Gatus pings unprivileged when non-root (pro-bing UDP mode), which the kernel denies unless net.ipv4.ping_group_range covers the gid. Set the namespaced safe sysctl for gid 65534 in both the pod spec and compose.
73 lines
2.3 KiB
YAML
73 lines
2.3 KiB
YAML
name: r2d2-status
|
|
|
|
services:
|
|
gatus:
|
|
build:
|
|
context: .
|
|
dockerfile: Dockerfile
|
|
image: ${GATUS_IMAGE:-r2d2-status/gatus}:${GATUS_TAG:-latest}
|
|
restart: unless-stopped
|
|
ports:
|
|
- "${GATUS_PORT:-8080}:8080"
|
|
environment:
|
|
GATUS_LOG_LEVEL: ${GATUS_LOG_LEVEL:-INFO}
|
|
GATUS_STORAGE_TYPE: ${GATUS_STORAGE_TYPE:-postgres}
|
|
# sqlite: GATUS_STORAGE_PATH=/data/gatus.db | memory: GATUS_STORAGE_PATH=
|
|
# ("-" not ":-": memory storage requires an explicitly EMPTY path)
|
|
GATUS_STORAGE_PATH: ${GATUS_STORAGE_PATH-postgres://${POSTGRES_USER}:${POSTGRES_PASSWORD}@postgres:5432/${POSTGRES_DB}?sslmode=disable}
|
|
# Unprivileged ICMP for icmp:// endpoints (gatus runs as 65534, no caps)
|
|
sysctls:
|
|
net.ipv4.ping_group_range: "65534 65534"
|
|
volumes:
|
|
- ./config:/config:ro
|
|
- gatus-data:/data
|
|
depends_on:
|
|
postgres:
|
|
condition: service_healthy
|
|
# Ignored when the postgres profile is disabled (sqlite/memory mode)
|
|
required: false
|
|
|
|
# NetBird VPN sidecar — joins gatus's network namespace so gatus can reach
|
|
# 100.85.x.x mesh peers. Setup-key auth only (no PAT). Enable by adding
|
|
# "netbird" to COMPOSE_PROFILES and setting NETBIRD_SETUP_KEY in .env.
|
|
netbird:
|
|
image: netbirdio/netbird:latest
|
|
profiles: ["netbird"]
|
|
restart: unless-stopped
|
|
network_mode: "service:gatus"
|
|
cap_add:
|
|
- NET_ADMIN
|
|
devices:
|
|
- /dev/net/tun
|
|
environment:
|
|
NB_SETUP_KEY: ${NETBIRD_SETUP_KEY:-}
|
|
NB_MANAGEMENT_URL: ${NETBIRD_MANAGEMENT_URL:-https://netbird.office.ilab.zone:33073}
|
|
NB_HOSTNAME: ${NETBIRD_HOSTNAME:-r2d2-status-compose}
|
|
NB_WG_MODE: userspace
|
|
NB_MTU: "1280"
|
|
NB_DISABLE_DNS: "true"
|
|
volumes:
|
|
- netbird-state:/var/lib/netbird
|
|
depends_on:
|
|
- gatus
|
|
|
|
postgres:
|
|
image: postgres:17-alpine
|
|
profiles: ["postgres"]
|
|
restart: unless-stopped
|
|
environment:
|
|
POSTGRES_USER: ${POSTGRES_USER:?set in .env}
|
|
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?set in .env}
|
|
POSTGRES_DB: ${POSTGRES_DB:?set in .env}
|
|
volumes:
|
|
- postgres-data:/var/lib/postgresql/data
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U $${POSTGRES_USER} -d $${POSTGRES_DB}"]
|
|
interval: 5s
|
|
timeout: 5s
|
|
retries: 10
|
|
|
|
volumes:
|
|
gatus-data:
|
|
netbird-state:
|
|
postgres-data:
|