# Production: `docker compose up -d --build` (with HTTPS: `docker compose --profile tls up -d --build`, see README) services: app: build: . image: gdziewjade:latest restart: unless-stopped # host:container. Behind Caddy or another proxy use APP_BIND=127.0.0.1:8080 so only the proxy can reach it. ports: - "${APP_BIND:-8080}:80" healthcheck: test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1/healthz"] interval: 30s timeout: 3s retries: 3 read_only: true tmpfs: - /var/cache/nginx - /var/run - /tmp caddy: profiles: ["tls"] image: caddy:2-alpine restart: unless-stopped depends_on: app: condition: service_healthy ports: - "80:80" - "443:443" environment: DOMAIN: ${DOMAIN:-localhost} # set DOMAIN=gdziewjade.example.org in .env for a real certificate volumes: - ./docker/Caddyfile:/etc/caddy/Caddyfile:ro - caddy_data:/data - caddy_config:/config volumes: caddy_data: caddy_config: