Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
39 lines (39 loc) · 1.58 KB
/
Copy pathdocker-compose.yml
File metadata and controls
39 lines (39 loc) · 1.58 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
services:
fakecloud:
image: ghcr.io/faiscadev/fakecloud:latest
build:
context: .
dockerfile: Dockerfile
ports:
- "4566:4566"
volumes:
- /var/run/docker.sock:/var/run/docker.sock
# Lambda / RDS / ElastiCache / ECS publish their backing-container ports on
# the host loopback; the fakecloud container reaches them via
# host.docker.internal. Docker Desktop maps this automatically, but on
# native-Linux Docker it must be wired explicitly (matches install.md).
extra_hosts:
- "host.docker.internal:host-gateway"
environment:
FAKECLOUD_ADDR: "0.0.0.0:4566"
FAKECLOUD_REGION: "us-east-1"
FAKECLOUD_ACCOUNT_ID: "123456789012"
FAKECLOUD_LOG: "info"
# Opt in to EC2 security-group / NACL packet enforcement (nftables).
# Off by default — uncomment together with the cap_add below. Needs
# CAP_NET_ADMIN + the `nft` binary (shipped in the image) on a native-
# Linux Docker daemon; degrades to metadata-only otherwise.
# FAKECLOUD_EC2_SG_ENFORCEMENT: "1"
# Required for EC2 security-group enforcement (FAKECLOUD_EC2_SG_ENFORCEMENT).
# Uncomment to let fakecloud install nftables rules on its per-subnet
# bridges. Leave commented for the default metadata-only behavior.
# cap_add:
# - NET_ADMIN
# The slim image ships no curl/wget — use the binary's own healthcheck
# subcommand, which probes 127.0.0.1:<port>/_fakecloud/health.
healthcheck:
test: ["CMD", "fakecloud", "healthcheck"]
interval: 5s
timeout: 3s
retries: 3
start_period: 2s