services: kb-site: image: nginx:alpine container_name: kb-site restart: unless-stopped ports: # PIHA 82x0 static-HTTP block: 8210 paperless, 8220 nextcloud, # 8230 kb-query, 8240 narty27 -> 8250 is the next free slot. # Publicly the site is reached only through the npm@PIHA vhost # kb.okit.pl; this bind is the proxy's upstream. - "8250:80" volumes: # Generated output of scripts/kb/gen_pages.py — never committed, never # bind-mounted from the repo. Read-only: nginx only serves it; writes go # through the helper-container procedure in kb/runbooks/kb-site-deploy.md # (docker cp cannot write into a :ro mount). - kb-site_content:/usr/share/nginx/html:ro # Docker on PIHA has exhausted its default address pools (~30 live stacks: # "all predefined address pools have been fully subnetted"), so this stack # must not ask for a subnet of its own. Declaring a network here suppresses # the implicit kb-site_default; we join the pre-existing shared "proxy" # bridge instead. This is only about subnet economy — npm@PIHA still reaches # this container over the published 8250 host port (npm itself lives on # nginxproxymanager_default), not over this network. networks: - proxy # busybox wget — nginx:alpine ships no curl. index.html is generated on # every run, so it is the one file that must always be there. healthcheck: test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1/index.html"] interval: 30s timeout: 10s retries: 5 start_period: 5s networks: # Created out-of-band on PIHA (docker network create proxy); never managed by # this stack. `docker network ls | grep -w proxy` must return a row before # deploy, otherwise compose fails with "network proxy declared as external, # but could not be found". proxy: external: true volumes: kb-site_content: