# Production stack (DOCKER_SPEC §2). Publishes no host ports — the existing host # reverse proxy routes cesnimda.co.uk -> site:8080 and /api/contact -> relay:8081 # over the shared external proxy network. services: site: build: context: ../site dockerfile: Dockerfile image: git.cesnimda.uk/cesnimda/resumesite-site:latest restart: unless-stopped read_only: true tmpfs: - /tmp - /var/cache/nginx - /var/run networks: [web] logging: driver: json-file options: { max-size: '10m', max-file: '3' } relay: build: context: ../relay dockerfile: Dockerfile image: git.cesnimda.uk/cesnimda/resumesite-relay:latest restart: unless-stopped read_only: true environment: - Smtp__Host=${SMTP_HOST} - Smtp__Port=${SMTP_PORT:-587} - Smtp__User=${SMTP_USER} - Smtp__Password=${SMTP_PASSWORD} - Relay__FromAddress=${RELAY_FROM:-} - Relay__ToAddress=${RELAY_TO} - Relay__AllowedOrigin=${RELAY_ALLOWED_ORIGIN:-https://cesnimda.co.uk} - Relay__RateLimitPerWindow=${RELAY_RATE_LIMIT:-5} - Relay__WindowSeconds=${RELAY_WINDOW_SECONDS:-600} networks: [web] logging: driver: json-file options: { max-size: '10m', max-file: '3' } networks: web: external: true name: ${PROXY_NETWORK:-web}