Expand description
Podman Compose file generation for yah-cloud service deployments (R040-F7).
Translates MachineConfig + LegacyServiceConfig[] into a ready-to-deploy
ComposeBundle containing:
compose.yml: Podman Compose (Docker Compose v3-compatible) stackCaddyfile: Caddy reverse-proxy config formesh_only: falseservices (omitted when all services are mesh-only)
§Tier isolation
Services share a Compose network named after the machine’s first tier:*
tag (tier:t2 → network tier-t2). Tier isolation at the software layer
(Postgres roles, Headscale ACL tags) is the camp owner’s responsibility;
this just scopes the container network so different-tier stacks on the
same host are not bridged together.
§Tenant isolation (W206 / R558-T2)
When a machine hosts services from a single tenant (the common, degenerate
case — every LegacyServiceConfig::tenant is the singleton), the scheme
above is unchanged. When it hosts services from two or more distinct
tenants, the network splits per tenant: each service joins
<tenant>-<tier> (e.g. ss-tier-t2, noisetable-tier-t2) so cross-tenant
stacks on the same host are not bridged together. The shared Caddy ingress
joins every tenant network so a single reverse proxy still reaches any
public service. See [NetworkPlan].
§Caddy reverse proxy
mesh_only: false services are exposed through a Caddy container that
Cloudflare orange-cloud (or a Cloudflare Tunnel via R040-F15) terminates
in front of. Caddy is chosen over nginx because it handles TLS from
Cloudflare origin certs without extra config, and its reverse_proxy
directive handles service discovery by container name.
§mesh_only services
Services with mesh_only: true use expose: only (no host-port
binding). They are reachable within the Compose network and, once
R040-F16 lands its bind_interface plumbing, directly via Tailscale.
Structs§
- Compose
Bundle - A rendered compose bundle ready to push to the yubaba’s
POST /compose.
Functions§
- generate_
compose_ bundle - Generate a
ComposeBundlefor a machine’s full service set.