# roomtsc API on the shared Hetzner box, after the pattern of the other small services # there. Private network only: no host port and no outbound Internet. The shared Caddy # proxy joins `roomtsc_private` and is the only way in. name: roomtsc services: api: build: context: .. dockerfile: deploy/Dockerfile image: roomtsc-api:${ROOMTSC_REVISION:-local} container_name: roomtsc-api restart: unless-stopped init: true read_only: true cap_drop: [ALL] security_opt: [no-new-privileges:true] cpus: 4 mem_limit: 4g pids_limit: 256 tmpfs: - /tmp:size=128m,mode=1777 networks: [private] healthcheck: test: [CMD, python, -c, "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8000/api/health', timeout=5)"] start_period: 120s interval: 30s timeout: 10s retries: 3 logging: driver: json-file options: max-size: 10m max-file: "3" networks: private: name: roomtsc_private internal: true