126 lines
4.6 KiB
YAML
126 lines
4.6 KiB
YAML
# Production overlay. Runs ONLY the three application containers — Postgres,
|
|
# Redis, Seq, Kafka, Elasticsearch, RabbitMQ, MinIO, Prometheus and Grafana are
|
|
# pre-existing external services referenced through .env.
|
|
#
|
|
# docker compose -f docker-compose.prod.yml --env-file .env up -d
|
|
#
|
|
# Does not extend docker-compose.yml. Local-dev infra stays in that file;
|
|
# this one ships only the three deployable apps.
|
|
|
|
name: vigilcare
|
|
|
|
services:
|
|
api:
|
|
image: ${REGISTRY}/clinical-api:${IMAGE_TAG}
|
|
container_name: vigilcare_api
|
|
restart: unless-stopped
|
|
ports:
|
|
- "${API_PORT:-5270}:8080"
|
|
environment:
|
|
ASPNETCORE_ENVIRONMENT: Production
|
|
ConnectionStrings__DefaultConnection: "${PG_CONNECTION}"
|
|
Redis__ConnectionString: "${REDIS_CONNECTION}"
|
|
Seq__ServerUrl: "${SEQ_URL}"
|
|
Serilog__WriteTo__1__Args__serverUrl: "${SEQ_URL}"
|
|
Serilog__WriteTo__1__Args__apiKey: "${SEQ_API_KEY}"
|
|
Kafka__BootstrapServers: "${KAFKA_BOOTSTRAP}"
|
|
Kafka__ReplicationFactor: "${KAFKA_REPLICATION_FACTOR:-3}"
|
|
Kafka__SecurityProtocol: "${KAFKA_SECURITY_PROTOCOL:-Plaintext}"
|
|
Kafka__SaslMechanism: "${KAFKA_SASL_MECHANISM:-}"
|
|
Kafka__SaslUsername: "${KAFKA_SASL_USERNAME:-}"
|
|
Kafka__SaslPassword: "${KAFKA_SASL_PASSWORD:-}"
|
|
Elasticsearch__Uri: "${ES_URI}"
|
|
Elasticsearch__Username: "${ES_USERNAME:-}"
|
|
Elasticsearch__Password: "${ES_PASSWORD:-}"
|
|
Elasticsearch__ApiKey: "${ES_API_KEY:-}"
|
|
RabbitMq__Host: "${RABBITMQ_HOST}"
|
|
RabbitMq__Port: "${RABBITMQ_PORT:-5672}"
|
|
RabbitMq__Username: "${RABBITMQ_USERNAME}"
|
|
RabbitMq__Password: "${RABBITMQ_PASSWORD}"
|
|
RabbitMq__UseSsl: "${RABBITMQ_USE_SSL:-true}"
|
|
Minio__Endpoint: "${MINIO_ENDPOINT}"
|
|
Minio__AccessKey: "${MINIO_ACCESS_KEY}"
|
|
Minio__SecretKey: "${MINIO_SECRET_KEY}"
|
|
Minio__UseSSL: "${MINIO_USE_SSL:-true}"
|
|
Jwt__SigningKey: "${JWT_SIGNING_KEY}"
|
|
Jwt__Issuer: "${JWT_ISSUER:-VigilCareClinical}"
|
|
Jwt__Audience: "${JWT_AUDIENCE:-VigilCareClinical.Dashboard}"
|
|
PhiEncryption__SearchTokenKey: "${PHI_SEARCH_TOKEN_KEY}"
|
|
DataProtection__KeyPath: "/app/data-protection-keys"
|
|
ApiKey__Gateway: "${GATEWAY_API_KEY}"
|
|
Fhir__ApiKey: "${FHIR_API_KEY}"
|
|
Dashboard__CorsOrigins__0: "${DASHBOARD_ORIGIN}"
|
|
Seeding__EnableDemoData: "false"
|
|
Swagger__Enabled: "false"
|
|
volumes:
|
|
# CRITICAL: the Data Protection keyring encrypts patient PHI. If this
|
|
# volume is lost, every encrypted patient record becomes unreadable.
|
|
# With `name: vigilcare` above, Docker creates vigilcare_dp_keys.
|
|
# Backed up by scripts/backup-dp-keys.sh — see Step 10.
|
|
- dp_keys:/app/data-protection-keys
|
|
networks:
|
|
- vigilcare_prod
|
|
- monitoring
|
|
logging:
|
|
driver: json-file
|
|
options: { max-size: "50m", max-file: "5" }
|
|
deploy:
|
|
resources:
|
|
limits: { memory: 2G }
|
|
|
|
gateway:
|
|
image: ${REGISTRY}/ward-gateway:${IMAGE_TAG}
|
|
container_name: vigilcare_gateway
|
|
restart: unless-stopped
|
|
ports:
|
|
- "${GATEWAY_PORT:-5081}:8080"
|
|
environment:
|
|
ASPNETCORE_ENVIRONMENT: Production
|
|
ConnectionStrings__GatewayDb: "${GATEWAY_PG_CONNECTION}"
|
|
Redis__ConnectionString: "${GATEWAY_REDIS_CONNECTION}"
|
|
RabbitMq__Host: "${GATEWAY_RABBITMQ_HOST}"
|
|
RabbitMq__Port: "${GATEWAY_RABBITMQ_PORT:-5672}"
|
|
RabbitMq__Username: "${GATEWAY_RABBITMQ_USERNAME}"
|
|
RabbitMq__Password: "${GATEWAY_RABBITMQ_PASSWORD}"
|
|
RabbitMq__UseSsl: "${GATEWAY_RABBITMQ_USE_SSL:-true}"
|
|
CentralApi__BaseUrl: "http://api:8080"
|
|
Gateway__GatewayId: "${GATEWAY_ID}"
|
|
Gateway__SiteId: "${GATEWAY_SITE_ID}"
|
|
Gateway__Department: "${GATEWAY_DEPARTMENT:-ICU}"
|
|
ApiKey__Gateway: "${GATEWAY_API_KEY}"
|
|
Jwt__SigningKey: "${GATEWAY_JWT_SIGNING_KEY}"
|
|
Jwt__Issuer: "${GATEWAY_JWT_ISSUER:-vigilcare-gateway}"
|
|
Jwt__Audience: "${GATEWAY_JWT_AUDIENCE:-vigilcare-dashboard}"
|
|
depends_on:
|
|
api:
|
|
condition: service_healthy
|
|
networks:
|
|
- vigilcare_prod
|
|
- monitoring
|
|
logging:
|
|
driver: json-file
|
|
options: { max-size: "50m", max-file: "5" }
|
|
|
|
dashboard:
|
|
image: ${REGISTRY}/dashboard:${IMAGE_TAG}
|
|
container_name: vigilcare_dashboard
|
|
restart: unless-stopped
|
|
ports:
|
|
- "${DASHBOARD_PORT:-8080}:80"
|
|
networks:
|
|
- vigilcare_prod
|
|
- monitoring
|
|
logging:
|
|
driver: json-file
|
|
options: { max-size: "20m", max-file: "3" }
|
|
|
|
volumes:
|
|
dp_keys:
|
|
# Named volume backed by a host bind is preferable if the host has a
|
|
# backed-up filesystem path; see Step 10. Full Docker name: vigilcare_dp_keys.
|
|
|
|
networks:
|
|
vigilcare_prod:
|
|
driver: bridge
|
|
monitoring:
|
|
external: true |