name: ita-ito-horaires x-restart: &restart restart: unless-stopped # No privilege escalation inside the containers (setuid binaries are ignored). x-hardening: &hardening security_opt: - no-new-privileges:true services: db: image: postgres:16-alpine <<: [*restart, *hardening] environment: POSTGRES_DB: ${POSTGRES_DB:-horaires} POSTGRES_USER: ${POSTGRES_USER:-horaires} POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env} volumes: - pgdata:/var/lib/postgresql/data ports: - "${DB_BIND:-127.0.0.1}:${DB_PORT:-55433}:5432" healthcheck: test: ["CMD-SHELL", "pg_isready -U $${POSTGRES_USER} -d $${POSTGRES_DB}"] interval: 5s timeout: 5s retries: 20 volumes: pgdata: