Adds a bws-CLI build stage to the Dockerfile and a docker-entrypoint.sh that runs `bws run -- node server.js` when BWS_ACCESS_TOKEN is set, falling back to a plain `node server.js` start when it's not. Lets AWS Route 53 credentials (and any future BWS-managed secret) reach the container without ever being written to the committed .env file. Fixed during phase 24 verification: - The bws CLI config only set state_dir; bws 2.x requires server_base (or server_identity) even for the default Bitwarden cloud instance, which crash-looped the container on every start. Added server_base = "https://vault.bitwarden.com". - docker-compose.yml's app.environment block re-declared BWS_ACCESS_TOKEN/BWS_PROJECT_ID as ${VAR:-} substitutions, which resolve against the root .env (not .env.local) and silently overrode the real token with an empty string. Removed the redundant re-declaration — env_file: .env.local already injects them. Verified live: pulse-app rebuilt and restarted with both fixes, AWS credentials confirmed reaching the Node process via BWS injection. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
176 lines
5.5 KiB
YAML
176 lines
5.5 KiB
YAML
services:
|
|
# Redis cache service on custom port 6380 (instead of default 6379)
|
|
redis:
|
|
image: redis:7-alpine
|
|
container_name: pulse-redis
|
|
restart: unless-stopped
|
|
ports:
|
|
- "6380:6379"
|
|
volumes:
|
|
- redis_data:/data
|
|
command: redis-server --appendonly yes
|
|
healthcheck:
|
|
test: ["CMD", "redis-cli", "ping"]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 5
|
|
logging:
|
|
driver: json-file
|
|
options:
|
|
max-size: "10m"
|
|
max-file: "5"
|
|
|
|
# PostgreSQL database for Autotask sync
|
|
postgres:
|
|
image: postgres:16-alpine
|
|
container_name: pulse-postgres
|
|
restart: unless-stopped
|
|
ports:
|
|
- "5432:5432"
|
|
env_file:
|
|
- .env.local
|
|
environment:
|
|
POSTGRES_DB: ${POSTGRES_DB:-pulse_autotask}
|
|
POSTGRES_USER: ${POSTGRES_USER:-pulse_user}
|
|
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
|
volumes:
|
|
- postgres_data:/var/lib/postgresql/data
|
|
- ./migrations:/docker-entrypoint-initdb.d:ro
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-pulse_user} -d ${POSTGRES_DB:-pulse_autotask}"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
logging:
|
|
driver: json-file
|
|
options:
|
|
max-size: "10m"
|
|
max-file: "5"
|
|
|
|
# Next.js application on port 3100 (instead of 3000)
|
|
app:
|
|
build:
|
|
context: .
|
|
dockerfile: Dockerfile
|
|
container_name: pulse-app
|
|
restart: unless-stopped
|
|
ports:
|
|
- "3100:3100"
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.pulse.rule=Host(`pulse.wulfconsulting.cloud`)"
|
|
- "traefik.http.routers.pulse.entrypoints=websecure"
|
|
- "traefik.http.routers.pulse.tls=true"
|
|
- "traefik.http.routers.pulse.tls.certresolver=cloudflare"
|
|
- "traefik.http.services.pulse.loadbalancer.server.port=3100"
|
|
- "traefik.docker.network=frontend"
|
|
networks:
|
|
- default
|
|
- frontend
|
|
env_file:
|
|
- .env.local
|
|
environment:
|
|
# Application settings
|
|
NODE_ENV: production
|
|
PORT: 3100
|
|
|
|
# Redis configuration
|
|
REDIS_URL: redis://redis:6379
|
|
|
|
# Autotask API Configuration
|
|
AUTOTASK_API_URL: ${AUTOTASK_API_URL}
|
|
AUTOTASK_USERNAME: ${AUTOTASK_USERNAME}
|
|
AUTOTASK_SECRET: ${AUTOTASK_SECRET}
|
|
AUTOTASK_API_INTEGRATION_CODE: ${AUTOTASK_API_INTEGRATION_CODE}
|
|
|
|
# Datto RMM API Configuration
|
|
DATTO_RMM_API_URL: ${DATTO_RMM_API_URL}
|
|
DATTO_RMM_API_KEY: ${DATTO_RMM_API_KEY}
|
|
DATTO_RMM_API_SECRET: ${DATTO_RMM_API_SECRET}
|
|
|
|
# Addigy API Configuration
|
|
ADDIGY_API_URL: ${ADDIGY_API_URL}
|
|
ADDIGY_API_TOKEN: ${ADDIGY_API_TOKEN}
|
|
ADDIGY_ORG_ID: ${ADDIGY_ORG_ID}
|
|
|
|
# Auvik API Configuration
|
|
AUVIK_API_URL: ${AUVIK_API_URL}
|
|
AUVIK_API_USER: ${AUVIK_API_USER}
|
|
AUVIK_API_KEY: ${AUVIK_API_KEY}
|
|
|
|
# SalesBldr API Configuration
|
|
SALESBLDR_API_URL: ${SALESBLDR_API_URL}
|
|
SALESBLDR_API_KEY: ${SALESBLDR_API_KEY}
|
|
|
|
# Veeam VSPC Configuration
|
|
VEEAM_VSPC_URL: ${VEEAM_VSPC_URL}
|
|
VEEAM_VSPC_API_KEY: ${VEEAM_VSPC_API_KEY}
|
|
VEEAM_RPO_SHADOW_MODE: "true"
|
|
ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY}
|
|
|
|
# Zabbix API Configuration
|
|
ZABBIX_API_URL: ${ZABBIX_API_URL}
|
|
ZABBIX_API_TOKEN: ${ZABBIX_API_TOKEN}
|
|
|
|
# ipinfo.io API token (optional)
|
|
IPINFO_TOKEN: ${IPINFO_TOKEN:-}
|
|
|
|
# Mimecast API Configuration
|
|
MIMECAST_CLIENT_ID: ${MIMECAST_CLIENT_ID}
|
|
MIMECAST_CLIENT_SECRET: ${MIMECAST_CLIENT_SECRET}
|
|
MIMECAST_BASE_URL: ${MIMECAST_BASE_URL:-https://api.services.mimecast.com}
|
|
MIMECAST_ACCOUNT_CODE: ${MIMECAST_ACCOUNT_CODE}
|
|
|
|
# IT Glue Configuration
|
|
ITGLUE_API_KEY: ${ITGLUE_API_KEY}
|
|
|
|
# Backblaze B2 Storage (S3-compatible)
|
|
B2_KEY_ID: ${B2_KEY_ID}
|
|
B2_APP_KEY: ${B2_APP_KEY}
|
|
B2_BUCKET: ${B2_BUCKET:-wulf-audits}
|
|
B2_REGION: ${B2_REGION:-us-west-002}
|
|
B2_ENDPOINT: ${B2_ENDPOINT:-s3.us-west-002.backblazeb2.com}
|
|
|
|
# Webhook Configuration
|
|
WEBHOOK_BASE_URL: ${WEBHOOK_BASE_URL:-https://pulse.wulfconsulting.cloud}
|
|
AUTOTASK_WEBHOOK_SECRET: ${AUTOTASK_WEBHOOK_SECRET}
|
|
|
|
# PostgreSQL Configuration
|
|
POSTGRES_HOST: postgres
|
|
POSTGRES_PORT: 5432
|
|
POSTGRES_DB: ${POSTGRES_DB:-pulse_autotask}
|
|
POSTGRES_USER: ${POSTGRES_USER:-pulse_user}
|
|
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-your_secure_password_here_change_in_production}
|
|
DATABASE_URL: postgresql://${POSTGRES_USER:-pulse_user}:${POSTGRES_PASSWORD:-your_secure_password_here_change_in_production}@postgres:5432/${POSTGRES_DB:-pulse_autotask}
|
|
|
|
# Bitwarden Secrets Manager (optional) — deliberately NOT re-declared here.
|
|
# env_file: .env.local already injects BWS_ACCESS_TOKEN/BWS_PROJECT_ID directly.
|
|
# Re-declaring them as ${VAR:-} substitutions resolves against the root .env /
|
|
# shell env (not .env.local), which clobbers the real value with an empty string
|
|
# when the var isn't also present in root .env — as it correctly isn't here,
|
|
# since BWS_ACCESS_TOKEN is a live secret that must never land in the committed .env.
|
|
depends_on:
|
|
redis:
|
|
condition: service_healthy
|
|
postgres:
|
|
condition: service_healthy
|
|
volumes:
|
|
# Mount .env.local for development (remove in production)
|
|
- ./.env.local:/app/.env.local:ro
|
|
logging:
|
|
driver: json-file
|
|
options:
|
|
max-size: "10m"
|
|
max-file: "5"
|
|
|
|
volumes:
|
|
redis_data:
|
|
driver: local
|
|
postgres_data:
|
|
driver: local
|
|
|
|
networks:
|
|
default:
|
|
name: pulse-network
|
|
frontend:
|
|
external: true
|