mirror of
				https://github.com/open-metadata/OpenMetadata.git
				synced 2025-11-03 20:19:31 +00:00 
			
		
		
		
	
		
			
				
	
	
		
			173 lines
		
	
	
		
			7.4 KiB
		
	
	
	
		
			YAML
		
	
	
	
	
	
			
		
		
	
	
			173 lines
		
	
	
		
			7.4 KiB
		
	
	
	
		
			YAML
		
	
	
	
	
	
#  Copyright 2021 Collate
 | 
						|
#  Licensed under the Apache License, Version 2.0 (the "License");
 | 
						|
#  you may not use this file except in compliance with the License.
 | 
						|
#  You may obtain a copy of the License at
 | 
						|
#  http://www.apache.org/licenses/LICENSE-2.0
 | 
						|
#  Unless required by applicable law or agreed to in writing, software
 | 
						|
#  distributed under the License is distributed on an "AS IS" BASIS,
 | 
						|
#  WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 | 
						|
#  See the License for the specific language governing permissions and
 | 
						|
#  limitations under the License.
 | 
						|
 | 
						|
version: "3.9"
 | 
						|
volumes:
 | 
						|
  ingestion-volume-dag-airflow:
 | 
						|
  ingestion-volume-dags:
 | 
						|
  ingestion-volume-tmp:
 | 
						|
services:
 | 
						|
  postgresql:
 | 
						|
    container_name: openmetadata_postgresql
 | 
						|
    image: openmetadata/postgresql:0.12.0
 | 
						|
    restart: always
 | 
						|
    environment:
 | 
						|
      POSTGRES_USER: postgres
 | 
						|
      POSTGRES_PASSWORD: password
 | 
						|
    expose:
 | 
						|
      - 5432
 | 
						|
    ports:
 | 
						|
      - "5432:5432"
 | 
						|
    networks:
 | 
						|
      - app_net
 | 
						|
    healthcheck:
 | 
						|
      test: psql -U postgres -tAc 'select 1' -d openmetadata_db
 | 
						|
      interval: 15s
 | 
						|
      timeout: 10s
 | 
						|
      retries: 10
 | 
						|
 | 
						|
  elasticsearch:
 | 
						|
    container_name: openmetadata_elasticsearch
 | 
						|
    image: docker.elastic.co/elasticsearch/elasticsearch:7.10.2
 | 
						|
    environment:
 | 
						|
      - discovery.type=single-node
 | 
						|
      - ES_JAVA_OPTS=-Xms1024m -Xmx1024m
 | 
						|
    networks:
 | 
						|
      - app_net
 | 
						|
    ports:
 | 
						|
      - "9200:9200"
 | 
						|
      - "9300:9300"
 | 
						|
 | 
						|
  openmetadata-server:
 | 
						|
    container_name: openmetadata_server
 | 
						|
    restart: always
 | 
						|
    image: openmetadata/server:0.12.0
 | 
						|
    environment:
 | 
						|
      ELASTICSEARCH_HOST: elasticsearch
 | 
						|
      # OpenMetadata Server Authentication Configuration
 | 
						|
      AUTHORIZER_CLASS_NAME: ${AUTHORIZER_CLASS_NAME:-org.openmetadata.service.security.DefaultAuthorizer}
 | 
						|
      AUTHORIZER_REQUEST_FILTER: ${AUTHORIZER_REQUEST_FILTER:-org.openmetadata.service.security.JwtFilter}
 | 
						|
      AUTHORIZER_ADMIN_PRINCIPALS: ${AUTHORIZER_ADMIN_PRINCIPALS:-[admin]}
 | 
						|
      AUTHORIZER_ALLOWED_REGISTRATION_DOMAIN: ${AUTHORIZER_ALLOWED_REGISTRATION_DOMAIN:-["all"]}
 | 
						|
      AUTHORIZER_INGESTION_PRINCIPALS: ${AUTHORIZER_INGESTION_PRINCIPALS:-[ingestion-bot]}
 | 
						|
      AUTHORIZER_PRINCIPAL_DOMAIN: ${AUTHORIZER_PRINCIPAL_DOMAIN:-"openmetadata.org"}
 | 
						|
      AUTHORIZER_ENFORCE_PRINCIPAL_DOMAIN: ${AUTHORIZER_ENFORCE_PRINCIPAL_DOMAIN:-false}
 | 
						|
      AUTHORIZER_ENABLE_SECURE_SOCKET: ${AUTHORIZER_ENABLE_SECURE_SOCKET:-false}
 | 
						|
      AUTHENTICATION_PROVIDER: ${AUTHENTICATION_PROVIDER:-basic}
 | 
						|
      CUSTOM_OIDC_AUTHENTICATION_PROVIDER_NAME: ${CUSTOM_OIDC_AUTHENTICATION_PROVIDER_NAME:-""}
 | 
						|
      AUTHENTICATION_PUBLIC_KEYS: ${AUTHENTICATION_PUBLIC_KEYS:-[http://localhost:8585/api/v1/config/jwks]}
 | 
						|
      AUTHENTICATION_AUTHORITY: ${AUTHENTICATION_AUTHORITY:-https://accounts.google.com}
 | 
						|
      AUTHENTICATION_CLIENT_ID: ${AUTHENTICATION_CLIENT_ID:-""}
 | 
						|
      AUTHENTICATION_CALLBACK_URL: ${AUTHENTICATION_CALLBACK_URL:-""}
 | 
						|
      AUTHENTICATION_JWT_PRINCIPAL_CLAIMS: ${AUTHENTICATION_JWT_PRINCIPAL_CLAIMS:-[email,preferred_username,sub]}
 | 
						|
      AUTHENTICATION_ENABLE_SELF_SIGNUP : ${AUTHENTICATION_ENABLE_SELF_SIGNUP:-true}
 | 
						|
      # JWT Configuration
 | 
						|
      RSA_PUBLIC_KEY_FILE_PATH: ${RSA_PUBLIC_KEY_FILE_PATH:-"./conf/public_key.der"}
 | 
						|
      RSA_PRIVATE_KEY_FILE_PATH: ${RSA_PRIVATE_KEY_FILE_PATH:-"./conf/private_key.der"}
 | 
						|
      JWT_ISSUER: ${JWT_ISSUER:-"open-metadata.org"}
 | 
						|
      JWT_KEY_ID: ${JWT_KEY_ID:-"Gb389a-9f76-gdjs-a92j-0242bk94356"}
 | 
						|
      # OpenMetadata Server Airflow Configuration
 | 
						|
      AIRFLOW_HOST: ${AIRFLOW_HOST:-http://ingestion:8080}
 | 
						|
      SERVER_HOST_API_URL: ${SERVER_HOST_API_URL:-http://openmetadata-server:8585/api}
 | 
						|
      AIRFLOW_AUTH_PROVIDER: ${AIRFLOW_AUTH_PROVIDER:-no-auth}
 | 
						|
      # OpenMetadata Airflow Azure SSO Configuration
 | 
						|
      OM_AUTH_AIRFLOW_AZURE_CLIENT_SECRET: ${OM_AUTH_AIRFLOW_AZURE_CLIENT_SECRET:-""}
 | 
						|
      OM_AUTH_AIRFLOW_AZURE_AUTHORITY_URL: ${OM_AUTH_AIRFLOW_AZURE_AUTHORITY_URL:-""}
 | 
						|
      OM_AUTH_AIRFLOW_AZURE_SCOPES: ${OM_AUTH_AIRFLOW_AZURE_SCOPES:-[]}
 | 
						|
      OM_AUTH_AIRFLOW_AZURE_CLIENT_ID: ${OM_AUTH_AIRFLOW_AZURE_CLIENT_ID:-""}
 | 
						|
      # OpenMetadata Airflow Google SSO Configuration
 | 
						|
      OM_AUTH_AIRFLOW_GOOGLE_SECRET_KEY_PATH: ${OM_AUTH_AIRFLOW_GOOGLE_SECRET_KEY_PATH:- ""}
 | 
						|
      OM_AUTH_AIRFLOW_GOOGLE_AUDIENCE: ${OM_AUTH_AIRFLOW_GOOGLE_AUDIENCE:-"https://www.googleapis.com/oauth2/v4/token"}
 | 
						|
      # OpenMetadata Airflow Okta SSO Configuration
 | 
						|
      OM_AUTH_AIRFLOW_OKTA_CLIENT_ID: ${OM_AUTH_AIRFLOW_OKTA_CLIENT_ID:-""}
 | 
						|
      OM_AUTH_AIRFLOW_OKTA_ORGANIZATION_URL: ${OM_AUTH_AIRFLOW_OKTA_ORGANIZATION_URL:-""}
 | 
						|
      OM_AUTH_AIRFLOW_OKTA_PRIVATE_KEY: ${OM_AUTH_AIRFLOW_OKTA_PRIVATE_KEY:-""}
 | 
						|
      OM_AUTH_AIRFLOW_OKTA_SA_EMAIL: ${OM_AUTH_AIRFLOW_OKTA_SA_EMAIL:-""}
 | 
						|
      OM_AUTH_AIRFLOW_OKTA_SCOPES: ${OM_AUTH_AIRFLOW_OKTA_SCOPES:-[]}
 | 
						|
      # OpenMetadata Airflow Auth0 SSO Configuration
 | 
						|
      OM_AUTH_AIRFLOW_AUTH0_CLIENT_ID: ${OM_AUTH_AIRFLOW_AUTH0_CLIENT_ID:-""}
 | 
						|
      OM_AUTH_AIRFLOW_AUTH0_CLIENT_SECRET: ${OM_AUTH_AIRFLOW_AUTH0_CLIENT_SECRET:-""}
 | 
						|
      OM_AUTH_AIRFLOW_AUTH0_DOMAIN_URL: ${OM_AUTH_AIRFLOW_AUTH0_DOMAIN_URL:-""}
 | 
						|
      # OpenMetadata Airflow Custom OIDC SSO Configuration
 | 
						|
      OM_AUTH_AIRFLOW_CUSTOM_OIDC_CLIENT_ID: ${OM_AUTH_AIRFLOW_CUSTOM_OIDC_CLIENT_ID:-""}
 | 
						|
      OM_AUTH_AIRFLOW_CUSTOM_OIDC_SECRET_KEY: ${OM_AUTH_AIRFLOW_CUSTOM_OIDC_SECRET_KEY:-""}
 | 
						|
      OM_AUTH_AIRFLOW_CUSTOM_OIDC_TOKEN_ENDPOINT_URL: ${OM_AUTH_AIRFLOW_CUSTOM_OIDC_TOKEN_ENDPOINT_URL:-""}
 | 
						|
      # OpenMetadata Airflow JWT Token Configuration
 | 
						|
      OM_AUTH_JWT_TOKEN: ${OM_AUTH_JWT_TOKEN:-""}
 | 
						|
      #Database configuration for postgresql
 | 
						|
      DB_DRIVER_CLASS: ${DB_DRIVER_CLASS:-org.postgresql.Driver}
 | 
						|
      DB_SCHEME: ${DB_SCHEME:-postgresql}
 | 
						|
      DB_USE_SSL: ${DB_USE_SSL:-false}
 | 
						|
      DB_USER: ${DB_USER:-openmetadata_user}
 | 
						|
      DB_USER_PASSWORD: ${DB_USER_PASSWORD:-openmetadata_password}
 | 
						|
      DB_HOST: ${DB_HOST:-postgresql}
 | 
						|
      DB_PORT: ${DB_PORT:-5432}
 | 
						|
      OM_DATABASE: ${OM_DATABASE:-openmetadata_db}
 | 
						|
      # Airflow SSL Configurations
 | 
						|
      AIRFLOW_VERIFY_SSL: ${AIRFLOW_VERIFY_SSL:-"no-ssl"}
 | 
						|
      AIRFLOW_SSL_CERT_PATH: ${AIRFLOW_SSL_CERT_PATH:-""}
 | 
						|
    expose:
 | 
						|
      - 8585
 | 
						|
      - 8586
 | 
						|
    ports:
 | 
						|
      - "8585:8585"
 | 
						|
      - "8586:8586"
 | 
						|
    depends_on:
 | 
						|
      elasticsearch:
 | 
						|
        condition: service_started
 | 
						|
      postgresql:
 | 
						|
        condition: service_healthy
 | 
						|
    networks:
 | 
						|
      - app_net
 | 
						|
    healthcheck:
 | 
						|
      test: [ "CMD", "curl", "-f", "http://localhost:8586/healthcheck" ]
 | 
						|
 | 
						|
  ingestion:
 | 
						|
    container_name: openmetadata_ingestion
 | 
						|
    image: openmetadata/ingestion:0.12.0
 | 
						|
    depends_on:
 | 
						|
      elasticsearch:
 | 
						|
        condition: service_started
 | 
						|
      postgresql:
 | 
						|
        condition: service_healthy
 | 
						|
      openmetadata-server:
 | 
						|
        condition: service_healthy
 | 
						|
    environment:
 | 
						|
      AIRFLOW__API__AUTH_BACKENDS: airflow.api.auth.backend.basic_auth
 | 
						|
      AIRFLOW__CORE__EXECUTOR: LocalExecutor
 | 
						|
      AIRFLOW__OPENMETADATA_AIRFLOW_APIS__DAG_GENERATED_CONFIGS: "/opt/airflow/dag_generated_configs"
 | 
						|
      DB_HOST: ${DB_HOST:-postgresql}
 | 
						|
      DB_PORT: ${DB_PORT:-5432}
 | 
						|
      AIRFLOW_DB: ${AIRFLOW_DB:-airflow_db}
 | 
						|
      DB_USER: ${DB_USER:-airflow_user}
 | 
						|
      DB_SCHEME: ${DB_SCHEME:-postgresql+psycopg2}
 | 
						|
      DB_PASSWORD: ${DB_PASSWORD:-airflow_pass}
 | 
						|
    entrypoint: /bin/bash
 | 
						|
    command:
 | 
						|
      - "/opt/airflow/ingestion_dependency.sh"
 | 
						|
    expose:
 | 
						|
      - 8080
 | 
						|
    ports:
 | 
						|
      - "8080:8080"
 | 
						|
    networks:
 | 
						|
      - app_net
 | 
						|
    volumes:
 | 
						|
      - ingestion-volume-dag-airflow:/opt/airflow/dag_generated_configs
 | 
						|
      - ingestion-volume-dags:/opt/airflow/dags
 | 
						|
      - ingestion-volume-tmp:/tmp
 | 
						|
 | 
						|
networks:
 | 
						|
  app_net:
 | 
						|
    ipam:
 | 
						|
      driver: default
 | 
						|
      config:
 | 
						|
        - subnet: "172.16.240.0/24"
 |