From acd37942e99dd45bd33a9dfd45f6d28e1bab6118 Mon Sep 17 00:00:00 2001 From: EugeneTes Date: Tue, 25 Aug 2026 10:07:05 +0000 Subject: [PATCH] Inline NATS config via docker-compose configs Coolify's compose executor rewrites relative bind mounts to a persistent app dir with no source file, causing docker to auto-create the mount target as a directory and fail with "not a directory". Delivering the config through configs.content instead avoids the rewrite entirely and lets Docker Compose substitute NATS_USER/NATS_PASSWORD at parse time. --- CLAUDE.md | 9 ++++----- docker-compose.yml | 31 ++++++++++++++++++++++++++++--- nats-server.conf | 21 --------------------- 3 files changed, 32 insertions(+), 29 deletions(-) delete mode 100644 nats-server.conf diff --git a/CLAUDE.md b/CLAUDE.md index c4daa13..5202da6 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -94,7 +94,7 @@ asyncio.run(main()) - `8080` — WebSocket listener, `no_tls: true`. Traefik terminates TLS and forwards `ws://nats:8080` from the public `wss://nats.tes.gd`. - `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), internal only. Used by the compose healthcheck. - **JetStream**: enabled, persisted to the named volume `nats-data` mounted at `/data`. Limits: 256MB memory / 4GB file. Bump `max_file_store` in `nats-server.conf` if you need more. -- **Auth**: a single user, whose name and password come from the `NATS_USER` / `NATS_PASSWORD` env vars via NATS' native `$VAR` substitution in the config. No accounts, no operator/JWT mode. +- **Auth**: a single user, whose name and password come from the `NATS_USER` / `NATS_PASSWORD` env vars. Substitution happens at Docker Compose parse time (the config lives inline in `docker-compose.yml` under `configs.nats-conf.content`), so NATS itself sees a static config. No accounts, no operator/JWT mode. ## Managing / redeploying @@ -108,15 +108,14 @@ curl -sS -X POST "$COOLIFY_URL/api/v1/deploy?uuid=$APP_UUID" \ # → { "deployments": [ { "deployment_uuid": "…" } ] } done, don't poll ``` -Rotating the password: PATCH the `NATS_PASSWORD` env on the Coolify app, then redeploy. Do not edit `nats-server.conf` — auth is env-driven. +Rotating the password: PATCH the `NATS_PASSWORD` env on the Coolify app, then redeploy. The value is substituted into `configs.nats-conf.content` at compose parse time. -To add a second user (e.g. a scoped app account), edit the `authorization.users` array in `nats-server.conf`, wire the new credential env vars into `docker-compose.yml`, and set them in Coolify. +To add a second user (e.g. a scoped app account), edit the `authorization.users` array in the `configs.nats-conf.content` block in `docker-compose.yml`, and set any new credential env vars in Coolify. ## Files in this repo | File | Purpose | |---|---| -| `docker-compose.yml` | Single `nats` service, exposes 4222/8080/8222 internally; only 8080 is routed publicly via `SERVICE_FQDN_NATS_8080` + Coolify's `docker_compose_domains`. | -| `nats-server.conf` | NATS config: JetStream, WebSocket listener (`no_tls`), env-driven auth. | +| `docker-compose.yml` | Single `nats` service, exposes 4222/8080/8222 internally; only 8080 is routed publicly via `SERVICE_FQDN_NATS_8080` + Coolify's `docker_compose_domains`. The NATS config lives inline under `configs.nats-conf.content` (delivered to the container as `/etc/nats/nats-server.conf`) — no separate config file, no bind mount (Coolify's compose executor rewrites relative host paths into a persistent app dir and can't materialise a source file for them). | | `.gitignore` | Keeps `deploy.json` out of git. | | `deploy.json` (local only) | Coolify app config used by the `deploying-to-coolify-via-api` skill. | diff --git a/docker-compose.yml b/docker-compose.yml index 25e80fc..5f2180e 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -5,10 +5,10 @@ services: command: ["-c", "/etc/nats/nats-server.conf"] environment: - SERVICE_FQDN_NATS_8080 - - NATS_USER=${NATS_USER} - - NATS_PASSWORD=${NATS_PASSWORD} + configs: + - source: nats-conf + target: /etc/nats/nats-server.conf volumes: - - ./nats-server.conf:/etc/nats/nats-server.conf:ro - nats-data:/data expose: - "4222" @@ -20,5 +20,30 @@ services: timeout: 5s retries: 3 +configs: + nats-conf: + content: | + server_name: "nats-volcanic" + + port: 4222 + http_port: 8222 + + jetstream { + store_dir: "/data" + max_memory_store: 256MB + max_file_store: 4GB + } + + websocket { + port: 8080 + no_tls: true + } + + authorization { + users = [ + { user: "${NATS_USER}", password: "${NATS_PASSWORD}" } + ] + } + volumes: nats-data: diff --git a/nats-server.conf b/nats-server.conf deleted file mode 100644 index ce923c3..0000000 --- a/nats-server.conf +++ /dev/null @@ -1,21 +0,0 @@ -server_name: "nats-volcanic" - -port: 4222 -http_port: 8222 - -jetstream { - store_dir: "/data" - max_memory_store: 256MB - max_file_store: 4GB -} - -websocket { - port: 8080 - no_tls: true -} - -authorization { - users = [ - { user: $NATS_USER, password: $NATS_PASSWORD } - ] -}