feat(albok-service): deploy the fleet knowledgebase service on nh3-docker

albok-service 0.1.0 (vh/albok 0b37431), image pfi/albok-service pinned by
digest, published on host port 8392 because 8390 is the post office.
Host prep playbook creates the fixed ids (albok 1500, albok-read 1510,
albok-personal 1511) and the local store/private roots; the container
gets a mounted /etc/group and group_add so the service can resolve and
chgrp its wing dirs. The config carries a LiteLLM key scoped to
qwen3-embedding and lives outside the deploy-synced conf dir. DNS name
albok.nh3.internal.
This commit is contained in:
vh
2026-10-02 17:56:34 -07:00
parent 9c233ca255
commit d3958655c1
7 changed files with 248 additions and 0 deletions
@@ -0,0 +1,45 @@
# albok-service configuration (template). The REAL file is /srv/albok/etc/albok.yaml on nh3-docker,
# rendered from this one with the embedder key filled in (vault `albok/litellm-key`) by
# playbooks/albok-service-host.yaml. It is not under /opt/docker/conf because it holds that key and
# deploy-stack would sync over it. Every path is absolute and used verbatim (nothing is expanded).
# Shape: packages/albok-service/albok.example.yaml in vh/albok @ 0b37431 (albok-service 0.1.0).
store_root: /srv/albok/store # host bind mount, local ext4, owned by uid 1500
private_root: /srv/albok/private # host bind mount, local ext4, owned by uid 1500; single-attach (lease)
git_identity:
name: Albok
email: albok@fleet.local
embedding: # fleet LiteLLM gateway (Anaheim); TEI behind it
provider: litellm-ana
type: openai_compat
base_url: http://10.250.50.70:4000/v1
model: qwen3-embedding
api_key: "__ALBOK_LITELLM_KEY__" # scoped key `albok-service`: qwen3-embedding only
reranker: null
ids_in_cap: 1000
search_defaults:
top_k: 20
inline_budget_chars: 8000
listen:
host: 0.0.0.0
port: 8390 # container port; published on the host as 8392 (8390 is the post office)
# First instance, per albok-dev's ask (2026-10-02): fleet/{memory,stash}, personal/notes.
# Restricted wings (agent-feedback, vault) come later with their own groups (gids 1512+).
buildings:
- id: fleet
default_group: albok-read # host gid 1510
wings:
- id: memory
probe_object_id: null
probe_query: null
- id: stash
near_duplicate_threshold: null
- id: personal
default_group: albok-personal # host gid 1511
wings:
- id: notes