feat: Add slcompose service orchestrator with Infisical secret injection
- Add slcompose.sh: Central orchestrator for managing all Docker services * Boot all services at startup with automated Infisical secret injection * Commands: up, down, restart, logs, logs-tail, env, env-all * Colored environment variable output (blue names, green values) - Add slcompose.service: Systemd service file for auto-boot on startup * Type=oneshot with RemainAfterExit=yes * Waits for Docker service before starting * Runs on multi-user.target - Add orchestration.md: Comprehensive documentation * Architecture and installation guide * Usage examples for all commands * Secret injection flow and troubleshooting * Performance and security notes - Update README.md and AI_CONTEXT.md * Document service orchestration architecture * Explain slcompose functionality and commands * Reference new orchestration documentation
This commit is contained in:
@@ -158,6 +158,29 @@ Verified subnet:
|
||||
172.22.0.0/16
|
||||
```
|
||||
|
||||
#### Gluetun PIA VPN Gateway
|
||||
|
||||
Purpose:
|
||||
|
||||
* Containerized VPN gateway for Private Internet Access (PIA)
|
||||
* Isolate VPN traffic from host networking and production services
|
||||
|
||||
Services:
|
||||
|
||||
* `gluetun-pia`
|
||||
* `xray-pia` (via `container:gluetun-pia` network mode)
|
||||
|
||||
Notes:
|
||||
|
||||
* `gluetun-pia` routes selected container traffic through PIA WireGuard
|
||||
* `xray-pia` is a secondary VLESS endpoint that uses the Gluetun VPN gateway
|
||||
* Production `xray` remains isolated on the direct OVH path
|
||||
|
||||
Verified isolation:
|
||||
|
||||
* VPN traffic is contained inside the `gluetun-pia` container namespace
|
||||
* Host routing remains unchanged by VPN activity
|
||||
|
||||
#### gitea-runner_default
|
||||
|
||||
Purpose:
|
||||
|
||||
Reference in New Issue
Block a user