fixes global
This commit is contained in:
1 parent
13dc4f39c8
commit
cad0f6aebe
64 files changed
+10379
-254
No files matched your search
@@ -9,6 +9,7 @@ ENV PYTHONUNBUFFERED=1 \
|
||||
|
||||
# Install system dependencies
|
||||
RUN apt-get update && apt-get install -y \
|
||||
vim-common
|
||||
build-essential \
|
||||
curl \
|
||||
ffmpeg \
|
||||
@@ -41,4 +42,4 @@ HEALTHCHECK --interval=30s --timeout=10s --start-period=60s --retries=3 \
|
||||
EXPOSE 15100 9090
|
||||
|
||||
# Default command
|
||||
CMD ["python", "start_my_network.py"]
|
||||
CMD ["python", "start_my_network.py"]
|
||||
@@ -0,0 +1,104 @@
|
||||
services:
|
||||
app:
|
||||
container_name: my-network-app
|
||||
build:
|
||||
context: ..
|
||||
dockerfile: deployment/Dockerfile.simple # при необходимости поменять на deployment/Dockerfile
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "8000:8000"
|
||||
env_file:
|
||||
- ../.env
|
||||
environment:
|
||||
- STORAGE_PATH=/app/storage
|
||||
- DOCKER_SOCK_PATH=/var/run/docker.sock
|
||||
- LOG_PATH=/app/logs
|
||||
- NODE_PRIVATE_KEY_PATH=/app/keys/node_private_key
|
||||
- NODE_PUBLIC_KEY_PATH=/app/keys/node_public_key
|
||||
- API_HOST=0.0.0.0
|
||||
- API_PORT=8000
|
||||
- UVICORN_HOST=0.0.0.0
|
||||
- UVICORN_PORT=8000
|
||||
volumes:
|
||||
- ./uploader-bot/storage:/app/storage
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./uploader-bot/logs:/app/logs
|
||||
- ./uploader-bot/config/keys:/app/keys
|
||||
# - ./uploader-bot/bootstrap.json:/app/bootstrap.json:ro # раскомментируйте если используете файл и задайте BOOTSTRAP_CONFIG=/app/bootstrap.json
|
||||
command: >
|
||||
/bin/bash -lc '
|
||||
set -e;
|
||||
mkdir -p /app/keys;
|
||||
if [ ! -f "/app/keys/node_private_key" ]; then
|
||||
echo "[init] Generating ed25519 keys...";
|
||||
openssl genpkey -algorithm ed25519 -out /app/keys/node_private_key;
|
||||
openssl pkey -in /app/keys/node_private_key -pubout -out /app/keys/node_public_key;
|
||||
chmod 600 /app/keys/node_private_key;
|
||||
chmod 644 /app/keys/node_public_key;
|
||||
else
|
||||
echo "[init] Existing ed25519 keys detected, skipping generation.";
|
||||
fi;
|
||||
if [ -f "/app/keys/node_private_key" ] && [ ! -s "/app/keys/node_public_key.hex" ]; then
|
||||
openssl pkey -in /app/keys/node_private_key -pubout -outform DER | tail -c 32 | xxd -p -c 32 > /app/keys/node_public_key.hex || true;
|
||||
fi;
|
||||
exec uvicorn app.fastapi_main:app --host 0.0.0.0 --port 8000
|
||||
'
|
||||
depends_on:
|
||||
postgres:
|
||||
condition: service_healthy
|
||||
redis:
|
||||
condition: service_healthy
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "curl -fsS http://localhost:8000/health || exit 1"]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
start_period: 20s
|
||||
networks:
|
||||
- my-network
|
||||
|
||||
postgres:
|
||||
image: postgres:15-alpine
|
||||
container_name: my-network-postgres
|
||||
restart: unless-stopped
|
||||
env_file:
|
||||
- ../.env
|
||||
environment:
|
||||
- POSTGRES_DB=${POSTGRES_DB}
|
||||
- POSTGRES_USER=${POSTGRES_USER}
|
||||
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD}
|
||||
volumes:
|
||||
- postgres_data:/var/lib/postgresql/data
|
||||
# - ./uploader-bot/init_db.sql:/docker-entrypoint-initdb.d/001_init.sql:ro
|
||||
- ./uploader-bot/deployment/scripts/init-db-production.sql:/docker-entrypoint-initdb.d/002_init_prod.sql:ro
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-myuser} -d ${POSTGRES_DB:-mynetwork} || exit 1"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 10
|
||||
start_period: 20s
|
||||
networks:
|
||||
- my-network
|
||||
|
||||
redis:
|
||||
image: redis:7-alpine
|
||||
container_name: my-network-redis
|
||||
restart: unless-stopped
|
||||
command: ["redis-server", "--appendonly", "yes"]
|
||||
volumes:
|
||||
- redis_data:/data
|
||||
healthcheck:
|
||||
test: ["CMD", "redis-cli", "ping"]
|
||||
interval: 10s
|
||||
timeout: 3s
|
||||
retries: 10
|
||||
start_period: 10s
|
||||
networks:
|
||||
- my-network
|
||||
|
||||
volumes:
|
||||
postgres_data: {}
|
||||
redis_data: {}
|
||||
|
||||
networks:
|
||||
my-network: {}
|
||||
@@ -0,0 +1,82 @@
|
||||
# Base image
|
||||
FROM python:3.11-slim AS base
|
||||
|
||||
ENV PYTHONDONTWRITEBYTECODE=1 \
|
||||
PYTHONUNBUFFERED=1 \
|
||||
PIP_DISABLE_PIP_VERSION_CHECK=on \
|
||||
PIP_NO_CACHE_DIR=on
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# System deps (build tools + libpq for Postgres)
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends \
|
||||
build-essential gcc g++ curl netcat-traditional libpq-dev git \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Build context is uploader-bot/, so use paths relative to it
|
||||
# Copy dependency manifest if exists; otherwise generate minimal requirements
|
||||
COPY ./requirements.txt /app/requirements.txt
|
||||
RUN if [ ! -s /app/requirements.txt ]; then \
|
||||
echo "fastapi==0.104.1" >> /app/requirements.txt && \
|
||||
echo "uvicorn[standard]==0.24.0" >> /app/requirements.txt && \
|
||||
echo "pydantic==2.4.2" >> /app/requirements.txt && \
|
||||
echo "pydantic-settings==2.0.3" >> /app/requirements.txt && \
|
||||
echo "SQLAlchemy==2.0.23" >> /app/requirements.txt && \
|
||||
echo "alembic==1.12.1" >> /app/requirements.txt && \
|
||||
echo "asyncpg==0.29.0" >> /app/requirements.txt && \
|
||||
echo "redis==5.0.1" >> /app/requirements.txt && \
|
||||
echo "aiofiles==23.2.1" >> /app/requirements.txt && \
|
||||
echo "python-jose[cryptography]==3.3.0" >> /app/requirements.txt && \
|
||||
echo "python-multipart==0.0.6" >> /app/requirements.txt && \
|
||||
echo "httpx==0.25.2" >> /app/requirements.txt && \
|
||||
echo "websockets==12.0" >> /app/requirements.txt && \
|
||||
echo "docker==6.1.3" >> /app/requirements.txt && \
|
||||
echo "structlog==23.2.0" >> /app/requirements.txt && \
|
||||
echo "ed25519==1.5" >> /app/requirements.txt ; \
|
||||
fi
|
||||
|
||||
# Install python deps
|
||||
RUN pip install --upgrade pip setuptools wheel \
|
||||
&& pip install -r /app/requirements.txt
|
||||
|
||||
# Copy application code (relative to uploader-bot/)
|
||||
COPY ./app /app/app
|
||||
COPY ./alembic /app/alembic
|
||||
COPY ./alembic.ini /app/alembic.ini
|
||||
|
||||
# Optional files: bootstrap and keys if they exist (do not fail build)
|
||||
# Use a shell step to copy conditionally
|
||||
RUN mkdir -p /app/keys && \
|
||||
if [ -f "/app/bootstrap.json" ]; then :; \
|
||||
elif [ -f "/workspace/bootstrap.json" ]; then cp /workspace/bootstrap.json /app/bootstrap.json || true; \
|
||||
elif [ -f "/src/bootstrap.json" ]; then cp /src/bootstrap.json /app/bootstrap.json || true; \
|
||||
fi
|
||||
|
||||
# Runtime dirs and user
|
||||
RUN mkdir -p /app/storage /app/logs \
|
||||
&& adduser --disabled-password --gecos "" appuser \
|
||||
&& chown -R appuser:appuser /app
|
||||
USER appuser
|
||||
|
||||
# Expose API port
|
||||
EXPOSE 8000
|
||||
|
||||
# Healthcheck script to avoid adding curl dependency
|
||||
RUN printf '%s\n' \
|
||||
"#!/usr/bin/env python3" \
|
||||
"import sys,urllib.request" \
|
||||
"try:" \
|
||||
" with urllib.request.urlopen('http://127.0.0.1:8000/health',timeout=2) as r:" \
|
||||
" sys.exit(0 if r.getcode()==200 else 1)" \
|
||||
"except Exception:" \
|
||||
" sys.exit(1)" > /app/healthcheck.py && chmod +x /app/healthcheck.py
|
||||
|
||||
# Environment defaults (overridable)
|
||||
ENV HOST=0.0.0.0 \
|
||||
PORT=8000 \
|
||||
UVICORN_HOST=0.0.0.0 \
|
||||
UVICORN_PORT=8000
|
||||
|
||||
# Start command
|
||||
CMD ["uvicorn", "app.fastapi_main:app", "--host", "0.0.0.0", "--port", "8000"]
|
||||
Reference in new issue
Block a user