# Try mode: an evaluation instance, and nothing a deployment depends on. # # Fetched by deploy/install.sh and brought up as project anchorpoint-try. It # differs from deploy/compose.client.yml in five ways, and every one of them # is deliberate: # # 1. The image is pulled from the public registry by digest rather than # loaded from a bundle. There is no bundle in this path and no signature # to check, which is why nothing here installs anything: an evaluation # instance holds generated data and governs nothing. # 2. Its own ports (8092, 9020) and its own volume, so it cannot collide # with an install on the same host. # 3. No worker. The worker is what sends a heartbeat, and an evaluator's # laptop must never appear in the fleet (S647). # 4. A seed one-shot, which runs anchorpoint-seed-trial once the migration # has finished and then exits. # 5. ANCHORPOINT_EVALUATION_INSTANCE, which is what puts the banner on the # console screen. # # Secrets here are fixed strings and that is correct rather than sloppy: this # stack holds generated data, is reachable only on loopback, and is destroyed # by one command. A random secret would imply it was worth protecting. # # The digest is substituted at promotion time by scripts/promote-release.py. # The default below is not a digest that resolves, on purpose: a try-compose # that was published unsubstituted must fail at the pull rather than quietly # start something else. services: postgres: image: postgres:18 restart: unless-stopped environment: POSTGRES_USER: anchorpoint_owner POSTGRES_PASSWORD: anchorpoint_try POSTGRES_DB: anchorpoint volumes: - anchorpoint_try_pgdata:/var/lib/postgresql healthcheck: test: ["CMD-SHELL", "pg_isready -U anchorpoint_owner -d anchorpoint"] interval: 2s timeout: 3s retries: 40 migrate: image: ghcr.io/sagacian/anchorpoint@sha256:80714b2c400ca11592258e36b50d7a421d287f0bb96235ad9184bd319d258b0b restart: "no" command: ["alembic", "upgrade", "head"] environment: ANCHORPOINT_DSN: postgresql+psycopg://anchorpoint_owner:anchorpoint_try@postgres:5432/anchorpoint depends_on: postgres: condition: service_healthy seed: image: ghcr.io/sagacian/anchorpoint@sha256:80714b2c400ca11592258e36b50d7a421d287f0bb96235ad9184bd319d258b0b restart: "no" command: ["anchorpoint-seed-trial", "--runs", "8"] environment: # The owner DSN on both, because the trial tenant has to be written into # the tenants table and anchorpoint_app holds only SELECT there. An # evaluation instance has one process doing the writing and no boundary # to keep, so it does not create the second role a real install does. ANCHORPOINT_DSN: postgresql+psycopg://anchorpoint_owner:anchorpoint_try@postgres:5432/anchorpoint ANCHORPOINT_ADMIN_DSN: postgresql+psycopg://anchorpoint_owner:anchorpoint_try@postgres:5432/anchorpoint depends_on: migrate: condition: service_completed_successfully gateway: image: ghcr.io/sagacian/anchorpoint@sha256:80714b2c400ca11592258e36b50d7a421d287f0bb96235ad9184bd319d258b0b restart: unless-stopped environment: ANCHORPOINT_GATEWAY_HOST: 0.0.0.0 ANCHORPOINT_GATEWAY_PORT: "8080" ANCHORPOINT_DSN: postgresql+psycopg://anchorpoint_owner:anchorpoint_try@postgres:5432/anchorpoint ports: - "127.0.0.1:9020:8080" depends_on: migrate: condition: service_completed_successfully console: image: ghcr.io/sagacian/anchorpoint@sha256:80714b2c400ca11592258e36b50d7a421d287f0bb96235ad9184bd319d258b0b restart: unless-stopped command: ["anchorpoint-dashboard"] environment: ANCHORPOINT_DASHBOARD_HOST: 0.0.0.0 ANCHORPOINT_DASHBOARD_PORT: "8081" ANCHORPOINT_DSN: postgresql+psycopg://anchorpoint_owner:anchorpoint_try@postgres:5432/anchorpoint ANCHORPOINT_ADMIN_DSN: postgresql+psycopg://anchorpoint_owner:anchorpoint_try@postgres:5432/anchorpoint ANCHORPOINT_DASHBOARD_SECRET: anchorpoint-try-not-a-secret ANCHORPOINT_EVALUATION_INSTANCE: "1" # No ANCHORPOINT_VAULT_PRIVATE_KEY here, and none anywhere in this file. # The console is browser facing and must never hold the key that opens a # stored provider credential, which is S93's split. It holds here for a # second reason too: an evaluation instance stores no provider # credential at all, so there is nothing for a vault to open (S645). ports: - "127.0.0.1:8092:8081" depends_on: migrate: condition: service_completed_successfully volumes: anchorpoint_try_pgdata: