summaryrefslogtreecommitdiffstats
path: root/docker-compose.yml
blob: 1b154f4d18e39873f0a791c4f562d8d43907cd2b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
version: "2.1"

services:
  ejbca:
    image: primekey/ejbca-ce:7.4.3.2
    hostname: cahostname
    container_name: oomcert-ejbca
    ports:
      - "80:8080"
      - "443:8443"
    environment:
      - INITIAL_ADMIN=;PublicAccessAuthenticationToken:TRANSPORT_ANY;
      - NO_CREATE_CA=true
    volumes:
      - ./compose-resources/ejbca-configuration.sh:/opt/primekey/scripts/ejbca-configuration.sh
      - ./compose-resources/certprofile_CUSTOM_ENDUSER-1834889499.xml:/opt/primekey/custom_profiles/certprofile_CUSTOM_ENDUSER-1834889499.xml
      - ./compose-resources/entityprofile_Custom_EndEntity-1356531849.xml:/opt/primekey/custom_profiles/entityprofile_Custom_EndEntity-1356531849.xml
    healthcheck:
      test: ["CMD-SHELL", "curl -kI https://localhost:8443/ejbca/publicweb/healthcheck/ejbcahealth"]
      interval: 10s
      timeout: 3s
      retries: 15
    networks:
      - certservice

  oom-cert-service:
    image: onap/org.onap.oom.platform.cert-service.oom-certservice-api:latest
    volumes:
      - ./compose-resources/cmpServers.json:/etc/onap/oom/certservice/cmpServers.json
      - ./certs/truststore.jks:/etc/onap/oom/certservice/certs/truststore.jks
      - ./certs/root.crt:/etc/onap/oom/certservice/certs/root.crt
      - ./certs/certServiceServer-keystore.jks:/etc/onap/oom/certservice/certs/certServiceServer-keystore.jks
      - ./certs/certServiceServer-keystore.p12:/etc/onap/oom/certservice/certs/certServiceServer-keystore.p12
    container_name: oomcert-service
    ports:
      - "8443:8443"
    depends_on:
      ejbca:
        condition: service_healthy
    healthcheck:
      test: ["CMD-SHELL", "curl https://localhost:8443/actuator/health --cacert /etc/onap/oom/certservice/certs/root.crt --cert-type p12 --cert /etc/onap/oom/certservice/certs/certServiceServer-keystore.p12 --pass secret"]
      interval: 10s
      timeout: 3s
      retries: 15
    networks:
      - certservice


networks:
  certservice:
    driver: bridge