Mirrors the hermes convention of keeping the consuming quadlet alongside the image definition. Four units: a private network, postgres 16 with wal_level=logical, remote-server, and electric. Records why the start order matters -- remote-server's migrations create the electric_sync role, its grants and the publication that electric then connects with, so electric cannot come up first -- and why electric has its own env file, which is to avoid depending on systemd expanding one Environment= value into another inside a quadlet. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TsmUEtbyTkgQ18tCFYXo1h
49 lines
1.9 KiB
Plaintext
49 lines
1.9 KiB
Plaintext
# vibe-kanban remote-server — the self-hosted server half of the suite.
|
|
# Serves both the API and the built SPA (from /srv/static in the image) on :8081
|
|
# as uid 10001; published to the LAN on 27180 (agent-zero=5080, open-webui=5090,
|
|
# hermes=5100). Fronted by nginx on hanzalova.internal as https://kanban.internal.
|
|
#
|
|
# Image is built by lair/containers from OUR mirror of BloopAI/vibe-kanban, never
|
|
# from GitHub — upstream is sunsetting. AutoUpdate=registry picks up rebuilds.
|
|
#
|
|
# Startup order matters and is not merely cosmetic: this unit's sqlx migrations
|
|
# are what CREATE the `electric_sync` role and the publication that Electric then
|
|
# connects with, and it ALTERs that role's password from ELECTRIC_ROLE_PASSWORD on
|
|
# every start. So db -> this -> electric. Notify=healthy makes systemd hold the
|
|
# unit "starting" until /v1/health answers, so electric genuinely waits for the
|
|
# migrations rather than racing them.
|
|
#
|
|
# Auth: local single-account mode only (SELF_HOST_LOCAL_AUTH_*), deliberately no
|
|
# OAuth — the server refuses to start unless at least one provider is configured.
|
|
# Swapping to a real IdP later means adding a provider, not changing this file.
|
|
[Unit]
|
|
Description=vibe-kanban remote-server
|
|
After=network-online.target vibe-kanban-db.service
|
|
Wants=network-online.target
|
|
Requires=vibe-kanban-db.service
|
|
|
|
[Container]
|
|
Image=git.lair.cafe/lair/vibe-kanban-remote:latest
|
|
ContainerName=vibe-kanban
|
|
AutoUpdate=registry
|
|
Network=vibe-kanban.network
|
|
PublishPort=27180:8081
|
|
EnvironmentFile=/etc/vibe-kanban/env
|
|
Environment=SERVER_LISTEN_ADDR=0.0.0.0:8081
|
|
Environment=ELECTRIC_URL=http://vibe-kanban-electric:3000
|
|
Environment=SERVER_PUBLIC_BASE_URL=https://kanban.internal
|
|
Environment=RUST_LOG=info,remote=info
|
|
Notify=healthy
|
|
HealthCmd=wget --spider -q http://127.0.0.1:8081/v1/health
|
|
HealthInterval=10s
|
|
HealthTimeout=5s
|
|
HealthRetries=12
|
|
HealthStartPeriod=20s
|
|
|
|
[Service]
|
|
Restart=always
|
|
TimeoutStartSec=300
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|