Files
vigilcare-clinical/docker-compose.prod.yml
T
Trent 1ade75b635
CI / backend (push) Successful in 10m2s
CI / frontend (push) Successful in 1m56s
Update for dns changes
2026-08-11 04:32:48 +08:00

135 lines
5.1 KiB
YAML

# Production overlay. Runs ONLY the three application containers — Postgres,
# Redis, Seq, Kafka, Elasticsearch, RabbitMQ, MinIO, Prometheus and Grafana are
# pre-existing external services referenced through .env.
#
# docker compose -f docker-compose.prod.yml --env-file .env up -d
#
# Does not extend docker-compose.yml. Local-dev infra stays in that file;
# this one ships only the three deployable apps.
name: vigilcare
services:
api:
image: ${REGISTRY}/clinical-api:${IMAGE_TAG}
container_name: vigilcare_api
restart: unless-stopped
ports:
- "${API_PORT:-5270}:8080"
environment:
ASPNETCORE_ENVIRONMENT: Production
ConnectionStrings__DefaultConnection: "${PG_CONNECTION}"
Redis__ConnectionString: "${REDIS_CONNECTION}"
Seq__ServerUrl: "${SEQ_URL}"
Serilog__WriteTo__1__Args__serverUrl: "${SEQ_URL}"
Serilog__WriteTo__1__Args__apiKey: "${SEQ_API_KEY}"
Kafka__BootstrapServers: "${KAFKA_BOOTSTRAP}"
Kafka__ReplicationFactor: "${KAFKA_REPLICATION_FACTOR:-3}"
Kafka__SecurityProtocol: "${KAFKA_SECURITY_PROTOCOL:-Plaintext}"
Kafka__SaslMechanism: "${KAFKA_SASL_MECHANISM:-}"
Kafka__SaslUsername: "${KAFKA_SASL_USERNAME:-}"
Kafka__SaslPassword: "${KAFKA_SASL_PASSWORD:-}"
Elasticsearch__Uri: "${ES_URI}"
Elasticsearch__Username: "${ES_USERNAME:-}"
Elasticsearch__Password: "${ES_PASSWORD:-}"
Elasticsearch__ApiKey: "${ES_API_KEY:-}"
RabbitMq__Host: "${RABBITMQ_HOST}"
RabbitMq__Port: "${RABBITMQ_PORT:-5672}"
RabbitMq__Username: "${RABBITMQ_USERNAME}"
RabbitMq__Password: "${RABBITMQ_PASSWORD}"
RabbitMq__UseSsl: "${RABBITMQ_USE_SSL:-true}"
Minio__Endpoint: "${MINIO_ENDPOINT}"
Minio__AccessKey: "${MINIO_ACCESS_KEY}"
Minio__SecretKey: "${MINIO_SECRET_KEY}"
Minio__UseSSL: "${MINIO_USE_SSL:-true}"
Jwt__SigningKey: "${JWT_SIGNING_KEY}"
Jwt__Issuer: "${JWT_ISSUER:-VigilCareClinical}"
Jwt__Audience: "${JWT_AUDIENCE:-VigilCareClinical.Dashboard}"
PhiEncryption__SearchTokenKey: "${PHI_SEARCH_TOKEN_KEY}"
DataProtection__KeyPath: "/app/data-protection-keys"
ApiKey__Gateway: "${GATEWAY_API_KEY}"
Fhir__ApiKey: "${FHIR_API_KEY}"
Dashboard__CorsOrigins__0: "${DASHBOARD_ORIGIN}"
Seeding__EnableDemoData: "false"
Swagger__Enabled: "false"
volumes:
# CRITICAL: the Data Protection keyring encrypts patient PHI. If this
# volume is lost, every encrypted patient record becomes unreadable.
# With `name: vigilcare` above, Docker creates vigilcare_dp_keys.
# Backed up by scripts/backup-dp-keys.sh — see Step 10.
- dp_keys:/app/data-protection-keys
networks:
- vigilcare_prod
- monitoring
- shared-services
logging:
driver: json-file
options: { max-size: "50m", max-file: "5" }
deploy:
resources:
limits: { memory: 2G }
gateway:
image: ${REGISTRY}/ward-gateway:${IMAGE_TAG}
container_name: vigilcare_gateway
restart: unless-stopped
ports:
- "${GATEWAY_PORT:-5081}:8080"
environment:
ASPNETCORE_ENVIRONMENT: Production
ConnectionStrings__GatewayDb: "${GATEWAY_PG_CONNECTION}"
Redis__ConnectionString: "${GATEWAY_REDIS_CONNECTION}"
RabbitMq__Host: "${GATEWAY_RABBITMQ_HOST}"
RabbitMq__Port: "${GATEWAY_RABBITMQ_PORT:-5672}"
RabbitMq__Username: "${GATEWAY_RABBITMQ_USERNAME}"
RabbitMq__Password: "${GATEWAY_RABBITMQ_PASSWORD}"
RabbitMq__UseSsl: "${GATEWAY_RABBITMQ_USE_SSL:-true}"
CentralApi__BaseUrl: "http://api:8080"
Gateway__GatewayId: "${GATEWAY_ID}"
Gateway__SiteId: "${GATEWAY_SITE_ID}"
Gateway__Department: "${GATEWAY_DEPARTMENT:-ICU}"
ApiKey__Gateway: "${GATEWAY_API_KEY}"
Dashboard__CorsOrigins__0: "${DASHBOARD_ORIGIN}"
Jwt__SigningKey: "${GATEWAY_JWT_SIGNING_KEY}"
Jwt__Issuer: "${GATEWAY_JWT_ISSUER:-vigilcare-gateway}"
Jwt__Audience: "${GATEWAY_JWT_AUDIENCE:-vigilcare-dashboard}"
depends_on:
api:
condition: service_healthy
networks:
- vigilcare_prod
- monitoring
- shared-services
logging:
driver: json-file
options: { max-size: "50m", max-file: "5" }
dashboard:
image: ${REGISTRY}/dashboard:${IMAGE_TAG}
container_name: vigilcare_dashboard
restart: unless-stopped
ports:
- "${DASHBOARD_PORT:-8080}:80"
networks:
- vigilcare_prod
- monitoring
logging:
driver: json-file
options: { max-size: "20m", max-file: "3" }
volumes:
dp_keys:
# Named volume backed by a host bind is preferable if the host has a
# backed-up filesystem path; see Step 10. Full Docker name: vigilcare_dp_keys.
networks:
vigilcare_prod:
driver: bridge
monitoring:
external: true
# Shared network owned by the Postgres/Redis compose project (it defines and
# creates "shared-services" via its own `docker compose up`). This project only
# consumes it, so the Postgres/Redis stack must already be running the first
# time this stack is deployed, or `docker compose up` here will fail to find it.
shared-services:
external: true