services: api: build: context: . dockerfile: Dockerfile image: fire-safety-ymd:test container_name: fire-safety-ymd restart: unless-stopped env_file: - .env environment: # The host binding below keeps this port private; the process must bind # all container interfaces for Docker's loopback publish to work. FIRE_SAFETY_HTTP_ADDR: ":8080" # A one-off owner/migration credential must never enter the long-lived # application container, even if an operator left it in the local file. FIRE_SAFETY_POSTGIS_MIGRATION_DSN: "" TZ: Asia/Shanghai ports: - "127.0.0.1:8080:8080" extra_hosts: # Use host.docker.internal in the DSN only when PostgreSQL runs on this # same host; a remote/private database hostname is preferred otherwise. - "host.docker.internal:host-gateway" healthcheck: test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:8080/health"] interval: 10s timeout: 3s retries: 6 start_period: 10s read_only: true tmpfs: - /tmp:size=16m,mode=1777 security_opt: - no-new-privileges:true cap_drop: - ALL pids_limit: 256 stop_grace_period: 20s logging: driver: json-file options: max-size: "10m" max-file: "3"