Repository navigation
Expand file tree
/
Copy pathcompose.yaml
More file actions
42 lines (42 loc) · 1.7 KB
/
Copy pathcompose.yaml
File metadata and controls
42 lines (42 loc) · 1.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
services:
dev-box:
# Name of the image to run. Left empty, the local build keeps Compose's
# default name. Set to the published image (ghcr.io/c4software/dev-box,
# built by the GitHub workflow) to skip the build:
# `docker compose pull && docker compose up -d`.
image: ${DEVBOX_IMAGE:-dev-box-dev-box}
build:
context: .
# Repo commit baked into the image (/etc/devbox/release): the update
# check inside the box compares it with the remote repo. Taken from the
# environment when set; left empty, the Dockerfile reads them from the
# clone itself.
args:
DEVBOX_COMMIT: ${DEVBOX_COMMIT:-}
DEVBOX_REPO: ${DEVBOX_REPO:-}
DEVBOX_BRANCH: ${DEVBOX_BRANCH:-}
DEVBOX_VERSION: ${DEVBOX_VERSION:-}
container_name: dev-box
hostname: ${TS_HOSTNAME:-dev-box}
init: true
restart: unless-stopped
env_file: .env
# Only used when TS_DISABLE=true (sshd); with no listener the port is
# simply closed. Bound to the host loopback by default.
ports:
- "${SSH_BIND:-127.0.0.1}:${SSH_PORT:-2222}:22"
volumes:
- ./data/home:/home/${USER_NAME:-dev}
- ${PROJECTS_DIR:-./data/projets}:/home/${USER_NAME:-dev}/projets
- ./data/tailscale:/var/lib/tailscale
devices:
# /dev/net/tun: tailscaled (userspace networking is off)
- /dev/net/tun
cap_add:
# tailscaled: tun interface, routes, filtering
- NET_ADMIN
- NET_RAW
# Rootless podman inside the box: off by default, because it forces the
# isolation of the container open (seccomp, /proc/sys, AppArmor). Settings
# and explanations in compose.override.example.yaml, turned on with
# PODMAN_ENABLE=true in .env.