mirror of
https://github.com/turnstonelabs/turnstone.git
synced 2026-08-24 12:54:48 -06:00
a315cabe71
Remove stale Redis/Bridge/MQ references found via vulture scan and manual grep: - bot.py docstring: remove Redis MQ reference - server.py trusted_sources: remove "bridge" - tls.py docstring: remove "bridge" from service list Delete 4 obsolete diagram pairs (puml + png): - 06-mq-protocol, 07-message-routing, 08-redis-key-schema, 10-simulator-architecture Update 7 diagrams to reflect direct HTTP architecture: - system-context, package-structure, workstream-states, console-data-flow, deployment, channel-architecture, settings-architecture Redraw architecture-overview.svg: Console router replaces Redis MQ, direct SSE data plane, hash ring routing.
86 lines
2.4 KiB
YAML
86 lines
2.4 KiB
YAML
# TLS overlay — enables mTLS across the turnstone cluster.
|
|
#
|
|
# Usage (requires base compose.yaml with production profile):
|
|
# docker compose -f compose.yaml -f deploy/docker-compose.tls.yml --profile production up
|
|
#
|
|
# The tls-init service bootstraps a CA and issues certs.
|
|
# All turnstone services auto-provision their own certs via the
|
|
# console's ACME endpoint.
|
|
|
|
services:
|
|
# Bootstrap: create CA before anything starts.
|
|
# Runs as root to create directories in the volume, then chowns
|
|
# to turnstone:turnstone with restrictive perms (keys 0600).
|
|
tls-init:
|
|
build: .
|
|
user: root
|
|
command:
|
|
- sh
|
|
- -c
|
|
- |
|
|
set -e
|
|
turnstone-admin tls-bootstrap --out /certs
|
|
chown -R turnstone:turnstone /certs
|
|
find /certs -type d -exec chmod 750 {} +
|
|
find /certs -type f -name '*key.pem' -exec chmod 600 {} +
|
|
find /certs -type f ! -name '*key.pem' -exec chmod 640 {} +
|
|
volumes:
|
|
- tls-certs:/certs
|
|
networks:
|
|
- turnstone-net
|
|
restart: "no"
|
|
|
|
# Console: runs the internal CA + ACME server
|
|
console:
|
|
depends_on:
|
|
tls-init:
|
|
condition: service_completed_successfully
|
|
volumes:
|
|
- tls-certs:/certs:ro
|
|
environment:
|
|
TURNSTONE_TLS_ENABLED: "true"
|
|
TURNSTONE_TLS_SANS: "console"
|
|
TURNSTONE_CONSOLE_URL: "http://console:8090"
|
|
command:
|
|
- turnstone-console
|
|
- --host=0.0.0.0
|
|
- --port=8090
|
|
- --poll-interval=${CONSOLE_POLL_INTERVAL:-10}
|
|
|
|
# Server: auto-provisions certs via console ACME, serves HTTPS
|
|
server:
|
|
depends_on:
|
|
console:
|
|
condition: service_healthy
|
|
volumes:
|
|
- tls-certs:/certs:ro
|
|
environment:
|
|
TURNSTONE_TLS_ENABLED: "true"
|
|
TURNSTONE_TLS_SANS: "server"
|
|
# Disable healthcheck — server serves HTTPS with mTLS which the
|
|
# stdlib healthcheck script can't satisfy. The base compose
|
|
# healthcheck uses plain HTTP which won't work on an HTTPS listener.
|
|
healthcheck:
|
|
disable: true
|
|
|
|
# Channel: TLS
|
|
channel:
|
|
depends_on:
|
|
console:
|
|
condition: service_healthy
|
|
volumes:
|
|
- tls-certs:/certs:ro
|
|
environment:
|
|
TURNSTONE_TLS_ENABLED: "true"
|
|
TURNSTONE_TLS_SANS: "channel"
|
|
command:
|
|
- sh
|
|
- -c
|
|
- >-
|
|
turnstone-channel
|
|
--http-host=0.0.0.0
|
|
$${TURNSTONE_DISCORD_GUILD:+--discord-guild $$TURNSTONE_DISCORD_GUILD}
|
|
|
|
volumes:
|
|
tls-certs:
|