Docker Compose
Docker Compose is a tool for defining and running multi-container Docker applications. With Docker Compose, you use a YAML file to configure your application’s services. Then, with a single command, you create and start all the services from your configuration. These Docker Compose files are available in the folder docker-compose:
Development
docker-compose-dev.yml- Starts the PostgreSQL database, as well as SecObserve's backend and frontend
- Backend and frontend are build automatically if necessary and are started in development mode with hot reloading
- The frontend's dependencies are installed inside the container into the Docker managed volume
dev_node_modules. This is necessary because packages with native bindings, e.g.rolldownandlightningcss, are platform and libc specific:npmonly installs the variant matching the machine it runs on, and the host is usually not Alpine Linux like the container. Thenpm installthat./bin/dev.shruns on the host is still needed to providenode_modulesfor the IDE (TypeScript, ESLint, Prettier).
docker-compose-dev-multi.yml- Starts the PostgreSQL database and the frontend, as well as SecObserve's backend split into one container per role:
init(migrations, admin user, parsers, licenses),background(Huey consumer) andapi(Django development server) - The roles are selected by the argument given to the backend's entrypoint, see
docker/backend/dev/django/entrypoint
- Starts the PostgreSQL database and the frontend, as well as SecObserve's backend split into one container per role:
docker-compose-dev-mysql.yml- Starts the MySQL database, as well as SecObserve's backend and frontend
- Backend and frontend are build automatically if necessary and are started in development mode with hot reloading
docker-compose-dev-keycloak.yml- Starts the PostgreSQL database, the SecObserve backend, Keycloak and Mailpit
- The frontend is only started, when the parameter
--profile frontendis given - A predefined realm calles
secobserveis imported on start-up. There is an administrator configured (username:admin, password:admin) and a regular user for SecObserve (username:keycloak_user, password:keycloak).
-
- Overrides the development stack for macOS on Apple Silicon
- Runs the main services on ARM64
- Start it together with the standard development file:
*docker compose -f docker-compose/docker-compose-dev.yml -f docker-compose/docker-compose-dev-arm.yaml up --builddocker-compose-playwright.yml- Starts the end-to-end tests with Playwright *docker-compose-prod-test.yml- Starts the PostgreSQL database, as well as SecObserve's backend and frontend - Backend and frontend are build automatically if necessary with the production Dockerfiles - The environment variables of the backend container are defined indocker/backend/prod/django/docker.env*docker-compose-prod-test-multi.yml- Same asdocker-compose-prod-test.yml, but with the backend split into one container per role:init(migrations, admin user, parsers, licenses),background(Huey consumer) andapi(Gunicorn) - The roles are selected by the argument given to the backend's entrypoint, seedocker/backend/prod/django/entrypoint- The environment variables of the backend containers are defined indocker/backend/prod/django/docker.env*docker-compose-unittests.yml- Starts the unit tests for the backend -./bin/unittests.shpasses its arguments tomanage.py test, e.g../bin/unittests.sh unittests.core.services.test_assessmentto run only the tests of one module. Without arguments all unit tests are run and the coverage is measured, with arguments the coverage measurement is skipped to get the results faster. - The database schemas are generated from the models, the migrations are not executed, seeMIGRATION_MODULESinbackend/config/settings/unittests.py. Running all migrations took a considerable amount of time for every run of the unit tests. - That the migrations result in the same schema is covered by the end to end tests, which start the backend with a fresh database and run all migrations *docker-compose.yml- This is a link todocker-compose-dev.ymland is used as a default for thedocker composecommand, when it is run in the folderdocker-compose
Production
See the installation guide how to use the productive Docker Compose files.