# Production override: join an existing Traefik network and let Traefik route # bookmark-api. -> this service with TLS. No host port published. # # docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d --build # # Set in .env: # BOOKMARK_API_HOST=bookmark-api.example.com # your subdomain (required) # BOOKMARK_WEB_HOST=bookmark.example.com # browser UI subdomain, same container (required) # PROXY_NETWORK=proxy # Traefik's network name, if not "proxy" # TRAEFIK_ENTRYPOINT=websecure # your HTTPS entrypoint name # TRAEFIK_CERTRESOLVER=le # your ACME/cert resolver name # # The network must already exist and Traefik must watch it: # docker network create proxy # if it doesn't yet services: bookmark-api: # Traffic arrives over the Traefik network, not a published port. ports: !reset [] # `networks:` here replaces the base file's list entirely, so both must be # named: `proxy` for Traefik routing, and `db` (defined in the base file) # to keep reaching Postgres without putting it on `proxy`. `proxy` also # carries the poller's outbound traffic — `db` is `internal: true`, so a # container on it alone has no egress at all. networks: - proxy - db labels: - "traefik.enable=true" - "traefik.docker.network=${PROXY_NETWORK:-proxy}" - "traefik.http.routers.bmapi.rule=Host(`${BOOKMARK_API_HOST:?set BOOKMARK_API_HOST in .env}`)" - "traefik.http.routers.bmapi.entrypoints=${TRAEFIK_ENTRYPOINT:-websecure}" - "traefik.http.routers.bmapi.tls=true" - "traefik.http.routers.bmapi.tls.certresolver=${TRAEFIK_CERTRESOLVER:-le}" - "traefik.http.services.bmapi.loadbalancer.server.port=8080" # Second hostname for the browser UI, same container. Traefik needs the # service named explicitly once more than one router targets it. - "traefik.http.routers.bmapi.service=bmapi" - "traefik.http.routers.bmweb.rule=Host(`${BOOKMARK_WEB_HOST:?set BOOKMARK_WEB_HOST in .env}`)" - "traefik.http.routers.bmweb.entrypoints=${TRAEFIK_ENTRYPOINT:-websecure}" - "traefik.http.routers.bmweb.tls=true" - "traefik.http.routers.bmweb.tls.certresolver=${TRAEFIK_CERTRESOLVER:-le}" - "traefik.http.routers.bmweb.service=bmapi" # No browser service here. It runs on the home machine as its own unit # (chrome/docker-compose.yml) and is reached over the tailnet — see # docs/adr/0006-browser-on-the-home-machine.md. It must never be given a # service on this host: `proxy` is shared with whatever else sits behind # Traefik, and an unauthenticated CDP endpoint on it is remote code # execution for any of them. networks: proxy: external: true name: ${PROXY_NETWORK:-proxy}