fix(scriberr): serve over HTTPS via the fleet TLS caddy so the browser recorder works
The in-browser recorder calls getUserMedia, which browsers refuse on http:// origins, so it sat at "Initializing recorder...". scriberr.nh3.phasefinal.com is now fronted by the fleet TLS caddy on nh3-dev (wildcard cert) and added to Scriberr's ALLOWED_ORIGINS; the Homepage link points at it. The plain http://10.251.50.54:8080 URL keeps working except for recording.
This commit is contained in:
@@ -160,6 +160,7 @@ _As of 2026-10-01 ~0446 PT._
|
|||||||
### Scriberr (fv-ml1 GPU 3)
|
### Scriberr (fv-ml1 GPU 3)
|
||||||
|
|
||||||
- **LIVE `scriberr:local-blackwell-a353078-dropout2`:** upstream a353078 plus patch 0001 (overlap slicer) and patch 0002 (gap retry, `PARAKEET_MODEL_PATH`), carried LOCALLY ONLY (Prime 2026-10-01: no upstream). v3 stays. `scripts/scriberr-rebuild` re-applies both. → `persistent-memory.d/2026-09-30-scriberr-slicer-gap-retry-gpu3.md`
|
- **LIVE `scriberr:local-blackwell-a353078-dropout2`:** upstream a353078 plus patch 0001 (overlap slicer) and patch 0002 (gap retry, `PARAKEET_MODEL_PATH`), carried LOCALLY ONLY (Prime 2026-10-01: no upstream). v3 stays. `scripts/scriberr-rebuild` re-applies both. → `persistent-memory.d/2026-09-30-scriberr-slicer-gap-retry-gpu3.md`
|
||||||
|
- **URL is https://scriberr.nh3.phasefinal.com since 2026-10-01** (fronted by the fleet TLS caddy on nh3-dev; Caddyfile backup `.bak-20261001-scriberr`). Prime's "can't initialize recorder" was the SecureContext rule: `getUserMedia` is refused on http://. The HTTPS name is in `ALLOWED_ORIGINS` (`playbooks/scriberr-https-origin.yaml`); http://10.251.50.54:8080 still works except for recording. ⚠ `/opt/docker/compose/scriberr` is lkraven-owned, so `deploy-stack.sh` as infra-ops FAILS there (Permission denied); upload single files with `elway --upload --sudo --owner lkraven:lkraven`.
|
||||||
|
|
||||||
### nh3-pve + nh3-ml1: post-visit, all live (2026-09-25/26)
|
### nh3-pve + nh3-ml1: post-visit, all live (2026-09-25/26)
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,39 @@
|
|||||||
|
# Let Scriberr accept its HTTPS name (2026-10-01). The fleet TLS caddy on nh3-dev now fronts
|
||||||
|
# https://scriberr.nh3.phasefinal.com -> fv-ml1:8080; Scriberr's server rejects requests whose
|
||||||
|
# Origin is not in ALLOWED_ORIGINS, so the name has to be added there, then the container
|
||||||
|
# recreated (env and labels apply only at creation). The http:// origins stay, so the old URL
|
||||||
|
# keeps working. SECURE_COOKIES stays false for the same reason.
|
||||||
|
# scripts/elway infra-ops@10.251.50.54 --playbook playbooks/scriberr-https-origin.yaml
|
||||||
|
vars:
|
||||||
|
dir: /opt/docker/compose/scriberr
|
||||||
|
origin: https://scriberr.nh3.phasefinal.com
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Back up .env once
|
||||||
|
sudo: true
|
||||||
|
shell: cp -p {{ dir }}/.env {{ dir }}/.env.bak-20261001-https
|
||||||
|
creates: "{{ dir }}/.env.bak-20261001-https"
|
||||||
|
|
||||||
|
- name: Append the HTTPS origin to SCRIBERR_ALLOWED_ORIGINS
|
||||||
|
sudo: true
|
||||||
|
shell: sed -i '/^SCRIBERR_ALLOWED_ORIGINS=/ s#$#,{{ origin }}#' {{ dir }}/.env
|
||||||
|
when: "! sudo -n grep -q '^SCRIBERR_ALLOWED_ORIGINS=.*{{ origin }}' {{ dir }}/.env"
|
||||||
|
|
||||||
|
- name: Dry-parse the stack
|
||||||
|
sudo: true
|
||||||
|
shell: cd {{ dir }} && docker compose config -q
|
||||||
|
changed_when: "false"
|
||||||
|
|
||||||
|
- name: Recreate the scriberr service (only if the running env lacks the origin)
|
||||||
|
sudo: true
|
||||||
|
shell: cd {{ dir }} && docker compose up -d scriberr
|
||||||
|
when: "! docker exec scriberr printenv ALLOWED_ORIGINS | grep -q '{{ origin }}'"
|
||||||
|
|
||||||
|
verify:
|
||||||
|
- name: Running container carries the HTTPS origin
|
||||||
|
shell: docker exec scriberr printenv ALLOWED_ORIGINS | grep -q '{{ origin }}'
|
||||||
|
changed_when: "false"
|
||||||
|
- name: .env kept its owner and mode
|
||||||
|
sudo: true
|
||||||
|
shell: test "$(stat -c '%U %a' {{ dir }}/.env)" = "lkraven 600"
|
||||||
|
changed_when: "false"
|
||||||
@@ -16,7 +16,7 @@ SCRIBERR_PORT=8080
|
|||||||
SCRIBERR_BIND=0.0.0.0
|
SCRIBERR_BIND=0.0.0.0
|
||||||
# CORS. Must list every origin the UI is actually reached from, or the
|
# CORS. Must list every origin the UI is actually reached from, or the
|
||||||
# browser blocks the API calls. Comma-separated, no spaces, no trailing /.
|
# browser blocks the API calls. Comma-separated, no spaces, no trailing /.
|
||||||
SCRIBERR_ALLOWED_ORIGINS=http://10.251.50.54:8080,http://scriberr.fv.internal:8080
|
SCRIBERR_ALLOWED_ORIGINS=http://10.251.50.54:8080,http://scriberr.fv.internal:8080,https://scriberr.nh3.phasefinal.com
|
||||||
|
|
||||||
# ── GPU ──────────────────────────────────────────────────────────────────
|
# ── GPU ──────────────────────────────────────────────────────────────────
|
||||||
# GPU 3 since 2026-09-30 (Prime): an on-demand tenant of the full-size-seat reserve; it steps aside
|
# GPU 3 since 2026-09-30 (Prime): an on-demand tenant of the full-size-seat reserve; it steps aside
|
||||||
|
|||||||
@@ -5,8 +5,14 @@ speaker diarization) with NVIDIA Parakeet/Canary also selectable; SQLite for
|
|||||||
state; optional summarisation and transcript chat against any OpenAI-compatible
|
state; optional summarisation and transcript chat against any OpenAI-compatible
|
||||||
endpoint.
|
endpoint.
|
||||||
|
|
||||||
- **Host:** `fv-ml1` (10.251.50.54) — GPU1
|
- **Host:** `fv-ml1` (10.251.50.54) — GPU 3
|
||||||
- **URL:** http://10.251.50.54:8080
|
- **URL:** **https://scriberr.nh3.phasefinal.com** (since 2026-10-01). The fleet TLS caddy on nh3-dev
|
||||||
|
(`~/.config/caddy-fleet/Caddyfile`, wildcard `*.nh3.phasefinal.com`) reverse-proxies it to
|
||||||
|
fv-ml1:8080. Use this name for **recording**: the browser recorder calls `getUserMedia`, which
|
||||||
|
browsers refuse on `http://` origins, and the page then sits at "Initializing recorder..."
|
||||||
|
(console: "Failed to initialize recorder"). The name must also be in `SCRIBERR_ALLOWED_ORIGINS`,
|
||||||
|
or Scriberr's CORS check rejects the app's own API calls (`playbooks/scriberr-https-origin.yaml`).
|
||||||
|
The plain http://10.251.50.54:8080 still works for everything except recording.
|
||||||
- **Upstream:** https://github.com/rishikanthc/Scriberr
|
- **Upstream:** https://github.com/rishikanthc/Scriberr
|
||||||
|
|
||||||
## The image is built locally, and that is not incidental
|
## The image is built locally, and that is not incidental
|
||||||
|
|||||||
@@ -125,7 +125,10 @@ services:
|
|||||||
- homepage.name=Scriberr
|
- homepage.name=Scriberr
|
||||||
- homepage.icon=mdi-microphone-message
|
- homepage.icon=mdi-microphone-message
|
||||||
- homepage.description=Audio/video transcription + diarization (fv-ml1, GPU3)
|
- homepage.description=Audio/video transcription + diarization (fv-ml1, GPU3)
|
||||||
- homepage.href=http://10.251.50.54:${SCRIBERR_PORT}
|
# HTTPS via the fleet TLS caddy on nh3-dev (wildcard *.nh3.phasefinal.com). The in-browser
|
||||||
|
# recorder needs a SecureContext: getUserMedia is refused on http:// (2026-10-01). The
|
||||||
|
# plain http://10.251.50.54:8080 URL still works for everything except recording.
|
||||||
|
- homepage.href=https://scriberr.nh3.phasefinal.com
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
tnet:
|
tnet:
|
||||||
|
|||||||
Reference in New Issue
Block a user