# Enveliq: ready-to-use install file.
#
# You only need to change the lines marked  <-- CHANGE THIS  (there are three). Everything else can stay as it is.
# Step-by-step instructions for your kind of computer: https://github.com/jlnau/enveliq/blob/main/docs/install/README.md
#
# Two small programs run together:
#   enveliq         the app itself
#   enveliq-render  draws PDF attachments as pictures. It has no internet and cannot see your data.

name: enveliq

services:
  enveliq:
    image: ghcr.io/jlnau/enveliq:latest
    pull_policy: always
    container_name: enveliq
    restart: unless-stopped
    environment:
      # 1. The address you will type in your browser to open Enveliq.
      #    Only on this computer:            http://localhost:8765
      #    On your home Wi-Fi (see the guide): http://192.168.1.50:8765   (use your own computer's number)
      #    With Tailscale or a web address:   https://enveliq.example.com
      ENVELIQ_PUBLIC_URL: "http://localhost:8765"          # <-- CHANGE THIS (or leave it for "only on this computer")

      # 2. A one-time code that proves you are the person setting Enveliq up. You type it once, on the first screen.
      #    Make up a long one (20 or more letters and numbers). Anyone who knows it can claim a new, empty Enveliq.
      ENVELIQ_SETUP_CODE: "CHANGE-ME-make-this-long-and-random"          # <-- CHANGE THIS

      # 3. Only if you open Enveliq with an address starting http:// on your home network (not localhost):
      #    change "" to "1". Leave it as "" for https:// addresses and for localhost.
      ENVELIQ_ALLOW_INSECURE_PUBLIC_URL: ""          # <-- CHANGE THIS only for http://192.168... addresses

      # Optional (you can ignore these until you want them; the guide explains each):
      # ENVELIQ_VAULT_KEY: ""      # lets Enveliq unlock itself after a restart (docs/VAULT_KEY.md)
      # ENVELIQ_LLM_URL: ""        # an AI model on your own network (you can also do this inside the app)

      # Keep this as it is: it connects Enveliq to the PDF drawing program below.
      ENVELIQ_RENDER_URL: http://enveliq-render:8766
    ports:
      # "127.0.0.1:8765:8765" = only this computer can open it (safest).
      # Change it to "8765:8765" to open it from other devices on your home network (see the guide).
      - "127.0.0.1:8765:8765"          # <-- CHANGE THIS only if you want other devices to reach it
    volumes:
      - enveliq-data:/data
    read_only: true
    tmpfs:
      - /tmp:size=64m,mode=1777
    cap_drop: [ALL]
    security_opt:
      - no-new-privileges:true
    networks: [default, render]
    mem_limit: 768m
    pids_limit: 128

  enveliq-render:
    image: ghcr.io/jlnau/enveliq-render:latest
    pull_policy: always
    container_name: enveliq-render
    restart: unless-stopped
    user: "10002:10002"
    read_only: true
    cap_drop: [ALL]
    security_opt:
      - no-new-privileges:true
    networks: [render]
    mem_limit: 1536m
    pids_limit: 64
    cpus: 1.0

networks:
  render:
    name: enveliq-render-net
    internal: true     # no internet, and no other containers

volumes:
  enveliq-data:
    name: enveliq-data     # all your Enveliq data lives here; the guide shows how to back it up
