-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
233 lines (225 loc) · 10.9 KB
/
Copy pathdocker-compose.yml
File metadata and controls
233 lines (225 loc) · 10.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
services:
postgres:
# Postgres 16. Tag is overridable via POSTGRES_IMAGE for
# air-gapped hosts that have a specific tag pre-cached.
image: ${POSTGRES_IMAGE:-postgres:16-alpine}
environment:
POSTGRES_DB: ${POSTGRES_DB:-simpleaudit}
POSTGRES_USER: ${POSTGRES_USER:-simpleaudit}
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env}
volumes:
- postgres_data:/var/lib/postgresql/data
# Creates the separate Hatchet queue database on first init.
# Only runs when the data volume is empty (fresh install).
- ./deploy/postgres-init.sql:/docker-entrypoint-initdb.d/10-hatchet-db.sql:ro
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-simpleaudit} -d ${POSTGRES_DB:-simpleaudit}"]
interval: 5s
timeout: 3s
retries: 20
# core stack (postgres + hatchet + web + worker) can run on hosts that cannot
# pull MinIO; enable with `docker compose --profile storage up`. The audit
# execution path does not require it — only large-artifact persistence does.
mock-model:
profiles: ["mock"]
# Compose application image (web + worker only). The root Dockerfile is the
# single-container HF Space image and must NOT be used here.
build:
context: .
dockerfile: deploy/compose/Dockerfile
command: python /app/deploy/mock_openai_server.py
environment:
PORT: "8901"
ports:
- "8901:8901"
healthcheck:
test: ["CMD-SHELL", "python -c \"import urllib.request;urllib.request.urlopen('http://localhost:8901/healthz',timeout=3)\" || exit 1"]
interval: 10s
timeout: 5s
retries: 10
# Durable workflow engine.
# Postgres-backed task queue that coordinates audit execution. It is NOT the
# authoritative SimpleAudit database; PostgreSQL domain tables remain source of truth.
#
# The default image is hatchet-lite-dev (authentication compiled out) so a
# fresh `docker compose up` works turnkey: workers connect with the fixed
# worker token the dev image seeds into the DB (see HATCHET_API_KEY below,
# populated by the bootstrap_platform command on first start). For hardened
# deployments set HATCHET_IMAGE to the auth-enabled hatchet-lite and provide
# your own HATCHET_API_KEY.
hatchet-server:
image: ${HATCHET_IMAGE:-ghcr.io/hatchet-dev/hatchet/hatchet-lite-dev:latest}
environment:
# Full config per https://docs.hatchet.run/self-hosting/configuration-options
DATABASE_URL: postgresql://${POSTGRES_USER:-simpleaudit}:${POSTGRES_PASSWORD}@postgres:5432/${HATCHET_DB:-hatchet}?sslmode=disable
# Session store requires an explicit cookie domain.
SERVER_AUTH_COOKIE_DOMAIN: ${HATCHET_COOKIE_DOMAIN:-localhost}
SERVER_AUTH_COOKIE_INSECURE: "t"
SERVER_AUTH_SET_EMAIL_VERIFIED: "t"
# gRPC: workers connect over plaintext inside the compose network.
SERVER_GRPC_BIND_ADDRESS: "0.0.0.0"
SERVER_GRPC_INSECURE: "t"
SERVER_GRPC_BROADCAST_ADDRESS: hatchet-server:7077
SERVER_GRPC_PORT: "7077"
SERVER_HTTP_PORT: "8888"
SERVER_URL: http://hatchet-server:8888
SERVER_LOG_LEVEL: info
SERVER_INTERNAL_CLIENT_INTERNAL_GRPC_BROADCAST_ADDRESS: hatchet-server:7077
ports:
- "8888:8888" # Hatchet HTTP API / dashboard
- "7077:7077" # gRPC (worker <-> server)
volumes:
# The auth-disabled dev image writes its fixed worker JWT here at startup.
# Mounted read-only into the worker so a fresh `docker compose up` works
# turnkey (see HATCHET_TOKEN_FILE on the worker). Ignored when using the
# auth-enabled image with an explicit HATCHET_API_KEY.
- hatchet_config:/config
depends_on:
postgres:
condition: service_healthy
healthcheck:
test: ["CMD-SHELL", "wget -qO- http://localhost:8888/healthz || exit 1"]
interval: 10s
timeout: 5s
retries: 20
# SimpleAudit worker pool. Runs separately from the web process; the web server
# never executes model calls. Scale by adding replicas or GPU-labeled workers.
worker:
# Compose application image (web + worker only). The root Dockerfile is the
# single-container HF Space image and must NOT be used here.
build:
context: .
dockerfile: deploy/compose/Dockerfile
env_file: .env
environment:
POSTGRES_HOST: postgres
HATCHET_SERVER_URL: http://hatchet-server:8888
HATCHET_GRPC_URL: hatchet-server:7077
WORKER_POOL: ${WORKER_POOL:-cpu}
# Worker reads its API token from this file (written by the auth-disabled
# hatchet dev image). Set HATCHET_API_KEY in .env to override with an
# explicit token for the auth-enabled image.
HATCHET_TOKEN_FILE: /config/authdisabled-token
volumes:
- hatchet_config:/config:ro
depends_on:
postgres:
condition: service_healthy
hatchet-server:
condition: service_healthy
command: python manage.py run_worker --pool ${WORKER_POOL:-cpu}
# Liveness: the worker runs as PID 1 and stays alive while connected to
# Hatchet; if it exits (e.g. cannot connect after retries) the container
# dies and restarts. The slim image has no ps/pgrep, so we read /proc/1/
# cmdline to confirm the run_worker process is the live entrypoint.
healthcheck:
test: ["CMD-SHELL", "tr '\\0' ' ' < /proc/1/cmdline | grep -q 'run_worker' || exit 1"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
restart: unless-stopped
web:
build:
context: .
dockerfile: deploy/compose/Dockerfile
env_file: .env
environment:
POSTGRES_HOST: postgres
HATCHET_SERVER_URL: http://hatchet-server:8888
HATCHET_GRPC_URL: hatchet-server:7077
# Web enqueues audit tasks to Hatchet, so it needs the same worker API
# token as the worker. The auth-disabled dev image writes a per-instance
# JWT to this file; mounting the shared config volume read-only makes a
# fresh `docker compose up` work turnkey. Set HATCHET_API_KEY in .env to
# override with an explicit token for the auth-enabled image.
HATCHET_TOKEN_FILE: /config/authdisabled-token
volumes:
- hatchet_config:/config:ro
depends_on:
postgres:
condition: service_healthy
hatchet-server:
condition: service_healthy
ports:
- "8000:8000"
# Single-line sh -c so the argument list is unambiguous (a folded YAML block
# previously broke the flag parsing). Migrate + idempotent bootstrap +
# idempotent seed (scenario packs + models + demo audits) + static
# collection, then serve with gunicorn. The seed is safe on every start:
# it skips anything already present. Set SEED_ON_BOOT=false to opt out.
# Set SEED_DEMO_AUDITS=false to skip demo audit runs only.
command: 'sh -c "python manage.py migrate --noinput && python manage.py bootstrap_platform --username ${BOOTSTRAP_USERNAME:-studio} --email ${BOOTSTRAP_EMAIL:-admin@example.local} --password ${BOOTSTRAP_PASSWORD:?Set BOOTSTRAP_PASSWORD in .env} --project-name ${BOOTSTRAP_PROJECT_NAME:-Default} && if [ "${SEED_ON_BOOT:-true}" != "false" ]; then SEED_ARGS=\"\"; if [ \"${SEED_DEMO_AUDITS:-true}\" = \"false\" ]; then SEED_ARGS=\"--skip-demo-audits\"; fi; python manage.py seed_platform $$SEED_ARGS || echo ''WARNING: seed_platform failed - continuing without seed data''; fi && python manage.py collectstatic --noinput && gunicorn config.wsgi:application --bind 0.0.0.0:8000 --workers 2"'
healthcheck:
test: ["CMD", "curl", "-fsS", "http://localhost:8000/healthz"]
interval: 30s
timeout: 5s
retries: 5
# Matches the worker. The whole command is idempotent (migrate, bootstrap
# and seed all skip what already exists), so a restart is safe and a
# gunicorn crash or a Postgres blip no longer leaves the UI down for good.
# A bad .env still fails every attempt, but the error repeats in the logs
# instead of being printed once into a container nobody looks at.
restart: unless-stopped
# Chat module — ON by default. .env carries both switches (SIMPLEAUDIT_CHAT=docker
# so the web service serves /chat/, COMPOSE_PROFILES=chat so these two
# containers are part of a plain `docker compose up -d`); comment them out to
# leave chat out entirely. See infra/chat.py.
#
# Open WebUI deliberately publishes NO port: chat-proxy is the only route to
# it, because it trusts the identity headers on any request it receives.
open-webui:
profiles: ["chat"]
image: ${OPEN_WEBUI_IMAGE:-ghcr.io/open-webui/open-webui:main}
environment:
WEBUI_AUTH_TRUSTED_EMAIL_HEADER: X-Studio-Email
WEBUI_AUTH_TRUSTED_NAME_HEADER: X-Studio-Name
WEBUI_AUTH_TRUSTED_ROLE_HEADER: X-Studio-Role
ENABLE_SIGNUP: "false"
# Nothing in this stack serves Ollama; Open WebUI polls it otherwise.
ENABLE_OLLAMA_API: "false"
WEBUI_URL: ${SIMPLEAUDIT_CHAT_URL:-http://localhost:8801}
# The image entrypoint is start.sh (no `open-webui` CLI on PATH); it reads
# HOST/PORT and launches uvicorn itself.
HOST: "0.0.0.0"
PORT: ${SIMPLEAUDIT_CHAT_UPSTREAM_PORT:-8080}
# Optional: export Open WebUI's spans to Studio's OTLP listener. Off by
# default — set SIMPLEAUDIT_CHAT_OTLP=true to enable. Open WebUI picks the
# HTTP exporter from OTEL_OTLP_SPAN_EXPORTER and appends /v1/traces to the
# endpoint, so the endpoint is the base URL (Studio's web origin). Exports
# unauthenticated by default (matches an enabled "none" credential); for a
# basic/bearer credential set OTEL_BASIC_AUTH_USERNAME / OTEL_BASIC_AUTH_PASSWORD.
ENABLE_OTEL: ${SIMPLEAUDIT_CHAT_OTLP:-false}
ENABLE_OTEL_TRACES: ${SIMPLEAUDIT_CHAT_OTLP:-false}
OTEL_OTLP_SPAN_EXPORTER: "http"
OTEL_EXPORTER_OTLP_ENDPOINT: ${SIMPLEAUDIT_CHAT_OTLP_ENDPOINT:-http://web:8000}
OTEL_SERVICE_NAME: ${SIMPLEAUDIT_CHAT_OTLP_SERVICE_NAME:-open-webui}
volumes:
- open_webui_data:/app/backend/data
restart: unless-stopped
chat-proxy:
profiles: ["chat"]
image: ${CADDY_IMAGE:-caddy:2-alpine}
environment:
STUDIO_URL: ${SIMPLEAUDIT_STUDIO_URL:-http://localhost:8000}
SIMPLEAUDIT_CHAT_PROXY_PORT: ${SIMPLEAUDIT_CHAT_PROXY_PORT:-8801}
SIMPLEAUDIT_CHAT_UPSTREAM_PORT: ${SIMPLEAUDIT_CHAT_UPSTREAM_PORT:-8080}
STUDIO_UPSTREAM: web:8000
volumes:
- ./deploy/compose/Caddyfile.chat:/etc/caddy/Caddyfile:ro
# Served as Open WebUI's /static/custom.css (see Caddyfile.chat) so the
# iframe hides the chat-history sidebar.
- ./chat/embed.css:/etc/caddy/embed/static/custom.css:ro
# Served as Open WebUI's favicon (see Caddyfile.chat).
- ./static/logo.svg:/etc/caddy/branding/logo.svg:ro
ports:
- "${SIMPLEAUDIT_CHAT_PROXY_PORT:-8801}:${SIMPLEAUDIT_CHAT_PROXY_PORT:-8801}"
depends_on:
- open-webui
- web
restart: unless-stopped
volumes:
postgres_data:
open_webui_data:
# Shared Hatchet config; carries the auth-disabled worker JWT from server -> worker.
hatchet_config: