Multi-layer DDoS protection for Minecraft servers. - rampart-core: Edge node with XDP/eBPF + Rust L7 filtering - rampart-manager: REST API with JWT auth, Redis sync - rampart-cli: CLI tool for operators - velocity-plugin: Domain check, HMAC verify, server registry, load balancer - paper-plugin: Auto-registration, heartbeat, HMAC verify - dashboard: React + Vite web UI for management
80 lines
1.9 KiB
YAML
80 lines
1.9 KiB
YAML
version: "3.9"
|
|
|
|
services:
|
|
redis:
|
|
image: redis:7-alpine
|
|
container_name: rampart-redis
|
|
command: redis-server --requirepass "${REDIS_PASSWORD:-rampart_dev}" --appendonly yes
|
|
ports:
|
|
- "6379:6379"
|
|
volumes:
|
|
- redis-data:/data
|
|
healthcheck:
|
|
test: ["CMD", "redis-cli", "--raw", "incr", "ping"]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 5
|
|
restart: unless-stopped
|
|
|
|
nats:
|
|
image: nats:2-alpine
|
|
container_name: rampart-nats
|
|
ports:
|
|
- "4222:4222"
|
|
command: -js -c /etc/nats/nats.conf
|
|
volumes:
|
|
- nats-data:/data
|
|
healthcheck:
|
|
test: ["CMD", "nats", "server", "check"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 3
|
|
restart: unless-stopped
|
|
|
|
clickhouse:
|
|
image: clickhouse/clickhouse-server:24-alpine
|
|
container_name: rampart-clickhouse
|
|
ports:
|
|
- "8123:8123" # HTTP
|
|
- "9000:9000" # Native TCP
|
|
volumes:
|
|
- clickhouse-data:/var/lib/clickhouse
|
|
- ./clickhouse-init:/docker-entrypoint-initdb.d
|
|
healthcheck:
|
|
test: ["CMD", "curl", "-f", "http://localhost:8123/ping"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
restart: unless-stopped
|
|
|
|
prometheus:
|
|
image: prom/prometheus:latest
|
|
container_name: rampart-prometheus
|
|
ports:
|
|
- "9090:9090"
|
|
volumes:
|
|
- ./prometheus.yml:/etc/prometheus/prometheus.yml
|
|
- prometheus-data:/prometheus
|
|
command:
|
|
- '--config.file=/etc/prometheus/prometheus.yml'
|
|
- '--storage.tsdb.path=/prometheus'
|
|
restart: unless-stopped
|
|
|
|
grafana:
|
|
image: grafana/grafana:latest
|
|
container_name: rampart-grafana
|
|
ports:
|
|
- "3000:3000"
|
|
environment:
|
|
- GF_SECURITY_ADMIN_PASSWORD=${GRAFANA_PASSWORD:-admin}
|
|
volumes:
|
|
- grafana-data:/var/lib/grafana
|
|
- ./dashboards:/etc/grafana/provisioning/dashboards
|
|
restart: unless-stopped
|
|
|
|
volumes:
|
|
redis-data:
|
|
nats-data:
|
|
clickhouse-data:
|
|
prometheus-data:
|
|
grafana-data:
|