Skip to content

Docker Compose — High Availability ​

Requirements ​

  • An application server that meets the system requirements, with Docker Engine and Docker Compose
  • PostgreSQL 15 (14 is supported)
  • Valkey 9 (standalone mode; Sentinel and Cluster are not supported)
  • S3-compatible storage with a bucket that allows anonymous read access
  • A reverse proxy with SSL termination (nginx, HAProxy or a cloud load balancer)
  • Two DNS names (for the application and the MCP server) and certificates for both
  • SMTP server credentials

Important

The external services must be deployed and reachable over the network from the application server.

Setup steps ​

1. Files ​

Use the deploy/docker-compose directory from the delivery archive; replace docker-compose.yaml with the HA version:

yaml
# flip on-premise — High Availability
# PostgreSQL, Valkey, S3 storage and the reverse proxy are deployed separately.
# Variables come from the .env file next to docker-compose.yaml

services:
  flip-file-handlers:
    image: ${FLIP_REGISTRY_IMAGE}/flip-file-handlers:${FLIP_VERSION}
    container_name: flip-file-handlers
    restart: unless-stopped
    volumes:
      - ./config/file-handlers/config.yaml:/flip/config/config.yaml:ro
    networks:
      - flip

  flip-backend:
    image: ${FLIP_REGISTRY_IMAGE}/flip-backend:${FLIP_VERSION}
    container_name: flip-backend
    restart: unless-stopped
    depends_on:
      - flip-file-handlers
    ports:
      - "9000:9000"
    volumes:
      - ./config/backend/config.yaml:/flip/cfg/config.yaml:ro
      # PostgreSQL root certificate for SSLmode: verify-full
      # - ./config/backend/ca.pem:/flip/certs/ca.pem:ro
    networks:
      - flip

  flip-frontend:
    image: ${FLIP_REGISTRY_IMAGE}/flip-frontend:${FLIP_VERSION}
    container_name: flip-frontend
    restart: unless-stopped
    depends_on:
      - flip-backend
    ports:
      - "8080:80"
    volumes:
      - ./config/frontend/config.js:/usr/share/nginx/html/app/assets/config.js:ro
    networks:
      - flip

  flip-mcp-server:
    image: ${FLIP_REGISTRY_IMAGE}/flip-mcp-server:${FLIP_VERSION}
    container_name: flip-mcp-server
    restart: unless-stopped
    depends_on:
      - flip-backend
    ports:
      - "8090:8090"
    volumes:
      - ./config/mcp-server/config.yaml:/flip/cfg/config.yaml:ro
    networks:
      - flip

networks:
  flip:
    driver: bridge

Download docker-compose.ha.yaml

The containers publish ports on the host: backend 9000, frontend 8080, mcp-server 8090. If the reverse proxy runs on the same server, you can connect it to the flip network instead of publishing the ports.

2. Environment variables ​

The .env file sets the image registry and version:

ini
FLIP_REGISTRY_IMAGE=cr.yandex/crpbj8irels1kqult74e/onpremise
FLIP_VERSION=v1.2.0

3. Configuration files ​

Fill in the files in the config directory, specifying the addresses of the external PostgreSQL, Valkey and S3:

FileDescriptionKey fields
config/backend/config.yamlBackendPostgres, RedisClient, S3, Mail, secrets
config/file-handlers/config.yamlFile-handlersS3Config, RedisConfig
config/frontend/config.jsFrontendAPI_URL, S3_URL, WEBSOCKET_URL
config/mcp-server/config.yamlMCP serverflipApi, RedisClient

File permissions

Processes in the containers do not run as root. The configuration files must be readable: chmod -R a+rX config.

PostgreSQL over TLS

For an external database, use SSLmode: require or verify-full. For verify-full, mount the root certificate into the container (see the commented-out line in docker-compose.ha.yaml) and set its path in Postgres.SSLRootCert.

4. S3 storage ​

  • Create a bucket and allow anonymous read access to its objects (the download / public-read policy).
  • Upload the application's media assets: unpack sources/gifs.tar and copy the gifs directory to the root of the bucket:
bash
tar -xf sources/gifs.tar -C .
aws --endpoint-url https://s3.example.ru s3 cp gifs s3://flip/gifs --recursive

5. Reverse proxy ​

Configure routes and timeouts as in the nginx configuration: WebSocket at /app/api/v1/ws, an increased request body limit for /app/api/v1/flip/backup/upload, S3 proxying at /app/s3/, and a separate virtual host for the MCP server.

6. Registry access and startup ​

bash
cat ../../credentials/authorized_key.json | docker login --username json_key --password-stdin cr.yandex
docker compose pull
docker compose up -d
docker compose ps

The application is available at https://example.flip-chart.ru/app. Then proceed to the first launch.

flip on-premise and cloud documentation