gitea, umami, influxdb, icecast and mailu require a secret and keep each of theirs under a local name (novox/hq ADR 0094); the broker account stays their own. The route proxy's recipe starts FROM the bases its manifest declares (ADR 0097).
153 lines
3.7 KiB
JSON
153 lines
3.7 KiB
JSON
{
|
|
"module": "umami",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"requires": [
|
|
"postgres-database",
|
|
"route",
|
|
"secret"
|
|
],
|
|
"contributes": {
|
|
"postgres-database": {
|
|
"name": "umami"
|
|
},
|
|
"route": {
|
|
"label": "umami",
|
|
"port": 3000
|
|
}
|
|
},
|
|
"binds": {
|
|
"postgres-database": "/var/lib/umami/database.json",
|
|
"route": "/var/lib/umami/route.json"
|
|
},
|
|
"secrets": {
|
|
"postgres-database": "/var/lib/umami/database.secret",
|
|
"secret": {
|
|
"app-secret": "/var/lib/umami/app.secret",
|
|
"admin": "/var/lib/umami/admin.secret"
|
|
}
|
|
},
|
|
"provides": [
|
|
{
|
|
"name": "analytics",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"serves": {
|
|
"analytics": {}
|
|
},
|
|
"receives": {
|
|
"analytics": "/var/lib/umami/grants/mesh.json"
|
|
},
|
|
"grants": {
|
|
"analytics": "/var/lib/umami/grants"
|
|
},
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/umami/broker"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 3000,
|
|
"protocol": "tcp",
|
|
"from": "anywhere",
|
|
"why": "one port serves two surfaces: the dashboard (the proxy gates it to the mesh) and the public collection endpoint that the browsers of every tracked site POST to \u2014 so the port itself must be reachable from anywhere"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/umami",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/umami",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"path": "/var/lib/umami/grants",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "/var/lib/umami/server.env",
|
|
"mode": "0600",
|
|
"content": "DATABASE_URL=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nDATABASE_TYPE=postgresql\nAPP_SECRET=${secret:app-secret}\n"
|
|
},
|
|
{
|
|
"id": "provisioner-env",
|
|
"type": "file",
|
|
"path": "/var/lib/umami/provisioner.env",
|
|
"mode": "0600",
|
|
"content": "MESH_PROVISION_UMAMI_URL=http://umami:3000\nGRANTS=/var/lib/umami/grants\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "umami"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "umami",
|
|
"image": "ghcr.io/umami-software/umami@sha256:fa32d116cf20cad52cbc3fad9a63b46e7fa02299d8f967168eb453d49c476b4a",
|
|
"network": "umami",
|
|
"env-file": [
|
|
"/var/lib/umami/server.env"
|
|
],
|
|
"ports": [
|
|
"3000"
|
|
],
|
|
"secrets-in-environment": "a Next.js/Prisma application: DATABASE_URL and APP_SECRET are read from the environment only; not convertible"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-umami",
|
|
"network": "umami",
|
|
"volumes": [
|
|
"/var/lib/mesh/umami/broker:/run/secrets/broker:ro",
|
|
"/var/lib/umami/grants:/var/lib/umami/grants",
|
|
"/var/lib/umami/admin.secret:/run/secrets/admin:ro"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_RECEIVES": "/var/lib/umami/grants/mesh.json",
|
|
"MESH_UMAMI_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
|
|
},
|
|
"env-file": [
|
|
"/var/lib/umami/provisioner.env"
|
|
],
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|