Files
OpenVPN-Monitoring-Simple/docker-compose.yml
T
iclaoudezinandClaude Sonnet 5.5 5de0501cbc Compose: require JWT secret, seed admin via env, stop publishing internal ports
- JWT_SECRET is mandatory (no more "supersecret" fallback).
- Pass OVPMON_INITIAL_ADMIN_USER/PASSWORD and OVPMON_CORS_ORIGINS to the
  APIs; add restart policy and drop the obsolete compose "version".
- Publish only 80/tcp and 1194/udp; expose 5001 and 8000 on ovp-net.
- CORS origins now come from OVPMON_CORS_ORIGINS instead of a hardcoded
  host (default: same-origin only).
- Update Docker/native deployment docs and README accordingly.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:14:22 +00:00

108 lines
2.8 KiB
YAML

# OpenVPN Monitor & Profiler (containers)
# Required: JWT_SECRET in .env (openssl rand -hex 32)
# First start only: OVPMON_INITIAL_ADMIN_USER / OVPMON_INITIAL_ADMIN_PASSWORD in .env
# Optional: OVPMON_CORS_ORIGINS (comma-separated origins; off by default, UI is same-origin via Nginx)
x-secret: &jwt-secret
OVPMON_API_SECRET_KEY: ${JWT_SECRET:?JWT_SECRET must be set in .env (openssl rand -hex 32)}
services:
app-ui:
build: ./APP_UI
container_name: ovp-ui
restart: unless-stopped
ports:
- "80:80"
depends_on:
- app-api
- app-profiler
networks:
- ovp-net
environment:
OVP_API_HOST: ovp-api
OVP_API_PORT: 5001
OVP_PROFILER_HOST: ovp-profiler
OVP_PROFILER_PORT: 8000
app-gatherer:
build:
context: ./APP_CORE
dockerfile: Dockerfile.gatherer
container_name: ovp-gatherer
restart: unless-stopped
volumes:
- ovp_logs:/var/log/openvpn
- db_data:/app/db
depends_on:
- app-profiler
networks:
- ovp-net
environment:
OVPMON_OPENVPN_MONITOR_DB_PATH: /app/db/openvpn_monitor.db
OVPMON_OPENVPN_MONITOR_LOG_PATH: /var/log/openvpn/openvpn-status.log
OVPMON_LOGGING_LEVEL: INFO
app-api:
build:
context: ./APP_CORE
dockerfile: Dockerfile.api
container_name: ovp-api
restart: unless-stopped
# Not published: reached only through app-ui (Nginx) on ovp-net
expose:
- "5001"
volumes:
- db_data:/app/db
networks:
- ovp-net
depends_on:
- app-gatherer
environment:
<<: *jwt-secret
OVPMON_API_PORT: 5001
OVPMON_OPENVPN_MONITOR_DB_PATH: /app/db/openvpn_monitor.db
OVPMON_LOGGING_LEVEL: INFO
# Initial admin: used only while the users table is empty (remove after first start)
OVPMON_INITIAL_ADMIN_USER: ${OVPMON_INITIAL_ADMIN_USER:-}
OVPMON_INITIAL_ADMIN_PASSWORD: ${OVPMON_INITIAL_ADMIN_PASSWORD:-}
OVPMON_CORS_ORIGINS: ${OVPMON_CORS_ORIGINS:-}
app-profiler:
build: ./APP_PROFILER
container_name: ovp-profiler
restart: unless-stopped
cap_add:
- NET_ADMIN
sysctls:
- net.ipv4.ip_forward=1
devices:
- "/dev/net/tun:/dev/net/tun"
ports:
# VPN port only; the profiler API (8000) is reached through app-ui
- "1194:1194/udp"
expose:
- "8000"
volumes:
- ovp_logs:/var/log/openvpn
- ovp_config:/etc/openvpn
- db_data:/app/db
- ovp_client_config:/app/client-config
- ovp_pki:/app/easy-rsa
networks:
- ovp-net
environment:
<<: *jwt-secret
OVPMON_PROFILER_DB_PATH: /app/db/ovpn_profiler.db
OVPMON_CORS_ORIGINS: ${OVPMON_CORS_ORIGINS:-}
networks:
ovp-net:
driver: bridge
volumes:
ovp_logs:
ovp_config:
ovp_pki:
ovp_client_config:
db_data: