renderer as a container.
|
||||
# imager:
|
||||
# build:
|
||||
# context: /var/www/Octane-Renderer
|
||||
# container_name: epicnext-octane-renderer
|
||||
# ports:
|
||||
# - "3030:3030"
|
||||
# restart: unless-stopped
|
||||
# volumes:
|
||||
# - /var/www/Gamedata:/var/www/Gamedata
|
||||
Reference in new issue
Block a user