jump to content

Docker Compose

Install the platform on a single host with the official Docker Compose definition, covering secrets,TLS, backups, upgrades, and troubleshooting steps.

Show as Markdown

The platform repository includes a Compose definition that runs the platform, PostgreSQL, SeaweedFS, and Chrome headless on a single host.

For work tasks that require independent scaling, managed data services or running updates, use Kubernetes deployment.

  • A Linux host with Docker Engine and Docker Compose v2
  • A DNS record for the host name you will use
  • A TLS-terminating reverse proxy or load balancer
  • A SMTP relay if you want the platform to send emails
  • Enough memory for the platform and its dependencies; only the provided PostgreSQL configuration requires 4 GB of shared buffers
  1. Clone the repository

    Terminal window
    git clone https://github.com/getprobo/probo.git
    cd probo

    Keep compose.prod.yaml and the compose/ directory together. The composite definition mounts the PostgreSQL initialization script and the SeaweedFS configuration in that directory.

  2. Generate application secrets

    Terminal window
    umask 077
    openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 \
    -out oauth2-signing-key.pem
    export PROBOD_ENCRYPTION_KEY="$(openssl rand -base64 32)"
    export PROBOD_AUTH_COOKIE_SECRET="$(openssl rand -base64 32)"
    export PROBOD_AUTH_PASSWORD_PEPPER="$(openssl rand -base64 32)"
    export PROBOD_TRUST_AUTH_TOKEN_SECRET="$(openssl rand -base64 32)"

    Changing the encryption, signature or authentication secrets after the existence of users and data may invalidate sessions or make stored data inaccessible.

  3. Create the environment file

    Replace probo.example.com and the SMTP values, then run:

    Terminal window
    cat > .env <<EOF
    PROBOD_ENCRYPTION_KEY=${PROBOD_ENCRYPTION_KEY}
    PROBOD_AUTH_COOKIE_SECRET=${PROBOD_AUTH_COOKIE_SECRET}
    PROBOD_AUTH_PASSWORD_PEPPER=${PROBOD_AUTH_PASSWORD_PEPPER}
    PROBOD_TRUST_AUTH_TOKEN_SECRET=${PROBOD_TRUST_AUTH_TOKEN_SECRET}
    PROBOD_BASE_URL=https://probo.example.com
    PROBOD_API_ADDR=0.0.0.0:8080
    PROBOD_API_CORS_ALLOWED_ORIGINS=https://probo.example.com
    PROBOD_SMTP_ADDR=smtp.example.com:587
    PROBOD_SMTP_USER=replace-with-smtp-user
    PROBOD_SMTP_PASSWORD=replace-with-smtp-password
    PROBOD_SMTP_TLS_REQUIRED=true
    PROBOD_MAILER_SENDER_EMAIL=no-reply@example.com
    EOF
    Terminal window
    chmod 600 .env oauth2-signing-key.pem
  4. Add the required OAuth signing key

    The current compose.prod.yaml does not pass the OAuth signature key on the platform. Create compose.local.yaml:

    services:
    probo:
    environment:
    PROBOD_OAUTH2_SERVER_SIGNING_KEY: ${PROBOD_OAUTH2_SERVER_SIGNING_KEY}
    PROBOD_SMTP_ADDR: ${PROBOD_SMTP_ADDR}
    PROBOD_SMTP_USER: ${PROBOD_SMTP_USER}
    PROBOD_SMTP_PASSWORD: ${PROBOD_SMTP_PASSWORD}
    PROBOD_SMTP_TLS_REQUIRED: ${PROBOD_SMTP_TLS_REQUIRED}
    PROBOD_MAILER_SENDER_EMAIL: ${PROBOD_MAILER_SENDER_EMAIL}

    Export the key before each Composite order:

    Terminal window
    export PROBOD_OAUTH2_SERVER_SIGNING_KEY="$(cat oauth2-signing-key.pem)"
  5. Review the rendered configuration

    Terminal window
    docker compose \
    -f compose.prod.yaml \
    -f compose.local.yaml \
    config

    Do not proceed if a requested value is empty. the rendered output contains secrets, so do not save it or share it.

  6. Start the Services

    Terminal window
    docker compose \
    -f compose.prod.yaml \
    -f compose.local.yaml \
    up -d
  7. Verify startup

    Terminal window
    docker compose \
    -f compose.prod.yaml \
    -f compose.local.yaml \
    ps
    docker compose \
    -f compose.prod.yaml \
    -f compose.local.yaml \
    logs --tail=100 probo
    curl --fail http://127.0.0.1:8080/

    A successful HTTP response and a functional service probo confirm that the application is accessible. Also test authentication, file uploading and email delivery before inviting users.

Put the platform behind HTTPS

“Put the platform behind HTTPS”

StopTLS at a reverse proxy or load balancer and send requests to the port 8080. Keep the original titles ___ZBT_I18N_RUNTIME_BLOCK_188__, X-Forwarded-For and X-Forwarded-Proto.

The Compose definition provided publishes the platform, PostgreSQL, SeaweedFS, and Chrome ports on each host interface.

  • restriction of incoming traffic with the host or cloud firewall;
  • expose only the ports ___ZBT_I18N_RUNTIME_BLOCK_191__ and ___ZBT_I18N_RUNTIME_BLOCK_192__ via the reverse proxy;
  • To prevent external access to ports 5432, 8443, 8081, 8333, 8443, 9222 and 9333;
  • Replace the PostgreSQL and SeaweedFS credentials combined or use external managed services;
  • Place the platform image in a tested version instead of latest.

Installing a certificate in the platform container does not configureTLSitself.

The implementation stores are presented in three volumes named:

  • probo-data for local platform data;
  • postgres-data for PostgreSQL;
  • seaweedfs-data for storing objects.

Backup PostgreSQL and SeaweedFS as a single recovery point. a dump of databases without its corresponding objects can leave document records whose files cannot be restored.

Create a database dump with:

Terminal window
docker compose \
-f compose.prod.yaml \
-f compose.local.yaml \
exec -T postgres \
pg_dump -U postgres -d probod --format=custom > probod.dump

Use a volume-conscious backup tool or instant storage capture for SeaweedFS. Stop writing while making an offline volume backup and test restoration on another host. Copy ___ZBT_I18N_RUNTIME_BLOCK_202__, oauth2-signing-key.pem and any proxy configuration into the encrypted backup system separately.

Read the launch notes and first make a tested backup, then drag and recreate the containers:

Terminal window
export PROBOD_OAUTH2_SERVER_SIGNING_KEY="$(cat oauth2-signing-key.pem)"
docker compose \
-f compose.prod.yaml \
-f compose.local.yaml \
pull
docker compose \
-f compose.prod.yaml \
-f compose.local.yaml \
up -d

Check the platform logs and repeat the functional checks used during installation.Data base migrations are executed when the platform starts; do not interrupt the start while a migration is executed.

the platform exits during startup

“The platform exits during startup”
Terminal window
docker compose \
-f compose.prod.yaml \
-f compose.local.yaml \
logs --tail=200 probo

If logs report a missing PROBOD_OAUTH2_SERVER_SIGNING_KEY, confirm that the key is exported to the current shell and that both Composite files are included in the order.

PostgreSQL is unhealthy

PostgreSQL is unhealthy
Terminal window
docker compose \
-f compose.prod.yaml \
-f compose.local.yaml \
logs --tail=200 postgres
docker compose \
-f compose.prod.yaml \
-f compose.local.yaml \
exec postgres pg_isready -U postgres -d probod

The PostgreSQL settings provided require much more than 4 GB of total host memory. If PostgreSQL is killed by the kernel, increase the host memory or revise its configuration before lowering the limits.

Check the platform logs, SeaweedFS and Chrome:

Terminal window
docker compose \
-f compose.prod.yaml \
-f compose.local.yaml \
logs --tail=200 probo seaweedfs chrome

See the environment variable reference when optional integrations are added or runtime behavior is changed.

Ultima actualizare: