Inline NATS config via docker-compose configs
Coolify's compose executor rewrites relative bind mounts to a persistent app dir with no source file, causing docker to auto-create the mount target as a directory and fail with "not a directory". Delivering the config through configs.content instead avoids the rewrite entirely and lets Docker Compose substitute NATS_USER/NATS_PASSWORD at parse time.
This commit is contained in:
@@ -94,7 +94,7 @@ asyncio.run(main())
|
||||
- `8080` — WebSocket listener, `no_tls: true`. Traefik terminates TLS and forwards `ws://nats:8080` from the public `wss://nats.tes.gd`.
|
||||
- `8222` — HTTP monitoring (`/healthz`, `/varz`, `/jsz`), internal only. Used by the compose healthcheck.
|
||||
- **JetStream**: enabled, persisted to the named volume `nats-data` mounted at `/data`. Limits: 256MB memory / 4GB file. Bump `max_file_store` in `nats-server.conf` if you need more.
|
||||
- **Auth**: a single user, whose name and password come from the `NATS_USER` / `NATS_PASSWORD` env vars via NATS' native `$VAR` substitution in the config. No accounts, no operator/JWT mode.
|
||||
- **Auth**: a single user, whose name and password come from the `NATS_USER` / `NATS_PASSWORD` env vars. Substitution happens at Docker Compose parse time (the config lives inline in `docker-compose.yml` under `configs.nats-conf.content`), so NATS itself sees a static config. No accounts, no operator/JWT mode.
|
||||
|
||||
## Managing / redeploying
|
||||
|
||||
@@ -108,15 +108,14 @@ curl -sS -X POST "$COOLIFY_URL/api/v1/deploy?uuid=$APP_UUID" \
|
||||
# → { "deployments": [ { "deployment_uuid": "…" } ] } done, don't poll
|
||||
```
|
||||
|
||||
Rotating the password: PATCH the `NATS_PASSWORD` env on the Coolify app, then redeploy. Do not edit `nats-server.conf` — auth is env-driven.
|
||||
Rotating the password: PATCH the `NATS_PASSWORD` env on the Coolify app, then redeploy. The value is substituted into `configs.nats-conf.content` at compose parse time.
|
||||
|
||||
To add a second user (e.g. a scoped app account), edit the `authorization.users` array in `nats-server.conf`, wire the new credential env vars into `docker-compose.yml`, and set them in Coolify.
|
||||
To add a second user (e.g. a scoped app account), edit the `authorization.users` array in the `configs.nats-conf.content` block in `docker-compose.yml`, and set any new credential env vars in Coolify.
|
||||
|
||||
## Files in this repo
|
||||
|
||||
| File | Purpose |
|
||||
|---|---|
|
||||
| `docker-compose.yml` | Single `nats` service, exposes 4222/8080/8222 internally; only 8080 is routed publicly via `SERVICE_FQDN_NATS_8080` + Coolify's `docker_compose_domains`. |
|
||||
| `nats-server.conf` | NATS config: JetStream, WebSocket listener (`no_tls`), env-driven auth. |
|
||||
| `docker-compose.yml` | Single `nats` service, exposes 4222/8080/8222 internally; only 8080 is routed publicly via `SERVICE_FQDN_NATS_8080` + Coolify's `docker_compose_domains`. The NATS config lives inline under `configs.nats-conf.content` (delivered to the container as `/etc/nats/nats-server.conf`) — no separate config file, no bind mount (Coolify's compose executor rewrites relative host paths into a persistent app dir and can't materialise a source file for them). |
|
||||
| `.gitignore` | Keeps `deploy.json` out of git. |
|
||||
| `deploy.json` (local only) | Coolify app config used by the `deploying-to-coolify-via-api` skill. |
|
||||
|
||||
Reference in New Issue
Block a user