feat(albok-service): deploy the fleet knowledgebase service on nh3-docker

albok-service 0.1.0 (vh/albok 0b37431), image pfi/albok-service pinned by
digest, published on host port 8392 because 8390 is the post office.
Host prep playbook creates the fixed ids (albok 1500, albok-read 1510,
albok-personal 1511) and the local store/private roots; the container
gets a mounted /etc/group and group_add so the service can resolve and
chgrp its wing dirs. The config carries a LiteLLM key scoped to
qwen3-embedding and lives outside the deploy-synced conf dir. DNS name
albok.nh3.internal.
This commit is contained in:
vh
2026-10-02 17:56:34 -07:00
parent 9c233ca255
commit d3958655c1
7 changed files with 248 additions and 0 deletions
+48
View File
@@ -0,0 +1,48 @@
# albok-service — the fleet knowledgebase service (vh/albok, packages/albok-service). The only
# writer of the buildings-and-wings store. Requested by albok-dev 2026-10-02 (operator-approved).
#
# Deploy: scripts/elway infra-ops@10.100.50.40 --playbook playbooks/albok-service-host.yaml (host prep, config)
# scripts/deploy-stack.sh nh3-docker albok-service (this file + conf/)
# Image: built from a clean `git archive` of vh/albok, pushed to the pfi org (see README.md).
#
# ⚠ Host port 8392, NOT 8390: 8390 on nh3-docker is the althing post office.
# ⚠ Exactly ONE instance per private root: a second one exits 75 on the lease. Never scale this.
# ⚠ Nothing else may mount /srv/albok/store read-write. Viewers mount it :ro with group_add by gid
# (1510 albok-read, 1511 albok-personal) and need GIT_OPTIONAL_LOCKS=0 + a safe.directory entry.
services:
albok-service:
image: gitea.phasefinal.com/pfi/albok-service:0.1.0@sha256:9ae2c94e39917d690aef2361e47abceff863f25338fd0ea2848b651bcb145ab6
container_name: albok-service
restart: unless-stopped
ports:
- "8392:8390"
# Membership the service needs to chgrp wing dirs to the read groups (it runs as uid 1500, not root).
group_add:
- "1510"
- "1511"
volumes:
- /srv/albok/store:/srv/albok/store
- /srv/albok/private:/srv/albok/private
- /srv/albok/etc/albok.yaml:/etc/albok/albok.yaml:ro
# the read groups must RESOLVE BY NAME inside the container (layout.py uses grp.getgrnam)
- /opt/docker/conf/albok-service/group:/etc/group:ro
mem_limit: 4g
healthcheck:
test: ["CMD", "python", "-c", "import urllib.request,sys; sys.exit(0 if urllib.request.urlopen('http://127.0.0.1:8390/health', timeout=5).status == 200 else 1)"]
interval: 30s
timeout: 10s
retries: 3
start_period: 60s
networks:
- tnet
labels:
- homepage.group=Agents (no UI)
- homepage.name=Albok
- homepage.icon=mdi-book-search
- homepage.description=Fleet knowledgebase service (albok-service) on nh3-docker
- homepage.href=http://10.100.50.40:8392/health
networks:
tnet:
name: traefik-net
external: true