-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
141 lines (134 loc) · 4.97 KB
/
Copy pathdocker-compose.yml
File metadata and controls
141 lines (134 loc) · 4.97 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
---
# GNAT — single-host Docker Compose deployment
# Services: scheduler (ingest cron), edl (block-list HTTP server), monitor (health)
#
# Quick start:
# cp .env.example .env # edit GNAT_CONFIG path
# docker compose up -d
#
# Logs:
# docker compose logs -f
version: "3.9"
services:
# ── Feed scheduler ──────────────────────────────────────────────────────
# Runs configured FeedJobs on cron schedule; writes to shared workspace.
scheduler:
build:
context: .
dockerfile: docker/scheduler/Dockerfile
container_name: gnat-scheduler
environment:
GNAT_CONFIG: /etc/gnat/config.ini
volumes:
- ${GNAT_CONFIG_DIR:-./config}:/etc/gnat:ro
- workspace:/var/gnat/workspace
restart: unless-stopped
healthcheck:
test: ["CMD", "python", "-c",
"from gnat.schedule import FeedScheduler; print('ok')"]
interval: 60s
timeout: 10s
retries: 3
# ── EDL server ──────────────────────────────────────────────────────────
# Serves dynamic enforcement-decision lists over HTTP (port 8080).
edl:
build:
context: .
dockerfile: docker/edl/Dockerfile
container_name: gnat-edl
environment:
GNAT_CONFIG: /etc/gnat/config.ini
volumes:
- ${GNAT_CONFIG_DIR:-./config}:/etc/gnat:ro
- workspace:/var/gnat/workspace:ro
ports:
- "${EDL_PORT:-8080}:8080"
restart: unless-stopped
depends_on:
- scheduler
healthcheck:
test: ["CMD", "python", "-c",
"import urllib.request; urllib.request.urlopen('http://localhost:8080/health')"]
interval: 30s
timeout: 5s
retries: 3
# ── Health monitor ──────────────────────────────────────────────────────
# Exposes /health endpoint and connector drift summary (port 8090).
monitor:
build:
context: .
dockerfile: docker/monitor/Dockerfile
container_name: gnat-monitor
environment:
GNAT_CONFIG: /etc/gnat/config.ini
volumes:
- ${GNAT_CONFIG_DIR:-./config}:/etc/gnat:ro
- workspace:/var/gnat/workspace:ro
ports:
- "${MONITOR_PORT:-8090}:8090"
restart: unless-stopped
healthcheck:
test: ["CMD", "python", "-c",
"import urllib.request; urllib.request.urlopen('http://localhost:8090/health')"]
interval: 30s
timeout: 5s
retries: 3
# ── Solr search sidecar (optional) ──────────────────────────────────────
# Provides full-text search over indexed STIX objects.
# Enable with: docker compose --profile search up -d
solr:
image: solr:9.6
container_name: gnat-solr
profiles: ["search", "full"]
ports:
- "${SOLR_PORT:-8983}:8983"
command: >
bash -c "
/opt/solr/bin/solr start -c -f &
sleep 10 &&
/opt/solr/bin/solr create_core -c gnat -p 8983 2>/dev/null || true &&
wait
"
volumes:
- solr-data:/var/solr
restart: unless-stopped
healthcheck:
test: ["CMD-SHELL", "curl -sf http://localhost:8983/solr/gnat/admin/ping | grep -q '\"status\":\"OK\"'"]
interval: 15s
timeout: 10s
retries: 10
start_period: 45s
# ── Grafana (optional) ───────────────────────────────────────────────────
# Pre-provisioned with GNAT datasources and dashboards.
# Enable with: docker compose --profile monitoring up -d
grafana:
image: grafana/grafana:10.4.2
container_name: gnat-grafana
profiles: ["monitoring", "full"]
ports:
- "${GRAFANA_PORT:-3000}:3000"
environment:
GF_SECURITY_ADMIN_PASSWORD: ${GRAFANA_ADMIN_PASSWORD:-gnat-admin}
GF_INSTALL_PLUGINS: grafana-simple-json-datasource
GF_USERS_ALLOW_SIGN_UP: "false"
GNAT_GRAFANA_HOST: ${GNAT_GRAFANA_HOST:-host.docker.internal}
GNAT_VIZ_PORT: ${GNAT_VIZ_PORT:-3001}
volumes:
- ./docker/grafana/provisioning:/etc/grafana/provisioning:ro
- ./docker/grafana/provisioning/dashboards:/var/lib/grafana/dashboards:ro
- grafana-data:/var/lib/grafana
restart: unless-stopped
healthcheck:
test: ["CMD-SHELL", "curl -sf http://localhost:3000/api/health | grep -q '\"database\":\"ok\"'"]
interval: 30s
timeout: 10s
retries: 5
start_period: 20s
# ── Named volumes ────────────────────────────────────────────────────────
volumes:
workspace:
name: gnat-workspace
solr-data:
name: gnat-solr-data
grafana-data:
name: gnat-grafana-data