corvid/docker-compose.yml
caoimhinr 961fc67528 security: timing-safe API key comparison, remove hardcoded DB password
- Use hmac.compare_digest for constant-time key check (router.py)
- Move POSTGRES_PASSWORD out of docker-compose.yml into .env (was a
  public default "corvid" now that the repo is public)
- Add .env.example with placeholder values

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-25 19:46:25 +02:00

29 lines
529 B
YAML

services:
postgres:
image: postgres:16-alpine
env_file:
- .env
environment:
POSTGRES_USER: corvid
POSTGRES_DB: corvid
volumes:
- pgdata:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U corvid"]
interval: 5s
timeout: 5s
retries: 10
app:
build: .
ports:
- "8090:8080"
env_file:
- .env
depends_on:
postgres:
condition: service_healthy
restart: unless-stopped
volumes:
pgdata: