asset-engine: drop traefik wiring, LAN-direct only

Internal tooling — accessed at http://10.250.50.70:8200, not through
Traefik. Removes the unused traefik labels (router rule, TLS, crowdsec
middleware, loadbalancer port) and the traefik-net network membership;
homepage.href now points at host:port for direct discovery, matching
task-board's pattern. Playbook verify drops the traefik-net membership
check.
This commit is contained in:
vh
2026-05-11 22:01:44 -07:00
parent 116ed15875
commit 44086248f6
4 changed files with 13 additions and 40 deletions
+5 -18
View File
@@ -13,9 +13,10 @@
# asset-engine:local .` before installing this compose and bringing
# it up. No registry.
#
# State persists under /opt/docker/conf/asset-engine/{db,outputs} on
# the host — separate bind-mounts so outputs/ can move to a bigger
# volume later without touching DB state.
# Internal tooling — accessed directly on host:port over the LAN, does
# NOT traverse Traefik. State persists under /opt/docker/conf/asset-engine/
# {db,outputs} on the host — separate bind-mounts so outputs/ can move
# to a bigger volume later without touching DB state.
#
# All tunables live in .env — edit that, not this file.
@@ -44,23 +45,9 @@ services:
timeout: 5s
retries: 3
start_period: 30s
networks:
- tnet
labels:
- traefik.enable=true
- traefik.http.routers.asset-engine.rule=Host(`asset-engine.phasefinal.com`)
- traefik.http.routers.asset-engine.entrypoints=websecure
- traefik.http.routers.asset-engine.tls=true
- traefik.http.routers.asset-engine.tls.certresolver=anaprod
- traefik.http.routers.asset-engine.middlewares=crowdsec@file
- traefik.http.services.asset-engine.loadbalancer.server.port=8000
- homepage.group=AI Systems
- homepage.name=Asset Engine
- homepage.icon=mdi-tools
- homepage.description=Control plane over the PFI inference fleet
- homepage.href=https://asset-engine.phasefinal.com
networks:
tnet:
name: traefik-net
external: true
- homepage.href=http://10.250.50.70:${ASSET_ENGINE_PORT}