forked from prebid/salesagent
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
168 lines (161 loc) · 6.46 KB
/
Copy pathdocker-compose.yml
File metadata and controls
168 lines (161 loc) · 6.46 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
# AdCP Sales Agent - Docker Compose for Development
#
# For local development with hot-reload.
#
# Usage:
# CONDUCTOR_PORT=8000 make compose-up
#
# Endpoints (default port 8000):
# http://localhost:8000/ - Admin UI (login here)
# http://localhost:8000/admin - Admin UI (alternate path)
# http://localhost:8000/mcp - MCP Server (for AI agents)
# http://localhost:8000/a2a - A2A Server (agent-to-agent)
#
# First-time setup:
# 1. Log in with test credentials (test_super_admin@example.com / test123)
# 2. Configure SSO in Users & Access
# 3. Disable Setup Mode once SSO is working
#
# Environment variables (optional, via .env file):
# CONDUCTOR_PORT: Required. Proxy host port (set per worktree by Conductor; no default to prevent silent collisions).
# CREATE_DEMO_TENANT=true: Create demo tenant with mock adapter
services:
postgres:
image: postgres:17-alpine
environment:
POSTGRES_DB: adcp
POSTGRES_USER: adcp_user
POSTGRES_PASSWORD: secure_password_change_me
volumes:
- adcp_postgres_data:/var/lib/postgresql/data
# No host port exposure - access via docker compose exec if needed
healthcheck:
test: ["CMD-SHELL", "pg_isready -U adcp_user -d adcp"]
interval: 10s
timeout: 5s
retries: 5
# Run database migrations before starting services
db-init:
build:
context: .
dockerfile: Dockerfile
# Same image as adcp-server (rebuilt independently by Compose
# for db-init's own service). Thread the lockfile hash through
# so the install layer's cache key invalidates on uv.lock change
# — see the comment on adcp-server.build.args for the full why.
args:
LOCKFILE_HASH: ${LOCKFILE_HASH:-set-this-build-arg}
GIT_SHA: ${GIT_SHA:-unknown}
GIT_BRANCH: ${GIT_BRANCH:-unknown}
entrypoint: []
env_file:
- path: .env
required: false
environment:
DATABASE_URL: postgresql://adcp_user:secure_password_change_me@postgres:5432/adcp?sslmode=disable
PYTHONPATH: "/app"
SEED_DEMO_AUTO_APPROVE: "${SEED_DEMO_AUTO_APPROVE:-0}"
WEBHOOK_SIGNING_KEYS_DIR: "/app/signing_keys"
depends_on:
postgres:
condition: service_healthy
volumes:
- ./audit_logs:/app/audit_logs
- adcp_signing_keys:/app/signing_keys
# ``migrate.py`` then ``seed_demo_data.py``: the second step is dev-only —
# the seed is idempotent so re-runs are safe, and the env-gated mock-adapter
# setup it relies on (``ADCP_TESTING``/``ADCP_MULTI_TENANT``) is set on the
# adcp-server below. Production deployments should override the command.
command: ["sh", "-c", "python scripts/ops/migrate.py && python scripts/ops/seed_demo_data.py"]
proxy:
image: nginx:stable
volumes:
- ./config/nginx/nginx-development.conf:/etc/nginx/nginx.conf:ro
depends_on:
- adcp-server
ports:
- "${CONDUCTOR_PORT:?CONDUCTOR_PORT is required (set per worktree by Conductor) — refusing to fall back to 8000 and risk colliding with another worktree}:8000"
healthcheck:
test: ["CMD-SHELL", "nginx -t >/dev/null 2>&1 && test -s /var/run/nginx.pid"]
interval: 30s
timeout: 10s
retries: 3
adcp-server:
build:
context: .
dockerfile: Dockerfile
# Force the install layer to invalidate when uv.lock changes.
# ``make compose-build`` / ``make compose-up`` set this to the
# current uv.lock content hash. Bare ``docker compose build``
# without the env var fails fast inside the Dockerfile — silently
# regressing dependency bumps is worse than a build error.
args:
LOCKFILE_HASH: ${LOCKFILE_HASH:-set-this-build-arg}
GIT_SHA: ${GIT_SHA:-unknown}
GIT_BRANCH: ${GIT_BRANCH:-unknown}
entrypoint: [] # Override image entrypoint for local dev
env_file:
- path: .env
required: false
environment:
DATABASE_URL: postgresql://adcp_user:secure_password_change_me@postgres:5432/adcp?sslmode=disable
SKIP_NGINX: "true"
SKIP_CRON: "true"
# Per-tenant Setup Mode enables test credentials for new tenants
# Override .env ports to match nginx-development.conf expectations
ADCP_SALES_PORT: "8080"
# Enable test login mode for development
ADCP_AUTH_TEST_MODE: "true"
# Allow mock-adapter setup to satisfy the "Ad Server Configured" gate.
# Skip the SSO gate (multi-tenant deployments treat auth as platform-managed).
ADCP_TESTING: "true"
ADCP_MULTI_TENANT: "true"
# Dev-only Fernet key so quickstart works without `make setup` first.
# The .env file (if present) overrides this — production deployments
# MUST set ENCRYPTION_KEY via their own env. Validate_configuration()
# refuses to start without one. Mirrors scripts/test-stack.sh.
ENCRYPTION_KEY: "${ENCRYPTION_KEY:-PEg0SNGQyvzi4Nft-ForSzK8AGXyhRtql1MgoUsfUHk=}"
# Development settings
PYTHONPATH: "/app/.venv/lib/python3.13/site-packages"
PYTHONUNBUFFERED: "1"
FLASK_ENV: development
WEBHOOK_SIGNING_KEYS_DIR: "/app/signing_keys"
depends_on:
postgres:
condition: service_healthy
db-init:
condition: service_completed_successfully
extra_hosts:
- "host.docker.internal:host-gateway"
volumes:
# Mount source code for hot reloading without shadowing the image venv.
- ./src:/app/src
- ./core:/app/core
- ./scripts:/app/scripts
- ./templates:/app/templates
- ./static:/app/static
- ./config:/app/config
- ./alembic:/app/alembic
- ./alembic.ini:/app/alembic.ini:ro
- ./pyproject.toml:/app/pyproject.toml:ro
- ./uv.lock:/app/uv.lock:ro
- ./crontab:/app/crontab:ro
# Mount local adcp library directly into venv (replaces installed package)
# - ../adcp-client-python/src/adcp:/app/.venv/lib/python3.13/site-packages/adcp:ro - Uncomment this if you want to use locally installed adcp-python-client for e2e testing purposes
# Optional: Mount audit logs
- ./audit_logs:/app/audit_logs
- adcp_signing_keys:/app/signing_keys
# Shared cache volumes for faster builds
- adcp_global_pip_cache:/root/.cache/pip
- adcp_global_uv_cache:/cache/uv
command: ["python", "scripts/run_server.py"]
healthcheck:
test: ["CMD", "python", "scripts/healthcheck.py", "8080"]
interval: 30s
timeout: 10s
retries: 3
volumes:
adcp_postgres_data:
adcp_signing_keys:
adcp_global_pip_cache:
adcp_global_uv_cache: