From 044a2c101d6dcae2d4d64478f202a89b78dfb7bf Mon Sep 17 00:00:00 2001 From: Hampus Date: Wed, 9 Sep 2026 01:17:58 +0200 Subject: [PATCH] feat(self-hosting): make the bundled services configurable (#2621) --- deploy/self-hosting/.env.example | 34 ++++++++++++++ deploy/self-hosting/docker-compose.yml | 45 ++++++++++--------- .../src/content/docs/operator/upgrading.mdx | 4 +- 3 files changed, 62 insertions(+), 21 deletions(-) diff --git a/deploy/self-hosting/.env.example b/deploy/self-hosting/.env.example index ec85e094f..1adb9f849 100644 --- a/deploy/self-hosting/.env.example +++ b/deploy/self-hosting/.env.example @@ -131,6 +131,40 @@ MEILI_MASTER_KEY=CHANGE_ME #FLUXER_S3_PUBLIC_ENDPOINT=https://cdn.example.com #FLUXER_S3_REGION=eu-central-1 #FLUXER_S3_FORCE_PATH_STYLE=false +# Bucket names. The bundled object store creates whichever names these hold, so +# the two stay in step. An object store outside the stack needs the buckets to +# exist already. +#FLUXER_S3_BUCKET_CDN=fluxer +#FLUXER_S3_BUCKET_UPLOADS=fluxer-uploads +#FLUXER_S3_BUCKET_DOWNLOADS=fluxer-downloads +#FLUXER_S3_BUCKET_REPORTS=fluxer-reports +#FLUXER_S3_BUCKET_HARVESTS=fluxer-harvests + +# The rest of the bundled services, pointed somewhere else the same way. Leave a +# line unset and the service in the stack is used. Taking a service out of the +# stack goes in an override file listed in COMPOSE_FILE, because an upgrade +# replaces docker-compose.yml. +#FLUXER_KV_URL=redis://cache.example.com:6379/0 +#FLUXER_NATS_URL=nats://mq.example.com:4222 +#FLUXER_NATS_JETSTREAM_URL=nats://mq.example.com:4222 +#FLUXER_SVC_NATS_URL=nats://mq.example.com:4222 +#FLUXER_SEARCH_URL=https://search.example.com +#FLUXER_LIVEKIT_INTERNAL_URL=http://livekit.example.com:7880 + +# Voice off. The livekit service still runs until an override file takes it out. +#FLUXER_LIVEKIT_ENABLED=false + +# Optional systems, each off unless the instance is configured for it. +#FLUXER_SMS_ENABLED=false +#FLUXER_STRIPE_ENABLED=false +#FLUXER_NCMEC_ENABLED=false +#FLUXER_CLAMAV_ENABLED=false + +# The client address. Set the header name a proxy in front actually writes, and +# turn the trust off when nothing sits in front, because a trusted header an +# attacker can set is a spoofed client address. +#FLUXER_CLIENT_IP_HEADER_NAME=cf-connecting-ip +#FLUXER_TRUST_CLIENT_IP_HEADER=true FLUXER_S3_ACCESS_KEY=fluxer FLUXER_S3_SECRET_KEY=CHANGE_ME diff --git a/deploy/self-hosting/docker-compose.yml b/deploy/self-hosting/docker-compose.yml index 437ba7999..6b63a9edd 100644 --- a/deploy/self-hosting/docker-compose.yml +++ b/deploy/self-hosting/docker-compose.yml @@ -19,20 +19,20 @@ x-fluxer-env: &fluxer-env FLUXER_PUBLIC_SCHEME: ${FLUXER_PUBLIC_SCHEME:-https} FLUXER_PUBLIC_PORT: ${FLUXER_PUBLIC_PORT:-443} FLUXER_PUBLIC_ORIGIN: ${FLUXER_PUBLIC_ORIGIN:-} - FLUXER_TRUST_CLIENT_IP_HEADER: "true" - FLUXER_CLIENT_IP_HEADER_NAME: x-forwarded-for + FLUXER_TRUST_CLIENT_IP_HEADER: "${FLUXER_TRUST_CLIENT_IP_HEADER:-true}" + FLUXER_CLIENT_IP_HEADER_NAME: ${FLUXER_CLIENT_IP_HEADER_NAME:-x-forwarded-for} FLUXER_API_HEADERS_TIMEOUT_MS: ${FLUXER_API_HEADERS_TIMEOUT_MS:-30000} FLUXER_API_REQUEST_TIMEOUT_MS: ${FLUXER_API_REQUEST_TIMEOUT_MS:-120000} - FLUXER_KV_URL: redis://valkey:6379/0 - FLUXER_NATS_URL: nats://nats:4222 - FLUXER_NATS_JETSTREAM_URL: nats://nats:4222 + FLUXER_KV_URL: ${FLUXER_KV_URL:-redis://valkey:6379/0} + FLUXER_NATS_URL: ${FLUXER_NATS_URL:-nats://nats:4222} + FLUXER_NATS_JETSTREAM_URL: ${FLUXER_NATS_JETSTREAM_URL:-${FLUXER_NATS_URL:-nats://nats:4222}} FLUXER_NATS_AUTH_TOKEN: ${FLUXER_NATS_AUTH_TOKEN:-} - FLUXER_SVC_NATS_URL: nats://nats:4222 + FLUXER_SVC_NATS_URL: ${FLUXER_SVC_NATS_URL:-${FLUXER_NATS_URL:-nats://nats:4222}} FLUXER_SVC_SHARD_COUNT: "1" FLUXER_SEARCH_ENGINE: meilisearch - FLUXER_SEARCH_URL: http://meilisearch:7700 + FLUXER_SEARCH_URL: ${FLUXER_SEARCH_URL:-http://meilisearch:7700} FLUXER_SEARCH_API_KEY: ${MEILI_MASTER_KEY:?set MEILI_MASTER_KEY in .env} FLUXER_S3_ENDPOINT: ${FLUXER_S3_ENDPOINT:-http://seaweedfs:8333} @@ -41,20 +41,20 @@ x-fluxer-env: &fluxer-env FLUXER_S3_ACCESS_KEY_ID: ${FLUXER_S3_ACCESS_KEY:?set FLUXER_S3_ACCESS_KEY in .env} FLUXER_S3_SECRET_ACCESS_KEY: ${FLUXER_S3_SECRET_KEY:?set FLUXER_S3_SECRET_KEY in .env} FLUXER_S3_FORCE_PATH_STYLE: "${FLUXER_S3_FORCE_PATH_STYLE:-true}" - FLUXER_S3_BUCKET_CDN: fluxer - FLUXER_S3_BUCKET_UPLOADS: fluxer-uploads - FLUXER_S3_BUCKET_DOWNLOADS: fluxer-downloads - FLUXER_S3_BUCKET_REPORTS: fluxer-reports - FLUXER_S3_BUCKET_HARVESTS: fluxer-harvests + FLUXER_S3_BUCKET_CDN: ${FLUXER_S3_BUCKET_CDN:-fluxer} + FLUXER_S3_BUCKET_UPLOADS: ${FLUXER_S3_BUCKET_UPLOADS:-fluxer-uploads} + FLUXER_S3_BUCKET_DOWNLOADS: ${FLUXER_S3_BUCKET_DOWNLOADS:-fluxer-downloads} + FLUXER_S3_BUCKET_REPORTS: ${FLUXER_S3_BUCKET_REPORTS:-fluxer-reports} + FLUXER_S3_BUCKET_HARVESTS: ${FLUXER_S3_BUCKET_HARVESTS:-fluxer-harvests} AWS_ACCESS_KEY_ID: ${FLUXER_S3_ACCESS_KEY:?set FLUXER_S3_ACCESS_KEY in .env} AWS_SECRET_ACCESS_KEY: ${FLUXER_S3_SECRET_KEY:?set FLUXER_S3_SECRET_KEY in .env} - AWS_DEFAULT_REGION: us-east-1 + AWS_DEFAULT_REGION: ${FLUXER_S3_REGION:-us-east-1} AWS_EC2_METADATA_DISABLED: "true" - FLUXER_LIVEKIT_ENABLED: "true" + FLUXER_LIVEKIT_ENABLED: "${FLUXER_LIVEKIT_ENABLED:-true}" FLUXER_LIVEKIT_API_KEY: ${LIVEKIT_API_KEY:?set LIVEKIT_API_KEY in .env} FLUXER_LIVEKIT_API_SECRET: ${LIVEKIT_API_SECRET:?set LIVEKIT_API_SECRET in .env} - FLUXER_LIVEKIT_INTERNAL_URL: http://livekit:7880 + FLUXER_LIVEKIT_INTERNAL_URL: ${FLUXER_LIVEKIT_INTERNAL_URL:-http://livekit:7880} FLUXER_LIVEKIT_WEBHOOK_URL: http://api:8080/webhooks/livekit FLUXER_LIVEKIT_DEFAULT_REGION: '{"id":"default","name":"Default","emoji":"🌍","latitude":0,"longitude":0}' FLUXER_LIVEKIT_URL: ${FLUXER_LIVEKIT_URL:-${FLUXER_PUBLIC_ORIGIN:-${FLUXER_PUBLIC_SCHEME:-https}://${FLUXER_DOMAIN}:${FLUXER_PUBLIC_PORT:-443}}/livekit} @@ -72,16 +72,16 @@ x-fluxer-env: &fluxer-env FLUXER_EMAIL_SMTP_PASSWORD: ${FLUXER_EMAIL_SMTP_PASSWORD:-} FLUXER_EMAIL_SMTP_SECURE: ${FLUXER_EMAIL_SMTP_SECURE:-true} - FLUXER_SMS_ENABLED: "false" + FLUXER_SMS_ENABLED: "${FLUXER_SMS_ENABLED:-false}" FLUXER_CAPTCHA_ENABLED: ${FLUXER_CAPTCHA_ENABLED:-false} FLUXER_CAPTCHA_PROVIDER: ${FLUXER_CAPTCHA_PROVIDER:-none} FLUXER_CAPTCHA_HCAPTCHA_SITE_KEY: ${FLUXER_CAPTCHA_HCAPTCHA_SITE_KEY:-} FLUXER_CAPTCHA_HCAPTCHA_SECRET_KEY: ${FLUXER_CAPTCHA_HCAPTCHA_SECRET_KEY:-} FLUXER_CAPTCHA_TURNSTILE_SITE_KEY: ${FLUXER_CAPTCHA_TURNSTILE_SITE_KEY:-} FLUXER_CAPTCHA_TURNSTILE_SECRET_KEY: ${FLUXER_CAPTCHA_TURNSTILE_SECRET_KEY:-} - FLUXER_STRIPE_ENABLED: "false" - FLUXER_NCMEC_ENABLED: "false" - FLUXER_CLAMAV_ENABLED: "false" + FLUXER_STRIPE_ENABLED: "${FLUXER_STRIPE_ENABLED:-false}" + FLUXER_NCMEC_ENABLED: "${FLUXER_NCMEC_ENABLED:-false}" + FLUXER_CLAMAV_ENABLED: "${FLUXER_CLAMAV_ENABLED:-false}" FLUXER_DISCOVERY_ENABLED: ${FLUXER_DISCOVERY_ENABLED:-true} FLUXER_SUDO_MODE_SECRET: ${FLUXER_SUDO_MODE_SECRET:?set FLUXER_SUDO_MODE_SECRET in .env} @@ -288,11 +288,16 @@ services: environment: FLUXER_S3_ACCESS_KEY: ${FLUXER_S3_ACCESS_KEY:?set FLUXER_S3_ACCESS_KEY in .env} FLUXER_S3_SECRET_KEY: ${FLUXER_S3_SECRET_KEY:?set FLUXER_S3_SECRET_KEY in .env} + FLUXER_S3_BUCKET_CDN: ${FLUXER_S3_BUCKET_CDN:-fluxer} + FLUXER_S3_BUCKET_UPLOADS: ${FLUXER_S3_BUCKET_UPLOADS:-fluxer-uploads} + FLUXER_S3_BUCKET_DOWNLOADS: ${FLUXER_S3_BUCKET_DOWNLOADS:-fluxer-downloads} + FLUXER_S3_BUCKET_REPORTS: ${FLUXER_S3_BUCKET_REPORTS:-fluxer-reports} + FLUXER_S3_BUCKET_HARVESTS: ${FLUXER_S3_BUCKET_HARVESTS:-fluxer-harvests} entrypoint: - /bin/sh - -c - > - buckets="fluxer fluxer-uploads fluxer-downloads fluxer-reports fluxer-harvests"; + buckets="$$FLUXER_S3_BUCKET_CDN $$FLUXER_S3_BUCKET_UPLOADS $$FLUXER_S3_BUCKET_DOWNLOADS $$FLUXER_S3_BUCKET_REPORTS $$FLUXER_S3_BUCKET_HARVESTS"; missing="$$buckets"; for attempt in $$(seq 1 60); do if ! nc -z seaweedfs 9333 2>/dev/null; then diff --git a/fluxer_docs/src/content/docs/operator/upgrading.mdx b/fluxer_docs/src/content/docs/operator/upgrading.mdx index 03a10e512..ff62e2b04 100644 --- a/fluxer_docs/src/content/docs/operator/upgrading.mdx +++ b/fluxer_docs/src/content/docs/operator/upgrading.mdx @@ -225,7 +225,9 @@ FLUXER_S3_REGION=eu-central-1 FLUXER_S3_FORCE_PATH_STYLE=false ``` -`FLUXER_S3_PUBLIC_ENDPOINT` follows `FLUXER_S3_ENDPOINT` when it is not set on its own, and the credentials stay `FLUXER_S3_ACCESS_KEY` and `FLUXER_S3_SECRET_KEY`. +`FLUXER_S3_PUBLIC_ENDPOINT` follows `FLUXER_S3_ENDPOINT` when it is not set on its own, and the credentials stay `FLUXER_S3_ACCESS_KEY` and `FLUXER_S3_SECRET_KEY`. `FLUXER_S3_BUCKET_CDN`, `FLUXER_S3_BUCKET_UPLOADS`, `FLUXER_S3_BUCKET_DOWNLOADS`, `FLUXER_S3_BUCKET_REPORTS` and `FLUXER_S3_BUCKET_HARVESTS` name the five buckets. The bundled object store creates whichever names they hold, and a store outside the stack needs those buckets to exist already. + +`FLUXER_KV_URL`, `FLUXER_NATS_URL`, `FLUXER_SEARCH_URL` and `FLUXER_LIVEKIT_INTERNAL_URL` move the other four bundled services the same way, and `FLUXER_NATS_JETSTREAM_URL` and `FLUXER_SVC_NATS_URL` follow `FLUXER_NATS_URL` when they are not set on their own. Pointing the stack elsewhere leaves the bundled service defined and running with nothing reading it. Take it out with an override file listed in `COMPOSE_FILE`, which [Keep a local compose change](#keep-a-local-compose-change) describes, rather than by editing `docker-compose.yml`, which the Place step replaces on every upgrade.