R2D2-Status-Gatus/docker-compose.yml
Joshua Belke 58acb08526 TF-X ITA check via ICMP; enable unprivileged ping (ping_group_range sysctl)
Gatus pings unprivileged when non-root (pro-bing UDP mode), which the kernel
denies unless net.ipv4.ping_group_range covers the gid. Set the namespaced
safe sysctl for gid 65534 in both the pod spec and compose.
2026-07-04 12:59:00 -04:00

73 lines
2.3 KiB
YAML

name: r2d2-status
services:
gatus:
build:
context: .
dockerfile: Dockerfile
image: ${GATUS_IMAGE:-r2d2-status/gatus}:${GATUS_TAG:-latest}
restart: unless-stopped
ports:
- "${GATUS_PORT:-8080}:8080"
environment:
GATUS_LOG_LEVEL: ${GATUS_LOG_LEVEL:-INFO}
GATUS_STORAGE_TYPE: ${GATUS_STORAGE_TYPE:-postgres}
# sqlite: GATUS_STORAGE_PATH=/data/gatus.db | memory: GATUS_STORAGE_PATH=
# ("-" not ":-": memory storage requires an explicitly EMPTY path)
GATUS_STORAGE_PATH: ${GATUS_STORAGE_PATH-postgres://${POSTGRES_USER}:${POSTGRES_PASSWORD}@postgres:5432/${POSTGRES_DB}?sslmode=disable}
# Unprivileged ICMP for icmp:// endpoints (gatus runs as 65534, no caps)
sysctls:
net.ipv4.ping_group_range: "65534 65534"
volumes:
- ./config:/config:ro
- gatus-data:/data
depends_on:
postgres:
condition: service_healthy
# Ignored when the postgres profile is disabled (sqlite/memory mode)
required: false
# NetBird VPN sidecar — joins gatus's network namespace so gatus can reach
# 100.85.x.x mesh peers. Setup-key auth only (no PAT). Enable by adding
# "netbird" to COMPOSE_PROFILES and setting NETBIRD_SETUP_KEY in .env.
netbird:
image: netbirdio/netbird:latest
profiles: ["netbird"]
restart: unless-stopped
network_mode: "service:gatus"
cap_add:
- NET_ADMIN
devices:
- /dev/net/tun
environment:
NB_SETUP_KEY: ${NETBIRD_SETUP_KEY:-}
NB_MANAGEMENT_URL: ${NETBIRD_MANAGEMENT_URL:-https://netbird.office.ilab.zone:33073}
NB_HOSTNAME: ${NETBIRD_HOSTNAME:-r2d2-status-compose}
NB_WG_MODE: userspace
NB_MTU: "1280"
NB_DISABLE_DNS: "true"
volumes:
- netbird-state:/var/lib/netbird
depends_on:
- gatus
postgres:
image: postgres:17-alpine
profiles: ["postgres"]
restart: unless-stopped
environment:
POSTGRES_USER: ${POSTGRES_USER:?set in .env}
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?set in .env}
POSTGRES_DB: ${POSTGRES_DB:?set in .env}
volumes:
- postgres-data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U $${POSTGRES_USER} -d $${POSTGRES_DB}"]
interval: 5s
timeout: 5s
retries: 10
volumes:
gatus-data:
netbird-state:
postgres-data: