Remove comments v3

This commit is contained in:
2025-07-19 20:34:39 +05:30
parent 948b0575b9
commit 422a0f6211
9 changed files with 96 additions and 212 deletions

View File

@@ -1,46 +1,30 @@
# Radicale CalDAV/CardDAV Server Configuration
services:
radicale:
# Basic container configuration
container_name: radicale
image: docker.io/tomsquest/docker-radicale:3.5.4.0
restart: unless-stopped
# Security hardening
init: true # Use init process for proper signal handling
read_only: true # Read-only filesystem for security
# Minimal required capabilities
init: true
read_only: true
cap_add:
- CHOWN # Required for file ownership changes
- KILL # Required for process management
- SETGID # Required for group permissions
- SETUID # Required for user permissions
# Security restrictions
- CHOWN
- KILL
- SETGID
- SETUID
cap_drop:
- ALL # Drop all capabilities by default
- ALL
security_opt:
- no-new-privileges:true # Prevent privilege escalation
# Resource limits
- no-new-privileges:true
deploy:
resources:
limits:
memory: 256M # Memory limit
pids: 50 # Maximum number of processes
# Persistent storage configuration
memory: 256M
pids: 50
volumes:
- ${APPDATA_PATH}/radicale/data:/data # Calendar and contact data
- ${APPDATA_PATH}/radicale/config:/config:ro # Read-only configuration
# Network configuration
- ${APPDATA_PATH}/radicale/data:/data
- ${APPDATA_PATH}/radicale/config:/config:ro
ports:
- ${PORT}:5232 # DAV service port
# Health monitoring
- ${PORT}:5232
healthcheck:
test: curl -f http://127.0.0.1:5232 || exit 1 # Simple HTTP check
interval: 30s # Check every 30 seconds
retries: 3 # Allow 3 failures before marking unhealthy
test: curl -f http://127.0.0.1:5232 || exit 1
interval: 30s
retries: 3