services: card-grader: build: . container_name: card-grader restart: unless-stopped # Proper PID-1 signal handling — a clean, immediate stop on # `docker compose down` instead of the 10s SIGKILL timeout. init: true # Without a cap, an always-on container's json log grows unbounded on # the array — this is a server that never reboots, so it would. logging: driver: json-file options: max-size: "10m" max-file: "3" # Bound to all interfaces (not 127.0.0.1) because Nginx Proxy Manager # runs in its own container on a separate macvlan IP (192.168.86.2), # not in this host's network namespace — it has to reach this over the # LAN at 192.168.86.33:8778, same as every other *arr-style service # already proxied through this box. That also means anything else on # the LAN can hit :8778 directly, bypassing the basic-auth NPM adds in # front of hippofam.com/cards — consistent with how the rest of this # box's services already work (LAN is the trust boundary here), but # worth knowing. ports: - "8778:8778" volumes: - ./data:/data environment: # Refuses settings writes from anyone but the host, so a visitor # can't overwrite the API key or switch to a pricier model. Set to 0 # temporarily (on the live server only, not here) while setting the # API key via the app's own Settings screen, then back to 1. - CARD_GRADER_LOCK=1 # This app is reverse-proxied at hippofam.com/cards, not the domain # root — see app.py's BASE_PATH handling. - CARD_GRADER_BASE_PATH=/cards # How long a grade keeps the original photo(s) that produced it, so # Regrade can re-run without asking for them again. Grades, their # thumbnails and every measurement are kept FOREVER regardless — only # the photos expire, since they're what makes the database grow (up # to ~16MB per grade at the upload cap). Past the window, Regrade # falls back to asking for the photo. 0 disables pruning. - CARD_GRADER_IMAGE_RETENTION_DAYS=7