-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathdocker-compose.yml
147 lines (137 loc) · 3.57 KB
/
docker-compose.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
version: "3.4"
services:
redis:
image: redis
networks:
- sso
auth:
image: yadd/lemonldap-ng-portal
volumes:
- ./lemon/ssl.conf:/etc/nginx/sites-enabled/0000default.conf
- ./ssl:/etc/nginx/ssl
environment:
- SSODOMAIN=example.com
- PORTAL=https://auth.example.com
- LOGLEVEL=notice
- LOGGER=stderr
- USERLOGGER=stderr
- REDIS_SERVER=redis:6379
networks:
frontend:
sso:
haproxy:
image: haproxy:2.6-bullseye
ports:
- 443:443
volumes:
- ./haproxy:/usr/local/etc/haproxy:ro
- ./ssl/both.pem:/etc/ssl/certs/both.pem
sysctls:
- net.ipv4.ip_unprivileged_port_start=0
depends_on:
- auth
networks:
frontend:
aliases:
- auth.example.com
jitsi-web:
image: jitsi/web:stable-8319
restart: unless-stopped
ports:
- 8443:443
volumes:
- ./jitsi-meet-cfg/web:/config:Z
- ./jitsi-meet-cfg/web/crontabs:/var/spool/cron/crontabs:Z
- ./jitsi-meet-cfg/transcripts:/usr/share/jitsi-meet/transcripts:Z
environment:
- TZ=UTC
- ENABLE_AUTH=1
networks:
- meet.jitsi
jitsi-prosody:
image: jitsi/prosody:stable-8319
restart: unless-stopped
expose:
- 5222
- 5347
- 5280
volumes:
- ./jitsi-meet-cfg/prosody/config:/config:Z
- ./jitsi-meet-cfg/prosody/prosody-plugins-custom:/prosody-plugins-custom:Z
environment:
- JIBRI_RECORDER_PASSWORD=5250fe842da9b3decbf67c61a81704c3
- JIBRI_XMPP_PASSWORD=7ae37752673b7c05250828b2ec0edbc2
- JICOFO_AUTH_PASSWORD=0dd986d69df01800b7baeebb2a277530
- JIGASI_XMPP_PASSWORD=43ceecc3f24dc2241ebb2d27aa427d5b
- JVB_AUTH_PASSWORD=9714089ce45e86177fb0c9127f511b3d
- TZ=UTC
- ENABLE_AUTH=1
- AUTH_TYPE=jwt
- JWT_APP_ID=meet.example.com
- JWT_APP_SECRET=HDWsmGjq2kGvBAMWM8pK55mREgxgjVYywX2lJDNp3a8brNpWRNDvNlVvY2H9m16aRQfqCKMhgKdIv35AMCTj9xR1wBEqUPnHMFN4Eg2trHwnC5G2PCgcyo1O5U6Kz8Lm
- JWT_ACCEPTED_ISSUERS=jitsi
- JWT_ACCEPTED_AUDIENCES=jitsi
- TOKEN_AUTH_URL=http://localhost:3000/room/{room}
networks:
meet.jitsi:
aliases:
- xmpp.meet.jitsi
jicofo:
image: jitsi/jicofo:stable-8319
restart: unless-stopped
ports:
- 8888:8888
volumes:
- ./jitsi-meet-cfg/jicofo:/config:Z
environment:
- JICOFO_AUTH_PASSWORD=0dd986d69df01800b7baeebb2a277530
- SENTRY_DSN=0
- TZ=UTC
- ENABLE_AUTH=1
- AUTH_TYPE=jwt
depends_on:
- jitsi-prosody
networks:
- meet.jitsi
jitsi-video-bridge:
image: jitsi/jvb:stable-8319
restart: unless-stopped
ports:
- 10000:10000/udp
- 8080:8080
volumes:
- ./jitsi-meet-cfg/jvb:/config:Z
environment:
- JVB_AUTH_PASSWORD=9714089ce45e86177fb0c9127f511b3d
- SENTRY_DSN=0
- TZ=UTC
depends_on:
- jitsi-prosody
networks:
- meet.jitsi
jitsi-openid:
build: ./jitsi-openid
restart: always
ports:
- 3000:3000
environment:
- JITSI_SECRET=HDWsmGjq2kGvBAMWM8pK55mREgxgjVYywX2lJDNp3a8brNpWRNDvNlVvY2H9m16aRQfqCKMhgKdIv35AMCTj9xR1wBEqUPnHMFN4Eg2trHwnC5G2PCgcyo1O5U6Kz8Lm
- JITSI_URL=https://localhost:8443
- JITSI_SUB=meet.jitsi
- ISSUER_URL=https://auth.example.com
- BASE_URL=http://localhost:3000
- CLIENT_ID=jitsi
- CLIENT_SECRET=jitsi
depends_on:
- auth
- jicofo
networks:
- meet.jitsi
- frontend
networks:
sso:
name: sso
frontend:
name: frontend
meet.jitsi:
name: meet.jitsi