forked from CoreWCF/CoreWCF
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathdocker-compose.yml
144 lines (138 loc) · 4.73 KB
/
docker-compose.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
version: "3.8"
services:
# The awaiter service uses a tiny image (~3MB) to await the health status
# of apps in other service containers.
awaiter:
image: alpine:latest
container_name: 'awaiter'
depends_on:
rabbitmq:
condition: service_healthy
broker:
condition: service_healthy
rabbitmq:
image: rabbitmq:3.11-management-alpine
container_name: 'rabbitmq'
ports:
- 5672:5672
- 15672:15672
healthcheck:
test: rabbitmqctl await_startup || exit 1
interval: 5s
timeout: 5s
retries: 12
start_period: 15s
networks:
- rabbitmq_network
generate-kafka-secrets:
image: mcr.microsoft.com/openjdk/jdk:11-ubuntu
container_name: 'generate-kafka-secrets'
working_dir: /root/.local/share/kafka-secrets
entrypoint: bash -c
command:
- |
/bin/bash
chmod +x /root/.local/share/kafka-secrets/generate-kafka-secrets.sh
/root/.local/share/kafka-secrets/generate-kafka-secrets.sh
volumes:
- ./src/CoreWCF.Kafka/tests/kafka-secrets:/root/.local/share/kafka-secrets:rw
networks:
- kafka_network
zookeeper:
image: confluentinc/cp-zookeeper
container_name: 'zookeeper'
environment:
ZOOKEEPER_CLIENT_PORT: 2181
ZOOKEEPER_TICK_TIME: 2000
ZOOKEEPER_ADMIN_ENABLE_SERVER: 'false'
healthcheck:
test: echo ruok | nc 127.0.0.1 2181 || exit -1
interval: 5s
timeout: 5s
retries: 12
start_period: 15s
networks:
- kafka_network
broker:
image: confluentinc/cp-kafka
container_name: 'broker'
depends_on:
generate-kafka-secrets:
condition: service_completed_successfully
zookeeper:
condition: service_healthy
ports:
- "9092:9092"
- "9093:9093"
- "9094:9094"
- "9095:9095"
- "9096:9096"
environment:
KAFKA_BROKER_ID: 1
KAFKA_ZOOKEEPER_CONNECT: 'zookeeper:2181'
ZOOKEEPER_SASL_ENABLED: 'false'
KAFKA_LISTENER_SECURITY_PROTOCOL_MAP: INTERNAL:PLAINTEXT,HOSTPLAINTEXT:PLAINTEXT,HOSTSSL:SSL,HOSTSASLPLAINTEXT:SASL_PLAINTEXT,HOSTSASLSSL:SASL_SSL,HOSTMTLS:SSL
KAFKA_ADVERTISED_LISTENERS: INTERNAL://broker:29092,HOSTPLAINTEXT://localhost:9092,HOSTSSL://localhost:9093,HOSTSASLPLAINTEXT://localhost:9094,HOSTSASLSSL://localhost:9095,HOSTMTLS://localhost:9096
KAFKA_OFFSETS_TOPIC_REPLICATION_FACTOR: 1
KAFKA_TRANSACTION_STATE_LOG_MIN_ISR: 1
KAFKA_TRANSACTION_STATE_LOG_REPLICATION_FACTOR: 1
KAFKA_CONFLUENT_SUPPORT_METRICS_ENABLE: 'false'
KAFKA_INTER_BROKER_LISTENER_NAME: INTERNAL
# KAFKA_JMX_PORT: '9091'
KAFKA_AUTO_CREATE_TOPICS_ENABLE: 'true'
# KAFKA_AUTHORIZER_CLASS_NAME: 'kafka.security.authorizer.AclAuthorizer'
# KAFKA_ALLOW_EVERYONE_IF_NO_ACL_FOUND: 'true'
KAFKA_SECURITY_PROTOCOL: PLAINTEXT,SSL,SASL_PLAINTEXT,SASL_SSL
KAFKA_SASL_ENABLED_MECHANISMS: PLAIN
# configure SSL for HOSTSSL
KAFKA_SSL_TRUSTSTORE_FILENAME: broker.truststore.jks
KAFKA_SSL_TRUSTSTORE_CREDENTIALS: broker.truststore.jks.cred
KAFKA_SSL_KEYSTORE_FILENAME: broker.keystore.jks
KAFKA_SSL_KEYSTORE_CREDENTIALS: broker.keystore.jks.cred
KAFKA_SSL_KEY_CREDENTIALS: broker.keystore.jks.cred
# configure MTLS
# default to required at broker level
KAFKA_SSL_CLIENT_AUTH: 'required'
# allow HOSTSASLSSL and HOSTSSL to provide only encryption security without authentication
KAFKA_LISTENER_NAME_HOSTSASLSSL_SSL_CLIENT_AUTH: 'none'
KAFKA_LISTENER_NAME_HOSTSSL_SSL_CLIENT_AUTH: 'none'
KAFKA_LISTENER_NAME_HOSTMTLS_SSL_CLIENT_AUTH: 'required'
# configure SASL for HOSTSASLPLAINTEXT
# KAFKA_LISTENER_NAME_HOSTSASLPLAINTEXT_SASL_ENABLED_MECHANISMS: PLAIN
# KAFKA_LISTENER_NAME_HOSTSASLPLAINTEXT_PLAIN_SASL_JAAS_CONFIG: |
# org.apache.kafka.common.security.plain.PlainLoginModule required \
# user_user="user-secret";
KAFKA_OPTS: -Djava.security.auth.login.config=/etc/kafka/secrets/broker_jaas.conf
healthcheck:
test: nc -z localhost 9092 || exit 1
interval: 5s
timeout: 5s
retries: 12
start_period: 15s
links:
- zookeeper
volumes:
- ./src/CoreWCF.Kafka/tests/kafka-secrets:/etc/kafka/secrets:ro
networks:
- kafka_network
akhq:
image: tchiotludo/akhq
container_name: 'akhq'
environment:
AKHQ_CONFIGURATION: |
akhq:
connections:
docker-kafka-server:
properties:
bootstrap.servers: "broker:29092"
ports:
- 9001:8080
links:
- broker
networks:
- kafka_network
networks:
rabbitmq_network:
driver: bridge
kafka_network:
driver: bridge