-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
58 lines (54 loc) · 1.6 KB
/
docker-compose.yml
File metadata and controls
58 lines (54 loc) · 1.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
version: '3.8'
services:
backend:
build:
context: .
dockerfile: Dockerfile
container_name: infra-scan-backend
restart: always
command: web
environment:
- FLASK_ENV=production
- DOCKER_HUB_USERNAME=${DOCKER_HUB_USERNAME}
- DOCKER_HUB_PASSWORD=${DOCKER_HUB_PASSWORD}
- SLACK_WEBHOOK_URL=${SLACK_WEBHOOK_URL}
- GOOGLE_TAG_ID=${GOOGLE_TAG_ID}
- CONTAINER_SCANNER=${CONTAINER_SCANNER:-docker-scout}
- CLEANUP_SCANNED_IMAGES=${CLEANUP_SCANNED_IMAGES:-true}
volumes:
- ./static:/opt/infrascan/static
- ./data:/opt/infrascan/data
- ./scan_results:/opt/infrascan/scan_results
- /var/run/docker.sock:/var/run/docker.sock # Docker socket for Docker Scout scanning
networks:
- app-network
nginx:
image: nginx:alpine
container_name: infra-scan-nginx
restart: always
ports:
- "80:80"
- "443:443"
volumes:
- ./nginx/nginx.conf:/etc/nginx/conf.d/default.conf:ro
- ./nginx/security_headers.inc:/etc/nginx/security_headers.inc:ro
- ./static:/opt/infrascan/static:ro
- ./certbot/conf:/etc/letsencrypt:ro
- ./certbot/www:/var/www/certbot:ro
depends_on:
- backend
networks:
- app-network
certbot:
image: certbot/certbot
container_name: infra-scan-certbot
restart: always
volumes:
- ./certbot/conf:/etc/letsencrypt
- ./certbot/www:/var/www/certbot
entrypoint: "/bin/sh -c 'trap exit TERM; while :; do certbot renew; sleep 12h & wait $${!}; done'"
networks:
- app-network
networks:
app-network:
driver: bridge