mirror of
https://github.com/mediacms-io/mediacms.git
synced 2025-12-10 05:52:31 -05:00
Compare commits
7 Commits
feat-docke
...
2216efa3a4
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2216efa3a4 | ||
|
|
e8377d4623 | ||
|
|
9ef4ef47f4 | ||
|
|
b816a12be1 | ||
|
|
b2b8035984 | ||
|
|
2007659844 | ||
|
|
6ef45640d9 |
113
.docker-backup/Dockerfile
Normal file
113
.docker-backup/Dockerfile
Normal file
@@ -0,0 +1,113 @@
|
|||||||
|
FROM python:3.13.5-slim-bookworm AS build-image
|
||||||
|
|
||||||
|
# Install system dependencies needed for downloading and extracting
|
||||||
|
RUN apt-get update -y && \
|
||||||
|
apt-get install -y --no-install-recommends wget xz-utils unzip && \
|
||||||
|
rm -rf /var/lib/apt/lists/* && \
|
||||||
|
apt-get purge --auto-remove && \
|
||||||
|
apt-get clean
|
||||||
|
|
||||||
|
RUN wget -q https://johnvansickle.com/ffmpeg/releases/ffmpeg-release-amd64-static.tar.xz
|
||||||
|
|
||||||
|
RUN mkdir -p ffmpeg-tmp && \
|
||||||
|
tar -xf ffmpeg-release-amd64-static.tar.xz --strip-components 1 -C ffmpeg-tmp && \
|
||||||
|
cp -v ffmpeg-tmp/ffmpeg ffmpeg-tmp/ffprobe ffmpeg-tmp/qt-faststart /usr/local/bin && \
|
||||||
|
rm -rf ffmpeg-tmp ffmpeg-release-amd64-static.tar.xz
|
||||||
|
|
||||||
|
# Install Bento4 in the specified location
|
||||||
|
RUN mkdir -p /home/mediacms.io/bento4 && \
|
||||||
|
wget -q http://zebulon.bok.net/Bento4/binaries/Bento4-SDK-1-6-0-637.x86_64-unknown-linux.zip && \
|
||||||
|
unzip Bento4-SDK-1-6-0-637.x86_64-unknown-linux.zip -d /home/mediacms.io/bento4 && \
|
||||||
|
mv /home/mediacms.io/bento4/Bento4-SDK-1-6-0-637.x86_64-unknown-linux/* /home/mediacms.io/bento4/ && \
|
||||||
|
rm -rf /home/mediacms.io/bento4/Bento4-SDK-1-6-0-637.x86_64-unknown-linux && \
|
||||||
|
rm -rf /home/mediacms.io/bento4/docs && \
|
||||||
|
rm Bento4-SDK-1-6-0-637.x86_64-unknown-linux.zip
|
||||||
|
|
||||||
|
############ BASE RUNTIME IMAGE ############
|
||||||
|
FROM python:3.13.5-slim-bookworm AS base
|
||||||
|
|
||||||
|
SHELL ["/bin/bash", "-c"]
|
||||||
|
|
||||||
|
ENV PYTHONUNBUFFERED=1
|
||||||
|
ENV PYTHONDONTWRITEBYTECODE=1
|
||||||
|
ENV CELERY_APP='cms'
|
||||||
|
ENV VIRTUAL_ENV=/home/mediacms.io
|
||||||
|
ENV PATH="$VIRTUAL_ENV/bin:$PATH"
|
||||||
|
|
||||||
|
# Install system dependencies first
|
||||||
|
RUN apt-get update -y && \
|
||||||
|
apt-get -y upgrade && \
|
||||||
|
apt-get install --no-install-recommends -y \
|
||||||
|
supervisor \
|
||||||
|
nginx \
|
||||||
|
imagemagick \
|
||||||
|
procps \
|
||||||
|
build-essential \
|
||||||
|
pkg-config \
|
||||||
|
zlib1g-dev \
|
||||||
|
zlib1g \
|
||||||
|
libxml2-dev \
|
||||||
|
libxmlsec1-dev \
|
||||||
|
libxmlsec1-openssl \
|
||||||
|
libpq-dev \
|
||||||
|
&& apt-get clean \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
# Set up virtualenv first
|
||||||
|
RUN mkdir -p /home/mediacms.io/mediacms/{logs} && \
|
||||||
|
cd /home/mediacms.io && \
|
||||||
|
python3 -m venv $VIRTUAL_ENV
|
||||||
|
|
||||||
|
# Copy requirements files
|
||||||
|
COPY requirements.txt requirements-dev.txt ./
|
||||||
|
|
||||||
|
# Install Python dependencies using pip (within virtualenv)
|
||||||
|
ARG DEVELOPMENT_MODE=False
|
||||||
|
RUN pip install --no-cache-dir uv && \
|
||||||
|
uv pip install --no-binary lxml --no-binary xmlsec -r requirements.txt && \
|
||||||
|
if [ "$DEVELOPMENT_MODE" = "True" ]; then \
|
||||||
|
echo "Installing development dependencies..." && \
|
||||||
|
uv pip install -r requirements-dev.txt; \
|
||||||
|
fi && \
|
||||||
|
apt-get purge -y --auto-remove \
|
||||||
|
build-essential \
|
||||||
|
pkg-config \
|
||||||
|
libxml2-dev \
|
||||||
|
libxmlsec1-dev \
|
||||||
|
libpq-dev
|
||||||
|
|
||||||
|
# Copy ffmpeg and Bento4 from build image
|
||||||
|
COPY --from=build-image /usr/local/bin/ffmpeg /usr/local/bin/ffmpeg
|
||||||
|
COPY --from=build-image /usr/local/bin/ffprobe /usr/local/bin/ffprobe
|
||||||
|
COPY --from=build-image /usr/local/bin/qt-faststart /usr/local/bin/qt-faststart
|
||||||
|
COPY --from=build-image /home/mediacms.io/bento4 /home/mediacms.io/bento4
|
||||||
|
|
||||||
|
# Copy application files
|
||||||
|
COPY . /home/mediacms.io/mediacms
|
||||||
|
WORKDIR /home/mediacms.io/mediacms
|
||||||
|
|
||||||
|
# required for sprite thumbnail generation for large video files
|
||||||
|
COPY deploy/docker/policy.xml /etc/ImageMagick-6/policy.xml
|
||||||
|
|
||||||
|
# Set process control environment variables
|
||||||
|
ENV ENABLE_UWSGI='yes' \
|
||||||
|
ENABLE_NGINX='yes' \
|
||||||
|
ENABLE_CELERY_BEAT='yes' \
|
||||||
|
ENABLE_CELERY_SHORT='yes' \
|
||||||
|
ENABLE_CELERY_LONG='yes' \
|
||||||
|
ENABLE_MIGRATIONS='yes'
|
||||||
|
|
||||||
|
EXPOSE 9000 80
|
||||||
|
|
||||||
|
RUN chmod +x ./deploy/docker/entrypoint.sh
|
||||||
|
|
||||||
|
ENTRYPOINT ["./deploy/docker/entrypoint.sh"]
|
||||||
|
CMD ["./deploy/docker/start.sh"]
|
||||||
|
|
||||||
|
############ FULL IMAGE ############
|
||||||
|
FROM base AS full
|
||||||
|
COPY requirements-full.txt ./
|
||||||
|
RUN mkdir -p /root/.cache/ && \
|
||||||
|
chmod go+rwx /root/ && \
|
||||||
|
chmod go+rwx /root/.cache/
|
||||||
|
RUN uv pip install -r requirements-full.txt
|
||||||
119
.docker-backup/docker-compose-cert.yaml
Normal file
119
.docker-backup/docker-compose-cert.yaml
Normal file
@@ -0,0 +1,119 @@
|
|||||||
|
version: "3"
|
||||||
|
|
||||||
|
services:
|
||||||
|
nginx-proxy:
|
||||||
|
image: nginxproxy/nginx-proxy
|
||||||
|
container_name: nginx-proxy
|
||||||
|
ports:
|
||||||
|
- "80:80"
|
||||||
|
- "443:443"
|
||||||
|
volumes:
|
||||||
|
- conf:/etc/nginx/conf.d
|
||||||
|
- vhost:/etc/nginx/vhost.d
|
||||||
|
- html:/usr/share/nginx/html
|
||||||
|
- dhparam:/etc/nginx/dhparam
|
||||||
|
- certs:/etc/nginx/certs:ro
|
||||||
|
- /var/run/docker.sock:/tmp/docker.sock:ro
|
||||||
|
- ./deploy/docker/reverse_proxy/client_max_body_size.conf:/etc/nginx/conf.d/client_max_body_size.conf:ro
|
||||||
|
|
||||||
|
acme-companion:
|
||||||
|
image: nginxproxy/acme-companion
|
||||||
|
container_name: nginx-proxy-acme
|
||||||
|
volumes_from:
|
||||||
|
- nginx-proxy
|
||||||
|
volumes:
|
||||||
|
- certs:/etc/nginx/certs:rw
|
||||||
|
- acme:/etc/acme.sh
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
|
|
||||||
|
migrations:
|
||||||
|
image: mediacms/mediacms:latest
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
environment:
|
||||||
|
ENABLE_UWSGI: 'no'
|
||||||
|
ENABLE_NGINX: 'no'
|
||||||
|
ENABLE_CELERY_SHORT: 'no'
|
||||||
|
ENABLE_CELERY_LONG: 'no'
|
||||||
|
ENABLE_CELERY_BEAT: 'no'
|
||||||
|
ADMIN_USER: 'admin'
|
||||||
|
ADMIN_EMAIL: 'Y'
|
||||||
|
ADMIN_PASSWORD: 'X'
|
||||||
|
command: "./deploy/docker/prestart.sh"
|
||||||
|
restart: on-failure
|
||||||
|
depends_on:
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
db:
|
||||||
|
condition: service_healthy
|
||||||
|
web:
|
||||||
|
image: mediacms/mediacms:latest
|
||||||
|
deploy:
|
||||||
|
replicas: 1
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
environment:
|
||||||
|
ENABLE_CELERY_BEAT: 'no'
|
||||||
|
ENABLE_CELERY_SHORT: 'no'
|
||||||
|
ENABLE_CELERY_LONG: 'no'
|
||||||
|
ENABLE_MIGRATIONS: 'no'
|
||||||
|
VIRTUAL_HOST: 'X.mediacms.io'
|
||||||
|
LETSENCRYPT_HOST: 'X.mediacms.io'
|
||||||
|
LETSENCRYPT_EMAIL: 'X'
|
||||||
|
depends_on:
|
||||||
|
- migrations
|
||||||
|
celery_beat:
|
||||||
|
image: mediacms/mediacms:latest
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
environment:
|
||||||
|
ENABLE_UWSGI: 'no'
|
||||||
|
ENABLE_NGINX: 'no'
|
||||||
|
ENABLE_CELERY_SHORT: 'no'
|
||||||
|
ENABLE_CELERY_LONG: 'no'
|
||||||
|
ENABLE_MIGRATIONS: 'no'
|
||||||
|
depends_on:
|
||||||
|
- redis
|
||||||
|
celery_worker:
|
||||||
|
image: mediacms/mediacms:full
|
||||||
|
deploy:
|
||||||
|
replicas: 1
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
environment:
|
||||||
|
ENABLE_UWSGI: 'no'
|
||||||
|
ENABLE_NGINX: 'no'
|
||||||
|
ENABLE_CELERY_BEAT: 'no'
|
||||||
|
ENABLE_MIGRATIONS: 'no'
|
||||||
|
depends_on:
|
||||||
|
- migrations
|
||||||
|
db:
|
||||||
|
image: postgres:17.2-alpine
|
||||||
|
volumes:
|
||||||
|
- ../postgres_data:/var/lib/postgresql/data/
|
||||||
|
restart: always
|
||||||
|
environment:
|
||||||
|
POSTGRES_USER: mediacms
|
||||||
|
POSTGRES_PASSWORD: mediacms
|
||||||
|
POSTGRES_DB: mediacms
|
||||||
|
TZ: Europe/London
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD-SHELL", "pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}"]
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 5
|
||||||
|
redis:
|
||||||
|
image: "redis:alpine"
|
||||||
|
restart: always
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "redis-cli","ping"]
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 3
|
||||||
|
volumes:
|
||||||
|
conf:
|
||||||
|
vhost:
|
||||||
|
html:
|
||||||
|
dhparam:
|
||||||
|
certs:
|
||||||
|
acme:
|
||||||
89
.docker-backup/docker-compose-dev.yaml
Normal file
89
.docker-backup/docker-compose-dev.yaml
Normal file
@@ -0,0 +1,89 @@
|
|||||||
|
version: "3"
|
||||||
|
|
||||||
|
services:
|
||||||
|
migrations:
|
||||||
|
build:
|
||||||
|
context: .
|
||||||
|
dockerfile: ./Dockerfile
|
||||||
|
target: base
|
||||||
|
args:
|
||||||
|
- DEVELOPMENT_MODE=True
|
||||||
|
image: mediacms/mediacms-dev:latest
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
command: "./deploy/docker/prestart.sh"
|
||||||
|
environment:
|
||||||
|
DEVELOPMENT_MODE: True
|
||||||
|
ENABLE_UWSGI: 'no'
|
||||||
|
ENABLE_NGINX: 'no'
|
||||||
|
ENABLE_CELERY_SHORT: 'no'
|
||||||
|
ENABLE_CELERY_LONG: 'no'
|
||||||
|
ENABLE_CELERY_BEAT: 'no'
|
||||||
|
ADMIN_USER: 'admin'
|
||||||
|
ADMIN_EMAIL: 'admin@localhost'
|
||||||
|
ADMIN_PASSWORD: 'admin'
|
||||||
|
restart: on-failure
|
||||||
|
depends_on:
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
db:
|
||||||
|
condition: service_healthy
|
||||||
|
frontend:
|
||||||
|
image: node:20
|
||||||
|
volumes:
|
||||||
|
- ${PWD}/frontend:/home/mediacms.io/mediacms/frontend/
|
||||||
|
working_dir: /home/mediacms.io/mediacms/frontend/
|
||||||
|
command: bash -c "npm install && npm run start"
|
||||||
|
env_file:
|
||||||
|
- ${PWD}/frontend/.env
|
||||||
|
ports:
|
||||||
|
- "8088:8088"
|
||||||
|
depends_on:
|
||||||
|
- web
|
||||||
|
web:
|
||||||
|
image: mediacms/mediacms-dev:latest
|
||||||
|
command: "python manage.py runserver 0.0.0.0:80"
|
||||||
|
environment:
|
||||||
|
DEVELOPMENT_MODE: True
|
||||||
|
ports:
|
||||||
|
- "80:80"
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
depends_on:
|
||||||
|
- migrations
|
||||||
|
db:
|
||||||
|
image: postgres:17.2-alpine
|
||||||
|
volumes:
|
||||||
|
- ../postgres_data:/var/lib/postgresql/data/
|
||||||
|
restart: always
|
||||||
|
environment:
|
||||||
|
POSTGRES_USER: mediacms
|
||||||
|
POSTGRES_PASSWORD: mediacms
|
||||||
|
POSTGRES_DB: mediacms
|
||||||
|
TZ: Europe/London
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD-SHELL", "pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}", "--host=db", "--dbname=$POSTGRES_DB", "--username=$POSTGRES_USER"]
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 5
|
||||||
|
redis:
|
||||||
|
image: "redis:alpine"
|
||||||
|
restart: always
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "redis-cli", "ping"]
|
||||||
|
interval: 30s
|
||||||
|
timeout: 10s
|
||||||
|
retries: 3
|
||||||
|
celery_worker:
|
||||||
|
image: mediacms/mediacms-dev:latest
|
||||||
|
deploy:
|
||||||
|
replicas: 1
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
environment:
|
||||||
|
ENABLE_UWSGI: 'no'
|
||||||
|
ENABLE_NGINX: 'no'
|
||||||
|
ENABLE_CELERY_BEAT: 'no'
|
||||||
|
ENABLE_MIGRATIONS: 'no'
|
||||||
|
depends_on:
|
||||||
|
- web
|
||||||
86
.docker-backup/docker-compose.yaml
Normal file
86
.docker-backup/docker-compose.yaml
Normal file
@@ -0,0 +1,86 @@
|
|||||||
|
version: "3"
|
||||||
|
|
||||||
|
services:
|
||||||
|
migrations:
|
||||||
|
image: mediacms/mediacms:latest
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
environment:
|
||||||
|
ENABLE_UWSGI: 'no'
|
||||||
|
ENABLE_NGINX: 'no'
|
||||||
|
ENABLE_CELERY_SHORT: 'no'
|
||||||
|
ENABLE_CELERY_LONG: 'no'
|
||||||
|
ENABLE_CELERY_BEAT: 'no'
|
||||||
|
ADMIN_USER: 'admin'
|
||||||
|
ADMIN_EMAIL: 'admin@localhost'
|
||||||
|
# ADMIN_PASSWORD: 'uncomment_and_set_password_here'
|
||||||
|
command: "./deploy/docker/prestart.sh"
|
||||||
|
restart: on-failure
|
||||||
|
depends_on:
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
db:
|
||||||
|
condition: service_healthy
|
||||||
|
web:
|
||||||
|
image: mediacms/mediacms:latest
|
||||||
|
deploy:
|
||||||
|
replicas: 1
|
||||||
|
ports:
|
||||||
|
- "80:80"
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
environment:
|
||||||
|
ENABLE_CELERY_BEAT: 'no'
|
||||||
|
ENABLE_CELERY_SHORT: 'no'
|
||||||
|
ENABLE_CELERY_LONG: 'no'
|
||||||
|
ENABLE_MIGRATIONS: 'no'
|
||||||
|
depends_on:
|
||||||
|
- migrations
|
||||||
|
celery_beat:
|
||||||
|
image: mediacms/mediacms:latest
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
environment:
|
||||||
|
ENABLE_UWSGI: 'no'
|
||||||
|
ENABLE_NGINX: 'no'
|
||||||
|
ENABLE_CELERY_SHORT: 'no'
|
||||||
|
ENABLE_CELERY_LONG: 'no'
|
||||||
|
ENABLE_MIGRATIONS: 'no'
|
||||||
|
depends_on:
|
||||||
|
- redis
|
||||||
|
celery_worker:
|
||||||
|
image: mediacms/mediacms:latest
|
||||||
|
deploy:
|
||||||
|
replicas: 1
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
environment:
|
||||||
|
ENABLE_UWSGI: 'no'
|
||||||
|
ENABLE_NGINX: 'no'
|
||||||
|
ENABLE_CELERY_BEAT: 'no'
|
||||||
|
ENABLE_MIGRATIONS: 'no'
|
||||||
|
depends_on:
|
||||||
|
- migrations
|
||||||
|
db:
|
||||||
|
image: postgres:17.2-alpine
|
||||||
|
volumes:
|
||||||
|
- ../postgres_data:/var/lib/postgresql/data/
|
||||||
|
restart: always
|
||||||
|
environment:
|
||||||
|
POSTGRES_USER: mediacms
|
||||||
|
POSTGRES_PASSWORD: mediacms
|
||||||
|
POSTGRES_DB: mediacms
|
||||||
|
TZ: Europe/London
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD-SHELL", "pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}"]
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 5
|
||||||
|
redis:
|
||||||
|
image: "redis:alpine"
|
||||||
|
restart: always
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "redis-cli","ping"]
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 3
|
||||||
@@ -1,2 +1,37 @@
|
|||||||
|
# Dependencies
|
||||||
node_modules
|
node_modules
|
||||||
npm-debug.log
|
npm-debug.log
|
||||||
|
|
||||||
|
# Local development files - exclude uploaded content but keep placeholder images
|
||||||
|
media_files/*
|
||||||
|
!media_files/userlogos/
|
||||||
|
media_files/userlogos/*
|
||||||
|
!media_files/userlogos/*.jpg
|
||||||
|
logs
|
||||||
|
static_collected
|
||||||
|
|
||||||
|
# Version control
|
||||||
|
.git
|
||||||
|
.github
|
||||||
|
.gitignore
|
||||||
|
|
||||||
|
# Development/testing
|
||||||
|
.pytest_cache
|
||||||
|
.qodo
|
||||||
|
.claude
|
||||||
|
|
||||||
|
# Docker
|
||||||
|
.dockerignore
|
||||||
|
Dockerfile
|
||||||
|
docker-compose*.yml
|
||||||
|
.docker-backup
|
||||||
|
|
||||||
|
# Documentation (if you don't need it in the image)
|
||||||
|
docs
|
||||||
|
|
||||||
|
# Other
|
||||||
|
*.pyc
|
||||||
|
__pycache__
|
||||||
|
.env
|
||||||
|
.vscode
|
||||||
|
.idea
|
||||||
94
.github/workflows/docker-build-push.yml
vendored
94
.github/workflows/docker-build-push.yml
vendored
@@ -21,8 +21,8 @@ jobs:
|
|||||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||||
|
|
||||||
- name: Docker meta for base image
|
- name: Docker meta for web image
|
||||||
id: meta-base
|
id: meta-web
|
||||||
uses: docker/metadata-action@v4
|
uses: docker/metadata-action@v4
|
||||||
with:
|
with:
|
||||||
images: |
|
images: |
|
||||||
@@ -40,39 +40,95 @@ jobs:
|
|||||||
org.opencontainers.image.source=https://github.com/mediacms-io/mediacms
|
org.opencontainers.image.source=https://github.com/mediacms-io/mediacms
|
||||||
org.opencontainers.image.licenses=AGPL-3.0
|
org.opencontainers.image.licenses=AGPL-3.0
|
||||||
|
|
||||||
- name: Docker meta for full image
|
- name: Build and push web image
|
||||||
id: meta-full
|
uses: docker/build-push-action@v4
|
||||||
|
with:
|
||||||
|
context: .
|
||||||
|
target: web
|
||||||
|
push: ${{ github.event_name != 'pull_request' }}
|
||||||
|
tags: ${{ steps.meta-web.outputs.tags }}
|
||||||
|
labels: ${{ steps.meta-web.outputs.labels }}
|
||||||
|
|
||||||
|
- name: Docker meta for worker image
|
||||||
|
id: meta-worker
|
||||||
uses: docker/metadata-action@v4
|
uses: docker/metadata-action@v4
|
||||||
with:
|
with:
|
||||||
images: |
|
images: |
|
||||||
mediacms/mediacms
|
mediacms/mediacms-worker
|
||||||
tags: |
|
tags: |
|
||||||
type=raw,value=full,enable=${{ github.ref == format('refs/heads/{0}', 'main') }}
|
type=raw,value=latest,enable=${{ github.ref == format('refs/heads/{0}', 'main') }}
|
||||||
type=semver,pattern={{version}}-full
|
type=semver,pattern={{version}}
|
||||||
type=semver,pattern={{major}}.{{minor}}-full
|
type=semver,pattern={{major}}.{{minor}}
|
||||||
type=semver,pattern={{major}}-full
|
type=semver,pattern={{major}}
|
||||||
labels: |
|
labels: |
|
||||||
org.opencontainers.image.title=MediaCMS Full
|
org.opencontainers.image.title=MediaCMS Worker
|
||||||
org.opencontainers.image.description=MediaCMS is a modern, fully featured open source video and media CMS, written in Python/Django and React, featuring a REST API. This is the full version with additional dependencies.
|
org.opencontainers.image.description=MediaCMS Celery worker for background task processing.
|
||||||
org.opencontainers.image.vendor=MediaCMS
|
org.opencontainers.image.vendor=MediaCMS
|
||||||
org.opencontainers.image.url=https://mediacms.io/
|
org.opencontainers.image.url=https://mediacms.io/
|
||||||
org.opencontainers.image.source=https://github.com/mediacms-io/mediacms
|
org.opencontainers.image.source=https://github.com/mediacms-io/mediacms
|
||||||
org.opencontainers.image.licenses=AGPL-3.0
|
org.opencontainers.image.licenses=AGPL-3.0
|
||||||
|
|
||||||
- name: Build and push full image
|
- name: Build and push worker image
|
||||||
uses: docker/build-push-action@v4
|
uses: docker/build-push-action@v4
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
target: full
|
target: worker
|
||||||
push: ${{ github.event_name != 'pull_request' }}
|
push: ${{ github.event_name != 'pull_request' }}
|
||||||
tags: ${{ steps.meta-full.outputs.tags }}
|
tags: ${{ steps.meta-worker.outputs.tags }}
|
||||||
labels: ${{ steps.meta-full.outputs.labels }}
|
labels: ${{ steps.meta-worker.outputs.labels }}
|
||||||
|
|
||||||
- name: Build and push base image
|
- name: Docker meta for worker-full image
|
||||||
|
id: meta-worker-full
|
||||||
|
uses: docker/metadata-action@v4
|
||||||
|
with:
|
||||||
|
images: |
|
||||||
|
mediacms/mediacms-worker
|
||||||
|
tags: |
|
||||||
|
type=raw,value=latest-full,enable=${{ github.ref == format('refs/heads/{0}', 'main') }}
|
||||||
|
type=semver,pattern={{version}}-full
|
||||||
|
type=semver,pattern={{major}}.{{minor}}-full
|
||||||
|
type=semver,pattern={{major}}-full
|
||||||
|
labels: |
|
||||||
|
org.opencontainers.image.title=MediaCMS Worker Full
|
||||||
|
org.opencontainers.image.description=MediaCMS Celery worker with additional codecs for advanced transcoding features.
|
||||||
|
org.opencontainers.image.vendor=MediaCMS
|
||||||
|
org.opencontainers.image.url=https://mediacms.io/
|
||||||
|
org.opencontainers.image.source=https://github.com/mediacms-io/mediacms
|
||||||
|
org.opencontainers.image.licenses=AGPL-3.0
|
||||||
|
|
||||||
|
- name: Build and push worker-full image
|
||||||
uses: docker/build-push-action@v4
|
uses: docker/build-push-action@v4
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
target: base
|
target: worker-full
|
||||||
push: ${{ github.event_name != 'pull_request' }}
|
push: ${{ github.event_name != 'pull_request' }}
|
||||||
tags: ${{ steps.meta-base.outputs.tags }}
|
tags: ${{ steps.meta-worker-full.outputs.tags }}
|
||||||
labels: ${{ steps.meta-base.outputs.labels }}
|
labels: ${{ steps.meta-worker-full.outputs.labels }}
|
||||||
|
|
||||||
|
- name: Docker meta for nginx image
|
||||||
|
id: meta-nginx
|
||||||
|
uses: docker/metadata-action@v4
|
||||||
|
with:
|
||||||
|
images: |
|
||||||
|
mediacms/mediacms-nginx
|
||||||
|
tags: |
|
||||||
|
type=raw,value=latest,enable=${{ github.ref == format('refs/heads/{0}', 'main') }}
|
||||||
|
type=semver,pattern={{version}}
|
||||||
|
type=semver,pattern={{major}}.{{minor}}
|
||||||
|
type=semver,pattern={{major}}
|
||||||
|
labels: |
|
||||||
|
org.opencontainers.image.title=MediaCMS Nginx
|
||||||
|
org.opencontainers.image.description=Nginx web server for MediaCMS, serving static and media files.
|
||||||
|
org.opencontainers.image.vendor=MediaCMS
|
||||||
|
org.opencontainers.image.url=https://mediacms.io/
|
||||||
|
org.opencontainers.image.source=https://github.com/mediacms-io/mediacms
|
||||||
|
org.opencontainers.image.licenses=AGPL-3.0
|
||||||
|
|
||||||
|
- name: Build and push nginx image
|
||||||
|
uses: docker/build-push-action@v4
|
||||||
|
with:
|
||||||
|
context: .
|
||||||
|
file: Dockerfile.nginx
|
||||||
|
push: ${{ github.event_name != 'pull_request' }}
|
||||||
|
tags: ${{ steps.meta-nginx.outputs.tags }}
|
||||||
|
labels: ${{ steps.meta-nginx.outputs.labels }}
|
||||||
|
|||||||
2
.gitignore
vendored
2
.gitignore
vendored
@@ -17,7 +17,7 @@ static/mptt/
|
|||||||
static/rest_framework/
|
static/rest_framework/
|
||||||
static/drf-yasg
|
static/drf-yasg
|
||||||
cms/local_settings.py
|
cms/local_settings.py
|
||||||
deploy/docker/local_settings.py
|
config/local_settings.py
|
||||||
yt.readme.md
|
yt.readme.md
|
||||||
/frontend-tools/video-editor/node_modules
|
/frontend-tools/video-editor/node_modules
|
||||||
/frontend-tools/video-editor/client/node_modules
|
/frontend-tools/video-editor/client/node_modules
|
||||||
|
|||||||
254
DOCKER_RESTRUCTURE_SUMMARY.md
Normal file
254
DOCKER_RESTRUCTURE_SUMMARY.md
Normal file
@@ -0,0 +1,254 @@
|
|||||||
|
# MediaCMS Docker Restructure Summary
|
||||||
|
|
||||||
|
## Overview
|
||||||
|
|
||||||
|
This document summarizes the complete Docker architecture restructure for MediaCMS 7.3, eliminating supervisord and implementing modern Docker best practices.
|
||||||
|
|
||||||
|
## What Was Created
|
||||||
|
|
||||||
|
### New Files
|
||||||
|
|
||||||
|
#### Dockerfiles
|
||||||
|
- `Dockerfile` - Multi-stage Dockerfile with targets (replaced old Dockerfile):
|
||||||
|
- `build-image` - FFmpeg and Bento4 builder
|
||||||
|
- `base` - Python/Django base image
|
||||||
|
- `web` - uWSGI web server
|
||||||
|
- `worker` - Celery worker (standard)
|
||||||
|
- `worker-full` - Celery worker with extra codecs
|
||||||
|
|
||||||
|
- `Dockerfile.nginx` - Vanilla nginx with MediaCMS configs baked in
|
||||||
|
|
||||||
|
#### Docker Compose Files
|
||||||
|
- `docker-compose.yaml` - Production deployment (no file mounts) - REPLACED
|
||||||
|
- `docker-compose-cert.yaml` - Production with HTTPS (Let's Encrypt) - REPLACED
|
||||||
|
- `docker-compose-dev.yaml` - Development with file mounts and hot reload - REPLACED
|
||||||
|
|
||||||
|
#### Scripts
|
||||||
|
- `scripts/entrypoint-web.sh` - Web container entrypoint
|
||||||
|
- `scripts/entrypoint-worker.sh` - Worker container entrypoint
|
||||||
|
- `scripts/run-migrations.sh` - Migration runner script
|
||||||
|
|
||||||
|
#### Configuration
|
||||||
|
- `config/nginx/nginx.conf` - Main nginx config (from deploy/docker/)
|
||||||
|
- `config/nginx/site.conf` - Virtual host config (from deploy/docker/nginx_http_only.conf)
|
||||||
|
- `config/nginx/uwsgi_params` - uWSGI params (from deploy/docker/)
|
||||||
|
- `config/nginx-proxy/client_max_body_size.conf` - For nginx-proxy (from deploy/docker/reverse_proxy/)
|
||||||
|
- `config/uwsgi/uwsgi.ini` - uWSGI configuration (from deploy/docker/)
|
||||||
|
- `config/imagemagick/policy.xml` - ImageMagick policy (from deploy/docker/)
|
||||||
|
|
||||||
|
#### Documentation
|
||||||
|
- `docs/DOCKER_V7.3_MIGRATION.md` - Complete migration guide
|
||||||
|
- Updated `docs/admins_docs.md` - Sections 4 and 5
|
||||||
|
|
||||||
|
## Architecture Changes
|
||||||
|
|
||||||
|
### Before (Old Architecture)
|
||||||
|
```
|
||||||
|
Single Container (supervisord managing multiple processes)
|
||||||
|
├── nginx (port 80)
|
||||||
|
├── uwsgi (port 9000)
|
||||||
|
├── celery beat
|
||||||
|
├── celery short workers
|
||||||
|
└── celery long workers
|
||||||
|
|
||||||
|
Controlled by ENABLE_* environment variables
|
||||||
|
```
|
||||||
|
|
||||||
|
### After (New Architecture)
|
||||||
|
```
|
||||||
|
Dedicated Containers (one process per container)
|
||||||
|
├── nginx (port 80) → web:9000
|
||||||
|
├── web (uwsgi on port 9000)
|
||||||
|
├── celery_beat
|
||||||
|
├── celery_short (scalable)
|
||||||
|
├── celery_long (scalable, optional :full image)
|
||||||
|
├── migrations (runs on startup)
|
||||||
|
├── db (PostgreSQL)
|
||||||
|
└── redis
|
||||||
|
|
||||||
|
Volumes:
|
||||||
|
- static_files (nginx ← web)
|
||||||
|
- media_files (nginx ← web, workers)
|
||||||
|
- postgres_data
|
||||||
|
```
|
||||||
|
|
||||||
|
## Key Improvements
|
||||||
|
|
||||||
|
### 1. **Removed Components**
|
||||||
|
- ❌ supervisord and all configs in `deploy/docker/supervisord/`
|
||||||
|
- ❌ `deploy/docker/start.sh`
|
||||||
|
- ❌ `deploy/docker/entrypoint.sh`
|
||||||
|
- ❌ All `ENABLE_*` environment variables
|
||||||
|
|
||||||
|
### 2. **Separated Services**
|
||||||
|
- Nginx runs in its own container
|
||||||
|
- Django/uWSGI in dedicated web container
|
||||||
|
- Celery workers split by task duration
|
||||||
|
- Migrations run automatically on every startup
|
||||||
|
|
||||||
|
### 3. **Production Ready**
|
||||||
|
- No file mounts in production (immutable images)
|
||||||
|
- Named volumes for data persistence
|
||||||
|
- Proper health checks
|
||||||
|
- Individual service scaling
|
||||||
|
|
||||||
|
### 4. **Development Friendly**
|
||||||
|
- Separate `-dev` compose file with file mounts
|
||||||
|
- Django debug mode
|
||||||
|
- Frontend hot reload
|
||||||
|
- Live code editing
|
||||||
|
|
||||||
|
## Images to Build
|
||||||
|
|
||||||
|
For production, these images need to be built and pushed to Docker Hub:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Build base and web image
|
||||||
|
docker build --target web -t mediacms/mediacms:7.3 .
|
||||||
|
|
||||||
|
# Build worker image
|
||||||
|
docker build --target worker -t mediacms/mediacms-worker:7.3 .
|
||||||
|
|
||||||
|
# Build worker-full image
|
||||||
|
docker build --target worker-full -t mediacms/mediacms-worker:7.3-full .
|
||||||
|
|
||||||
|
# Build nginx image
|
||||||
|
docker build -f Dockerfile.nginx -t mediacms/mediacms-nginx:7.3 .
|
||||||
|
```
|
||||||
|
|
||||||
|
## Deployment Options
|
||||||
|
|
||||||
|
### 1. Development
|
||||||
|
```bash
|
||||||
|
docker compose -f docker-compose-dev.yaml up
|
||||||
|
```
|
||||||
|
- File mounts for live editing
|
||||||
|
- Django runserver
|
||||||
|
- Frontend dev server
|
||||||
|
|
||||||
|
### 2. Production (HTTP)
|
||||||
|
```bash
|
||||||
|
# Rename .new files first
|
||||||
|
mv docker-compose.yaml.new docker-compose.yaml
|
||||||
|
|
||||||
|
docker compose up -d
|
||||||
|
```
|
||||||
|
- Immutable images
|
||||||
|
- No file mounts
|
||||||
|
- Port 80
|
||||||
|
|
||||||
|
### 3. Production (HTTPS)
|
||||||
|
```bash
|
||||||
|
# Rename .new files first
|
||||||
|
mv docker-compose-cert.yaml.new docker-compose-cert.yaml
|
||||||
|
|
||||||
|
# Edit and set your domain/email
|
||||||
|
docker compose -f docker-compose-cert.yaml up -d
|
||||||
|
```
|
||||||
|
- Automatic Let's Encrypt certificates
|
||||||
|
- Auto-renewal
|
||||||
|
|
||||||
|
## Migration Path for Existing Systems
|
||||||
|
|
||||||
|
### For Production Systems Currently Running
|
||||||
|
|
||||||
|
1. **Backup first**
|
||||||
|
```bash
|
||||||
|
docker exec <db_container> pg_dump -U mediacms mediacms > backup.sql
|
||||||
|
```
|
||||||
|
|
||||||
|
2. **Update compose file**
|
||||||
|
- Replace old docker-compose files with new ones
|
||||||
|
- Update domain settings in cert file if using HTTPS
|
||||||
|
|
||||||
|
3. **Pull new images**
|
||||||
|
```bash
|
||||||
|
docker pull mediacms/mediacms:7.3
|
||||||
|
docker pull mediacms/mediacms-worker:7.3
|
||||||
|
docker pull mediacms/mediacms-nginx:7.3
|
||||||
|
```
|
||||||
|
|
||||||
|
4. **Restart**
|
||||||
|
```bash
|
||||||
|
docker compose down
|
||||||
|
docker compose up -d
|
||||||
|
```
|
||||||
|
|
||||||
|
### Breaking Changes
|
||||||
|
|
||||||
|
1. **No more ENABLE_* variables** - Remove from any custom configs
|
||||||
|
2. **deploy/docker/local_settings.py** - Now use environment variables or custom image
|
||||||
|
3. **Service names changed**:
|
||||||
|
- `celery_worker` → `celery_short` + `celery_long`
|
||||||
|
- Added `nginx` service
|
||||||
|
|
||||||
|
## Testing Checklist
|
||||||
|
|
||||||
|
Before deploying to production, test:
|
||||||
|
|
||||||
|
- [ ] Migrations run successfully
|
||||||
|
- [ ] Static files served correctly
|
||||||
|
- [ ] Media files served correctly
|
||||||
|
- [ ] Django admin accessible
|
||||||
|
- [ ] Video upload works
|
||||||
|
- [ ] Video transcoding works (celery_long)
|
||||||
|
- [ ] Thumbnail generation works (celery_short)
|
||||||
|
- [ ] HTTPS redirects work (if using cert file)
|
||||||
|
- [ ] Database persistence across restarts
|
||||||
|
- [ ] Media files persistence across restarts
|
||||||
|
|
||||||
|
## Configuration Examples
|
||||||
|
|
||||||
|
### Use Full Worker Image
|
||||||
|
```yaml
|
||||||
|
celery_long:
|
||||||
|
image: mediacms/mediacms-worker:7.3-full
|
||||||
|
```
|
||||||
|
|
||||||
|
### Set Custom Domain
|
||||||
|
```yaml
|
||||||
|
environment:
|
||||||
|
FRONTEND_HOST: 'https://videos.example.com'
|
||||||
|
PORTAL_NAME: 'My Video Portal'
|
||||||
|
```
|
||||||
|
|
||||||
|
### Scale Workers
|
||||||
|
```bash
|
||||||
|
docker compose up -d --scale celery_short=3 --scale celery_long=2
|
||||||
|
```
|
||||||
|
|
||||||
|
## Files to Review Before Finalizing
|
||||||
|
|
||||||
|
1. **Dockerfile** - Review Python/Django/uWSGI configuration
|
||||||
|
2. **config/nginx/site.conf** - Review nginx paths and proxy settings
|
||||||
|
3. **docker-compose.yaml** - Review volume mounts and service dependencies
|
||||||
|
4. **scripts/run-migrations.sh** - Review migration logic
|
||||||
|
|
||||||
|
## Next Steps
|
||||||
|
|
||||||
|
To finalize this restructure:
|
||||||
|
|
||||||
|
1. **Test locally** with docker-compose-dev.yaml
|
||||||
|
2. **Build images** and push to Docker Hub
|
||||||
|
3. **Update CI/CD** to build new images
|
||||||
|
4. **Test in staging environment**
|
||||||
|
5. **Create release notes** referencing migration guide
|
||||||
|
|
||||||
|
## Backup
|
||||||
|
|
||||||
|
Old Docker files have been backed up to `.docker-backup/` directory.
|
||||||
|
|
||||||
|
## Rollback Plan
|
||||||
|
|
||||||
|
If issues arise, rollback by:
|
||||||
|
1. Reverting to old docker-compose files
|
||||||
|
2. Using old image tags
|
||||||
|
3. Restoring database from backup if needed
|
||||||
|
|
||||||
|
Old files are preserved in `.docker-backup/` directory.
|
||||||
|
|
||||||
|
## Support
|
||||||
|
|
||||||
|
- Migration Guide: `docs/DOCKER_V7.3_MIGRATION.md`
|
||||||
|
- Admin Docs: `docs/admins_docs.md` (updated sections 4, 5)
|
||||||
|
- Issues: https://github.com/mediacms-io/mediacms/issues
|
||||||
87
Dockerfile
87
Dockerfile
@@ -26,20 +26,22 @@ RUN mkdir -p /home/mediacms.io/bento4 && \
|
|||||||
############ BASE RUNTIME IMAGE ############
|
############ BASE RUNTIME IMAGE ############
|
||||||
FROM python:3.13.5-slim-bookworm AS base
|
FROM python:3.13.5-slim-bookworm AS base
|
||||||
|
|
||||||
|
LABEL org.opencontainers.image.version="7.3"
|
||||||
|
LABEL org.opencontainers.image.title="MediaCMS"
|
||||||
|
LABEL org.opencontainers.image.description="Modern, scalable and open source video platform"
|
||||||
|
|
||||||
SHELL ["/bin/bash", "-c"]
|
SHELL ["/bin/bash", "-c"]
|
||||||
|
|
||||||
ENV PYTHONUNBUFFERED=1
|
ENV PYTHONUNBUFFERED=1 \
|
||||||
ENV PYTHONDONTWRITEBYTECODE=1
|
PYTHONDONTWRITEBYTECODE=1 \
|
||||||
ENV CELERY_APP='cms'
|
CELERY_APP='cms' \
|
||||||
ENV VIRTUAL_ENV=/home/mediacms.io
|
VIRTUAL_ENV=/home/mediacms.io \
|
||||||
ENV PATH="$VIRTUAL_ENV/bin:$PATH"
|
PATH="$VIRTUAL_ENV/bin:$PATH"
|
||||||
|
|
||||||
# Install system dependencies first
|
# Install system dependencies (no nginx, no supervisor)
|
||||||
RUN apt-get update -y && \
|
RUN apt-get update -y && \
|
||||||
apt-get -y upgrade && \
|
apt-get -y upgrade && \
|
||||||
apt-get install --no-install-recommends -y \
|
apt-get install --no-install-recommends -y \
|
||||||
supervisor \
|
|
||||||
nginx \
|
|
||||||
imagemagick \
|
imagemagick \
|
||||||
procps \
|
procps \
|
||||||
build-essential \
|
build-essential \
|
||||||
@@ -50,11 +52,12 @@ RUN apt-get update -y && \
|
|||||||
libxmlsec1-dev \
|
libxmlsec1-dev \
|
||||||
libxmlsec1-openssl \
|
libxmlsec1-openssl \
|
||||||
libpq-dev \
|
libpq-dev \
|
||||||
|
gosu \
|
||||||
&& apt-get clean \
|
&& apt-get clean \
|
||||||
&& rm -rf /var/lib/apt/lists/*
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
# Set up virtualenv first
|
# Set up virtualenv
|
||||||
RUN mkdir -p /home/mediacms.io/mediacms/{logs} && \
|
RUN mkdir -p /home/mediacms.io/mediacms/{logs,media_files,static} && \
|
||||||
cd /home/mediacms.io && \
|
cd /home/mediacms.io && \
|
||||||
python3 -m venv $VIRTUAL_ENV
|
python3 -m venv $VIRTUAL_ENV
|
||||||
|
|
||||||
@@ -82,32 +85,58 @@ COPY --from=build-image /usr/local/bin/ffprobe /usr/local/bin/ffprobe
|
|||||||
COPY --from=build-image /usr/local/bin/qt-faststart /usr/local/bin/qt-faststart
|
COPY --from=build-image /usr/local/bin/qt-faststart /usr/local/bin/qt-faststart
|
||||||
COPY --from=build-image /home/mediacms.io/bento4 /home/mediacms.io/bento4
|
COPY --from=build-image /home/mediacms.io/bento4 /home/mediacms.io/bento4
|
||||||
|
|
||||||
# Copy application files
|
# Copy application files with correct ownership
|
||||||
COPY . /home/mediacms.io/mediacms
|
COPY --chown=www-data:www-data . /home/mediacms.io/mediacms
|
||||||
WORKDIR /home/mediacms.io/mediacms
|
WORKDIR /home/mediacms.io/mediacms
|
||||||
|
|
||||||
# required for sprite thumbnail generation for large video files
|
# Copy imagemagick policy for sprite thumbnail generation
|
||||||
COPY deploy/docker/policy.xml /etc/ImageMagick-6/policy.xml
|
COPY config/imagemagick/policy.xml /etc/ImageMagick-6/policy.xml
|
||||||
|
|
||||||
# Set process control environment variables
|
# Copy local_settings.py from config to cms/ for default Docker config (if exists)
|
||||||
ENV ENABLE_UWSGI='yes' \
|
RUN if [ -f config/local_settings.py ]; then \
|
||||||
ENABLE_NGINX='yes' \
|
cp config/local_settings.py cms/local_settings.py && \
|
||||||
ENABLE_CELERY_BEAT='yes' \
|
chown www-data:www-data cms/local_settings.py && \
|
||||||
ENABLE_CELERY_SHORT='yes' \
|
echo "Docker local_settings.py applied"; \
|
||||||
ENABLE_CELERY_LONG='yes' \
|
else \
|
||||||
ENABLE_MIGRATIONS='yes'
|
echo "No config/local_settings.py found, using default settings"; \
|
||||||
|
fi
|
||||||
|
|
||||||
EXPOSE 9000 80
|
# Create www-data user directories and set permissions
|
||||||
|
RUN mkdir -p /var/run/mediacms && \
|
||||||
|
chown -R www-data:www-data /home/mediacms.io/mediacms/logs \
|
||||||
|
/home/mediacms.io/mediacms/media_files \
|
||||||
|
/home/mediacms.io/mediacms/static \
|
||||||
|
/var/run/mediacms
|
||||||
|
|
||||||
RUN chmod +x ./deploy/docker/entrypoint.sh
|
# Copy and set up entrypoint script
|
||||||
|
COPY scripts/docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
|
||||||
|
RUN chmod +x /usr/local/bin/docker-entrypoint.sh
|
||||||
|
|
||||||
ENTRYPOINT ["./deploy/docker/entrypoint.sh"]
|
ENTRYPOINT ["/usr/local/bin/docker-entrypoint.sh"]
|
||||||
CMD ["./deploy/docker/start.sh"]
|
|
||||||
|
############ WEB IMAGE (Django/uWSGI) ############
|
||||||
|
FROM base AS web
|
||||||
|
|
||||||
|
# Install uWSGI
|
||||||
|
RUN uv pip install uwsgi
|
||||||
|
|
||||||
|
# Copy uWSGI configuration
|
||||||
|
COPY config/uwsgi/uwsgi.ini /home/mediacms.io/mediacms/uwsgi.ini
|
||||||
|
|
||||||
|
EXPOSE 9000
|
||||||
|
|
||||||
|
CMD ["/home/mediacms.io/bin/uwsgi", "--ini", "/home/mediacms.io/mediacms/uwsgi.ini"]
|
||||||
|
|
||||||
|
############ WORKER IMAGE (Celery) ############
|
||||||
|
FROM base AS worker
|
||||||
|
|
||||||
|
# CMD will be overridden in docker-compose for different worker types
|
||||||
|
|
||||||
|
############ FULL WORKER IMAGE (Celery with extra codecs) ############
|
||||||
|
FROM worker AS worker-full
|
||||||
|
|
||||||
############ FULL IMAGE ############
|
|
||||||
FROM base AS full
|
|
||||||
COPY requirements-full.txt ./
|
COPY requirements-full.txt ./
|
||||||
RUN mkdir -p /root/.cache/ && \
|
RUN mkdir -p /root/.cache/ && \
|
||||||
chmod go+rwx /root/ && \
|
chmod go+rwx /root/ && \
|
||||||
chmod go+rwx /root/.cache/
|
chmod go+rwx /root/.cache/ && \
|
||||||
RUN uv pip install -r requirements-full.txt
|
uv pip install -r requirements-full.txt
|
||||||
|
|||||||
18
Dockerfile.nginx
Normal file
18
Dockerfile.nginx
Normal file
@@ -0,0 +1,18 @@
|
|||||||
|
FROM nginx:alpine
|
||||||
|
|
||||||
|
LABEL org.opencontainers.image.version="7.3"
|
||||||
|
LABEL org.opencontainers.image.title="MediaCMS Nginx"
|
||||||
|
LABEL org.opencontainers.image.description="Nginx server for MediaCMS"
|
||||||
|
|
||||||
|
# Copy nginx configurations
|
||||||
|
COPY config/nginx/nginx.conf /etc/nginx/nginx.conf
|
||||||
|
COPY config/nginx/site.conf /etc/nginx/conf.d/default.conf
|
||||||
|
COPY config/nginx/uwsgi_params /etc/nginx/uwsgi_params
|
||||||
|
|
||||||
|
# Create directories for static and media files (will be volumes)
|
||||||
|
RUN mkdir -p /var/www/media /var/www/static && \
|
||||||
|
chown -R nginx:nginx /var/www
|
||||||
|
|
||||||
|
EXPOSE 80
|
||||||
|
|
||||||
|
CMD ["nginx", "-g", "daemon off;"]
|
||||||
@@ -253,7 +253,7 @@ POST_UPLOAD_AUTHOR_MESSAGE_UNLISTED_NO_COMMENTARY = ""
|
|||||||
CANNOT_ADD_MEDIA_MESSAGE = "User cannot add media, or maximum number of media uploads has been reached."
|
CANNOT_ADD_MEDIA_MESSAGE = "User cannot add media, or maximum number of media uploads has been reached."
|
||||||
|
|
||||||
# mp4hls command, part of Bento4
|
# mp4hls command, part of Bento4
|
||||||
MP4HLS_COMMAND = "/home/mediacms.io/mediacms/Bento4-SDK-1-6-0-637.x86_64-unknown-linux/bin/mp4hls"
|
MP4HLS_COMMAND = "/home/mediacms.io/bento4/bin/mp4hls"
|
||||||
|
|
||||||
# highly experimental, related with remote workers
|
# highly experimental, related with remote workers
|
||||||
ADMIN_TOKEN = ""
|
ADMIN_TOKEN = ""
|
||||||
@@ -370,41 +370,30 @@ FILE_UPLOAD_HANDLERS = [
|
|||||||
"django.core.files.uploadhandler.TemporaryFileUploadHandler",
|
"django.core.files.uploadhandler.TemporaryFileUploadHandler",
|
||||||
]
|
]
|
||||||
|
|
||||||
LOGS_DIR = os.path.join(BASE_DIR, "logs")
|
|
||||||
|
|
||||||
error_filename = os.path.join(LOGS_DIR, "debug.log")
|
|
||||||
if not os.path.exists(LOGS_DIR):
|
|
||||||
try:
|
|
||||||
os.mkdir(LOGS_DIR)
|
|
||||||
except PermissionError:
|
|
||||||
pass
|
|
||||||
|
|
||||||
if not os.path.isfile(error_filename):
|
|
||||||
open(error_filename, 'a').close()
|
|
||||||
|
|
||||||
LOGGING = {
|
LOGGING = {
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"disable_existing_loggers": False,
|
"disable_existing_loggers": False,
|
||||||
|
"formatters": {
|
||||||
|
"verbose": {
|
||||||
|
"format": "%(levelname)s %(asctime)s %(module)s "
|
||||||
|
"%(process)d %(thread)d %(message)s"
|
||||||
|
}
|
||||||
|
},
|
||||||
"handlers": {
|
"handlers": {
|
||||||
"file": {
|
"console": {
|
||||||
"level": "ERROR",
|
"level": "DEBUG",
|
||||||
"class": "logging.FileHandler",
|
"class": "logging.StreamHandler",
|
||||||
"filename": error_filename,
|
"formatter": "verbose",
|
||||||
},
|
}
|
||||||
},
|
|
||||||
"loggers": {
|
|
||||||
"django": {
|
|
||||||
"handlers": ["file"],
|
|
||||||
"level": "ERROR",
|
|
||||||
"propagate": True,
|
|
||||||
},
|
|
||||||
},
|
},
|
||||||
|
"root": {"level": "INFO", "handlers": ["console"]},
|
||||||
}
|
}
|
||||||
|
|
||||||
DATABASES = {"default": {"ENGINE": "django.db.backends.postgresql", "NAME": "mediacms", "HOST": "127.0.0.1", "PORT": "5432", "USER": "mediacms", "PASSWORD": "mediacms", "OPTIONS": {'pool': True}}}
|
DATABASES = {"default": {"ENGINE": "django.db.backends.postgresql", "NAME": "mediacms", "HOST": "db", "PORT": "5432", "USER": "mediacms", "PASSWORD": "mediacms", "OPTIONS": {'pool': True}}}
|
||||||
|
|
||||||
|
|
||||||
REDIS_LOCATION = "redis://127.0.0.1:6379/1"
|
REDIS_LOCATION = "redis://redis:6379/1"
|
||||||
CACHES = {
|
CACHES = {
|
||||||
"default": {
|
"default": {
|
||||||
"BACKEND": "django_redis.cache.RedisCache",
|
"BACKEND": "django_redis.cache.RedisCache",
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
user www-data;
|
user nginx;
|
||||||
worker_processes auto;
|
worker_processes auto;
|
||||||
pid /run/nginx.pid;
|
pid /run/nginx.pid;
|
||||||
|
|
||||||
@@ -23,8 +23,8 @@ http {
|
|||||||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # Dropping SSLv3, ref: POODLE
|
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # Dropping SSLv3, ref: POODLE
|
||||||
ssl_prefer_server_ciphers on;
|
ssl_prefer_server_ciphers on;
|
||||||
|
|
||||||
access_log /var/log/nginx/access.log;
|
access_log /var/log/mediacms/nginx-main.access.log;
|
||||||
error_log /var/log/nginx/error.log;
|
error_log /var/log/mediacms/nginx-main.error.log;
|
||||||
|
|
||||||
gzip on;
|
gzip on;
|
||||||
gzip_disable "msie6";
|
gzip_disable "msie6";
|
||||||
@@ -2,20 +2,20 @@ server {
|
|||||||
listen 80 ;
|
listen 80 ;
|
||||||
|
|
||||||
gzip on;
|
gzip on;
|
||||||
access_log /var/log/nginx/mediacms.io.access.log;
|
access_log /var/log/mediacms/nginx.access.log;
|
||||||
|
|
||||||
error_log /var/log/nginx/mediacms.io.error.log warn;
|
error_log /var/log/mediacms/nginx.error.log warn;
|
||||||
|
|
||||||
location /static {
|
location /static {
|
||||||
alias /home/mediacms.io/mediacms/static ;
|
alias /var/www/static ;
|
||||||
}
|
}
|
||||||
|
|
||||||
location /media/original {
|
location /media/original {
|
||||||
alias /home/mediacms.io/mediacms/media_files/original;
|
alias /var/www/media/original;
|
||||||
}
|
}
|
||||||
|
|
||||||
location /media {
|
location /media {
|
||||||
alias /home/mediacms.io/mediacms/media_files ;
|
alias /var/www/media ;
|
||||||
add_header 'Access-Control-Allow-Origin' '*';
|
add_header 'Access-Control-Allow-Origin' '*';
|
||||||
add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS';
|
add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS';
|
||||||
add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range';
|
add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range';
|
||||||
@@ -28,7 +28,7 @@ server {
|
|||||||
add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range';
|
add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range';
|
||||||
add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range';
|
add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range';
|
||||||
|
|
||||||
include /etc/nginx/sites-enabled/uwsgi_params;
|
include /etc/nginx/uwsgi_params;
|
||||||
uwsgi_pass 127.0.0.1:9000;
|
uwsgi_pass web:9000;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -12,7 +12,7 @@ threads = 2
|
|||||||
|
|
||||||
master = true
|
master = true
|
||||||
|
|
||||||
socket = 127.0.0.1:9000
|
socket = 0.0.0.0:9000
|
||||||
|
|
||||||
workers = 2
|
workers = 2
|
||||||
|
|
||||||
@@ -1,7 +1,7 @@
|
|||||||
# MediaCMS: Document Changes for DEIC
|
# MediaCMS: Document Changes for DEIC
|
||||||
|
|
||||||
## Configuration Changes
|
## Configuration Changes
|
||||||
The following changes are required in `deploy/docker/local_settings.py`:
|
The following changes are required in `config/local_settings.py`:
|
||||||
|
|
||||||
```python
|
```python
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +0,0 @@
|
|||||||
# MediaCMS on Docker
|
|
||||||
|
|
||||||
See: [Details](../../docs/Docker_deployment.md)
|
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
set -e
|
|
||||||
|
|
||||||
# forward request and error logs to docker log collector
|
|
||||||
ln -sf /dev/stdout /var/log/nginx/access.log && ln -sf /dev/stderr /var/log/nginx/error.log && \
|
|
||||||
ln -sf /dev/stdout /var/log/nginx/mediacms.io.access.log && ln -sf /dev/stderr /var/log/nginx/mediacms.io.error.log
|
|
||||||
|
|
||||||
cp /home/mediacms.io/mediacms/deploy/docker/local_settings.py /home/mediacms.io/mediacms/cms/local_settings.py
|
|
||||||
|
|
||||||
|
|
||||||
mkdir -p /home/mediacms.io/mediacms/{logs,media_files/hls}
|
|
||||||
touch /home/mediacms.io/mediacms/logs/debug.log
|
|
||||||
|
|
||||||
mkdir -p /var/run/mediacms
|
|
||||||
chown www-data:www-data /var/run/mediacms
|
|
||||||
|
|
||||||
TARGET_GID=$(stat -c "%g" /home/mediacms.io/mediacms/)
|
|
||||||
|
|
||||||
EXISTS=$(cat /etc/group | grep $TARGET_GID | wc -l)
|
|
||||||
|
|
||||||
# Create new group using target GID and add www-data user
|
|
||||||
if [ $EXISTS == "0" ]; then
|
|
||||||
groupadd -g $TARGET_GID tempgroup
|
|
||||||
usermod -a -G tempgroup www-data
|
|
||||||
else
|
|
||||||
# GID exists, find group name and add
|
|
||||||
GROUP=$(getent group $TARGET_GID | cut -d: -f1)
|
|
||||||
usermod -a -G $GROUP www-data
|
|
||||||
fi
|
|
||||||
|
|
||||||
# We should do this only for folders that have a different owner, since it is an expensive operation
|
|
||||||
# Also ignoring .git folder to fix this issue https://github.com/mediacms-io/mediacms/issues/934
|
|
||||||
# Exclude package-lock.json files that may not exist or be removed during frontend setup
|
|
||||||
find /home/mediacms.io/mediacms ! \( -path "*.git*" -o -name "package-lock.json" \) -exec chown www-data:$TARGET_GID {} + 2>/dev/null || true
|
|
||||||
|
|
||||||
chmod +x /home/mediacms.io/mediacms/deploy/docker/start.sh /home/mediacms.io/mediacms/deploy/docker/prestart.sh
|
|
||||||
|
|
||||||
exec "$@"
|
|
||||||
@@ -1,36 +0,0 @@
|
|||||||
import os
|
|
||||||
|
|
||||||
FRONTEND_HOST = os.getenv('FRONTEND_HOST', 'http://localhost')
|
|
||||||
PORTAL_NAME = os.getenv('PORTAL_NAME', 'MediaCMS')
|
|
||||||
SECRET_KEY = os.getenv('SECRET_KEY', 'ma!s3^b-cw!f#7s6s0m3*jx77a@riw(7701**(r=ww%w!2+yk2')
|
|
||||||
REDIS_LOCATION = os.getenv('REDIS_LOCATION', 'redis://redis:6379/1')
|
|
||||||
|
|
||||||
DATABASES = {
|
|
||||||
"default": {
|
|
||||||
"ENGINE": "django.db.backends.postgresql",
|
|
||||||
"NAME": os.getenv('POSTGRES_NAME', 'mediacms'),
|
|
||||||
"HOST": os.getenv('POSTGRES_HOST', 'db'),
|
|
||||||
"PORT": os.getenv('POSTGRES_PORT', '5432'),
|
|
||||||
"USER": os.getenv('POSTGRES_USER', 'mediacms'),
|
|
||||||
"PASSWORD": os.getenv('POSTGRES_PASSWORD', 'mediacms'),
|
|
||||||
"OPTIONS": {'pool': True},
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
CACHES = {
|
|
||||||
"default": {
|
|
||||||
"BACKEND": "django_redis.cache.RedisCache",
|
|
||||||
"LOCATION": REDIS_LOCATION,
|
|
||||||
"OPTIONS": {
|
|
||||||
"CLIENT_CLASS": "django_redis.client.DefaultClient",
|
|
||||||
},
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# CELERY STUFF
|
|
||||||
BROKER_URL = REDIS_LOCATION
|
|
||||||
CELERY_RESULT_BACKEND = BROKER_URL
|
|
||||||
|
|
||||||
MP4HLS_COMMAND = "/home/mediacms.io/bento4/bin/mp4hls"
|
|
||||||
|
|
||||||
DEBUG = os.getenv('DEBUG', 'False') == 'True'
|
|
||||||
@@ -1,71 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
|
|
||||||
RANDOM_ADMIN_PASS=`python -c "import secrets;chars = 'abcdefghijklmnopqrstuvwxyz0123456789';print(''.join(secrets.choice(chars) for i in range(10)))"`
|
|
||||||
ADMIN_PASSWORD=${ADMIN_PASSWORD:-$RANDOM_ADMIN_PASS}
|
|
||||||
|
|
||||||
if [ X"$ENABLE_MIGRATIONS" = X"yes" ]; then
|
|
||||||
echo "Running migrations service"
|
|
||||||
python manage.py migrate
|
|
||||||
EXISTING_INSTALLATION=`echo "from users.models import User; print(User.objects.exists())" |python manage.py shell`
|
|
||||||
if [ "$EXISTING_INSTALLATION" = "True" ]; then
|
|
||||||
echo "Loaddata has already run"
|
|
||||||
else
|
|
||||||
echo "Running loaddata and creating admin user"
|
|
||||||
python manage.py loaddata fixtures/encoding_profiles.json
|
|
||||||
python manage.py loaddata fixtures/categories.json
|
|
||||||
|
|
||||||
# post_save, needs redis to succeed (ie. migrate depends on redis)
|
|
||||||
DJANGO_SUPERUSER_PASSWORD=$ADMIN_PASSWORD python manage.py createsuperuser \
|
|
||||||
--no-input \
|
|
||||||
--username=$ADMIN_USER \
|
|
||||||
--email=$ADMIN_EMAIL \
|
|
||||||
--database=default || true
|
|
||||||
echo "Created admin user with password: $ADMIN_PASSWORD"
|
|
||||||
|
|
||||||
fi
|
|
||||||
echo "RUNNING COLLECTSTATIC"
|
|
||||||
|
|
||||||
python manage.py collectstatic --noinput
|
|
||||||
|
|
||||||
# echo "Updating hostname ..."
|
|
||||||
# TODO: Get the FRONTEND_HOST from cms/local_settings.py
|
|
||||||
# echo "from django.contrib.sites.models import Site; Site.objects.update(name='$FRONTEND_HOST', domain='$FRONTEND_HOST')" | python manage.py shell
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Setting up internal nginx server
|
|
||||||
# HTTPS setup is delegated to a reverse proxy running infront of the application
|
|
||||||
|
|
||||||
cp deploy/docker/nginx_http_only.conf /etc/nginx/sites-available/default
|
|
||||||
cp deploy/docker/nginx_http_only.conf /etc/nginx/sites-enabled/default
|
|
||||||
cp deploy/docker/uwsgi_params /etc/nginx/sites-enabled/uwsgi_params
|
|
||||||
cp deploy/docker/nginx.conf /etc/nginx/
|
|
||||||
|
|
||||||
#### Supervisord Configurations #####
|
|
||||||
|
|
||||||
cp deploy/docker/supervisord/supervisord-debian.conf /etc/supervisor/conf.d/supervisord-debian.conf
|
|
||||||
|
|
||||||
if [ X"$ENABLE_UWSGI" = X"yes" ] ; then
|
|
||||||
echo "Enabling uwsgi app server"
|
|
||||||
cp deploy/docker/supervisord/supervisord-uwsgi.conf /etc/supervisor/conf.d/supervisord-uwsgi.conf
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ X"$ENABLE_NGINX" = X"yes" ] ; then
|
|
||||||
echo "Enabling nginx as uwsgi app proxy and media server"
|
|
||||||
cp deploy/docker/supervisord/supervisord-nginx.conf /etc/supervisor/conf.d/supervisord-nginx.conf
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ X"$ENABLE_CELERY_BEAT" = X"yes" ] ; then
|
|
||||||
echo "Enabling celery-beat scheduling server"
|
|
||||||
cp deploy/docker/supervisord/supervisord-celery_beat.conf /etc/supervisor/conf.d/supervisord-celery_beat.conf
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ X"$ENABLE_CELERY_SHORT" = X"yes" ] ; then
|
|
||||||
echo "Enabling celery-short task worker"
|
|
||||||
cp deploy/docker/supervisord/supervisord-celery_short.conf /etc/supervisor/conf.d/supervisord-celery_short.conf
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ X"$ENABLE_CELERY_LONG" = X"yes" ] ; then
|
|
||||||
echo "Enabling celery-long task worker"
|
|
||||||
cp deploy/docker/supervisord/supervisord-celery_long.conf /etc/supervisor/conf.d/supervisord-celery_long.conf
|
|
||||||
rm /var/run/mediacms/* -f # remove any stale id, so that on forced restarts of celery workers there are no stale processes that prevent new ones
|
|
||||||
fi
|
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
-----BEGIN CERTIFICATE-----
|
|
||||||
MIICwzCCAaugAwIBAgIJAOyvdwguJQd+MA0GCSqGSIb3DQEBBQUAMBQxEjAQBgNV
|
|
||||||
BAMTCWxvY2FsaG9zdDAeFw0yMTAxMjQxMjUwMzFaFw0zMTAxMjIxMjUwMzFaMBQx
|
|
||||||
EjAQBgNVBAMTCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
|
|
||||||
ggEBAONswEwBzkgoO+lkewiKUnwvYqC54qleCUg9hidqjoyzd5XWKh1mIF7aaSCG
|
|
||||||
rJGSxCce8CbqAqGkpvsgXzwwbY72l7FwmAXFHO5ObQfpmFhjt2fsKRM9MTCo/UyU
|
|
||||||
liuhgP+Q+BNzUontTUC40NVHs8R7IHG4z8unB7qB/7zGK2tfilLB8JDqPTkc22vN
|
|
||||||
C4P1YxiGyY5bm37wQrroC9zPJ8bqanrF9Y90QJHubibnPWqnZvK2HkDWjp5LYkn8
|
|
||||||
IuzBycs1cLd8eMjU9aT72kweykvnGDDc3YbXFzT2zBTGSFEBROsVdPrNF9PaeE3j
|
|
||||||
pu4UZ8Ge3Fp3VYd+04DnWtbQq0MCAwEAAaMYMBYwFAYDVR0RBA0wC4IJbG9jYWxo
|
|
||||||
b3N0MA0GCSqGSIb3DQEBBQUAA4IBAQAdm2aGn4evosbdWgBHgzr6oYWBIiPpf1SA
|
|
||||||
GXizuf5OaMActFP0rZ0mogndLH5d51J2qqSfOtaWSA5qwlPvDSTn1nvJeHoVLfZf
|
|
||||||
kQHaB7/DaOPGsZCQBELPhYHwl7+Ej3HYE+siiaRfjC2NVgf8P/pAsTlKbe2e+34l
|
|
||||||
GwWSFol24w5xAmUezCF41JiZbqHoZhSh7s/PuJnK2RvhpjkrIot8GvxnbvOcKDIv
|
|
||||||
JzEKo3qPq8pc5RBkpP7Kp2+EgAYn1xAn0CekxZracW/MY+tg2mCeFucZW2V1iwVs
|
|
||||||
LpAw6GJnjYz5mbrQskPbrJ9t78JGUKQ0kL/VUTfryUHMHYCiJlvd
|
|
||||||
-----END CERTIFICATE-----
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
-----BEGIN RSA PRIVATE KEY-----
|
|
||||||
MIIEpAIBAAKCAQEA42zATAHOSCg76WR7CIpSfC9ioLniqV4JSD2GJ2qOjLN3ldYq
|
|
||||||
HWYgXtppIIaskZLEJx7wJuoCoaSm+yBfPDBtjvaXsXCYBcUc7k5tB+mYWGO3Z+wp
|
|
||||||
Ez0xMKj9TJSWK6GA/5D4E3NSie1NQLjQ1UezxHsgcbjPy6cHuoH/vMYra1+KUsHw
|
|
||||||
kOo9ORzba80Lg/VjGIbJjlubfvBCuugL3M8nxupqesX1j3RAke5uJuc9aqdm8rYe
|
|
||||||
QNaOnktiSfwi7MHJyzVwt3x4yNT1pPvaTB7KS+cYMNzdhtcXNPbMFMZIUQFE6xV0
|
|
||||||
+s0X09p4TeOm7hRnwZ7cWndVh37TgOda1tCrQwIDAQABAoIBAQCmKKyOW7tlCNBN
|
|
||||||
AzbI1JbTWKOMnoM2DxhlCV5cqgOgVPcIKEL428bGxniMZRjr+vkJRBddtxdZFj1R
|
|
||||||
uSMbjJ5fF1dZMtQ/UvaCPhZ283p1CdXUPbz863ZnAPCf5Oea1RK0piw5ucYSM6h/
|
|
||||||
owgg65Qx92uK6uYW+uAwqg440+ihNvnaZoVTx5CjZbL9KISkrlNJnuYiB5vzOD0i
|
|
||||||
UVklO5Qz8VCuOcOVGZCA2SxHm4HAbg/aiQnpaUa9de4TsZ4ygF66pZh77T0wNOos
|
|
||||||
sS1riKtHQpX+osJyoTI/rIKFAhycsZ+AA7Qpu6GW4xQlNS6K8vRiIbktwkC+IT0O
|
|
||||||
RSn8Dg7BAoGBAPe5R8SpgXx9jKdA1eFa/Vjx5bmB96r2MviIOIWF8rs2K33xe+rj
|
|
||||||
v+BZ2ZjdpVjcm2nRMf9r/eDq2ScNFWmKoZsUmdyT84Qq9yLcTSUdno+zCy+L0LNH
|
|
||||||
DqJq5jIxJaV7amHeR/w10BVuiDmzhSsTmhfnXTUGRO/h2PjRyC3yEYdxAoGBAOsF
|
|
||||||
2+gTsdOGlq6AVzW5MLZkreq8WCU2wWpZRiCPh6HJa8htuynYxO5AWUiNUbYKddj2
|
|
||||||
0za9DFiXgH+Oo8wrkTYLEdN0T5/o+ScL5t3VG3m9R6pnuudLC2vmGQP0hNuZUpnF
|
|
||||||
7FzdJ85h6taR2bM1zFzOfl81K0BhTHGxTU2r70vzAoGAVXuLJ3LyqtnMKn72DzDN
|
|
||||||
0d6PTkdqBoW0qwyerHy/eRjFQ02MXE7BDJMUwmphv1tJCefVX/WNAwsnahFavTPI
|
|
||||||
dnJSccpgMtB8vXvV5yPkbmPzTTHrD6JKi4Nl8hYBjqwa1rDUmFSdfHfK7FZlcqrt
|
|
||||||
9qexAzYpnbmKnLoPYMNyhxECgYEAm5OCUeuPoL2MS7GLiXWwyFx3QFczZlcLzBGS
|
|
||||||
uYUpvLBwF/qDlhz3p9uS/tMFzyK3hktF4Ate+9o2ZroOtd31PzgusbJh7zIylGVt
|
|
||||||
i1VB3eGtaiFGeUuVIPTthE++Dvw80KxTXdnMOvNYmHduDBLF2H2c6/tvSSvfhbdf
|
|
||||||
u9XgD38CgYAiLcVySxMKNpsXatuC31wjT+rnaH22SD/7pXe2q6MRW/s+bGOspu0v
|
|
||||||
NeJSLoM98v8F99q0W0lgqesYJVI20Frru0DfXIp60ryaDolzve3Iwk8SOJUlcnUG
|
|
||||||
cCtmPUkjyr18QAlrcCB4PozJGjpPWyabaY8gGwo8wAEpJWHrIJlHew==
|
|
||||||
-----END RSA PRIVATE KEY-----
|
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
#! /usr/bin/env sh
|
|
||||||
set -e
|
|
||||||
|
|
||||||
# If there's a prestart.sh script in the /app directory, run it before starting
|
|
||||||
PRE_START_PATH=deploy/docker/prestart.sh
|
|
||||||
echo "Checking for script in $PRE_START_PATH"
|
|
||||||
if [ -f $PRE_START_PATH ] ; then
|
|
||||||
echo "Running script $PRE_START_PATH"
|
|
||||||
. $PRE_START_PATH
|
|
||||||
else
|
|
||||||
echo "There is no script $PRE_START_PATH"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Start Supervisor, with Nginx and uWSGI
|
|
||||||
echo "Starting server using supervisord..."
|
|
||||||
|
|
||||||
exec /usr/bin/supervisord
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
[program:celery_beat]
|
|
||||||
stdout_logfile=/dev/stdout
|
|
||||||
stdout_logfile_maxbytes=0
|
|
||||||
stderr_logfile=/dev/stderr
|
|
||||||
stderr_logfile_maxbytes=0
|
|
||||||
startsecs=0
|
|
||||||
numprocs=1
|
|
||||||
user=www-data
|
|
||||||
directory=/home/mediacms.io/mediacms
|
|
||||||
priority=300
|
|
||||||
startinorder=true
|
|
||||||
command=/home/mediacms.io/bin/celery beat --pidfile=/var/run/mediacms/beat%%n.pid --loglevel=INFO --logfile=/home/mediacms.io/mediacms/logs/celery_beat.log
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
[program:celery_long]
|
|
||||||
stdout_logfile=/dev/stdout
|
|
||||||
stdout_logfile_maxbytes=0
|
|
||||||
stderr_logfile=/dev/stderr
|
|
||||||
stderr_logfile_maxbytes=0
|
|
||||||
startsecs=10
|
|
||||||
numprocs=1
|
|
||||||
user=www-data
|
|
||||||
directory=/home/mediacms.io/mediacms
|
|
||||||
priority=500
|
|
||||||
startinorder=true
|
|
||||||
startsecs=0
|
|
||||||
command=/home/mediacms.io/bin/celery multi start long1 --pidfile=/var/run/mediacms/%%n.pid --loglevel=INFO --logfile=/home/mediacms.io/mediacms/logs/celery_long.log -Ofair --prefetch-multiplier=1 -Q long_tasks
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
[program:celery_short]
|
|
||||||
stdout_logfile=/dev/stdout
|
|
||||||
stdout_logfile_maxbytes=0
|
|
||||||
stderr_logfile=/dev/stderr
|
|
||||||
stderr_logfile_maxbytes=0
|
|
||||||
startsecs=0
|
|
||||||
numprocs=1
|
|
||||||
user=www-data
|
|
||||||
directory=/home/mediacms.io/mediacms
|
|
||||||
priority=400
|
|
||||||
startinorder=true
|
|
||||||
command=/home/mediacms.io/bin/celery multi start short1 short2 --pidfile=/var/run/mediacms/%%n.pid --loglevel=INFO --logfile=/home/mediacms.io/mediacms/logs/celery_short.log --soft-time-limit=300 -c10 -Q short_tasks
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
[supervisord]
|
|
||||||
nodaemon=true
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
[program:nginx]
|
|
||||||
command=/usr/sbin/nginx -g 'daemon off;'
|
|
||||||
stdout_logfile=/dev/stdout
|
|
||||||
stdout_logfile_maxbytes=0
|
|
||||||
stderr_logfile=/dev/stderr
|
|
||||||
stderr_logfile_maxbytes=0
|
|
||||||
priority=200
|
|
||||||
startinorder=true
|
|
||||||
startsecs=0
|
|
||||||
# Graceful stop, see http://nginx.org/en/docs/control.html
|
|
||||||
stopsignal=QUIT
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
[program:uwsgi]
|
|
||||||
command=/home/mediacms.io/bin/uwsgi --ini /home/mediacms.io/mediacms/deploy/docker/uwsgi.ini
|
|
||||||
stdout_logfile=/dev/stdout
|
|
||||||
stdout_logfile_maxbytes=0
|
|
||||||
stderr_logfile=/dev/stderr
|
|
||||||
stderr_logfile_maxbytes=0
|
|
||||||
priority=100
|
|
||||||
startinorder=true
|
|
||||||
startsecs=0
|
|
||||||
161
docker-compose-cert.yaml
Normal file
161
docker-compose-cert.yaml
Normal file
@@ -0,0 +1,161 @@
|
|||||||
|
version: "3.8"
|
||||||
|
|
||||||
|
# Production setup with automatic HTTPS via Let's Encrypt
|
||||||
|
# Uses https://github.com/nginx-proxy/acme-companion
|
||||||
|
|
||||||
|
services:
|
||||||
|
nginx-proxy:
|
||||||
|
image: nginxproxy/nginx-proxy
|
||||||
|
container_name: nginx-proxy
|
||||||
|
restart: unless-stopped
|
||||||
|
ports:
|
||||||
|
- "80:80"
|
||||||
|
- "443:443"
|
||||||
|
volumes:
|
||||||
|
- conf:/etc/nginx/conf.d
|
||||||
|
- vhost:/etc/nginx/vhost.d
|
||||||
|
- html:/usr/share/nginx/html
|
||||||
|
- dhparam:/etc/nginx/dhparam
|
||||||
|
- certs:/etc/nginx/certs:ro
|
||||||
|
- /var/run/docker.sock:/tmp/docker.sock:ro
|
||||||
|
- ./config/nginx-proxy/client_max_body_size.conf:/etc/nginx/conf.d/client_max_body_size.conf:ro
|
||||||
|
|
||||||
|
acme-companion:
|
||||||
|
image: nginxproxy/acme-companion
|
||||||
|
container_name: nginx-proxy-acme
|
||||||
|
restart: unless-stopped
|
||||||
|
volumes_from:
|
||||||
|
- nginx-proxy
|
||||||
|
volumes:
|
||||||
|
- certs:/etc/nginx/certs:rw
|
||||||
|
- acme:/etc/acme.sh
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
|
|
||||||
|
migrations:
|
||||||
|
image: mediacms/mediacms:7.3
|
||||||
|
command: ["/bin/bash", "/home/mediacms.io/mediacms/scripts/run-migrations.sh"]
|
||||||
|
environment:
|
||||||
|
ADMIN_USER: 'admin'
|
||||||
|
ADMIN_EMAIL: 'admin@localhost'
|
||||||
|
# ADMIN_PASSWORD: 'uncomment_and_set_password_here'
|
||||||
|
restart: "no"
|
||||||
|
depends_on:
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
db:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- static_files:/home/mediacms.io/mediacms/static_files
|
||||||
|
- media_files:/home/mediacms.io/mediacms/media_files
|
||||||
|
- logs:/home/mediacms.io/mediacms/logs
|
||||||
|
|
||||||
|
web:
|
||||||
|
image: mediacms/mediacms:7.3
|
||||||
|
restart: unless-stopped
|
||||||
|
expose:
|
||||||
|
- "9000"
|
||||||
|
depends_on:
|
||||||
|
migrations:
|
||||||
|
condition: service_completed_successfully
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
db:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- static_files:/home/mediacms.io/mediacms/static_files
|
||||||
|
- media_files:/home/mediacms.io/mediacms/media_files
|
||||||
|
- logs:/home/mediacms.io/mediacms/logs
|
||||||
|
|
||||||
|
nginx:
|
||||||
|
image: mediacms/mediacms-nginx:7.3
|
||||||
|
restart: unless-stopped
|
||||||
|
expose:
|
||||||
|
- "80"
|
||||||
|
environment:
|
||||||
|
# These are required for nginx-proxy to route traffic correctly
|
||||||
|
VIRTUAL_HOST: 'mediacms.example.com' # CHANGE THIS to your domain
|
||||||
|
LETSENCRYPT_HOST: 'mediacms.example.com' # CHANGE THIS to your domain
|
||||||
|
LETSENCRYPT_EMAIL: 'admin@example.com' # CHANGE THIS to your email
|
||||||
|
depends_on:
|
||||||
|
- web
|
||||||
|
volumes:
|
||||||
|
- static_files:/var/www/static:ro
|
||||||
|
- media_files:/var/www/media:ro
|
||||||
|
- logs:/var/log/mediacms
|
||||||
|
|
||||||
|
celery_beat:
|
||||||
|
image: mediacms/mediacms-worker:7.3
|
||||||
|
restart: unless-stopped
|
||||||
|
command: ["/home/mediacms.io/bin/celery", "-A", "cms", "beat", "--loglevel=INFO"]
|
||||||
|
depends_on:
|
||||||
|
migrations:
|
||||||
|
condition: service_completed_successfully
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- media_files:/home/mediacms.io/mediacms/media_files
|
||||||
|
- logs:/home/mediacms.io/mediacms/logs
|
||||||
|
|
||||||
|
celery_short:
|
||||||
|
image: mediacms/mediacms-worker:7.3
|
||||||
|
restart: unless-stopped
|
||||||
|
command: ["/home/mediacms.io/bin/celery", "-A", "cms", "worker", "-Q", "short_tasks", "-c", "10", "--soft-time-limit=300", "--loglevel=INFO", "-n", "short@%h"]
|
||||||
|
depends_on:
|
||||||
|
migrations:
|
||||||
|
condition: service_completed_successfully
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- media_files:/home/mediacms.io/mediacms/media_files
|
||||||
|
- logs:/home/mediacms.io/mediacms/logs
|
||||||
|
|
||||||
|
celery_long:
|
||||||
|
image: mediacms/mediacms-worker:7.3
|
||||||
|
# To use extra codecs, change image to: mediacms/mediacms-worker:7.3-full
|
||||||
|
restart: unless-stopped
|
||||||
|
command: ["/home/mediacms.io/bin/celery", "-A", "cms", "worker", "-Q", "long_tasks", "-c", "1", "-Ofair", "--prefetch-multiplier=1", "--loglevel=INFO", "-n", "long@%h"]
|
||||||
|
depends_on:
|
||||||
|
migrations:
|
||||||
|
condition: service_completed_successfully
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- media_files:/home/mediacms.io/mediacms/media_files
|
||||||
|
- logs:/home/mediacms.io/mediacms/logs
|
||||||
|
|
||||||
|
db:
|
||||||
|
image: postgres:17.2-alpine
|
||||||
|
restart: unless-stopped
|
||||||
|
environment:
|
||||||
|
POSTGRES_USER: mediacms
|
||||||
|
POSTGRES_PASSWORD: mediacms
|
||||||
|
POSTGRES_DB: mediacms
|
||||||
|
TZ: Europe/London
|
||||||
|
volumes:
|
||||||
|
- postgres_data:/var/lib/postgresql/data
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD-SHELL", "pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}"]
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 5
|
||||||
|
|
||||||
|
redis:
|
||||||
|
image: redis:alpine
|
||||||
|
restart: unless-stopped
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "redis-cli", "ping"]
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
conf:
|
||||||
|
vhost:
|
||||||
|
html:
|
||||||
|
dhparam:
|
||||||
|
certs:
|
||||||
|
acme:
|
||||||
|
postgres_data:
|
||||||
|
static_files:
|
||||||
|
media_files:
|
||||||
|
logs:
|
||||||
@@ -1,4 +1,7 @@
|
|||||||
version: "3"
|
version: "3.8"
|
||||||
|
|
||||||
|
# Development setup with hot-reload and file mounts
|
||||||
|
# This is the ONLY compose file that mounts the source code
|
||||||
|
|
||||||
services:
|
services:
|
||||||
migrations:
|
migrations:
|
||||||
@@ -8,82 +11,126 @@ services:
|
|||||||
target: base
|
target: base
|
||||||
args:
|
args:
|
||||||
- DEVELOPMENT_MODE=True
|
- DEVELOPMENT_MODE=True
|
||||||
image: mediacms/mediacms-dev:latest
|
image: mediacms/mediacms-dev:7.3
|
||||||
volumes:
|
command: ["/bin/bash", "/home/mediacms.io/mediacms/scripts/run-migrations.sh"]
|
||||||
- ./:/home/mediacms.io/mediacms/
|
|
||||||
command: "./deploy/docker/prestart.sh"
|
|
||||||
environment:
|
environment:
|
||||||
DEVELOPMENT_MODE: True
|
DEVELOPMENT_MODE: 'True'
|
||||||
ENABLE_UWSGI: 'no'
|
DEBUG: 'True'
|
||||||
ENABLE_NGINX: 'no'
|
|
||||||
ENABLE_CELERY_SHORT: 'no'
|
|
||||||
ENABLE_CELERY_LONG: 'no'
|
|
||||||
ENABLE_CELERY_BEAT: 'no'
|
|
||||||
ADMIN_USER: 'admin'
|
ADMIN_USER: 'admin'
|
||||||
ADMIN_EMAIL: 'admin@localhost'
|
ADMIN_EMAIL: 'admin@localhost'
|
||||||
ADMIN_PASSWORD: 'admin'
|
ADMIN_PASSWORD: 'admin'
|
||||||
restart: on-failure
|
restart: "no"
|
||||||
depends_on:
|
depends_on:
|
||||||
redis:
|
redis:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
db:
|
db:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
frontend:
|
|
||||||
image: node:20
|
|
||||||
volumes:
|
|
||||||
- ${PWD}/frontend:/home/mediacms.io/mediacms/frontend/
|
|
||||||
working_dir: /home/mediacms.io/mediacms/frontend/
|
|
||||||
command: bash -c "npm install && npm run start"
|
|
||||||
env_file:
|
|
||||||
- ${PWD}/frontend/.env
|
|
||||||
ports:
|
|
||||||
- "8088:8088"
|
|
||||||
depends_on:
|
|
||||||
- web
|
|
||||||
web:
|
|
||||||
image: mediacms/mediacms-dev:latest
|
|
||||||
command: "python manage.py runserver 0.0.0.0:80"
|
|
||||||
environment:
|
|
||||||
DEVELOPMENT_MODE: True
|
|
||||||
ports:
|
|
||||||
- "80:80"
|
|
||||||
volumes:
|
volumes:
|
||||||
- ./:/home/mediacms.io/mediacms/
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
|
||||||
|
web:
|
||||||
|
image: mediacms/mediacms-dev:7.3
|
||||||
|
restart: unless-stopped
|
||||||
|
ports:
|
||||||
|
- "80:8000"
|
||||||
|
command: ["python", "manage.py", "runserver", "0.0.0.0:8000"]
|
||||||
|
environment:
|
||||||
|
DEVELOPMENT_MODE: 'True'
|
||||||
|
DEBUG: 'True'
|
||||||
depends_on:
|
depends_on:
|
||||||
- migrations
|
migrations:
|
||||||
|
condition: service_completed_successfully
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
db:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
|
||||||
|
frontend:
|
||||||
|
image: node:20-alpine
|
||||||
|
working_dir: /home/mediacms.io/mediacms/frontend/
|
||||||
|
command: sh -c "npm install && npm run start"
|
||||||
|
ports:
|
||||||
|
- "8088:8088"
|
||||||
|
environment:
|
||||||
|
- NODE_ENV=development
|
||||||
|
env_file:
|
||||||
|
- ./frontend/.env
|
||||||
|
volumes:
|
||||||
|
- ./frontend:/home/mediacms.io/mediacms/frontend/
|
||||||
|
depends_on:
|
||||||
|
- web
|
||||||
|
|
||||||
|
celery_beat:
|
||||||
|
image: mediacms/mediacms-dev:7.3
|
||||||
|
restart: unless-stopped
|
||||||
|
command: ["/home/mediacms.io/bin/celery", "-A", "cms", "beat", "--loglevel=INFO"]
|
||||||
|
environment:
|
||||||
|
DEVELOPMENT_MODE: 'True'
|
||||||
|
DEBUG: 'True'
|
||||||
|
depends_on:
|
||||||
|
migrations:
|
||||||
|
condition: service_completed_successfully
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
|
||||||
|
celery_short:
|
||||||
|
image: mediacms/mediacms-dev:7.3
|
||||||
|
restart: unless-stopped
|
||||||
|
command: ["/home/mediacms.io/bin/celery", "-A", "cms", "worker", "-Q", "short_tasks", "-c", "10", "--soft-time-limit=300", "--loglevel=INFO", "-n", "short@%h"]
|
||||||
|
environment:
|
||||||
|
DEVELOPMENT_MODE: 'True'
|
||||||
|
DEBUG: 'True'
|
||||||
|
depends_on:
|
||||||
|
migrations:
|
||||||
|
condition: service_completed_successfully
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
|
||||||
|
celery_long:
|
||||||
|
image: mediacms/mediacms-dev:7.3
|
||||||
|
restart: unless-stopped
|
||||||
|
command: ["/home/mediacms.io/bin/celery", "-A", "cms", "worker", "-Q", "long_tasks", "-c", "1", "-Ofair", "--prefetch-multiplier=1", "--loglevel=INFO", "-n", "long@%h"]
|
||||||
|
environment:
|
||||||
|
DEVELOPMENT_MODE: 'True'
|
||||||
|
DEBUG: 'True'
|
||||||
|
depends_on:
|
||||||
|
migrations:
|
||||||
|
condition: service_completed_successfully
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- ./:/home/mediacms.io/mediacms/
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: postgres:17.2-alpine
|
image: postgres:17.2-alpine
|
||||||
volumes:
|
restart: unless-stopped
|
||||||
- ../postgres_data:/var/lib/postgresql/data/
|
|
||||||
restart: always
|
|
||||||
environment:
|
environment:
|
||||||
POSTGRES_USER: mediacms
|
POSTGRES_USER: mediacms
|
||||||
POSTGRES_PASSWORD: mediacms
|
POSTGRES_PASSWORD: mediacms
|
||||||
POSTGRES_DB: mediacms
|
POSTGRES_DB: mediacms
|
||||||
TZ: Europe/London
|
TZ: Europe/London
|
||||||
|
volumes:
|
||||||
|
- postgres_data:/var/lib/postgresql/data
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD-SHELL", "pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}", "--host=db", "--dbname=$POSTGRES_DB", "--username=$POSTGRES_USER"]
|
test: ["CMD-SHELL", "pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}"]
|
||||||
interval: 10s
|
interval: 10s
|
||||||
timeout: 5s
|
timeout: 5s
|
||||||
retries: 5
|
retries: 5
|
||||||
|
|
||||||
redis:
|
redis:
|
||||||
image: "redis:alpine"
|
image: redis:alpine
|
||||||
restart: always
|
restart: unless-stopped
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD", "redis-cli", "ping"]
|
test: ["CMD", "redis-cli", "ping"]
|
||||||
interval: 30s
|
interval: 10s
|
||||||
timeout: 10s
|
timeout: 5s
|
||||||
retries: 3
|
retries: 3
|
||||||
celery_worker:
|
|
||||||
image: mediacms/mediacms-dev:latest
|
volumes:
|
||||||
deploy:
|
postgres_data:
|
||||||
replicas: 1
|
|
||||||
volumes:
|
|
||||||
- ./:/home/mediacms.io/mediacms/
|
|
||||||
environment:
|
|
||||||
ENABLE_UWSGI: 'no'
|
|
||||||
ENABLE_NGINX: 'no'
|
|
||||||
ENABLE_CELERY_BEAT: 'no'
|
|
||||||
ENABLE_MIGRATIONS: 'no'
|
|
||||||
depends_on:
|
|
||||||
- web
|
|
||||||
|
|||||||
@@ -1,86 +1,120 @@
|
|||||||
version: "3"
|
version: "3.8"
|
||||||
|
|
||||||
services:
|
services:
|
||||||
migrations:
|
migrations:
|
||||||
image: mediacms/mediacms:latest
|
image: mediacms/mediacms:7.3
|
||||||
volumes:
|
command: ["/bin/bash", "/home/mediacms.io/mediacms/scripts/run-migrations.sh"]
|
||||||
- ./:/home/mediacms.io/mediacms/
|
|
||||||
environment:
|
environment:
|
||||||
ENABLE_UWSGI: 'no'
|
|
||||||
ENABLE_NGINX: 'no'
|
|
||||||
ENABLE_CELERY_SHORT: 'no'
|
|
||||||
ENABLE_CELERY_LONG: 'no'
|
|
||||||
ENABLE_CELERY_BEAT: 'no'
|
|
||||||
ADMIN_USER: 'admin'
|
ADMIN_USER: 'admin'
|
||||||
ADMIN_EMAIL: 'admin@localhost'
|
ADMIN_EMAIL: 'admin@localhost'
|
||||||
# ADMIN_PASSWORD: 'uncomment_and_set_password_here'
|
ADMIN_PASSWORD: # ADMIN_PASSWORD: 'uncomment_and_set_password_here'
|
||||||
command: "./deploy/docker/prestart.sh"
|
restart: "no"
|
||||||
restart: on-failure
|
|
||||||
depends_on:
|
depends_on:
|
||||||
redis:
|
redis:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
db:
|
db:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- static_files:/home/mediacms.io/mediacms/static
|
||||||
|
- media_files:/home/mediacms.io/mediacms/media_files
|
||||||
|
- logs:/home/mediacms.io/mediacms/logs
|
||||||
|
|
||||||
web:
|
web:
|
||||||
image: mediacms/mediacms:latest
|
image: mediacms/mediacms:7.3
|
||||||
deploy:
|
restart: unless-stopped
|
||||||
replicas: 1
|
expose:
|
||||||
|
- "9000"
|
||||||
|
depends_on:
|
||||||
|
migrations:
|
||||||
|
condition: service_completed_successfully
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
db:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- static_files:/home/mediacms.io/mediacms/static
|
||||||
|
- media_files:/home/mediacms.io/mediacms/media_files
|
||||||
|
- logs:/home/mediacms.io/mediacms/logs
|
||||||
|
|
||||||
|
nginx:
|
||||||
|
image: mediacms/mediacms-nginx:7.3
|
||||||
|
restart: unless-stopped
|
||||||
ports:
|
ports:
|
||||||
- "80:80"
|
- "80:80"
|
||||||
volumes:
|
|
||||||
- ./:/home/mediacms.io/mediacms/
|
|
||||||
environment:
|
|
||||||
ENABLE_CELERY_BEAT: 'no'
|
|
||||||
ENABLE_CELERY_SHORT: 'no'
|
|
||||||
ENABLE_CELERY_LONG: 'no'
|
|
||||||
ENABLE_MIGRATIONS: 'no'
|
|
||||||
depends_on:
|
depends_on:
|
||||||
- migrations
|
- web
|
||||||
|
volumes:
|
||||||
|
- static_files:/var/www/static:ro
|
||||||
|
- media_files:/var/www/media:ro
|
||||||
|
- logs:/var/log/mediacms
|
||||||
|
|
||||||
celery_beat:
|
celery_beat:
|
||||||
image: mediacms/mediacms:latest
|
image: mediacms/mediacms-worker:7.3
|
||||||
volumes:
|
restart: unless-stopped
|
||||||
- ./:/home/mediacms.io/mediacms/
|
command: ["/home/mediacms.io/bin/celery", "-A", "cms", "beat", "--loglevel=INFO", "--schedule=/home/mediacms.io/mediacms/logs/celerybeat-schedule"]
|
||||||
environment:
|
|
||||||
ENABLE_UWSGI: 'no'
|
|
||||||
ENABLE_NGINX: 'no'
|
|
||||||
ENABLE_CELERY_SHORT: 'no'
|
|
||||||
ENABLE_CELERY_LONG: 'no'
|
|
||||||
ENABLE_MIGRATIONS: 'no'
|
|
||||||
depends_on:
|
depends_on:
|
||||||
- redis
|
migrations:
|
||||||
celery_worker:
|
condition: service_completed_successfully
|
||||||
image: mediacms/mediacms:latest
|
redis:
|
||||||
deploy:
|
condition: service_healthy
|
||||||
replicas: 1
|
|
||||||
volumes:
|
volumes:
|
||||||
- ./:/home/mediacms.io/mediacms/
|
- media_files:/home/mediacms.io/mediacms/media_files
|
||||||
environment:
|
- logs:/home/mediacms.io/mediacms/logs
|
||||||
ENABLE_UWSGI: 'no'
|
|
||||||
ENABLE_NGINX: 'no'
|
celery_short:
|
||||||
ENABLE_CELERY_BEAT: 'no'
|
image: mediacms/mediacms-worker:7.3
|
||||||
ENABLE_MIGRATIONS: 'no'
|
restart: unless-stopped
|
||||||
|
command: ["/home/mediacms.io/bin/celery", "-A", "cms", "worker", "-Q", "short_tasks", "-c", "10", "--soft-time-limit=300", "--loglevel=INFO", "-n", "short@%h"]
|
||||||
depends_on:
|
depends_on:
|
||||||
- migrations
|
migrations:
|
||||||
|
condition: service_completed_successfully
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- media_files:/home/mediacms.io/mediacms/media_files
|
||||||
|
- logs:/home/mediacms.io/mediacms/logs
|
||||||
|
|
||||||
|
celery_long:
|
||||||
|
image: mediacms/mediacms-worker:7.3
|
||||||
|
# To use extra codecs, change image to: mediacms/mediacms-worker:7.3-full
|
||||||
|
restart: unless-stopped
|
||||||
|
command: ["/home/mediacms.io/bin/celery", "-A", "cms", "worker", "-Q", "long_tasks", "-c", "1", "-Ofair", "--prefetch-multiplier=1", "--loglevel=INFO", "-n", "long@%h"]
|
||||||
|
depends_on:
|
||||||
|
migrations:
|
||||||
|
condition: service_completed_successfully
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
- media_files:/home/mediacms.io/mediacms/media_files
|
||||||
|
- logs:/home/mediacms.io/mediacms/logs
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: postgres:17.2-alpine
|
image: postgres:17.2-alpine
|
||||||
volumes:
|
restart: unless-stopped
|
||||||
- ../postgres_data:/var/lib/postgresql/data/
|
|
||||||
restart: always
|
|
||||||
environment:
|
environment:
|
||||||
POSTGRES_USER: mediacms
|
POSTGRES_USER: mediacms
|
||||||
POSTGRES_PASSWORD: mediacms
|
POSTGRES_PASSWORD: mediacms
|
||||||
POSTGRES_DB: mediacms
|
POSTGRES_DB: mediacms
|
||||||
TZ: Europe/London
|
TZ: Europe/London
|
||||||
|
volumes:
|
||||||
|
- postgres_data:/var/lib/postgresql/data
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD-SHELL", "pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}"]
|
test: ["CMD-SHELL", "pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}"]
|
||||||
interval: 10s
|
interval: 10s
|
||||||
timeout: 5s
|
timeout: 5s
|
||||||
retries: 5
|
retries: 5
|
||||||
|
|
||||||
redis:
|
redis:
|
||||||
image: "redis:alpine"
|
image: redis:alpine
|
||||||
restart: always
|
restart: unless-stopped
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD", "redis-cli","ping"]
|
test: ["CMD", "redis-cli", "ping"]
|
||||||
interval: 10s
|
interval: 10s
|
||||||
timeout: 5s
|
timeout: 5s
|
||||||
retries: 3
|
retries: 3
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
postgres_data:
|
||||||
|
static_files:
|
||||||
|
media_files:
|
||||||
|
logs:
|
||||||
|
|||||||
367
docs/DOCKER_V7.3_MIGRATION.md
Normal file
367
docs/DOCKER_V7.3_MIGRATION.md
Normal file
@@ -0,0 +1,367 @@
|
|||||||
|
# MediaCMS 7.3 Docker Architecture Migration Guide
|
||||||
|
|
||||||
|
## Overview
|
||||||
|
|
||||||
|
MediaCMS 7.3 introduces a modernized Docker architecture that removes supervisord and implements Docker best practices with one process per container.
|
||||||
|
|
||||||
|
## What Changed
|
||||||
|
|
||||||
|
### Old Architecture (pre-7.3)
|
||||||
|
- Single multi-purpose image with supervisord
|
||||||
|
- Environment variables (`ENABLE_UWSGI`, `ENABLE_NGINX`, etc.) to control services
|
||||||
|
- All services bundled in `deploy/docker/` folder
|
||||||
|
- File mounts required for all deployments
|
||||||
|
|
||||||
|
### New Architecture (7.3+)
|
||||||
|
- **Dedicated images** for each service:
|
||||||
|
- `mediacms/mediacms:7.3` - Django/uWSGI application
|
||||||
|
- `mediacms/mediacms-worker:7.3` - Celery workers
|
||||||
|
- `mediacms/mediacms-worker:7.3-full` - Celery workers with extra codecs
|
||||||
|
- `mediacms/mediacms-nginx:7.3` - Nginx web server
|
||||||
|
- **No supervisord** - Native Docker process management
|
||||||
|
- **Separated services**:
|
||||||
|
- `migrations` - Runs database migrations on every startup
|
||||||
|
- `nginx` - Serves static/media files and proxies to Django
|
||||||
|
- `web` - Django application (uWSGI)
|
||||||
|
- `celery_short` - Short-running tasks (thumbnails, etc.)
|
||||||
|
- `celery_long` - Long-running tasks (video encoding)
|
||||||
|
- `celery_beat` - Task scheduler
|
||||||
|
- **No ENABLE_* environment variables**
|
||||||
|
- **Config centralized** in `config/` directory
|
||||||
|
- **File mounts only for development** (`docker-compose-dev.yaml`)
|
||||||
|
|
||||||
|
## Directory Structure
|
||||||
|
|
||||||
|
```
|
||||||
|
config/
|
||||||
|
├── nginx/
|
||||||
|
│ ├── nginx.conf # Main nginx config
|
||||||
|
│ ├── site.conf # Virtual host config
|
||||||
|
│ └── uwsgi_params # uWSGI parameters
|
||||||
|
├── nginx-proxy/
|
||||||
|
│ └── client_max_body_size.conf # For production HTTPS proxy
|
||||||
|
├── uwsgi/
|
||||||
|
│ └── uwsgi.ini # uWSGI configuration
|
||||||
|
└── imagemagick/
|
||||||
|
└── policy.xml # ImageMagick policy
|
||||||
|
|
||||||
|
scripts/
|
||||||
|
├── entrypoint-web.sh # Web container entrypoint
|
||||||
|
├── entrypoint-worker.sh # Worker container entrypoint
|
||||||
|
└── run-migrations.sh # Migration script
|
||||||
|
|
||||||
|
Dockerfile.new # Main Dockerfile (base, web, worker, worker-full)
|
||||||
|
Dockerfile.nginx # Nginx Dockerfile
|
||||||
|
docker-compose.yaml # Production deployment
|
||||||
|
docker-compose-cert.yaml # Production with HTTPS
|
||||||
|
docker-compose-dev.yaml # Development with file mounts
|
||||||
|
```
|
||||||
|
|
||||||
|
## Migration Steps
|
||||||
|
|
||||||
|
### For Existing Production Systems
|
||||||
|
|
||||||
|
#### Step 1: Backup your data
|
||||||
|
```bash
|
||||||
|
# Backup database
|
||||||
|
docker exec mediacms_db_1 pg_dump -U mediacms mediacms > backup.sql
|
||||||
|
|
||||||
|
# Backup media files
|
||||||
|
cp -r media_files media_files.backup
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Step 2: Update configuration location
|
||||||
|
```bash
|
||||||
|
# The client_max_body_size.conf has moved
|
||||||
|
# No action needed if you haven't customized it
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Step 3: Pull latest images
|
||||||
|
```bash
|
||||||
|
docker pull mediacms/mediacms:7.3
|
||||||
|
docker pull mediacms/mediacms-worker:7.3
|
||||||
|
docker pull mediacms/mediacms-nginx:7.3
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Step 4: Update docker-compose file
|
||||||
|
If using **docker-compose.yaml**:
|
||||||
|
- No changes needed, just use the new version
|
||||||
|
|
||||||
|
If using **docker-compose-cert.yaml** (HTTPS):
|
||||||
|
- Update `VIRTUAL_HOST`, `LETSENCRYPT_HOST`, and `LETSENCRYPT_EMAIL` in the nginx service
|
||||||
|
- Update the path to client_max_body_size.conf:
|
||||||
|
```yaml
|
||||||
|
- ./config/nginx-proxy/client_max_body_size.conf:/etc/nginx/conf.d/client_max_body_size.conf:ro
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Step 5: Restart services
|
||||||
|
```bash
|
||||||
|
docker compose down
|
||||||
|
docker compose up -d
|
||||||
|
```
|
||||||
|
|
||||||
|
### For Development Systems
|
||||||
|
|
||||||
|
Development now requires the `-dev` compose file:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Old way (no longer works)
|
||||||
|
docker compose up
|
||||||
|
|
||||||
|
# New way (development)
|
||||||
|
docker compose -f docker-compose-dev.yaml up
|
||||||
|
```
|
||||||
|
|
||||||
|
## Deployment Options
|
||||||
|
|
||||||
|
### Standard Deployment (HTTP)
|
||||||
|
|
||||||
|
**File**: `docker-compose.yaml`
|
||||||
|
|
||||||
|
**Command**:
|
||||||
|
```bash
|
||||||
|
docker compose up -d
|
||||||
|
```
|
||||||
|
|
||||||
|
**Features**:
|
||||||
|
- Self-contained images (no file mounts)
|
||||||
|
- Nginx serves on port 80
|
||||||
|
- Separate containers for each service
|
||||||
|
- Named volumes for persistence
|
||||||
|
|
||||||
|
**Architecture**:
|
||||||
|
```
|
||||||
|
Client → nginx:80 → web:9000 (uWSGI)
|
||||||
|
↓
|
||||||
|
static_files (volume)
|
||||||
|
media_files (volume)
|
||||||
|
```
|
||||||
|
|
||||||
|
### Production Deployment (HTTPS with Let's Encrypt)
|
||||||
|
|
||||||
|
**File**: `docker-compose-cert.yaml`
|
||||||
|
|
||||||
|
**Prerequisites**:
|
||||||
|
1. Domain name pointing to your server
|
||||||
|
2. Ports 80 and 443 open
|
||||||
|
|
||||||
|
**Setup**:
|
||||||
|
```bash
|
||||||
|
# 1. Edit docker-compose-cert.yaml
|
||||||
|
# Update these values in the nginx service:
|
||||||
|
# VIRTUAL_HOST: 'your-domain.com'
|
||||||
|
# LETSENCRYPT_HOST: 'your-domain.com'
|
||||||
|
# LETSENCRYPT_EMAIL: 'your-email@example.com'
|
||||||
|
|
||||||
|
# 2. Start services
|
||||||
|
docker compose -f docker-compose-cert.yaml up -d
|
||||||
|
|
||||||
|
# 3. Check logs
|
||||||
|
docker compose -f docker-compose-cert.yaml logs -f nginx-proxy acme-companion
|
||||||
|
```
|
||||||
|
|
||||||
|
**Features**:
|
||||||
|
- Automatic HTTPS via Let's Encrypt
|
||||||
|
- Certificate auto-renewal
|
||||||
|
- Reverse proxy handles SSL termination
|
||||||
|
|
||||||
|
**Architecture**:
|
||||||
|
```
|
||||||
|
Client → nginx-proxy:443 (HTTPS) → nginx:80 → web:9000 (uWSGI)
|
||||||
|
```
|
||||||
|
|
||||||
|
### Development Deployment
|
||||||
|
|
||||||
|
**File**: `docker-compose-dev.yaml`
|
||||||
|
|
||||||
|
**Command**:
|
||||||
|
```bash
|
||||||
|
docker compose -f docker-compose-dev.yaml up
|
||||||
|
```
|
||||||
|
|
||||||
|
**Features**:
|
||||||
|
- Source code mounted for live editing
|
||||||
|
- Django debug mode enabled
|
||||||
|
- Django's `runserver` instead of uWSGI
|
||||||
|
- Frontend hot-reload on port 8088
|
||||||
|
- No nginx (direct Django access on port 80)
|
||||||
|
|
||||||
|
**Ports**:
|
||||||
|
- `80` - Django API
|
||||||
|
- `8088` - Frontend dev server
|
||||||
|
|
||||||
|
## Configuration
|
||||||
|
|
||||||
|
### Environment Variables
|
||||||
|
|
||||||
|
All configuration is done via environment variables or `cms/local_settings.py`.
|
||||||
|
|
||||||
|
**Key Variables**:
|
||||||
|
- `FRONTEND_HOST` - Your domain (e.g., `https://mediacms.example.com`)
|
||||||
|
- `PORTAL_NAME` - Your portal name
|
||||||
|
- `SECRET_KEY` - Django secret key
|
||||||
|
- `POSTGRES_*` - Database credentials
|
||||||
|
- `REDIS_LOCATION` - Redis connection string
|
||||||
|
- `DEBUG` - Enable debug mode (development only)
|
||||||
|
|
||||||
|
**Setting variables**:
|
||||||
|
|
||||||
|
Option 1: In docker-compose file:
|
||||||
|
```yaml
|
||||||
|
environment:
|
||||||
|
FRONTEND_HOST: 'https://mediacms.example.com'
|
||||||
|
PORTAL_NAME: 'My MediaCMS'
|
||||||
|
```
|
||||||
|
|
||||||
|
Option 2: Using .env file (recommended):
|
||||||
|
```bash
|
||||||
|
# Create .env file
|
||||||
|
cat > .env << EOF
|
||||||
|
FRONTEND_HOST=https://mediacms.example.com
|
||||||
|
PORTAL_NAME=My MediaCMS
|
||||||
|
SECRET_KEY=your-secret-key-here
|
||||||
|
EOF
|
||||||
|
```
|
||||||
|
|
||||||
|
### Customizing Settings
|
||||||
|
|
||||||
|
For advanced customization, you can build a custom image:
|
||||||
|
|
||||||
|
```dockerfile
|
||||||
|
# Dockerfile.custom
|
||||||
|
FROM mediacms/mediacms:7.3
|
||||||
|
COPY my_local_settings.py /home/mediacms.io/mediacms/cms/local_settings.py
|
||||||
|
```
|
||||||
|
|
||||||
|
## Celery Workers
|
||||||
|
|
||||||
|
### Standard Workers
|
||||||
|
|
||||||
|
By default, `celery_long` uses the standard image:
|
||||||
|
```yaml
|
||||||
|
celery_long:
|
||||||
|
image: mediacms/mediacms-worker:7.3
|
||||||
|
```
|
||||||
|
|
||||||
|
### Full Workers (Extra Codecs)
|
||||||
|
|
||||||
|
To enable extra codecs for better transcoding (including Whisper for subtitles):
|
||||||
|
|
||||||
|
**Edit docker-compose file**:
|
||||||
|
```yaml
|
||||||
|
celery_long:
|
||||||
|
image: mediacms/mediacms-worker:7.3-full # Changed from :7.3
|
||||||
|
```
|
||||||
|
|
||||||
|
**Then restart**:
|
||||||
|
```bash
|
||||||
|
docker compose up -d celery_long
|
||||||
|
```
|
||||||
|
|
||||||
|
### Scaling Workers
|
||||||
|
|
||||||
|
You can scale workers independently:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Scale short task workers
|
||||||
|
docker compose up -d --scale celery_short=3
|
||||||
|
|
||||||
|
# Scale long task workers
|
||||||
|
docker compose up -d --scale celery_long=2
|
||||||
|
```
|
||||||
|
|
||||||
|
## Troubleshooting
|
||||||
|
|
||||||
|
### Migrations not running
|
||||||
|
```bash
|
||||||
|
# Check migrations container logs
|
||||||
|
docker compose logs migrations
|
||||||
|
|
||||||
|
# Manually run migrations
|
||||||
|
docker compose run --rm migrations
|
||||||
|
```
|
||||||
|
|
||||||
|
### Static files not loading
|
||||||
|
```bash
|
||||||
|
# Ensure migrations completed (it runs collectstatic)
|
||||||
|
docker compose logs migrations
|
||||||
|
|
||||||
|
# Check nginx can access volumes
|
||||||
|
docker compose exec nginx ls -la /var/www/static
|
||||||
|
```
|
||||||
|
|
||||||
|
### Permission issues
|
||||||
|
```bash
|
||||||
|
# Check volume ownership
|
||||||
|
docker compose exec web ls -la /home/mediacms.io/mediacms/media_files
|
||||||
|
|
||||||
|
# If needed, rebuild images
|
||||||
|
docker compose build --no-cache
|
||||||
|
```
|
||||||
|
|
||||||
|
### Celery workers not processing tasks
|
||||||
|
```bash
|
||||||
|
# Check worker logs
|
||||||
|
docker compose logs celery_short celery_long
|
||||||
|
|
||||||
|
# Check Redis connection
|
||||||
|
docker compose exec redis redis-cli ping
|
||||||
|
|
||||||
|
# Restart workers
|
||||||
|
docker compose restart celery_short celery_long celery_beat
|
||||||
|
```
|
||||||
|
|
||||||
|
## Removed Components
|
||||||
|
|
||||||
|
The following are **no longer used** in 7.3:
|
||||||
|
|
||||||
|
- ❌ `deploy/docker/supervisord/` - Supervisord configs
|
||||||
|
- ❌ `deploy/docker/start.sh` - Start script
|
||||||
|
- ❌ `deploy/docker/entrypoint.sh` - Old entrypoint
|
||||||
|
- ❌ Environment variables: `ENABLE_UWSGI`, `ENABLE_NGINX`, `ENABLE_CELERY_BEAT`, `ENABLE_CELERY_SHORT`, `ENABLE_CELERY_LONG`, `ENABLE_MIGRATIONS`
|
||||||
|
|
||||||
|
**These are still available but moved**:
|
||||||
|
- ✅ `config/nginx/` - Nginx configs (moved from `deploy/docker/`)
|
||||||
|
- ✅ `config/uwsgi/` - uWSGI config (moved from `deploy/docker/`)
|
||||||
|
- ✅ `config/nginx-proxy/` - Reverse proxy config (moved from `deploy/docker/reverse_proxy/`)
|
||||||
|
|
||||||
|
## Persistent Volumes
|
||||||
|
|
||||||
|
MediaCMS 7.3 uses Docker named volumes for data persistence:
|
||||||
|
|
||||||
|
- **`media_files`** - All uploaded media (videos, images, thumbnails, HLS streams)
|
||||||
|
- Mounted on: migrations, web, nginx, celery_beat, celery_short, celery_long
|
||||||
|
- Persists across container restarts, updates, and image removals
|
||||||
|
|
||||||
|
- **`logs`** - Application and nginx logs
|
||||||
|
- Mounted on: migrations, web, nginx, celery_beat, celery_short, celery_long
|
||||||
|
- Nginx logs: `/var/log/mediacms/nginx.access.log`, `/var/log/mediacms/nginx.error.log`
|
||||||
|
- Django/Celery logs: `/home/mediacms.io/mediacms/logs/`
|
||||||
|
- Persists across container restarts, updates, and image removals
|
||||||
|
|
||||||
|
- **`static_files`** - Django static files (CSS, JS, images)
|
||||||
|
- Mounted on: migrations, web, nginx
|
||||||
|
- Regenerated during migrations via `collectstatic`
|
||||||
|
|
||||||
|
- **`postgres_data`** - PostgreSQL database
|
||||||
|
- Mounted on: db
|
||||||
|
- Persists across container restarts, updates, and image removals
|
||||||
|
|
||||||
|
**Important**: Use `docker compose down -v` to remove volumes (⚠️ causes data loss!)
|
||||||
|
|
||||||
|
## Benefits of New Architecture
|
||||||
|
|
||||||
|
1. **Better resource management** - Scale services independently
|
||||||
|
2. **Easier debugging** - Clear separation of concerns
|
||||||
|
3. **Faster restarts** - Restart only affected services
|
||||||
|
4. **Production-ready** - No file mounts, immutable images
|
||||||
|
5. **Standard Docker practices** - One process per container
|
||||||
|
6. **Clearer logs** - Each service has isolated logs, persistent storage
|
||||||
|
7. **Better health checks** - Per-service monitoring
|
||||||
|
8. **Data persistence** - media_files and logs survive all container operations
|
||||||
|
|
||||||
|
## Support
|
||||||
|
|
||||||
|
For issues or questions:
|
||||||
|
- GitHub Issues: https://github.com/mediacms-io/mediacms/issues
|
||||||
|
- Documentation: https://docs.mediacms.io
|
||||||
@@ -164,53 +164,123 @@ Database is stored on ../postgres_data/ and media_files on media_files/
|
|||||||
|
|
||||||
## 4. Docker Deployment options
|
## 4. Docker Deployment options
|
||||||
|
|
||||||
The mediacms image is built to use supervisord as the main process, which manages one or more services required to run mediacms. We can toggle which services are run in a given container by setting the environment variables below to `yes` or `no`:
|
**⚠️ IMPORTANT**: MediaCMS 7.3 introduces a new Docker architecture. If you're upgrading from an earlier version, please see the [Migration Guide](DOCKER_V7.3_MIGRATION.md).
|
||||||
|
|
||||||
* ENABLE_UWSGI
|
### Architecture Overview
|
||||||
* ENABLE_NGINX
|
|
||||||
* ENABLE_CELERY_BEAT
|
|
||||||
* ENABLE_CELERY_SHORT
|
|
||||||
* ENABLE_CELERY_LONG
|
|
||||||
* ENABLE_MIGRATIONS
|
|
||||||
|
|
||||||
By default, all these services are enabled, but in order to create a scaleable deployment, some of them can be disabled, splitting the service up into smaller services.
|
MediaCMS 7.3+ uses a modern microservices architecture with dedicated containers:
|
||||||
|
|
||||||
Also see the `Dockerfile` for other environment variables which you may wish to override. Application settings, eg. `FRONTEND_HOST` can also be overridden by updating the `deploy/docker/local_settings.py` file.
|
- **nginx** - Web server for static/media files and reverse proxy
|
||||||
|
- **web** - Django application (uWSGI)
|
||||||
|
- **celery_short** - Short-running background tasks
|
||||||
|
- **celery_long** - Long-running tasks (video encoding)
|
||||||
|
- **celery_beat** - Task scheduler
|
||||||
|
- **migrations** - Database migrations (runs on startup)
|
||||||
|
- **db** - PostgreSQL database
|
||||||
|
- **redis** - Cache and message broker
|
||||||
|
|
||||||
To run, update the configs above if necessary, build the image by running `docker compose build`, then run `docker compose run`
|
### Key Changes from Previous Versions
|
||||||
|
|
||||||
### Simple Deployment, accessed as http://localhost
|
- ✅ **No supervisord** - Native Docker process management
|
||||||
|
- ✅ **Dedicated images** per service
|
||||||
|
- ✅ **No ENABLE_* environment variables** - Services are separated into individual containers
|
||||||
|
- ✅ **Production images** don't mount source code (immutable)
|
||||||
|
- ✅ **config/** directory for centralized configuration
|
||||||
|
- ✅ **Separate celery workers** for short and long tasks
|
||||||
|
|
||||||
The main container runs migrations, mediacms_web, celery_beat, celery_workers (celery_short and celery_long services), exposed on port 80 supported by redis and postgres database.
|
### Configuration
|
||||||
|
|
||||||
The FRONTEND_HOST in `deploy/docker/local_settings.py` is configured as http://localhost, on the docker host machine.
|
Application settings can be overridden using environment variables in your docker-compose file or by building a custom image with a modified `cms/local_settings.py` file.
|
||||||
|
|
||||||
### Server with ssl certificate through letsencrypt service, accessed as https://my_domain.com
|
Key environment variables:
|
||||||
Before trying this out make sure the ip points to my_domain.com.
|
- `FRONTEND_HOST` - Your domain (e.g., `https://mediacms.example.com`)
|
||||||
|
- `PORTAL_NAME` - Portal name
|
||||||
|
- `SECRET_KEY` - Django secret key
|
||||||
|
- `DEBUG` - Enable debug mode (development only)
|
||||||
|
- Database and Redis connection settings
|
||||||
|
|
||||||
With this method [this deployment](../docker-compose-letsencrypt.yaml) is used.
|
See the [Migration Guide](DOCKER_V7.3_MIGRATION.md) for detailed configuration options
|
||||||
|
|
||||||
Edit this file and set `VIRTUAL_HOST` as my_domain.com, `LETSENCRYPT_HOST` as my_domain.com, and your email on `LETSENCRYPT_EMAIL`
|
### Simple Deployment (HTTP)
|
||||||
|
|
||||||
Edit `deploy/docker/local_settings.py` and set https://my_domain.com as `FRONTEND_HOST`
|
Use `docker-compose.yaml` for a standard HTTP deployment on port 80:
|
||||||
|
|
||||||
Now run `docker compose -f docker-compose-letsencrypt.yaml up`, when installation finishes you will be able to access https://my_domain.com using a valid Letsencrypt certificate!
|
```bash
|
||||||
|
docker compose up -d
|
||||||
|
```
|
||||||
|
|
||||||
### Advanced Deployment, accessed as http://localhost:8000
|
This starts all services (nginx, web, celery workers, database, redis) with the nginx container exposed on port 80. Access at http://localhost or http://your-server-ip.
|
||||||
|
|
||||||
Here we can run 1 mediacms_web instance, with the FRONTEND_HOST in `deploy/docker/local_settings.py` configured as http://localhost:8000. This is bootstrapped by a single migrations instance and supported by a single celery_beat instance and 1 or more celery_worker instances. Redis and postgres containers are also used for persistence. Clients can access the service on http://localhost:8000, on the docker host machine. This is similar to [this deployment](../docker-compose.yaml), with a `port` defined in FRONTEND_HOST.
|
**Features:**
|
||||||
|
- Production-ready with immutable images
|
||||||
|
- Named volumes for data persistence
|
||||||
|
- Separate containers for each service
|
||||||
|
|
||||||
### Advanced Deployment, with reverse proxy, accessed as http://mediacms.io
|
### Production Deployment with HTTPS (Let's Encrypt)
|
||||||
|
|
||||||
Here we can use `jwilder/nginx-proxy` to reverse proxy to 1 or more instances of mediacms_web supported by other services as mentioned in the previous deployment. The FRONTEND_HOST in `deploy/docker/local_settings.py` is configured as http://mediacms.io, nginx-proxy has port 80 exposed. Clients can access the service on http://mediacms.io (Assuming DNS or the hosts file is setup correctly to point to the IP of the nginx-proxy instance). This is similar to [this deployment](../docker-compose-http-proxy.yaml).
|
Use `docker-compose-cert.yaml` for automatic HTTPS with Let's Encrypt:
|
||||||
|
|
||||||
### Advanced Deployment, with reverse proxy, accessed as https://localhost
|
**Prerequisites:**
|
||||||
|
- Domain name pointing to your server
|
||||||
|
- Ports 80 and 443 open
|
||||||
|
|
||||||
The reverse proxy (`jwilder/nginx-proxy`) can be configured to provide SSL termination using self-signed certificates, letsencrypt or CA signed certificates (see: https://hub.docker.com/r/jwilder/nginx-proxy or [LetsEncrypt Example](https://www.singularaspect.com/use-nginx-proxy-and-letsencrypt-companion-to-host-multiple-websites/) ). In this case the FRONTEND_HOST should be set to https://mediacms.io. This is similar to [this deployment](../docker-compose-http-proxy.yaml).
|
**Setup:**
|
||||||
|
1. Edit `docker-compose-cert.yaml` and update:
|
||||||
|
- `VIRTUAL_HOST` - Your domain
|
||||||
|
- `LETSENCRYPT_HOST` - Your domain
|
||||||
|
- `LETSENCRYPT_EMAIL` - Your email
|
||||||
|
|
||||||
|
2. Run:
|
||||||
|
```bash
|
||||||
|
docker compose -f docker-compose-cert.yaml up -d
|
||||||
|
```
|
||||||
|
|
||||||
|
This uses `nginxproxy/nginx-proxy` with `acme-companion` for automatic HTTPS certificate management. Access at https://your-domain.com.
|
||||||
|
|
||||||
|
### Development Deployment
|
||||||
|
|
||||||
|
Use `docker-compose-dev.yaml` for development with live code reloading:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker compose -f docker-compose-dev.yaml up
|
||||||
|
```
|
||||||
|
|
||||||
|
**Features:**
|
||||||
|
- Source code mounted for live editing
|
||||||
|
- Django debug mode enabled
|
||||||
|
- Frontend dev server on port 8088
|
||||||
|
- Direct Django access (no nginx) on port 80
|
||||||
|
|
||||||
|
### Scaling Workers
|
||||||
|
|
||||||
|
Scale celery workers independently based on load:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Scale short task workers to 3 instances
|
||||||
|
docker compose up -d --scale celery_short=3
|
||||||
|
|
||||||
|
# Scale long task workers to 2 instances
|
||||||
|
docker compose up -d --scale celery_long=2
|
||||||
|
```
|
||||||
|
|
||||||
|
### Using Extra Codecs (Full Image)
|
||||||
|
|
||||||
|
For advanced transcoding features (including Whisper for automatic subtitles), use the full worker image:
|
||||||
|
|
||||||
|
Edit your docker-compose file:
|
||||||
|
```yaml
|
||||||
|
celery_long:
|
||||||
|
image: mediacms/mediacms-worker:7.3-full # Changed from :7.3
|
||||||
|
```
|
||||||
|
|
||||||
|
Then restart:
|
||||||
|
```bash
|
||||||
|
docker compose up -d celery_long
|
||||||
|
```
|
||||||
|
|
||||||
### A Scaleable Deployment Architecture (Docker, Swarm, Kubernetes)
|
### A Scaleable Deployment Architecture (Docker, Swarm, Kubernetes)
|
||||||
|
|
||||||
The architecture below generalises all the deployment scenarios above, and provides a conceptual design for other deployments based on kubernetes and docker swarm. It allows for horizontal scaleability through the use of multiple mediacms_web instances and celery_workers. For large deployments, managed postgres, redis and storage may be adopted.
|
The architecture below provides a conceptual design for deployments based on kubernetes and docker swarm. It allows for horizontal scaleability through the use of multiple web instances and celery workers. For large deployments, managed postgres, redis and storage may be adopted.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@@ -218,24 +288,36 @@ The architecture below generalises all the deployment scenarios above, and provi
|
|||||||
## 5. Configuration
|
## 5. Configuration
|
||||||
Several options are available on `cms/settings.py`, most of the things that are allowed or should be disallowed are described there.
|
Several options are available on `cms/settings.py`, most of the things that are allowed or should be disallowed are described there.
|
||||||
|
|
||||||
It is advisable to override any of them by adding it to `local_settings.py` .
|
It is advisable to override any of them by adding it to `local_settings.py`.
|
||||||
|
|
||||||
In case of a the single server installation, add to `cms/local_settings.py` .
|
**Single server installation:** edit `cms/local_settings.py`, make changes and restart MediaCMS:
|
||||||
|
|
||||||
In case of a docker compose installation, add to `deploy/docker/local_settings.py` . This will automatically overwrite `cms/local_settings.py` .
|
|
||||||
|
|
||||||
Any change needs restart of MediaCMS in order to take effect.
|
|
||||||
|
|
||||||
Single server installation: edit `cms/local_settings.py`, make a change and restart MediaCMS
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
#systemctl restart mediacms
|
systemctl restart mediacms celery_beat celery_short celery_long
|
||||||
```
|
```
|
||||||
|
|
||||||
Docker Compose installation: edit `deploy/docker/local_settings.py`, make a change and restart MediaCMS containers
|
**Docker installation:** Configuration can be done in two ways:
|
||||||
|
|
||||||
|
1. **Environment variables** (recommended for simple changes):
|
||||||
|
Add to your docker-compose file:
|
||||||
|
```yaml
|
||||||
|
environment:
|
||||||
|
FRONTEND_HOST: 'https://mediacms.example.com'
|
||||||
|
PORTAL_NAME: 'My MediaCMS'
|
||||||
|
```
|
||||||
|
|
||||||
|
2. **Custom image with local_settings.py** (for complex changes):
|
||||||
|
- Create a custom Dockerfile:
|
||||||
|
```dockerfile
|
||||||
|
FROM mediacms/mediacms:7.3
|
||||||
|
COPY my_custom_settings.py /home/mediacms.io/mediacms/cms/local_settings.py
|
||||||
|
```
|
||||||
|
- Build and use your custom image
|
||||||
|
|
||||||
|
After changes, restart the affected containers:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
#docker compose restart web celery_worker celery_beat
|
docker compose restart web celery_short celery_long celery_beat
|
||||||
```
|
```
|
||||||
|
|
||||||
### 5.1 Change portal logo
|
### 5.1 Change portal logo
|
||||||
|
|||||||
@@ -46,7 +46,7 @@ Before beginning, ensure the following:
|
|||||||
|
|
||||||
## Step 1: Configure MediaCMS for SAML
|
## Step 1: Configure MediaCMS for SAML
|
||||||
|
|
||||||
The first step in enabling SAML authentication is to modify the `local_settings.py` (for Docker: `./deploy/docker/local_settings.py`) file of your MediaCMS deployment. Add the following configuration block to enable SAML support, role-based access control (RBAC), and enforce secure communication settings:
|
The first step in enabling SAML authentication is to modify the `local_settings.py` (for Docker: `./config/local_settings.py`) file of your MediaCMS deployment. Add the following configuration block to enable SAML support, role-based access control (RBAC), and enforce secure communication settings:
|
||||||
|
|
||||||
```python
|
```python
|
||||||
USE_RBAC = True
|
USE_RBAC = True
|
||||||
@@ -292,7 +292,7 @@ Another issue you might encounter is an **infinite redirect loop**. This can hap
|
|||||||
https://<MyDomainName>/accounts/saml/mediacms_entraid/login/
|
https://<MyDomainName>/accounts/saml/mediacms_entraid/login/
|
||||||
```
|
```
|
||||||
|
|
||||||
* Add the following line to `./deploy/docker/local_settings.py`:
|
* Add the following line to `./config/local_settings.py`:
|
||||||
|
|
||||||
```python
|
```python
|
||||||
LOGIN_URL = "/accounts/saml/mediacms_entraid/login/"
|
LOGIN_URL = "/accounts/saml/mediacms_entraid/login/"
|
||||||
|
|||||||
@@ -110,7 +110,7 @@ urlpatterns = [
|
|||||||
re_path(r"^manage/users$", views.manage_users, name="manage_users"),
|
re_path(r"^manage/users$", views.manage_users, name="manage_users"),
|
||||||
# Media uploads in ADMIN created pages
|
# Media uploads in ADMIN created pages
|
||||||
re_path(r"^tinymce/upload/", tinymce_handlers.upload_image, name="tinymce_upload_image"),
|
re_path(r"^tinymce/upload/", tinymce_handlers.upload_image, name="tinymce_upload_image"),
|
||||||
re_path("^(?P<slug>[\w.-]*)$", views.get_page, name="get_page"), # noqa: W605
|
re_path(r"^(?P<slug>[\w.-]*)$", views.get_page, name="get_page"),
|
||||||
] + static(settings.MEDIA_URL, document_root=settings.MEDIA_ROOT)
|
] + static(settings.MEDIA_URL, document_root=settings.MEDIA_ROOT)
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
12
scripts/docker-entrypoint.sh
Normal file
12
scripts/docker-entrypoint.sh
Normal file
@@ -0,0 +1,12 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -e
|
||||||
|
|
||||||
|
# Fix permissions on volume mounts
|
||||||
|
chown -R www-data:www-data \
|
||||||
|
/home/mediacms.io/mediacms/logs \
|
||||||
|
/home/mediacms.io/mediacms/media_files \
|
||||||
|
/home/mediacms.io/mediacms/static \
|
||||||
|
2>/dev/null || true
|
||||||
|
|
||||||
|
# Run as www-data user
|
||||||
|
exec gosu www-data "$@"
|
||||||
19
scripts/entrypoint.sh
Normal file
19
scripts/entrypoint.sh
Normal file
@@ -0,0 +1,19 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -e
|
||||||
|
|
||||||
|
# Fix permissions on mounted volumes if running as root
|
||||||
|
if [ "$(id -u)" = "0" ]; then
|
||||||
|
echo "Fixing permissions on data directories..."
|
||||||
|
chown -R www-data:www-data /home/mediacms.io/mediacms/logs \
|
||||||
|
/home/mediacms.io/mediacms/media_files \
|
||||||
|
/home/mediacms.io/mediacms/static_files \
|
||||||
|
/var/run/mediacms 2>/dev/null || true
|
||||||
|
|
||||||
|
# If command starts with python or celery, run as www-data
|
||||||
|
if [ "${1:0:1}" != '-' ]; then
|
||||||
|
exec gosu www-data "$@"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Execute the command
|
||||||
|
exec "$@"
|
||||||
55
scripts/run-migrations.sh
Executable file
55
scripts/run-migrations.sh
Executable file
@@ -0,0 +1,55 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -e
|
||||||
|
|
||||||
|
echo "========================================="
|
||||||
|
echo "MediaCMS Migrations Starting..."
|
||||||
|
echo "========================================="
|
||||||
|
|
||||||
|
# Ensure virtualenv is activated
|
||||||
|
export VIRTUAL_ENV=/home/mediacms.io
|
||||||
|
export PATH="$VIRTUAL_ENV/bin:$PATH"
|
||||||
|
|
||||||
|
# Use explicit python path from virtualenv
|
||||||
|
PYTHON="$VIRTUAL_ENV/bin/python"
|
||||||
|
|
||||||
|
echo "Using Python: $PYTHON"
|
||||||
|
$PYTHON --version
|
||||||
|
|
||||||
|
# Run migrations
|
||||||
|
echo "Running database migrations..."
|
||||||
|
$PYTHON manage.py migrate
|
||||||
|
|
||||||
|
# Check if this is a new installation
|
||||||
|
EXISTING_INSTALLATION=$(echo "from users.models import User; print(User.objects.exists())" | $PYTHON manage.py shell)
|
||||||
|
|
||||||
|
if [ "$EXISTING_INSTALLATION" = "True" ]; then
|
||||||
|
echo "Existing installation detected, skipping initial data load"
|
||||||
|
else
|
||||||
|
echo "New installation detected, loading initial data..."
|
||||||
|
|
||||||
|
# Load fixtures
|
||||||
|
$PYTHON manage.py loaddata fixtures/encoding_profiles.json
|
||||||
|
$PYTHON manage.py loaddata fixtures/categories.json
|
||||||
|
|
||||||
|
# Create admin user
|
||||||
|
RANDOM_ADMIN_PASS=$($PYTHON -c "import secrets;chars = 'abcdefghijklmnopqrstuvwxyz0123456789';print(''.join(secrets.choice(chars) for i in range(10)))")
|
||||||
|
ADMIN_PASSWORD=${ADMIN_PASSWORD:-$RANDOM_ADMIN_PASS}
|
||||||
|
|
||||||
|
DJANGO_SUPERUSER_PASSWORD=$ADMIN_PASSWORD $PYTHON manage.py createsuperuser \
|
||||||
|
--no-input \
|
||||||
|
--username=${ADMIN_USER:-admin} \
|
||||||
|
--email=${ADMIN_EMAIL:-admin@localhost} \
|
||||||
|
--database=default || true
|
||||||
|
|
||||||
|
echo "========================================="
|
||||||
|
echo "Admin user created with password: $ADMIN_PASSWORD"
|
||||||
|
echo "========================================="
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Collect static files
|
||||||
|
echo "Collecting static files..."
|
||||||
|
$PYTHON manage.py collectstatic --noinput
|
||||||
|
|
||||||
|
echo "========================================="
|
||||||
|
echo "Migrations completed successfully!"
|
||||||
|
echo "========================================="
|
||||||
Reference in New Issue
Block a user