Dockerfile, compose.yml, env template, and runbook for the second-brain web container. Targets herbys-dev (10.0.21.207); Traefik (file-provider on 10.0.11.20) reaches the published host port at 10.0.21.207:8080. Image: - python:3.12-slim + the official uv binary copied from the upstream image, plus apt-installed git + ca-certificates so the Gitea VCS pin for embedding-chunking resolves at build time. - uv sync --frozen --no-dev --no-install-project, source copy, then a second uv sync to install the project itself. Two-step so the lock install layer caches independently of source edits. - No ffmpeg / claude CLI / faster-whisper — web role doesn't need any of them. Extraction runs on the dev host's CLI; transcription on the tower. - Drops to uid 1000 (`app`) before CMD. Uvicorn binds 0.0.0.0:8000 inside the container, with --proxy-headers + --forwarded-allow-ips=* so Traefik's X-Forwarded-* survive. compose.yml: - Joins the existing external `homelab` bridge network so the container reaches homelab-postgres:5432 and ollama:11434 by service DNS. - Publishes the uvicorn port at 10.0.21.207:8080 (LAN IP bound, not 0.0.0.0) for Traefik on the separate VM to reach. NO traefik.* labels — file-provider Traefik can't read them. - env_file: .env (0600, gitignored) — SECOND_BRAIN_DATABASE_URL points at homelab-postgres:5432 (containerised), NOT the host's 127.0.0.1:5433 port-map. - restart: unless-stopped. README.md: - Build + bring-up commands. - SECURITY note: no SSO / no CSRF / mutating endpoints — Traefik route must be LAN-only for now (Travis's call). - The two infra steps Travis applies himself, with ready-to-paste snippets: - Knot DNS: brain.herbylab.dev → 10.0.11.20. - Traefik dynamic config: file-provider router + service block. - Verification checklist for both before-and-after-DNS states. Live-verified on herbys-dev: container Up, dashboard returns 200 with real status counts from petalbrain, settings save round-trip works, no tracebacks in logs.
21 lines
938 B
Plaintext
21 lines
938 B
Plaintext
# deploy/web/.env — runtime secrets for the second-brain-web container.
|
|
#
|
|
# Copy this to deploy/web/.env, fill in REPLACE_ME, chmod 0600. The real
|
|
# .env is gitignored (see deploy/web/.gitignore). Source of truth for
|
|
# the lovebug password: /opt/backups/postgres-consolidation/credentials.env
|
|
# on herbys-dev (mode 0600, host-only).
|
|
|
|
# REQUIRED. Containerised connection — the web container reaches Postgres
|
|
# by docker-network DNS name, NOT via the host's 127.0.0.1:5433 publish.
|
|
SECOND_BRAIN_DATABASE_URL=postgresql+psycopg://lovebug:REPLACE_ME@homelab-postgres:5432/petalbrain
|
|
|
|
# OPTIONAL. The dashboard does not currently embed search queries, but
|
|
# the embedding module reads this lazily. Default targets the homelab
|
|
# `ollama` container.
|
|
OLLAMA_URL=http://ollama:11434
|
|
EMBEDDING_MODEL=nomic-embed-text
|
|
|
|
# OPTIONAL. Pool sizing — single-instance web doesn't need much.
|
|
# SECOND_BRAIN_DB_POOL_MIN=1
|
|
# SECOND_BRAIN_DB_POOL_MAX=4
|