init public release
This commit is contained in:
@@ -0,0 +1,284 @@
|
||||
services:
|
||||
neo4j-certs-perm-fix:
|
||||
image: busybox
|
||||
command: ["chmod", "-R", "755", "/certs"]
|
||||
volumes:
|
||||
- ./neo4j-certs:/certs
|
||||
networks:
|
||||
- medax-network
|
||||
|
||||
neo4j:
|
||||
image: neo4j:5.7
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
neo4j-certs-perm-fix:
|
||||
condition: service_completed_successfully
|
||||
environment:
|
||||
- NEO4J_AUTH=${NEO4J_AUTH:-neo4j/password}
|
||||
- NEO4J_PLUGINS=["apoc"]
|
||||
- NEO4J_server_config_strict__validation_enabled=false
|
||||
- NEO4J_apoc_export_file_enabled=true
|
||||
- NEO4J_apoc_import_file_enabled=true
|
||||
- NEO4J_apoc_import_file_use__neo4j__config=true
|
||||
- SHARED_PATH=/neo4j_import
|
||||
- NO_PROXY=${NO_PROXY},10.0.0.0/8
|
||||
- DISABLE_IMPORT=${DISABLE_IMPORT:-false}
|
||||
- ENABLE_BOLT_TLS=${ENABLE_BOLT_TLS:-false}
|
||||
|
||||
command: >
|
||||
bash -c '
|
||||
if [ "$${DISABLE_IMPORT:-false}" != "true" ]; then
|
||||
echo "running cmd from docker compose" &&
|
||||
# Copy plugin files if they exist
|
||||
if [ -f /init_files/semspect_neo4j-plugin-8.2.0.jar ]; then
|
||||
echo "Copying Semspect plugin..." &&
|
||||
cp /init_files/semspect_neo4j-plugin-8.2.0.jar /var/lib/neo4j/plugins/
|
||||
fi
|
||||
if [ -f /init_files/semspect.lic ]; then
|
||||
echo "Copying Semspect license..." &&
|
||||
cp /init_files/semspect.lic /var/lib/neo4j/plugins/
|
||||
fi
|
||||
# Copy neo4j.conf if it exists
|
||||
ls
|
||||
ls /init_files/
|
||||
if [ -f /init_files/neo4j.conf ]; then
|
||||
echo "Copying Neo4j configuration..." &&
|
||||
cp /init_files/neo4j.conf /var/lib/neo4j/conf/
|
||||
fi
|
||||
if [ "$${ENABLE_BOLT_TLS:-false}" != "true" ]; then
|
||||
echo "ENABLE_BOLT_TLS is not true - disabling required bolt TLS (no certs mounted in ./neo4j-certs locally)." &&
|
||||
sed -i \
|
||||
-e "s/^server.bolt.tls_level=REQUIRED/#server.bolt.tls_level=REQUIRED/" \
|
||||
-e "s/^dbms.ssl.policy.bolt.enabled=true/#dbms.ssl.policy.bolt.enabled=true/" \
|
||||
/var/lib/neo4j/conf/neo4j.conf
|
||||
fi
|
||||
echo "<----------------"
|
||||
# Set proper permissions
|
||||
#chown -R neo4j:neo4j /var/lib/neo4j/plugins
|
||||
#chown -R neo4j:neo4j /var/lib/neo4j/conf
|
||||
echo "Import loop is enabled."
|
||||
|
||||
while true; do
|
||||
if [ -f /neo4j_import/ready-to-import ]; then
|
||||
echo "Starting import process..."
|
||||
neo4j stop &&
|
||||
bash /neo4j_import/neo4j-admin-import-call.sh &&
|
||||
rm /neo4j_import/ready-to-import &&
|
||||
touch /neo4j_import/import-complete &&
|
||||
chmod 777 /neo4j_import/import-complete
|
||||
neo4j start
|
||||
echo "The container is running. CTRL+C will end the bash command and thus, the neo4j container"
|
||||
fi
|
||||
sleep 10
|
||||
done
|
||||
else
|
||||
echo "Import loop is disabled. Keeping Neo4j container alive..."
|
||||
cp /init_files/neo4j.conf /var/lib/neo4j/conf/
|
||||
if [ "$${ENABLE_BOLT_TLS:-false}" != "true" ]; then
|
||||
echo "ENABLE_BOLT_TLS is not true - disabling required bolt TLS (no certs mounted in ./neo4j-certs locally)." &&
|
||||
sed -i \
|
||||
-e "s/^server.bolt.tls_level=REQUIRED/#server.bolt.tls_level=REQUIRED/" \
|
||||
-e "s/^dbms.ssl.policy.bolt.enabled=true/#dbms.ssl.policy.bolt.enabled=true/" \
|
||||
/var/lib/neo4j/conf/neo4j.conf
|
||||
fi
|
||||
neo4j start
|
||||
echo "The container is running. CTRL+C will end the bash command and thus, the neo4j container"
|
||||
tail -f /dev/null
|
||||
fi
|
||||
'
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "wget --no-verbose --tries=1 --spider http://localhost:7474 || exit 1"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
ports:
|
||||
- "8080:7474" # direct access — remove in production
|
||||
- "8081:7687" # remove in production
|
||||
#- "127.0.0.1:8080:7474" #production
|
||||
#- "127.0.0.1:8081:7687"
|
||||
|
||||
volumes:
|
||||
- neo4j_data:/data
|
||||
- neo4j_logs:/logs
|
||||
- neo4j_import:/neo4j_import
|
||||
- ${INPUT_DATA_PATH:-./data}:/input_data
|
||||
- ./init_scripts:/init_scripts
|
||||
- ./init_files:/init_files
|
||||
- ./importData:/importData
|
||||
- ./neo4j-certs:/var/lib/neo4j/certificates
|
||||
networks:
|
||||
- medax-network
|
||||
|
||||
python_app:
|
||||
depends_on:
|
||||
loader:
|
||||
condition: service_completed_successfully
|
||||
required: false
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
args:
|
||||
HTTP_PROXY: ${HTTP_PROXY}
|
||||
HTTPS_PROXY: ${HTTPS_PROXY}
|
||||
NO_PROXY: ${NO_PROXY}
|
||||
env_file:
|
||||
- .env
|
||||
environment:
|
||||
- NEO4J_URI=bolt://neo4j:7687
|
||||
- NEO4J_USER=${NEO4J_USER:-neo4j}
|
||||
- NEO4J_PASSWORD=${NEO4J_PASSWORD:-password}
|
||||
- DISABLE_IMPORT=${DISABLE_IMPORT:-false}
|
||||
- INPUT_DATA_PATH=/input_data
|
||||
- POETRY_VIRTUALENVS_CREATE=false
|
||||
- NEO4J_dbms_directories_import=/neo4j_import
|
||||
volumes:
|
||||
- neo4j_import:/neo4j_import
|
||||
- ${INPUT_DATA_PATH:-./data}:/input_data
|
||||
- ./importData:/importData # Share the import data directory
|
||||
# depends_on:
|
||||
# neo4j:
|
||||
# condition: service_healthy
|
||||
networks:
|
||||
- medax-network
|
||||
|
||||
oauth2-proxy:
|
||||
profiles:
|
||||
- server
|
||||
image: quay.io/oauth2-proxy/oauth2-proxy:v7.6.0
|
||||
container_name: oauth2-proxy
|
||||
restart: unless-stopped
|
||||
extra_hosts:
|
||||
- "keycloak-test.miracum.med.uni-greifswald.de:10.66.82.11"
|
||||
- "host.docker.internal:host-gateway"
|
||||
|
||||
command:
|
||||
- --config=/etc/oauth2-proxy.cfg
|
||||
ports:
|
||||
# - "80:80"
|
||||
- "443:443"
|
||||
volumes:
|
||||
- ./oauth_conf/oauth2-proxy.cfg:/etc/oauth2-proxy.cfg:ro
|
||||
- ./oauth_templates:/templates:ro
|
||||
- ./oauth-certs:/etc/oauth-certs:ro
|
||||
- ./logs:/var/log/oauth2-proxy
|
||||
depends_on:
|
||||
- neo4j
|
||||
|
||||
networks:
|
||||
- medax-network
|
||||
|
||||
nginx:
|
||||
profiles:
|
||||
- server
|
||||
image: nginx:latest
|
||||
container_name: neo4j-nginx
|
||||
|
||||
## ports:
|
||||
## - "8088:80"
|
||||
# - "7687:7687"
|
||||
|
||||
volumes:
|
||||
- ./nginx/default.conf:/etc/nginx/conf.d/default.conf:ro
|
||||
- ./logs:/var/log/nginx
|
||||
depends_on:
|
||||
- neo4j
|
||||
|
||||
networks:
|
||||
- medax-network
|
||||
|
||||
neo4j-proxy:
|
||||
profiles:
|
||||
- proxy
|
||||
image: quay.io/oauth2-proxy/oauth2-proxy:latest
|
||||
restart: on-failure
|
||||
environment:
|
||||
OAUTH2_PROXY_PROVIDER: keycloak-oidc
|
||||
OAUTH2_PROXY_CLIENT_ID: ${NEO4J_OAUTH_CLIENT_ID:-neo4j-client}
|
||||
OAUTH2_PROXY_CLIENT_SECRET: ${NEO4J_OAUTH_SECRET}
|
||||
OAUTH2_PROXY_OIDC_ISSUER_URL: ${KEYCLOAK_ISSUER_URL}
|
||||
OAUTH2_PROXY_UPSTREAMS: http://neo4j:7474/
|
||||
OAUTH2_PROXY_HTTP_ADDRESS: 0.0.0.0:4180
|
||||
OAUTH2_PROXY_REDIRECT_URL: ${NEO4J_PROXY_REDIRECT_URL:-http://localhost:8082/oauth2/callback}
|
||||
OAUTH2_PROXY_COOKIE_SECRET: ${NEO4J_COOKIE_SECRET}
|
||||
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
|
||||
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|
||||
OAUTH2_PROXY_INSECURE_OIDC_SKIP_ISSUER_VERIFICATION: "true"
|
||||
OAUTH2_PROXY_COOKIE_SECURE: "false"
|
||||
extra_hosts:
|
||||
- "localhost:host-gateway"
|
||||
ports:
|
||||
- "8082:4180"
|
||||
depends_on:
|
||||
- neo4j
|
||||
#- keycloak # enable if a local keycloak is set up
|
||||
|
||||
keycloak:
|
||||
profiles:
|
||||
- keycloak
|
||||
image: quay.io/keycloak/keycloak:latest
|
||||
command: start-dev
|
||||
restart: on-failure
|
||||
environment:
|
||||
KC_BOOTSTRAP_ADMIN_USERNAME: admin
|
||||
KC_BOOTSTRAP_ADMIN_PASSWORD: admin
|
||||
KC_HOSTNAME: http://localhost:4040
|
||||
KC_HOSTNAME_BACKCHANNEL_DYNAMIC: "true"
|
||||
ports:
|
||||
- "4040:8080"
|
||||
volumes:
|
||||
- keycloak_data:/opt/keycloak/data
|
||||
|
||||
blaze:
|
||||
profiles:
|
||||
- blaze
|
||||
image: samply/blaze:latest
|
||||
ports:
|
||||
- "8090:8080"
|
||||
environment:
|
||||
JAVA_TOOL_OPTIONS: "-Xmx2g"
|
||||
ENFORCE_REFERENTIAL_INTEGRITY: "false"
|
||||
volumes:
|
||||
- blaze-data:/app/data
|
||||
healthcheck:
|
||||
test: curl -f http://localhost:8080/fhir/metadata || exit 1
|
||||
interval: 5s
|
||||
timeout: 10s
|
||||
retries: 30
|
||||
networks:
|
||||
- medax-network
|
||||
|
||||
|
||||
loader:
|
||||
profiles:
|
||||
- blaze
|
||||
image: curlimages/curl:latest
|
||||
depends_on:
|
||||
blaze:
|
||||
condition: service_healthy
|
||||
volumes:
|
||||
- ./testData/POLAR_mock:/bundles:ro #adapt first part to whereever the testfiles are stored
|
||||
entrypoint: /bin/sh
|
||||
command: >
|
||||
-c '
|
||||
for f in /bundles/*.json; do
|
||||
echo "Loading $$f ...";
|
||||
curl -s -X POST http://blaze:8080/fhir \
|
||||
-H "Content-Type: application/fhir+json" \
|
||||
-d @"$$f" > /dev/null;
|
||||
echo "";
|
||||
done;
|
||||
echo "Done loading all bundles."
|
||||
'
|
||||
networks:
|
||||
- medax-network
|
||||
# Define named volumes
|
||||
volumes:
|
||||
neo4j_data:
|
||||
neo4j_logs:
|
||||
neo4j_import:
|
||||
keycloak_data:
|
||||
blaze-data:
|
||||
|
||||
networks:
|
||||
medax-network:
|
||||
driver: bridge
|
||||
Reference in New Issue
Block a user