- Clear default passwords in all service configs, require env vars
- Add JWT auth + role middleware to WebSocket endpoints
- Add origin whitelist to WebSocket upgrader (CORS protection)
- Fix goroutine leak in WS proxy (double errCh read)
- Update docker-compose to require secrets via ${VAR:?...} syntax
- Mark deprecated k8s configmap passwords as REPLACE_AT_DEPLOY_TIME
Co-Authored-By: Claude <noreply@anthropic.com>
129 lines
3.4 KiB
YAML
129 lines
3.4 KiB
YAML
# iloom 集成模式 — 连接 muyu-apiserver 的 MySQL 和 gRPC
|
||
# 用法:docker compose -f docker-compose.integrated.yml up -d
|
||
|
||
services:
|
||
gateway:
|
||
build:
|
||
context: .
|
||
dockerfile: gateway/Dockerfile
|
||
ports:
|
||
- "${GATEWAY_PORT:-8080}:8080"
|
||
environment:
|
||
- PORT=8080
|
||
- JWT_SECRET=${JWT_SECRET:?Set JWT_SECRET in .env}
|
||
- AUTH_SERVICE_URL=http://auth-service:8081
|
||
- PURCHASER_SERVICE_URL=http://purchaser-service:8082
|
||
- TEXTILE_SERVICE_URL=http://textile-service:8083
|
||
- WASHING_SERVICE_URL=http://washing-service:8084
|
||
- ALLOW_ORIGINS=${ALLOW_ORIGINS:-http://localhost:3015}
|
||
depends_on:
|
||
auth-service:
|
||
condition: service_healthy
|
||
purchaser-service:
|
||
condition: service_healthy
|
||
textile-service:
|
||
condition: service_healthy
|
||
washing-service:
|
||
condition: service_healthy
|
||
networks:
|
||
- muyu-net
|
||
- default
|
||
|
||
auth-service:
|
||
build:
|
||
context: .
|
||
dockerfile: auth-service/Dockerfile
|
||
ports:
|
||
- "${AUTH_SERVICE_PORT:-8081}:8081"
|
||
environment:
|
||
- PORT=8081
|
||
- DB_DSN=${DB_DSN:?Set DB_DSN in .env}
|
||
- JWT_SECRET=${JWT_SECRET:?Set JWT_SECRET in .env}
|
||
- JWT_REFRESH_SECRET=${JWT_REFRESH_SECRET:?Set JWT_REFRESH_SECRET in .env}
|
||
- MUYU_SYSTEM_RPC_ADDR=muyu-system-rpc:9001
|
||
healthcheck:
|
||
test: ["CMD", "wget", "-qO-", "http://localhost:8081/health"]
|
||
interval: 10s
|
||
timeout: 3s
|
||
retries: 5
|
||
networks:
|
||
- muyu-net
|
||
- default
|
||
|
||
purchaser-service:
|
||
build:
|
||
context: .
|
||
dockerfile: purchaser-service/Dockerfile
|
||
ports:
|
||
- "${PURCHASER_SERVICE_PORT:-8082}:8082"
|
||
environment:
|
||
- PORT=8082
|
||
- DB_DSN=${DB_DSN:?Set DB_DSN in .env}
|
||
- INTERNAL_SERVICE_KEY=${INTERNAL_SERVICE_KEY:?Set INTERNAL_SERVICE_KEY in .env}
|
||
- MUYU_INVENTORY_RPC_ADDR=muyu-inventory-rpc:9002
|
||
healthcheck:
|
||
test: ["CMD", "wget", "-qO-", "http://localhost:8082/health"]
|
||
interval: 10s
|
||
timeout: 3s
|
||
retries: 5
|
||
networks:
|
||
- muyu-net
|
||
- default
|
||
|
||
textile-service:
|
||
build:
|
||
context: .
|
||
dockerfile: textile-service/Dockerfile
|
||
ports:
|
||
- "${TEXTILE_SERVICE_PORT:-8083}:8083"
|
||
environment:
|
||
- PORT=8083
|
||
- DB_DSN=${DB_DSN:?Set DB_DSN in .env}
|
||
- INTERNAL_SERVICE_KEY=${INTERNAL_SERVICE_KEY:?Set INTERNAL_SERVICE_KEY in .env}
|
||
- PURCHASER_SERVICE_URL=http://purchaser-service:8082
|
||
healthcheck:
|
||
test: ["CMD", "wget", "-qO-", "http://localhost:8083/health"]
|
||
interval: 10s
|
||
timeout: 3s
|
||
retries: 5
|
||
networks:
|
||
- muyu-net
|
||
- default
|
||
|
||
washing-service:
|
||
build:
|
||
context: .
|
||
dockerfile: washing-service/Dockerfile
|
||
ports:
|
||
- "${WASHING_SERVICE_PORT:-8084}:8084"
|
||
environment:
|
||
- PORT=8084
|
||
- DB_DSN=${DB_DSN:?Set DB_DSN in .env}
|
||
- INTERNAL_SERVICE_KEY=${INTERNAL_SERVICE_KEY:?Set INTERNAL_SERVICE_KEY in .env}
|
||
- PURCHASER_SERVICE_URL=http://purchaser-service:8082
|
||
healthcheck:
|
||
test: ["CMD", "wget", "-qO-", "http://localhost:8084/health"]
|
||
interval: 10s
|
||
timeout: 3s
|
||
retries: 5
|
||
networks:
|
||
- muyu-net
|
||
- default
|
||
|
||
frontend:
|
||
build:
|
||
context: .
|
||
dockerfile: iloom-flatten/Dockerfile
|
||
ports:
|
||
- "${FRONTEND_PORT:-3015}:3015"
|
||
depends_on:
|
||
gateway:
|
||
condition: service_started
|
||
networks:
|
||
- default
|
||
|
||
networks:
|
||
muyu-net:
|
||
external: true
|
||
name: deploy_default
|