diff --git a/src/RemoteExec.Server/appsettings.json b/src/RemoteExec.Server/appsettings.json index 19d318e..6f7aefb 100644 --- a/src/RemoteExec.Server/appsettings.json +++ b/src/RemoteExec.Server/appsettings.json @@ -10,7 +10,6 @@ // Authentication configuration "Authentication": { // List of API keys for authenticating clients - // Each entry should contain key identification and validation information "ApiKeys": [ // Example: // { @@ -44,39 +43,41 @@ // Docker execution configuration (only used when ExecutionEnvironment = "DockerContainer") "DockerExecution": { // Docker host URL + // null = uses default Docker client settings // Linux: "unix:///var/run/docker.sock" // Windows: "npipe://./pipe/docker_engine" - "DockerHost": "unix:///var/run/docker.sock", - + // Default: null + "DockerHost": null, + // Docker worker image name to use for task execution // Must be built and available on the Docker host // Default: "remoteexec-worker:latest" "WorkerImageName": "remoteexec-worker:latest", - + // Maximum execution time per container in seconds // Containers exceeding this time will be forcefully terminated // Default: 300 (5 minutes) "ContainerTimeoutSeconds": 300, - + // Memory limit per container in MB // Prevents containers from consuming excessive memory // Default: 512 MB "ContainerMemoryLimitMb": 512, - + // CPU shares allocated to each container (relative weight) // Higher values = more CPU priority // Default: 1024 "ContainerCpuShares": 1024, - + // Disable network access in containers for security // Set to false if tasks require network connectivity // Default: true "DisableNetwork": true, - + // Make container filesystem read-only - // Enhances security by preventing file modifications - // Default: true - "ReadOnlyFilesystem": true + // Enhances security by preventing file modifications but does not work when additional assemblies are requested at runtime + // Default: false + "ReadOnlyFilesystem": false }, // Server metrics broadcasting configuration diff --git a/src/RemoteExec.Server/docker-compose.yml b/src/RemoteExec.Server/docker-compose.yml new file mode 100644 index 0000000..9af4e06 --- /dev/null +++ b/src/RemoteExec.Server/docker-compose.yml @@ -0,0 +1,28 @@ +services: + remoteexec-server: + image: stonered/remoteexec:latest + container_name: remoteexec-server + restart: unless-stopped + environment: + - ASPNETCORE_ENVIRONMENT=Production + - ASPNETCORE_URLS=http://+:80 + ports: + - "8080:80" + volumes: + # Application configuration (edit the template below then mount here) + - ./RemoteExec.Server/appsettings.docker.json:/app/appsettings.json:ro + # Mount docker socket only if you will use Execution.ExecutionEnvironment = "DockerContainer" + - /var/run/docker.sock:/var/run/docker.sock:ro + # Optional: timezone sync + - /etc/localtime:/etc/localtime:ro + healthcheck: + test: ["CMD-SHELL", "curl -f http://localhost/health || exit 1"] + interval: 30s + timeout: 10s + retries: 3 + start_period: 10s + logging: + driver: "json-file" + options: + max-size: "10m" + max-file: "3" \ No newline at end of file