-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
283 lines (274 loc) · 10.1 KB
/
Copy pathdocker-compose.yml
File metadata and controls
283 lines (274 loc) · 10.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
# ============================================================
# OpenMetadata 1.9.1 — Local Development Stack
# ============================================================
# Login URL: http://localhost:8585
# Default user: admin@open-metadata.org
# Default pass: admin
# Airflow URL: http://localhost:8080 (user: admin, pass: admin)
#
# LOCAL DEV ONLY — do not use these credentials in production.
# ============================================================
volumes:
ometa_db_data:
ometa_es_data:
ingestion-volume-dag-airflow:
ingestion-volume-dags:
ingestion-volume-tmp:
networks:
app_net:
driver: bridge
services:
# ----------------------------------------------------------
# 1. MySQL — metadata store
# ----------------------------------------------------------
mysql:
image: docker.getcollate.io/openmetadata/db:1.9.1
container_name: openmetadata_mysql
restart: unless-stopped
command: "--sort_buffer_size=10M"
environment:
MYSQL_ROOT_PASSWORD: password
ports:
- "3306:3306"
volumes:
- ometa_db_data:/var/lib/mysql
networks:
- app_net
healthcheck:
test: mysqladmin ping -h localhost
interval: 15s
timeout: 10s
retries: 10
# ----------------------------------------------------------
# 2. Elasticsearch — search index
# ----------------------------------------------------------
elasticsearch:
image: docker.elastic.co/elasticsearch/elasticsearch:7.17.22
container_name: openmetadata_elasticsearch
restart: unless-stopped
environment:
- discovery.type=single-node
- xpack.security.enabled=false
- ES_JAVA_OPTS=-Xms512m -Xmx512m
- "bootstrap.memory_lock=false"
ulimits:
nofile:
soft: 65536
hard: 65536
ports:
- "9200:9200"
- "9300:9300"
volumes:
- ometa_es_data:/usr/share/elasticsearch/data
networks:
- app_net
healthcheck:
test: ["CMD-SHELL", "curl -sf http://localhost:9200/_cluster/health | grep -qE '\"status\":\"(green|yellow)\"'"]
interval: 30s
timeout: 10s
retries: 15
start_period: 60s
# ----------------------------------------------------------
# 3. Database migration init container
# Runs once on first boot, then exits.
# ----------------------------------------------------------
execute-migrate-all:
image: docker.getcollate.io/openmetadata/server:1.9.1
container_name: execute_migrate_all
command: "./bootstrap/openmetadata-ops.sh migrate"
environment:
OPENMETADATA_CLUSTER_NAME: openmetadata
SERVER_PORT: 8585
SERVER_ADMIN_PORT: 8586
LOG_LEVEL: INFO
MIGRATION_LIMIT_PARAM: 1200
# Authentication
AUTHORIZER_CLASS_NAME: org.openmetadata.service.security.DefaultAuthorizer
AUTHORIZER_REQUEST_FILTER: org.openmetadata.service.security.JwtFilter
AUTHORIZER_ADMIN_PRINCIPALS: "[admin]"
AUTHORIZER_ALLOWED_REGISTRATION_DOMAIN: '["all"]'
AUTHORIZER_INGESTION_PRINCIPALS: "[ingestion-bot]"
AUTHORIZER_PRINCIPAL_DOMAIN: "open-metadata.org"
AUTHORIZER_ENFORCE_PRINCIPAL_DOMAIN: "false"
AUTHORIZER_ENABLE_SECURE_SOCKET: "false"
AUTHENTICATION_PROVIDER: basic
AUTHENTICATION_PUBLIC_KEYS: "[http://localhost:8585/api/v1/system/config/jwks]"
AUTHENTICATION_AUTHORITY: https://accounts.google.com
AUTHENTICATION_CLIENT_ID: ""
AUTHENTICATION_CALLBACK_URL: ""
AUTHENTICATION_JWT_PRINCIPAL_CLAIMS: "[email,preferred_username,sub]"
AUTHENTICATION_ENABLE_SELF_SIGNUP: "true"
AUTHENTICATION_CLIENT_TYPE: public
# JWT
RSA_PUBLIC_KEY_FILE_PATH: "./conf/public_key.der"
RSA_PRIVATE_KEY_FILE_PATH: "./conf/private_key.der"
JWT_ISSUER: "open-metadata.org"
JWT_KEY_ID: "Gb389a-9f76-gdjs-a92j-0242bk94356"
# Pipeline service client
PIPELINE_SERVICE_CLIENT_ENDPOINT: http://ingestion:8080
SERVER_HOST_API_URL: http://openmetadata-server:8585/api
PIPELINE_SERVICE_CLIENT_VERIFY_SSL: "no-ssl"
PIPELINE_SERVICE_CLIENT_SSL_CERT_PATH: ""
PIPELINE_SERVICE_CLIENT_CLASS_NAME: "org.openmetadata.service.clients.pipeline.airflow.AirflowRESTClient"
PIPELINE_SERVICE_CLIENT_SECRETS_MANAGER_LOADER: "noop"
# Airflow parameters
AIRFLOW_USERNAME: admin
AIRFLOW_PASSWORD: admin
AIRFLOW_TIMEOUT: 10
FERNET_KEY: "jJ/9sz0g0OHxsfxOoSfdFdmk3ysNmPRnH3TUAbz3IHA="
# Database — MySQL
DB_DRIVER_CLASS: com.mysql.cj.jdbc.Driver
DB_SCHEME: mysql
DB_PARAMS: "allowPublicKeyRetrieval=true&useSSL=false&serverTimezone=UTC"
DB_USE_SSL: "false"
DB_USER: openmetadata_user
DB_USER_PASSWORD: openmetadata_password
DB_HOST: mysql
DB_PORT: 3306
OM_DATABASE: openmetadata_db
# Elasticsearch
ELASTICSEARCH_HOST: elasticsearch
ELASTICSEARCH_PORT: 9200
ELASTICSEARCH_SCHEME: http
SEARCH_TYPE: "elasticsearch"
# Secrets manager
SECRET_MANAGER: db
depends_on:
mysql:
condition: service_healthy
elasticsearch:
condition: service_healthy
networks:
- app_net
# ----------------------------------------------------------
# 3. OpenMetadata Server
# ----------------------------------------------------------
openmetadata-server:
image: docker.getcollate.io/openmetadata/server:1.9.1
container_name: openmetadata_server
restart: always
environment:
OPENMETADATA_CLUSTER_NAME: openmetadata
SERVER_PORT: 8585
SERVER_ADMIN_PORT: 8586
LOG_LEVEL: INFO
# Authentication — basic auth (default admin user)
AUTHORIZER_CLASS_NAME: org.openmetadata.service.security.DefaultAuthorizer
AUTHORIZER_REQUEST_FILTER: org.openmetadata.service.security.JwtFilter
AUTHORIZER_ADMIN_PRINCIPALS: "[admin]"
AUTHORIZER_ALLOWED_REGISTRATION_DOMAIN: '["all"]'
AUTHORIZER_INGESTION_PRINCIPALS: "[ingestion-bot]"
AUTHORIZER_PRINCIPAL_DOMAIN: "open-metadata.org"
AUTHORIZER_ENFORCE_PRINCIPAL_DOMAIN: "false"
AUTHORIZER_ENABLE_SECURE_SOCKET: "false"
AUTHENTICATION_PROVIDER: basic
AUTHENTICATION_PUBLIC_KEYS: "[http://localhost:8585/api/v1/system/config/jwks]"
AUTHENTICATION_AUTHORITY: https://accounts.google.com
AUTHENTICATION_CLIENT_ID: ""
AUTHENTICATION_CALLBACK_URL: ""
AUTHENTICATION_JWT_PRINCIPAL_CLAIMS: "[email,preferred_username,sub]"
AUTHENTICATION_ENABLE_SELF_SIGNUP: "true"
AUTHENTICATION_CLIENT_TYPE: public
# JWT keys (shipped inside the server image)
RSA_PUBLIC_KEY_FILE_PATH: "./conf/public_key.der"
RSA_PRIVATE_KEY_FILE_PATH: "./conf/private_key.der"
JWT_ISSUER: "open-metadata.org"
JWT_KEY_ID: "Gb389a-9f76-gdjs-a92j-0242bk94356"
# Pipeline service client → Airflow ingestion container
PIPELINE_SERVICE_CLIENT_ENDPOINT: http://ingestion:8080
PIPELINE_SERVICE_CLIENT_HEALTH_CHECK_INTERVAL: 300
SERVER_HOST_API_URL: http://openmetadata-server:8585/api
PIPELINE_SERVICE_CLIENT_VERIFY_SSL: "no-ssl"
PIPELINE_SERVICE_CLIENT_SSL_CERT_PATH: ""
PIPELINE_SERVICE_CLIENT_ENABLED: "true"
PIPELINE_SERVICE_CLIENT_CLASS_NAME: "org.openmetadata.service.clients.pipeline.airflow.AirflowRESTClient"
PIPELINE_SERVICE_IP_INFO_ENABLED: "false"
PIPELINE_SERVICE_CLIENT_HOST_IP: ""
PIPELINE_SERVICE_CLIENT_SECRETS_MANAGER_LOADER: "noop"
# Airflow parameters
AIRFLOW_USERNAME: admin
AIRFLOW_PASSWORD: admin
AIRFLOW_TIMEOUT: 10
FERNET_KEY: "jJ/9sz0g0OHxsfxOoSfdFdmk3ysNmPRnH3TUAbz3IHA="
# Database — MySQL
DB_DRIVER_CLASS: com.mysql.cj.jdbc.Driver
DB_SCHEME: mysql
DB_PARAMS: "allowPublicKeyRetrieval=true&useSSL=false&serverTimezone=UTC"
DB_USE_SSL: "false"
DB_USER: openmetadata_user
DB_USER_PASSWORD: openmetadata_password
DB_HOST: mysql
DB_PORT: 3306
OM_DATABASE: openmetadata_db
# Elasticsearch
ELASTICSEARCH_HOST: elasticsearch
ELASTICSEARCH_PORT: 9200
ELASTICSEARCH_SCHEME: http
ELASTICSEARCH_USER: ""
ELASTICSEARCH_PASSWORD: ""
SEARCH_TYPE: "elasticsearch"
ELASTICSEARCH_CONNECTION_TIMEOUT_SECS: 5
ELASTICSEARCH_SOCKET_TIMEOUT_SECS: 60
ELASTICSEARCH_KEEP_ALIVE_TIMEOUT_SECS: 600
ELASTICSEARCH_BATCH_SIZE: 100
ELASTICSEARCH_INDEX_MAPPING_LANG: EN
# Event monitoring
EVENT_MONITOR: prometheus
EVENT_MONITOR_BATCH_SIZE: 10
# Secrets manager
SECRET_MANAGER: db
# Heap
OPENMETADATA_HEAP_OPTS: "-Xmx1G -Xms1G"
MASK_PASSWORDS_API: "false"
# Web config
WEB_CONF_URI_PATH: "/api"
ports:
- "8585:8585"
- "8586:8586"
depends_on:
mysql:
condition: service_healthy
elasticsearch:
condition: service_healthy
execute-migrate-all:
condition: service_completed_successfully
networks:
- app_net
healthcheck:
test: ["CMD", "wget", "-q", "--spider", "http://localhost:8586/healthcheck"]
interval: 15s
timeout: 10s
retries: 10
# ----------------------------------------------------------
# 4. Ingestion — Airflow-based ingestion worker
# ----------------------------------------------------------
ingestion:
image: docker.getcollate.io/openmetadata/ingestion:1.9.1
container_name: openmetadata_ingestion
restart: always
environment:
AIRFLOW__API__AUTH_BACKENDS: "airflow.api.auth.backend.basic_auth,airflow.api.auth.backend.session"
AIRFLOW__CORE__EXECUTOR: LocalExecutor
AIRFLOW__OPENMETADATA_AIRFLOW_APIS__DAG_GENERATED_CONFIGS: "/opt/airflow/dag_generated_configs"
DB_HOST: mysql
DB_PORT: 3306
AIRFLOW_DB: airflow_db
DB_SCHEME: mysql+mysqldb
DB_USER: airflow_user
DB_PASSWORD: airflow_pass
entrypoint: /bin/bash
command:
- "/opt/airflow/ingestion_dependency.sh"
ports:
- "8080:8080"
depends_on:
mysql:
condition: service_healthy
openmetadata-server:
condition: service_started
networks:
- app_net
volumes:
- ingestion-volume-dag-airflow:/opt/airflow/dag_generated_configs
- ingestion-volume-dags:/opt/airflow/dags
- ingestion-volume-tmp:/tmp