From abcf4c316608d96f7b6d86654f0b8e5cfd9aaa76 Mon Sep 17 00:00:00 2001 From: Vuong Hoang Date: Thu, 1 Oct 2026 13:07:18 -0700 Subject: [PATCH] fix(scriberr): serve over HTTPS via the fleet TLS caddy so the browser recorder works The in-browser recorder calls getUserMedia, which browsers refuse on http:// origins, so it sat at "Initializing recorder...". scriberr.nh3.phasefinal.com is now fronted by the fleet TLS caddy on nh3-dev (wildcard cert) and added to Scriberr's ALLOWED_ORIGINS; the Homepage link points at it. The plain http://10.251.50.54:8080 URL keeps working except for recording. --- persistent-memory.md | 1 + playbooks/scriberr-https-origin.yaml | 39 ++++++++++++++++++++++++++++ stacks/scriberr/.env.example | 2 +- stacks/scriberr/README.md | 10 +++++-- stacks/scriberr/compose.yaml | 5 +++- 5 files changed, 53 insertions(+), 4 deletions(-) create mode 100644 playbooks/scriberr-https-origin.yaml diff --git a/persistent-memory.md b/persistent-memory.md index 7c52f44..fbf990e 100644 --- a/persistent-memory.md +++ b/persistent-memory.md @@ -160,6 +160,7 @@ _As of 2026-10-01 ~0446 PT._ ### Scriberr (fv-ml1 GPU 3) - **LIVE `scriberr:local-blackwell-a353078-dropout2`:** upstream a353078 plus patch 0001 (overlap slicer) and patch 0002 (gap retry, `PARAKEET_MODEL_PATH`), carried LOCALLY ONLY (Prime 2026-10-01: no upstream). v3 stays. `scripts/scriberr-rebuild` re-applies both. → `persistent-memory.d/2026-09-30-scriberr-slicer-gap-retry-gpu3.md` +- **URL is https://scriberr.nh3.phasefinal.com since 2026-10-01** (fronted by the fleet TLS caddy on nh3-dev; Caddyfile backup `.bak-20261001-scriberr`). Prime's "can't initialize recorder" was the SecureContext rule: `getUserMedia` is refused on http://. The HTTPS name is in `ALLOWED_ORIGINS` (`playbooks/scriberr-https-origin.yaml`); http://10.251.50.54:8080 still works except for recording. ⚠ `/opt/docker/compose/scriberr` is lkraven-owned, so `deploy-stack.sh` as infra-ops FAILS there (Permission denied); upload single files with `elway --upload --sudo --owner lkraven:lkraven`. ### nh3-pve + nh3-ml1: post-visit, all live (2026-09-25/26) diff --git a/playbooks/scriberr-https-origin.yaml b/playbooks/scriberr-https-origin.yaml new file mode 100644 index 0000000..99fb1de --- /dev/null +++ b/playbooks/scriberr-https-origin.yaml @@ -0,0 +1,39 @@ +# Let Scriberr accept its HTTPS name (2026-10-01). The fleet TLS caddy on nh3-dev now fronts +# https://scriberr.nh3.phasefinal.com -> fv-ml1:8080; Scriberr's server rejects requests whose +# Origin is not in ALLOWED_ORIGINS, so the name has to be added there, then the container +# recreated (env and labels apply only at creation). The http:// origins stay, so the old URL +# keeps working. SECURE_COOKIES stays false for the same reason. +# scripts/elway infra-ops@10.251.50.54 --playbook playbooks/scriberr-https-origin.yaml +vars: + dir: /opt/docker/compose/scriberr + origin: https://scriberr.nh3.phasefinal.com + +steps: + - name: Back up .env once + sudo: true + shell: cp -p {{ dir }}/.env {{ dir }}/.env.bak-20261001-https + creates: "{{ dir }}/.env.bak-20261001-https" + + - name: Append the HTTPS origin to SCRIBERR_ALLOWED_ORIGINS + sudo: true + shell: sed -i '/^SCRIBERR_ALLOWED_ORIGINS=/ s#$#,{{ origin }}#' {{ dir }}/.env + when: "! sudo -n grep -q '^SCRIBERR_ALLOWED_ORIGINS=.*{{ origin }}' {{ dir }}/.env" + + - name: Dry-parse the stack + sudo: true + shell: cd {{ dir }} && docker compose config -q + changed_when: "false" + + - name: Recreate the scriberr service (only if the running env lacks the origin) + sudo: true + shell: cd {{ dir }} && docker compose up -d scriberr + when: "! docker exec scriberr printenv ALLOWED_ORIGINS | grep -q '{{ origin }}'" + +verify: + - name: Running container carries the HTTPS origin + shell: docker exec scriberr printenv ALLOWED_ORIGINS | grep -q '{{ origin }}' + changed_when: "false" + - name: .env kept its owner and mode + sudo: true + shell: test "$(stat -c '%U %a' {{ dir }}/.env)" = "lkraven 600" + changed_when: "false" diff --git a/stacks/scriberr/.env.example b/stacks/scriberr/.env.example index d1e710a..94991b5 100644 --- a/stacks/scriberr/.env.example +++ b/stacks/scriberr/.env.example @@ -16,7 +16,7 @@ SCRIBERR_PORT=8080 SCRIBERR_BIND=0.0.0.0 # CORS. Must list every origin the UI is actually reached from, or the # browser blocks the API calls. Comma-separated, no spaces, no trailing /. -SCRIBERR_ALLOWED_ORIGINS=http://10.251.50.54:8080,http://scriberr.fv.internal:8080 +SCRIBERR_ALLOWED_ORIGINS=http://10.251.50.54:8080,http://scriberr.fv.internal:8080,https://scriberr.nh3.phasefinal.com # ── GPU ────────────────────────────────────────────────────────────────── # GPU 3 since 2026-09-30 (Prime): an on-demand tenant of the full-size-seat reserve; it steps aside diff --git a/stacks/scriberr/README.md b/stacks/scriberr/README.md index 242b708..88d0bbb 100644 --- a/stacks/scriberr/README.md +++ b/stacks/scriberr/README.md @@ -5,8 +5,14 @@ speaker diarization) with NVIDIA Parakeet/Canary also selectable; SQLite for state; optional summarisation and transcript chat against any OpenAI-compatible endpoint. -- **Host:** `fv-ml1` (10.251.50.54) — GPU1 -- **URL:** http://10.251.50.54:8080 +- **Host:** `fv-ml1` (10.251.50.54) — GPU 3 +- **URL:** **https://scriberr.nh3.phasefinal.com** (since 2026-10-01). The fleet TLS caddy on nh3-dev + (`~/.config/caddy-fleet/Caddyfile`, wildcard `*.nh3.phasefinal.com`) reverse-proxies it to + fv-ml1:8080. Use this name for **recording**: the browser recorder calls `getUserMedia`, which + browsers refuse on `http://` origins, and the page then sits at "Initializing recorder..." + (console: "Failed to initialize recorder"). The name must also be in `SCRIBERR_ALLOWED_ORIGINS`, + or Scriberr's CORS check rejects the app's own API calls (`playbooks/scriberr-https-origin.yaml`). + The plain http://10.251.50.54:8080 still works for everything except recording. - **Upstream:** https://github.com/rishikanthc/Scriberr ## The image is built locally, and that is not incidental diff --git a/stacks/scriberr/compose.yaml b/stacks/scriberr/compose.yaml index ca0723b..f7bd424 100644 --- a/stacks/scriberr/compose.yaml +++ b/stacks/scriberr/compose.yaml @@ -125,7 +125,10 @@ services: - homepage.name=Scriberr - homepage.icon=mdi-microphone-message - homepage.description=Audio/video transcription + diarization (fv-ml1, GPU3) - - homepage.href=http://10.251.50.54:${SCRIBERR_PORT} + # HTTPS via the fleet TLS caddy on nh3-dev (wildcard *.nh3.phasefinal.com). The in-browser + # recorder needs a SecureContext: getUserMedia is refused on http:// (2026-10-01). The + # plain http://10.251.50.54:8080 URL still works for everything except recording. + - homepage.href=https://scriberr.nh3.phasefinal.com networks: tnet: