This repository was archived by the owner on Nov 3, 2025. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathdocker-compose.yaml
More file actions
130 lines (119 loc) · 3.3 KB
/
Copy pathdocker-compose.yaml
File metadata and controls
130 lines (119 loc) · 3.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
# This docker-compose file requires a .env file in the same directory
name: litesiem
services:
fluentd:
build:
context: ./fluentd
args:
ELASTIC_VERSION: ${ELASTIC_VERSION:-7.6.2}
expose:
# Input plugin source port is configured in fluentd.conf
- "${FLUENTD_SOURCE_PORT:-9880}"
volumes:
- "${ROOT:-.}/fluentd/conf:/fluentd/etc"
- "${ROOT:-.}/fluentd/index-template.d:/fluentd/index-template.d"
- "${ROOT:-.}/dsiem/logs:/dsiem/logs"
depends_on:
- dsiem-proxy
dsiem-proxy:
build: ./dsiem-proxy
expose:
- "${DSIEM_PROXY_PORT:-9000}"
environment:
DSIEM_URL: http://dsiem:${DSIEM_PORT:-8080}
PROXY_PORT: ${DSIEM_PROXY_PORT:-9000}
depends_on:
- dsiem
dsiem:
image: defenxor/dsiem:0.33.5
volumes:
- "${ROOT:-.}/dsiem/conf:/dsiem/configs"
- "${ROOT:-.}/dsiem/logs:/dsiem/logs"
expose:
- "${DSIEM_PORT:-8080}"
environment:
DSIEM_DEBUG: 'false'
DSIEM_MODE: standalone
DSIEM_NODE: dsiem
DSIEM_PORT: ${DSIEM_PORT:-8080}
depends_on:
- elasticsearch
geoipupdate:
image: maxmindinc/geoipupdate:4.9
environment:
- "GEOIPUPDATE_ACCOUNT_ID=${MAXMIND_ACCOUNT_ID}"
- "GEOIPUPDATE_LICENSE_KEY=${MAXMIND_LICENSE_KEY}"
- "GEOIPUPDATE_EDITION_IDS=GeoLite2-City"
volumes:
- "${ROOT:-.}/api/geolite:/usr/share/GeoIP maxmindinc/geoipupdate"
profiles:
- tools
dashboard:
build: dashboard/
expose:
# Default SvelteKit/Vite port
- "${PORT:-3000}"
depends_on:
- api
landing-page:
build: landing-page/
expose:
# Default Nginx port
- "80"
api:
build:
context: ./api
dockerfile: Dockerfile.production
image: litesiem_api_production:latest
env_file:
- ./api/.env
- ./api/.env.production
command: serve --http="0.0.0.0:${API_PORT:-8090}"
expose:
- "${API_PORT:-8090}"
volumes:
- "${ROOT:-.}/api/geolite:/app/geolite"
- "${ROOT:-.}/api/pb_data:/app/pb_data"
- "${ROOT:-.}/dsiem/conf:/conf"
- "/var/run/docker.sock:/var/run/docker.sock"
environment:
ELASTIC_URL: "http://elasticsearch:${ELASTIC_PORT:-9200}"
BUILD_ENV: docker
ROOT_DIR: "/"
# Restart container "dsiem" when configuration changes
CONFIG_DSIEM_RESTART: 1
depends_on:
elasticsearch:
condition: service_healthy
kibana:
build:
context: kibana/
args:
ELASTIC_VERSION: ${ELASTIC_VERSION}
volumes:
- "${ROOT:-.}/kibana/config/kibana.yml:/usr/share/kibana/config/kibana.yml:z"
profiles:
- tools
depends_on:
- elasticsearch
elasticsearch:
build:
context: ./elasticsearch
args:
ELASTIC_VERSION: ${ELASTIC_VERSION}
volumes:
- "${ROOT:-.}/elasticsearch/config/elasticsearch.yml:/usr/share/elasticsearch/config/elasticsearch.yml:z"
- "elasticsearch:/usr/share/elasticsearch/data"
expose:
# Default Elasticsearch port
- "${ELASTIC_PORT:-9200}"
environment:
discovery.type: single-node
ES_JAVA_OPTS: '-Xms512m -Xmx512m'
healthcheck:
test: curl -s -f http://elasticsearch:${ELASTIC_PORT:-9200}/_nodes/http || exit 1
interval: 30s
timeout: 10s
retries: 3
volumes:
elasticsearch: