From c2b508c17150a8de0ca5eccb176d16d2e7b78d4b Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Sun, 20 Sep 2026 14:34:57 +0700 Subject: [PATCH] chore: set restart: unless-stopped on every service Coolify injects the same value when a compose service omits one, but Dokploy runs the file as written, so in its default compose mode an omitted policy leaves the container down after a crash or a host reboot. --- CLAUDE.md | 8 +++++++- README.md | 8 ++++++-- alloy/README.md | 5 ++--- code-server/compose.yml | 1 + couchbase/README.md | 6 +++--- diun/compose.yml | 2 ++ gitea-mirror/compose.yml | 3 +++ opencode-web/compose.yml | 1 + paseo/compose.yml | 1 + traffmonetizer/README.md | 6 +++--- 10 files changed, 29 insertions(+), 12 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 9793271..9791f97 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -106,13 +106,19 @@ unprompted: - **No `ports:`.** Coolify and Dokploy attach the container to their proxy network and map a domain to the internal port. Publishing a port is redundant and would additionally expose it on the host. -- **No `restart:` policy.** The platform manages the container lifecycle. - **No `container_name:`.** Let Compose derive it from the directory. More generally: these files are tuned to one person's setup and are not meant to be portable, standard, or turnkey. Prefer leaving a service minimal over adding hardening or convention that the platform already provides. +`restart:` is the exception that is *not* omitted. Every service sets +`restart: unless-stopped`, on every container. Coolify injects that exact value +when a service does not declare one, and keeps the declared value when it does; +Dokploy does not inject anything, so in its default compose mode an omitted +policy leaves the container down after a crash or a host reboot. Setting it is +correct on both. + ## Secrets Every service reads secrets from a sibling `.env`. Never commit one — the root diff --git a/README.md b/README.md index c7258fc..da9e4f0 100644 --- a/README.md +++ b/README.md @@ -10,10 +10,14 @@ otherwise declare: - **No published ports.** The platform attaches the container to its proxy network and maps a domain to the internal port. Publishing one would also expose it on the host. -- **No `restart:` policy.** The platform manages the container lifecycle. - **No `container_name:`.** Compose derives it from the directory. -Services that do publish ports or set `restart:` say so in their own README. +Every container does set `restart: unless-stopped`. Coolify would inject the +same value on its own, but Dokploy leaves an omitted policy alone, which in its +default compose mode means the container stays down after a reboot. + +Services that publish ports or set `container_name:` say so in their own +README. ## Layout diff --git a/alloy/README.md b/alloy/README.md index 16194ec..1f46c35 100644 --- a/alloy/README.md +++ b/alloy/README.md @@ -10,9 +10,8 @@ API to it. The Alloy config is embedded inline via Compose `configs:`, so there is no `config.alloy` on disk, and every setting comes from a shell variable rather than a `.env` file. -Uses `docker-compose.yml`, and sets `restart: unless-stopped` and -`container_name: alloy` — unlike the platform-managed services described in the -[root README](../README.md). +Uses `docker-compose.yml`, and sets `container_name: alloy` — unlike the +platform-managed services described in the [root README](../README.md). ## What it collects diff --git a/code-server/compose.yml b/code-server/compose.yml index 0ea781a..da60e03 100644 --- a/code-server/compose.yml +++ b/code-server/compose.yml @@ -1,6 +1,7 @@ services: code-server: build: . + restart: unless-stopped hostname: ${SERVICE_HOSTNAME} environment: - PUID=1000 diff --git a/couchbase/README.md b/couchbase/README.md index 0dbcc39..839a6e6 100644 --- a/couchbase/README.md +++ b/couchbase/README.md @@ -2,9 +2,9 @@ [Couchbase Server](https://www.couchbase.com), single node. -Uses `docker-compose.yml`, publishes ports, and sets `restart: unless-stopped` -and `container_name: db` — unlike the platform-managed services described in -the [root README](../README.md). +Uses `docker-compose.yml`, publishes ports, and sets `container_name: db` — +unlike the platform-managed services described in the +[root README](../README.md). ## Networking diff --git a/diun/compose.yml b/diun/compose.yml index 4759c13..daac06d 100644 --- a/diun/compose.yml +++ b/diun/compose.yml @@ -4,6 +4,7 @@ services: diun: image: crazymax/diun:4 + restart: unless-stopped command: serve environment: DIUN_PROVIDERS_DOCKER: "true" @@ -26,6 +27,7 @@ services: # Read-only slice of the Docker API. POST is revoked by default in this image. dockerproxy: image: tecnativa/docker-socket-proxy:latest + restart: unless-stopped environment: CONTAINERS: 1 IMAGES: 1 diff --git a/gitea-mirror/compose.yml b/gitea-mirror/compose.yml index 9380c7b..b1d80e4 100644 --- a/gitea-mirror/compose.yml +++ b/gitea-mirror/compose.yml @@ -1,6 +1,7 @@ services: db: image: postgres:16-alpine + restart: unless-stopped environment: POSTGRES_DB: gitea POSTGRES_USER: gitea @@ -15,6 +16,7 @@ services: gitea: image: gitea/gitea:latest + restart: unless-stopped depends_on: db: condition: service_healthy @@ -33,6 +35,7 @@ services: gitea-mirror: image: ghcr.io/raylabshq/gitea-mirror:latest + restart: unless-stopped pull_policy: always volumes: - gitea-mirror-data:/app/data diff --git a/opencode-web/compose.yml b/opencode-web/compose.yml index 13fab35..8db20e0 100644 --- a/opencode-web/compose.yml +++ b/opencode-web/compose.yml @@ -1,6 +1,7 @@ services: opencode-web: build: . + restart: unless-stopped command: - web - '--hostname' diff --git a/paseo/compose.yml b/paseo/compose.yml index d3a22eb..84543e7 100644 --- a/paseo/compose.yml +++ b/paseo/compose.yml @@ -1,6 +1,7 @@ services: paseo: build: . + restart: unless-stopped hostname: ${SERVICE_HOSTNAME} environment: - PASEO_PASSWORD=${PASEO_PASSWORD} diff --git a/traffmonetizer/README.md b/traffmonetizer/README.md index 63cdd56..083c8ff 100644 --- a/traffmonetizer/README.md +++ b/traffmonetizer/README.md @@ -2,9 +2,9 @@ [TraffMonetizer](https://traffmonetizer.com) bandwidth-sharing client. -Uses `docker-compose.yml`, and sets `restart: always` and -`container_name: tm` — unlike the platform-managed services described in the -[root README](../README.md). Publishes no ports; the client only makes outbound +Uses `docker-compose.yml`, and sets `container_name: tm` and `restart: always` +rather than the `unless-stopped` everything else uses — unlike the +platform-managed services described in the [root README](../README.md). Publishes no ports; the client only makes outbound connections. The image tag is `arm64v8`. Change it to match the host architecture.