Adds stacks/share/ — a dedicated stack of userspace Tailscale 'serve' nodes that expose individual internal services to external tailnet users (a friend on his own tailnet) over each node's 100.x identity. No public exposure, no LAN access, immune to the friend's home-subnet addressing. First node ts-roms serves RomM at roms-share.<tailnet>.ts.net -> romm:8080. One reusable tag:share auth key + one ACL rule cover every node; adding a service is a serve-<svc>.json + a copied service block. roms stack reverted to a pointer comment.
69 lines
2.2 KiB
YAML
69 lines
2.2 KiB
YAML
# roms stack — RomM ROM library manager + its dedicated MariaDB.
|
|
#
|
|
# RomM bundles its own Redis (persisted via /redis-data), so there is no cache
|
|
# container here. The library is the existing EmuDeck tree at /storage1/Emulation,
|
|
# which is already RomM "Structure A" (a roms/ parent with per-platform subfolders).
|
|
# It is mounted READ-WRITE per request, so RomM file operations (rename/move/
|
|
# delete, manual matches) can mutate the tree — default scanning stays read-only.
|
|
#
|
|
# All secrets/config come from env_file (stack.env) using container-exact var
|
|
# names (DB_PASSWD, MARIADB_PASSWORD, ...), so this git stack needs NO Portainer
|
|
# UI env vars for ${VAR} substitution. See memory portainer-env-interpolation.
|
|
#
|
|
# Tiered binds: DB + RomM config + bundled-redis -> /config/romm (SSD);
|
|
# RomM blobs (downloaded art + user saves/states) -> /storage1/labdata/romm (ZFS).
|
|
# The labdata/romm/* targets are auto-created by Docker as root on first start.
|
|
#
|
|
# Only romm joins `edge` (Caddy proxies romm:8080); romm-db stays on `roms` only.
|
|
#
|
|
# To share RomM with an EXTERNAL tailnet user (a friend on his own tailnet), see
|
|
# the dedicated `share` stack (stacks/share/), which runs a Tailscale `serve`
|
|
# node joined to this `roms` network.
|
|
|
|
services:
|
|
romm:
|
|
image: rommapp/romm:4
|
|
container_name: romm
|
|
restart: unless-stopped
|
|
networks: [roms, edge]
|
|
depends_on:
|
|
romm-db:
|
|
condition: service_healthy
|
|
env_file:
|
|
- stack.env
|
|
environment:
|
|
- DB_HOST=romm-db
|
|
- DB_NAME=romm
|
|
volumes:
|
|
- /storage1/Emulation:/romm/library
|
|
- /storage1/labdata/romm/resources:/romm/resources
|
|
- /storage1/labdata/romm/assets:/romm/assets
|
|
- /config/romm/config:/romm/config
|
|
- /config/romm/redis:/redis-data
|
|
ports:
|
|
- "8997:8080"
|
|
|
|
romm-db:
|
|
image: mariadb:latest
|
|
container_name: romm-db
|
|
restart: unless-stopped
|
|
networks: [roms]
|
|
env_file:
|
|
- stack.env
|
|
command: ["--max-allowed-packet=64M"]
|
|
healthcheck:
|
|
test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
volumes:
|
|
- /config/romm/mariadb:/var/lib/mysql
|
|
|
|
networks:
|
|
roms:
|
|
name: roms
|
|
driver: bridge
|
|
edge:
|
|
name: edge
|
|
external: true
|