# Copy to .env.prod per host and fill in only what that host needs. # # docker compose -f docker-compose.yml -f docker-compose.prod.yml --env-file .env.prod up -d --build # # COMPOSE_PROFILES controls which services THIS host runs — pick one: # control-plane host: control-plane,dashboard # external prober site: prober # OpenStack validator VM: validator # single all-in-one host: control-plane,dashboard,prober,validator COMPOSE_PROFILES=control-plane,dashboard # --- control-api (only needed when this host runs the control-plane profile) --- # Real config with validators/sites/targets/ip_addresses — see # configs/control-api.example.yaml and docs/SETUP.md. Required. CONTROL_API_CONFIG_PATH=/etc/cloud-ip-validator/control-api.yaml # OpenStack creds — only read when the mounted control-api.yaml has # openstack.mode: real. Leave blank in mock mode. OS_AUTH_URL= OS_PROJECT_ID= OS_REGION_NAME= OS_INTERFACE= OS_TOKEN= # auth_method: password instead of token: # OS_USERNAME= # OS_USER_DOMAIN_NAME= # OS_PASSWORD= # --- prober (only needed on a prober-profile host) --- PROBER_SITE_ID= # Real, network-reachable control-api URL — NOT http://control-api:8080 # unless this host also runs the control-plane profile in the same # compose invocation. PROBER_CONTROL_API_URL=https://control-api.internal.example.com # --- validator-agent (only needed on a validator-profile host) --- VALIDATOR_AGENT_VALIDATOR_ID= VALIDATOR_AGENT_CONTROL_API_URL=https://control-api.internal.example.com # --- admin-dashboard (only needed on a dashboard-profile host) --- ADMIN_DASHBOARD_CONTROL_API_URL=http://control-api:8080 # --- authentication (fill in only what this host needs; empty = open + warning) --- # Generate each secret with: openssl rand -hex 32 # Rollout order without downtime: update all binaries first, then give the # tokens to prober / validator-agent / dashboard, and set the control-api # tokens (and restart it) last. # # control-plane host: tokens that control-api enforces CONTROL_API_ADMIN_TOKEN= CONTROL_API_AGENT_TOKEN= # dashboard host: control-api's admin token, the login, and the cookie-signing key ADMIN_DASHBOARD_CONTROL_API_TOKEN= ADMIN_DASHBOARD_USERNAME= ADMIN_DASHBOARD_PASSWORD= ADMIN_DASHBOARD_SESSION_SECRET= # prober / validator hosts use CONTROL_API_AGENT_TOKEN (same value as above)