Files
bambuddy/docker-compose.yml
T
maziggy e927ccefb1 feat(docker): Tailscale integration support via host socket mount
Add the Tailscale CLI to the production image and document how to
  enable Let's Encrypt cert provisioning for virtual printers from a
  Docker-deployed Bambuddy.

  - Dockerfile installs `tailscale` from the official Debian repo. Only
    the CLI is used at runtime; tailscaled itself stays on the host.
    The binary is harmless if the socket isn't mounted — the code logs
    an actionable hint and falls back to self-signed certs.
  - docker-compose.yml adds a commented-out volume mount for
    /var/run/tailscale/tailscaled.sock with inline setup instructions.
  - tailscale.py's docker-socket hint now also fires when the binary is
    present but the daemon socket is unreachable (i.e. the new Docker
    pattern), not just when the binary is missing, so users get the
    actionable "mount the socket" message instead of opaque CLI stderr.

  Enabling the integration on a Docker host:
    1. `curl -fsSL https://tailscale.com/install.sh | sh` on host
    2. `sudo tailscale up`
    3. `sudo tailscale set --operator=<user>` for the container PUID
    4. Uncomment the tailscaled.sock mount in docker-compose.yml
    5. `docker compose up -d --force-recreate`
    6. Flip the Tailscale toggle on the VP card
2026-04-24 12:01:22 +02:00

90 lines
3.8 KiB
YAML

services:
bambuddy:
image: ghcr.io/maziggy/bambuddy:latest
build: .
# Usage:
# docker compose up -d → pulls pre-built image from ghcr.io
# docker compose up -d --build → builds locally from source
container_name: bambuddy
# Run as current user to avoid permission issues with mounted volumes
# Override with: PUID=$(id -u) PGID=$(id -g) docker compose up -d
user: "${PUID:-1000}:${PGID:-1000}"
#
# Proxy mode: allow binding to privileged ports (322, 990) as non-root user.
# Without this, the FTP and RTSP proxies silently fail.
cap_add:
- NET_BIND_SERVICE
#
# LINUX: Use host mode for printer discovery and camera streaming
network_mode: host
#
# macOS/WINDOWS: Docker Desktop doesn't support host mode.
# Comment out "network_mode: host" above and uncomment "ports:" below.
# Note: Printer discovery won't work - add printers manually by IP.
#ports:
# - "${PORT:-8000}:8000"
# - "3000:3000" # Virtual printer bind/detect
# - "3002:3002" # Virtual printer bind/detect
# - "8883:8883" # Virtual printer MQTT
# - "990:990" # Virtual printer FTP control
# - "6000:6000" # Virtual printer file transfer tunnel
# - "322:322" # Virtual printer RTSP camera (X1/H2/P2)
# - "2024-2026:2024-2026" # Virtual printer proprietary ports (A1/P1S)
# - "50000-50100:50000-50100" # Virtual printer FTP passive data
volumes:
- bambuddy_data:/app/data
- bambuddy_logs:/app/logs
#
# Share virtual printer certs with native installation
# This ensures the slicer only needs to trust one CA certificate.
- ./virtual_printer:/app/data/virtual_printer
#
# Mount scheduled backup output to NAS or external storage
# Backups default to DATA_DIR/backups/ inside the data volume.
# Uncomment to store them externally (e.g. on a NAS share).
#- /path/to/nas/bambuddy-backups:/app/data/backups
#
# Tailscale integration (optional): mount the host's tailscaled socket
# so Bambuddy can request Let's Encrypt certs for virtual printers via
# your tailnet's MagicDNS name. Requires:
# 1. Tailscale installed + `tailscale up` completed on the host
# 2. `sudo tailscale set --operator=<container-user>` on the host so
# the user running the container can call `tailscale cert`
# Without this mount, the Tailscale toggle in the UI is harmless —
# Bambuddy falls back to self-signed certs.
#- /var/run/tailscale/tailscaled.sock:/var/run/tailscale/tailscaled.sock
environment:
- TZ=${TZ:-Europe/Berlin}
# Port BamBuddy runs on (default: 8000)
# Usage: PORT=8080 docker compose up -d
- PORT=${PORT:-8000}
# Virtual printer: Set to the Docker host's IP when using bridge mode (ports:).
# Required for FTP passive mode to work behind NAT.
# Example: VIRTUAL_PRINTER_PASV_ADDRESS=192.168.1.100
#- VIRTUAL_PRINTER_PASV_ADDRESS=
#
# External PostgreSQL (optional — uses SQLite by default)
# Example: DATABASE_URL=postgresql+asyncpg://bambuddy:password@db-host:5432/bambuddy
#- DATABASE_URL=
restart: unless-stopped
# Optional: External PostgreSQL database
# Uncomment to run Postgres alongside Bambuddy (or use an external Postgres host)
#postgres:
# image: postgres:16-alpine
# container_name: bambuddy-db
# restart: unless-stopped
# environment:
# POSTGRES_USER: bambuddy
# POSTGRES_PASSWORD: changeme
# POSTGRES_DB: bambuddy
# volumes:
# - bambuddy_pgdata:/var/lib/postgresql/data
# ports:
# - "5432:5432"
volumes:
bambuddy_data:
bambuddy_logs:
#bambuddy_pgdata: