services: runtime: ports: - target: 443 published: "443" protocol: tcp mode: host edge: image: truf-local:edge build: context: . dockerfile: deploy/edge/Dockerfile target: edge depends_on: runtime: condition: service_healthy network_mode: service:runtime read_only: true user: "10001:10001" cap_drop: [ALL] cap_add: [NET_BIND_SERVICE] security_opt: [no-new-privileges:true] environment: TRUF_EDGE_HOST: ${TRUF_EDGE_HOST:?set TRUF_EDGE_HOST in the protected edge env file} TRUF_ADMIN_PREFIX: ${TRUF_ADMIN_PREFIX:?set TRUF_ADMIN_PREFIX in the protected edge env file} TRUF_ADMIN_USER: ${TRUF_ADMIN_USER:?set TRUF_ADMIN_USER in the protected edge env file} TRUF_ADMIN_PASSWORD_HASH: ${TRUF_ADMIN_PASSWORD_HASH:?set TRUF_ADMIN_PASSWORD_HASH in the protected edge env file} TRUF_ADMIN_EDGE_MARKER: ${TRUF_ADMIN_EDGE_MARKER:?set TRUF_ADMIN_EDGE_MARKER in the protected edge env file} volumes: - edge_data:/data - edge_config:/config - type: bind source: ${TRUF_EDGE_AUTH_LOG_DIR:?set TRUF_EDGE_AUTH_LOG_DIR in the protected edge env file} target: /var/log/caddy - type: bind source: ${TRUF_EDGE_DENYLIST_DIR:?set TRUF_EDGE_DENYLIST_DIR in the protected edge env file} target: /etc/caddy/denylist read_only: true tmpfs: - /tmp:rw,nosuid,nodev,noexec,size=16m,mode=1777 - /run:rw,nosuid,nodev,noexec,size=4m,mode=0700,uid=10001,gid=10001 pids_limit: 128 mem_limit: 256m cpus: 1.0 restart: unless-stopped stop_grace_period: 30s logging: driver: json-file options: max-size: "8m" max-file: "4" volumes: edge_data: edge_config: