The browser half of M3. Flows open on a full-bleed canvas with their chrome floating over it: flow tabs top, dock bottom, node settings in a panel on the right that leaves the graph visible and running behind it. - Connections are derived, not stored. A node declares the messages it reads and publishes; every matching pair draws an edge, so two producers of one message converge on their consumer. Dragging output to input is shorthand for pointing that input at the producer's message, and asks before it replaces an existing one. - Values land on the edges as they flow, over a websocket that feeds a store outside React, so a value arriving re-renders its own chip and nothing else. Clicking an edge shows the last payload and when it arrived. - Node source is edited in Monaco, loaded only when a panel opens and themed from the design tokens. - Edits autosave; identical documents are skipped server-side, so a quiet canvas writes nothing. - Validation from the API shows on the node it belongs to and is summarised in the dock, where each entry pans to its node. - Works on a phone: touch-connect, 44px dock targets, and the node panel becomes a full-screen sheet. Two new tokens (--status-success, --font-mono) are mirrored in the website repo and recorded in DESIGN-GUIDELINES.md. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016WzrvW7rjQbynnhF6pxh6i
193 lines
6.6 KiB
YAML
193 lines
6.6 KiB
YAML
# Production stack. Layered by the Makefile:
|
|
# compose.yml → production (Traefik + TLS, restart always)
|
|
# + compose.dev.yml → local dev (published ports, hot reload)
|
|
# + compose.local.yml → integrated stack on the shared `proxy` net
|
|
# Paths are relative to this directory, which compose uses as the project
|
|
# directory (build contexts therefore point at `..`, the repo root).
|
|
|
|
services:
|
|
|
|
db:
|
|
image: postgres:18
|
|
container_name: fluksio-db
|
|
restart: always
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER} -d ${POSTGRES_DB}"]
|
|
interval: 10s
|
|
retries: 5
|
|
start_period: 30s
|
|
timeout: 10s
|
|
volumes:
|
|
- app-db-data:/var/lib/postgresql/data/pgdata
|
|
env_file:
|
|
- ../.env
|
|
environment:
|
|
- PGDATA=/var/lib/postgresql/data/pgdata
|
|
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD?Variable not set}
|
|
- POSTGRES_USER=${POSTGRES_USER?Variable not set}
|
|
- POSTGRES_DB=${POSTGRES_DB?Variable not set}
|
|
|
|
adminer:
|
|
image: adminer
|
|
container_name: fluksio-adminer
|
|
restart: always
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
# Deliberately not on `proxy`: the Postgres UI is reachable from the host
|
|
# in dev only (see compose.dev.yml), never routed from the internet.
|
|
networks:
|
|
- default
|
|
depends_on:
|
|
- db
|
|
environment:
|
|
- ADMINER_DESIGN=pepa-linha-dark
|
|
|
|
prestart:
|
|
image: '${DOCKER_IMAGE_BACKEND?Variable not set}:${TAG-latest}'
|
|
container_name: fluksio-prestart
|
|
build:
|
|
context: ..
|
|
dockerfile: backend/Dockerfile
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
networks:
|
|
- proxy
|
|
- default
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
restart: true
|
|
command: bash scripts/prestart.sh
|
|
env_file:
|
|
- ../.env
|
|
environment:
|
|
- DOMAIN=${DOMAIN}
|
|
- FRONTEND_HOST=${FRONTEND_HOST?Variable not set}
|
|
- ENVIRONMENT=${ENVIRONMENT}
|
|
- BACKEND_CORS_ORIGINS=${BACKEND_CORS_ORIGINS}
|
|
- SECRET_KEY=${SECRET_KEY?Variable not set}
|
|
- FIRST_SUPERUSER=${FIRST_SUPERUSER?Variable not set}
|
|
- FIRST_SUPERUSER_PASSWORD=${FIRST_SUPERUSER_PASSWORD?Variable not set}
|
|
- SMTP_HOST=${SMTP_HOST}
|
|
- SMTP_USER=${SMTP_USER}
|
|
- SMTP_PASSWORD=${SMTP_PASSWORD}
|
|
- EMAILS_FROM_EMAIL=${EMAILS_FROM_EMAIL}
|
|
- POSTGRES_SERVER=db
|
|
- POSTGRES_PORT=${POSTGRES_PORT}
|
|
- POSTGRES_DB=${POSTGRES_DB}
|
|
- POSTGRES_USER=${POSTGRES_USER?Variable not set}
|
|
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD?Variable not set}
|
|
- SENTRY_DSN=${SENTRY_DSN}
|
|
|
|
backend:
|
|
image: '${DOCKER_IMAGE_BACKEND?Variable not set}:${TAG-latest}'
|
|
container_name: fluksio-api
|
|
restart: always
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
networks:
|
|
- proxy
|
|
- default
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
restart: true
|
|
prestart:
|
|
condition: service_completed_successfully
|
|
env_file:
|
|
- ../.env
|
|
environment:
|
|
- DOMAIN=${DOMAIN}
|
|
- FRONTEND_HOST=${FRONTEND_HOST?Variable not set}
|
|
- ENVIRONMENT=${ENVIRONMENT}
|
|
- BACKEND_CORS_ORIGINS=${BACKEND_CORS_ORIGINS}
|
|
- SECRET_KEY=${SECRET_KEY?Variable not set}
|
|
- FIRST_SUPERUSER=${FIRST_SUPERUSER?Variable not set}
|
|
- FIRST_SUPERUSER_PASSWORD=${FIRST_SUPERUSER_PASSWORD?Variable not set}
|
|
- SMTP_HOST=${SMTP_HOST}
|
|
- SMTP_USER=${SMTP_USER}
|
|
- SMTP_PASSWORD=${SMTP_PASSWORD}
|
|
- EMAILS_FROM_EMAIL=${EMAILS_FROM_EMAIL}
|
|
- POSTGRES_SERVER=db
|
|
- POSTGRES_PORT=${POSTGRES_PORT}
|
|
- POSTGRES_DB=${POSTGRES_DB}
|
|
- POSTGRES_USER=${POSTGRES_USER?Variable not set}
|
|
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD?Variable not set}
|
|
- SENTRY_DSN=${SENTRY_DSN}
|
|
# Flows are files in a git repository; secrets sit encrypted beside it.
|
|
- FLOWS_DIR=/data/flows
|
|
- SECRETS_FILE=/data/secrets.enc
|
|
|
|
volumes:
|
|
- app-flow-data:/data
|
|
|
|
healthcheck:
|
|
test: ["CMD", "curl", "-f", "http://localhost:8000/api/v1/utils/health-check/"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
|
|
build:
|
|
context: ..
|
|
dockerfile: backend/Dockerfile
|
|
labels:
|
|
- traefik.enable=true
|
|
- traefik.docker.network=proxy
|
|
- traefik.constraint-label=proxy
|
|
|
|
- traefik.http.services.${STACK_NAME?Variable not set}-backend.loadbalancer.server.port=8000
|
|
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-backend-http.rule=Host(`api.${DOMAIN?Variable not set}`)
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-backend-http.entrypoints=http
|
|
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-backend-https.rule=Host(`api.${DOMAIN?Variable not set}`)
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-backend-https.entrypoints=https
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-backend-https.tls=true
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-backend-https.tls.certresolver=le
|
|
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-backend-http.middlewares=https-redirect
|
|
|
|
frontend:
|
|
image: '${DOCKER_IMAGE_FRONTEND?Variable not set}:${TAG-latest}'
|
|
container_name: fluksio-app
|
|
restart: always
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
networks:
|
|
- proxy
|
|
- default
|
|
build:
|
|
context: ..
|
|
dockerfile: frontend/Dockerfile
|
|
args:
|
|
- VITE_API_URL=https://api.${DOMAIN?Variable not set}
|
|
- NODE_ENV=production
|
|
labels:
|
|
- traefik.enable=true
|
|
- traefik.docker.network=proxy
|
|
- traefik.constraint-label=proxy
|
|
|
|
- traefik.http.services.${STACK_NAME?Variable not set}-frontend.loadbalancer.server.port=80
|
|
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-frontend-http.rule=Host(`app.${DOMAIN?Variable not set}`)
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-frontend-http.entrypoints=http
|
|
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-frontend-https.rule=Host(`app.${DOMAIN?Variable not set}`)
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-frontend-https.entrypoints=https
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-frontend-https.tls=true
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-frontend-https.tls.certresolver=le
|
|
|
|
- traefik.http.routers.${STACK_NAME?Variable not set}-frontend-http.middlewares=https-redirect
|
|
|
|
volumes:
|
|
app-db-data:
|
|
app-flow-data:
|
|
|
|
networks:
|
|
# Shared with the website stack and whatever reverse proxy fronts them.
|
|
# Created once by the workspace root's scripts/setup.sh.
|
|
proxy:
|
|
external: true
|