472170784b
The prod box is behind NAT (private 192.168.88.61 behind public 118.95.33.89), so LiveKit auto-IP-detection would pick the wrong (outbound) address. Pin rtc.node_ip=118.95.33.89 and collapse media to one UDP port (50000) + TCP 7881 to minimize the upstream gateway port-forward the network team must add. Docs updated with the exact forward table. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
58 lines
2.3 KiB
YAML
58 lines
2.3 KiB
YAML
# BizGaze Support — deployed behind the existing Nginx Proxy Manager.
|
|
# No host ports are published: NPM reaches this container by name on the
|
|
# shared `nginx_proxy_manager_default` network. TLS is terminated by NPM,
|
|
# which proxies https://remote.bizgaze.com -> bizgaze-support:8090.
|
|
services:
|
|
app:
|
|
build: .
|
|
image: bizgaze-support:latest
|
|
container_name: bizgaze-support
|
|
restart: unless-stopped
|
|
environment:
|
|
- PORT=8090
|
|
- DB_PATH=/data/data.db
|
|
# Desktop installers + auto-update feed live on the persistent volume so uploaded
|
|
# builds survive image rebuilds (a plain image path would be wiped on every deploy).
|
|
- DOWNLOADS_DIR=/data/downloads
|
|
# Secrets (TURN credentials, SSO_SECRET, BIZGAZE_WEBHOOK_URL, etc.) live in
|
|
# a .env file next to this compose file. It is gitignored — never committed.
|
|
# See .env.example for the expected keys.
|
|
env_file:
|
|
- path: .env
|
|
required: false
|
|
volumes:
|
|
- bizgaze_support_data:/data # persists data.db across rebuilds
|
|
networks:
|
|
- npm
|
|
|
|
# LiveKit SFU — meeting media server. Optional: only started/used when the app's .env has
|
|
# LIVEKIT_URL/API_KEY/API_SECRET set (otherwise meetings use the built-in P2P mesh). NPM proxies
|
|
# wss://livekit.bizgaze.com -> livekit:7880 (signaling); media flows over the published UDP/TCP
|
|
# ports below, NOT through NPM. Single-node (no Redis) — consistent with the app's single-instance rule.
|
|
livekit:
|
|
image: livekit/livekit-server:v1.7
|
|
container_name: bizgaze-livekit
|
|
restart: unless-stopped
|
|
# Dormant by default: a normal `docker compose up -d` / deploy.sh does NOT start it. Enable SFU
|
|
# explicitly with `docker compose --profile sfu up -d` after setting the LIVEKIT_* vars (see DEPLOY.md).
|
|
profiles: ["sfu"]
|
|
command: --config /etc/livekit.yaml
|
|
environment:
|
|
# key: secret, sourced from the same .env as the app so both sign/verify with the same secret.
|
|
- "LIVEKIT_KEYS=${LIVEKIT_API_KEY}: ${LIVEKIT_API_SECRET}"
|
|
volumes:
|
|
- ./livekit.yaml:/etc/livekit.yaml:ro
|
|
ports:
|
|
- "7881:7881" # WebRTC over TCP (fallback)
|
|
- "50000:50000/udp" # single WebRTC media UDP port (must match livekit.yaml rtc.udp_port)
|
|
networks:
|
|
- npm
|
|
|
|
networks:
|
|
npm:
|
|
external: true
|
|
name: nginx_proxy_manager_default
|
|
|
|
volumes:
|
|
bizgaze_support_data:
|