-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
173 lines (164 loc) · 5.44 KB
/
Copy pathdocker-compose.yml
File metadata and controls
173 lines (164 loc) · 5.44 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
# IsolateX full dev stack
# Services: orchestrator, worker (docker runtime), CTFd, Postgres, Redis, Traefik
#
# Start everything:
# docker compose up -d
#
# Kata-backed Kubernetes workers are NOT in this compose.
# See docs/setup.md and docs/kata-setup.md
#
# CTFd: http://localhost:8000
# Orchestrator API: http://localhost:8080
# Traefik dashboard: disabled in prod; enable in gateway/traefik/traefik.yml for dev
networks:
isolatex_internal:
driver: bridge
isolatex_challenges:
driver: bridge
driver_opts:
com.docker.network.bridge.enable_icc: "false"
volumes:
postgres_data:
redis_data:
traefik_acme:
ctfd_db_data:
ctfd_uploads:
services:
# ── Postgres ────────────────────────────────────────────────────────────────
postgres:
image: postgres:16-alpine
restart: unless-stopped
environment:
POSTGRES_USER: isolatex
POSTGRES_PASSWORD: isolatex
POSTGRES_DB: isolatex
volumes:
- postgres_data:/var/lib/postgresql/data
networks:
- isolatex_internal
healthcheck:
test: ["CMD-SHELL", "pg_isready -U isolatex"]
interval: 5s
retries: 10
# ── Redis ───────────────────────────────────────────────────────────────────
redis:
image: redis:7-alpine
restart: unless-stopped
command: redis-server --save "" --appendonly no
volumes:
- redis_data:/data
networks:
- isolatex_internal
healthcheck:
test: ["CMD", "redis-cli", "ping"]
interval: 5s
retries: 10
# ── Orchestrator ────────────────────────────────────────────────────────────
orchestrator:
build:
context: ./orchestrator
dockerfile: Dockerfile
restart: unless-stopped
environment:
DATABASE_URL: postgresql+asyncpg://isolatex:isolatex@postgres:5432/isolatex
REDIS_URL: redis://redis:6379/0
SECRET_KEY: ${SECRET_KEY:?SECRET_KEY must be set in .env}
API_KEY: ${API_KEY:?API_KEY must be set in .env}
FLAG_HMAC_SECRET: ${FLAG_HMAC_SECRET:?FLAG_HMAC_SECRET must be set in .env}
GATEWAY_TYPE: traefik
BASE_DOMAIN: localhost
TLS_ENABLED: "false"
DEFAULT_TTL_SECONDS: "3600"
LOG_LEVEL: INFO
depends_on:
postgres:
condition: service_healthy
redis:
condition: service_healthy
networks:
- isolatex_internal
ports:
- "8080:8080"
volumes:
- ./orchestrator:/srv/orchestrator
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:8080/health"]
interval: 10s
retries: 5
# ── Worker (Docker runtime — usable without KVM) ─────────────────────────
worker-docker:
build:
context: ./worker
dockerfile: Dockerfile
restart: unless-stopped
environment:
RUNTIME: docker
ORCHESTRATOR_URL: http://orchestrator:8080
ORCHESTRATOR_API_KEY: ${API_KEY:?API_KEY must be set in .env}
WORKER_ID: worker-docker-01
ADVERTISE_ADDRESS: worker-docker
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./worker:/app
depends_on:
orchestrator:
condition: service_healthy
postgres:
condition: service_healthy
networks:
- isolatex_internal
# ── CTFd ───────────────────────────────────────────────────────────────────
ctfd:
build:
context: .
dockerfile: ctfd/Dockerfile
args:
CTFD_BASE_IMAGE: ${CTFD_BASE_IMAGE:-ctfd/ctfd:latest}
restart: unless-stopped
environment:
DATABASE_URL: mysql+pymysql://ctfd:ctfd@ctfd-db/ctfd
REDIS_URL: redis://redis:6379/1
SECRET_KEY: ${CTFD_SECRET_KEY:?CTFD_SECRET_KEY must be set in .env}
PERMANENT_SESSION_LIFETIME: ${CTFD_PERMANENT_SESSION_LIFETIME:-2592000}
ISOLATEX_URL: http://orchestrator:8080
ISOLATEX_API_KEY: ${API_KEY:?API_KEY must be set in .env}
depends_on:
- ctfd-db
- redis
networks:
- isolatex_internal
ports:
- "8000:8000"
volumes:
- ./ctfd-plugin:/opt/CTFd/CTFd/plugins/isolatex
- ctfd_uploads:/var/uploads
ctfd-db:
image: mariadb:10.11
restart: unless-stopped
environment:
MYSQL_ROOT_PASSWORD: ctfdrootpassword
MYSQL_DATABASE: ctfd
MYSQL_USER: ctfd
MYSQL_PASSWORD: ctfd
volumes:
- ctfd_db_data:/var/lib/mysql
networks:
- isolatex_internal
# ── Traefik gateway ─────────────────────────────────────────────────────────
traefik:
image: traefik:v3.0
restart: unless-stopped
command:
- "--configFile=/etc/traefik/traefik.yml"
ports:
- "80:80"
- "443:443"
volumes:
- ./gateway/traefik/traefik.yml:/etc/traefik/traefik.yml:ro
- ./gateway/traefik/dynamic.yml:/etc/traefik/dynamic.yml:ro
- traefik_acme:/data
networks:
- isolatex_internal
depends_on:
- orchestrator
- ctfd