Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
93 lines (92 loc) · 5.01 KB
/
Copy pathdocker-compose.yml
File metadata and controls
93 lines (92 loc) · 5.01 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
# Blimp prod-source kit — one `docker compose up` on ANY Docker host gives you
# both halves the client node needs, with zero host prep:
#
# • nessie : an Iceberg REST catalog (:8181) over an S3 warehouse — the
# endpoint you point the Blimp node at (Production tab).
# • blimp : the CLI image (python+pyiceberg, aws, duckdb, the kit) —
# connects the node to your data and validates it.
#
# This is OPTIONAL and it is choice A2. `blimp --setup` defaults to the Blimp
# node's OWN Nessie (A1) — nothing to run here at all — and can stand this same
# container up for you on demand. Bring it up yourself only when you want the
# catalog to outlive a --setup run, or to manage it with the rest of your stack.
#
# It is NESSIE, the same catalog the Blimp node runs. It used to be
# tabulario/iceberg-rest, which speaks a different dialect (routes at the root
# instead of under a branch prefix, and `warehouse` as an s3:// PATH instead of
# a server-configured NAME) — so a kit standing up one catalog while the node
# ran another meant every consumer had to branch on which it was talking to.
#
# export CLUSTER_ID=1700000000000 ORIGIN_BUCKET=my-bucket
# export S3_ENDPOINT=http://minio:9000 S3_KEY=… S3_SECRET=… # any S3-compatible store
# docker compose up -d nessie # catalog comes up on :8181
# docker compose run --rm blimp --setup # connect + save wiring (once)
# docker compose run --rm blimp --query # author → CDC delta-merge
# docker compose run --rm blimp --storage # storage suite
#
# On a bucket your host reaches with its own cloud identity, leave S3_KEY/
# S3_SECRET unset.
services:
nessie:
image: ghcr.io/projectnessie/nessie:latest
container_name: blimp-nessie
ports:
- "8181:19120" # <-- point Blimp's "Iceberg REST URL" here
# (…:8181/iceberg, branch prefix "main")
environment:
# Durable version store on a volume, so the catalog survives a restart.
NESSIE_VERSION_STORE_TYPE: ROCKSDB
NESSIE_VERSION_STORE_PERSIST_ROCKS_DATABASE_PATH: /data/nessie
# A Nessie warehouse is a NAME the server already knows, not a path: clients
# ask for `?warehouse=src` and Nessie resolves it to the location below.
# Asking for `?warehouse=s3://…` is answered with 500 "not known".
NESSIE_CATALOG_DEFAULT_WAREHOUSE: ${ICEBERG_WAREHOUSE:-src}
NESSIE_CATALOG_WAREHOUSES_SRC_LOCATION: s3://${ORIGIN_BUCKET:?set ORIGIN_BUCKET}/
NESSIE_CATALOG_SERVICE_S3_DEFAULT_OPTIONS_REGION: ${REGION:-us-east-1}
NESSIE_CATALOG_SERVICE_S3_DEFAULT_OPTIONS_ENDPOINT: ${S3_ENDPOINT:-}
NESSIE_CATALOG_SERVICE_S3_DEFAULT_OPTIONS_PATH_STYLE_ACCESS: "true"
# NO remote request signing. With it on, LoadTable vends s3.signer.* to every
# client and DuckDB (the Blimp node's query engine) follows that instead of
# its own S3 secret — every manifest read then comes back 403 and the delta
# merge falls back to a slow path. Each client carries its own keys.
NESSIE_CATALOG_SERVICE_S3_DEFAULT_OPTIONS_REQUEST_SIGNING_ENABLED: "false"
NESSIE_CATALOG_SERVICE_S3_DEFAULT_OPTIONS_ACCESS_KEY: urn:nessie-secret:quarkus:nessie.catalog.secrets.access-key
nessie.catalog.secrets.access-key.name: ${S3_KEY:-}
nessie.catalog.secrets.access-key.secret: ${S3_SECRET:-}
QUARKUS_HTTP_PORT: "19120"
QUARKUS_MANAGEMENT_ENABLED: "false"
volumes:
- ./catalog:/data/nessie # version store — MUST be writable
restart: unless-stopped
blimp:
build: .
image: 0chaindev/blimp-kit:latest
# Host networking so the CLI reaches the Blimp node's PRIVATE address and,
# on a cloud instance, the metadata service that supplies role credentials —
# that is what makes the key-free path work.
network_mode: host
environment:
CLUSTER_ID: ${CLUSTER_ID:-}
REGION: ${REGION:-us-east-1}
WAREHOUSE: ${WAREHOUSE:-}
ORIGIN_BUCKET: ${ORIGIN_BUCKET:-}
NAMESPACE: ${NAMESPACE:-tpcds}
S3_ENDPOINT: ${S3_ENDPOINT:-}
S3_KEY: ${S3_KEY:-}
S3_SECRET: ${S3_SECRET:-}
# Set these two to drive --setup unattended with THIS compose catalog
# (A = 3, an existing REST URL). Leave them unset to be asked, or to take
# the default A = 1, the Blimp node's own Nessie — in which case the
# `nessie` service above is not needed at all.
# CATALOG_CHOICE: "3"
# ICEBERG_URL: http://localhost:8181/iceberg
CATALOG_CHOICE: ${CATALOG_CHOICE:-}
ICEBERG_URL: ${ICEBERG_URL:-}
ICEBERG_PREFIX: ${ICEBERG_PREFIX:-main}
AWS_ACCESS_KEY_ID: ${AWS_ACCESS_KEY_ID:-}
AWS_SECRET_ACCESS_KEY: ${AWS_SECRET_ACCESS_KEY:-}
volumes:
- ./state:/kit/state # persists ~/.blimp_env wiring across runs
- ./tpcds_queries:/root/tpcds_queries # generated query set (reused)
# ENTRYPOINT is `blimp`; args come from `docker compose run blimp <args>`.
profiles: ["cli"] # only runs on explicit `run`, never `up`