fv-ml1: finish the renumber the cutover missed -- 16 dead dashboard links
Every fv-ml1 link on the Homepage dashboard was broken. Measured against the
live dashboard API before the fix: 16 entries pointing at the dead 10.250.50.54
and zero at the live 10.251.50.54, covering gen, M.O.G.-SEC, Scriberr, Embed,
Rerank, Reward, Coder, Dockge and six dormant seats.
The miss was structural, not careless. fv-ml1-rename-sweep.sh works from an
allowlist assembled from files that mention the HOST, and a homepage.href label
mentions only an IP -- so every stack whose sole stale reference was a label
fell outside it. The allowlist now covers those 24 files, and records how to
derive the list next time (grep the old address, subtract history) rather than
enumerating from memory.
History is still untouched, and the exclusions are now written down with the
reason each one keeps the old address: recorded benchmark results, whose
base_url is part of a measurement's provenance; the one LiteLLM comment
preserving a retired hand-test endpoint; and the cutover runbooks, where the old
address is the subject matter.
Two bugs found while applying it, both fixed here:
- deploy-stack.sh rejected any stack name containing a dot, so qwen3.5-122b,
qwopus3.5-122b and mistral-medium-3.5 could not be deployed by the script at
all. The check exists to stop path traversal, which means rejecting ".." and
"/" -- not every dot. Traversal is now rejected explicitly and tested.
- stacks/scriberr/.env.example allowed CORS only from the dead IP and from
scriberr.ana.internal, which no longer resolves; the box is at the fv site
and DNS already carries scriberr.fv.internal. The live .env had both stale
origins, i.e. an allowlist with nothing reachable in it.
Host side, applied separately: canonical pushed for the 16 stacks whose only
difference from the host was this renumber, and an in-place address-only fix for
the nine whose host copy has genuinely drifted or has no canonical copy, so that
drift survives for a deliberate reconciliation instead of being clobbered. Every
compose.yaml on fv-ml1 now reads 10.251.50.54. The labels themselves only take
effect at container creation, so the running containers still need recreating.
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
# Scriberr — copy to .env on the host at /opt/docker/compose/scriberr/.env
|
||||
# Real .env is gitignored and lives only on ana-ml2.
|
||||
# Real .env is gitignored and lives only on fv-ml1.
|
||||
|
||||
# ── Image ────────────────────────────────────────────────────────────────
|
||||
# Built locally from Dockerfile.cuda.12.9 — see the compose header for why
|
||||
@@ -11,7 +11,7 @@ SCRIBERR_PORT=8080
|
||||
SCRIBERR_BIND=0.0.0.0
|
||||
# CORS. Must list every origin the UI is actually reached from, or the
|
||||
# browser blocks the API calls. Comma-separated, no spaces, no trailing /.
|
||||
SCRIBERR_ALLOWED_ORIGINS=http://10.250.50.54:8080,http://scriberr.ana.internal:8080
|
||||
SCRIBERR_ALLOWED_ORIGINS=http://10.251.50.54:8080,http://scriberr.fv.internal:8080
|
||||
|
||||
# ── GPU ──────────────────────────────────────────────────────────────────
|
||||
# GPU0 is fully committed to the `gen` seat; GPU1 is the one with headroom.
|
||||
|
||||
@@ -1,17 +1,17 @@
|
||||
# scriberr — self-hosted transcription + diarization (ana-ml2, GPU1)
|
||||
# scriberr — self-hosted transcription + diarization (fv-ml1, GPU1)
|
||||
|
||||
Web UI for transcribing audio/video locally. WhisperX (Whisper + pyannote
|
||||
speaker diarization) with NVIDIA Parakeet/Canary also selectable; SQLite for
|
||||
state; optional summarisation and transcript chat against any OpenAI-compatible
|
||||
endpoint.
|
||||
|
||||
- **Host:** `ana-ml2` (10.250.50.54) — GPU1
|
||||
- **URL:** http://10.250.50.54:8080
|
||||
- **Host:** `fv-ml1` (10.251.50.54) — GPU1
|
||||
- **URL:** http://10.251.50.54:8080
|
||||
- **Upstream:** https://github.com/rishikanthc/Scriberr
|
||||
|
||||
## The image is built locally, and that is not incidental
|
||||
|
||||
ana-ml2's RTX PRO 6000 Blackwell cards are **sm_120**. Upstream's published
|
||||
fv-ml1's RTX PRO 6000 Blackwell cards are **sm_120**. Upstream's published
|
||||
images do not cover that:
|
||||
|
||||
| image | built for | usable here |
|
||||
@@ -28,7 +28,7 @@ image** — it will fail on these cards or quietly fall back to CPU.
|
||||
### Rebuilding
|
||||
|
||||
```bash
|
||||
ssh ana-ml2
|
||||
ssh fv-ml1
|
||||
cd /tank/scriberr/src/Scriberr
|
||||
git pull
|
||||
docker build -f Dockerfile.cuda.12.9 -t scriberr:local-blackwell .
|
||||
@@ -41,7 +41,7 @@ Source checkout lives on `/tank`, not the root pool — see storage below.
|
||||
|
||||
```bash
|
||||
# from this workstation
|
||||
scripts/deploy-stack.sh ana-ml2 scriberr
|
||||
scripts/deploy-stack.sh fv-ml1 scriberr
|
||||
```
|
||||
|
||||
Then on the host, the usual:
|
||||
@@ -54,7 +54,7 @@ docker compose up -d scriberr # target the service, not the whole stack
|
||||
|
||||
## Storage — deliberately on /tank
|
||||
|
||||
`/var/lib/docker` on ana-ml2 sits on `zroot` at ~87% used. Whisper, pyannote
|
||||
`/var/lib/docker` on fv-ml1 sits on `zroot` at ~87% used. Whisper, pyannote
|
||||
and NeMo weights are multi-GB and land in the `whisperx-env` volume, so both
|
||||
mounts are bind-mounted onto `/tank` (4+ TB) instead of named volumes:
|
||||
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
# point it at the LiteLLM gateway rather than a paid API (see README).
|
||||
#
|
||||
# ── IMAGE: BUILT LOCALLY, ON PURPOSE ──────────────────────────────────────
|
||||
# ana-ml2's RTX PRO 6000 Blackwell cards are **sm_120**. Upstream publishes
|
||||
# fv-ml1's RTX PRO 6000 Blackwell cards are **sm_120**. Upstream publishes
|
||||
# `scriberr-cuda` (built for sm_61…sm_89 — no sm_120 kernels) and documents a
|
||||
# `scriberr-cuda-blackwell` image that **has never actually been published**
|
||||
# (GHCR returns no tags for it, checked 2026-08-23). The sm_120 path upstream
|
||||
@@ -15,7 +15,7 @@
|
||||
# Do NOT "simplify" this to the published `scriberr-cuda` image — it will
|
||||
# fail on these cards or silently fall back to CPU.
|
||||
# Rebuild: see README "Rebuilding" — checkout lives at
|
||||
# /tank/scriberr/src/Scriberr on ana-ml2.
|
||||
# /tank/scriberr/src/Scriberr on fv-ml1.
|
||||
#
|
||||
# ── GPU PINNING ───────────────────────────────────────────────────────────
|
||||
# Pinned to **GPU1** via explicit device_ids, per the house convention and
|
||||
@@ -34,7 +34,7 @@ services:
|
||||
ports:
|
||||
- "${SCRIBERR_BIND:-0.0.0.0}:${SCRIBERR_PORT}:8080"
|
||||
volumes:
|
||||
# Bind mounts rather than named volumes: /var/lib/docker on ana-ml2
|
||||
# Bind mounts rather than named volumes: /var/lib/docker on fv-ml1
|
||||
# lives on zroot with limited headroom, while /tank has terabytes.
|
||||
# Model weights (Whisper, pyannote, NeMo) land in whisperx-env and are
|
||||
# multi-GB — they must not go anywhere near the root pool.
|
||||
@@ -102,8 +102,8 @@ services:
|
||||
- homepage.group=AI - Studios
|
||||
- homepage.name=Scriberr
|
||||
- homepage.icon=mdi-microphone-message
|
||||
- homepage.description=Audio/video transcription + diarization (ana-ml2, GPU1)
|
||||
- homepage.href=http://10.250.50.54:${SCRIBERR_PORT}
|
||||
- homepage.description=Audio/video transcription + diarization (fv-ml1, GPU1)
|
||||
- homepage.href=http://10.251.50.54:${SCRIBERR_PORT}
|
||||
|
||||
networks:
|
||||
tnet:
|
||||
|
||||
Reference in New Issue
Block a user