feat(arbo): add irv-ml1 co-located engine stack (ADR-0001)
New stack mirroring the canonical convention for the Arbo (catalog) engine, co-located beside comfyui on irv-ml1 per ADR-0001 D1/D3: - engine<->ComfyUI over traefik-net container DNS (http://comfyui:8188), SSH dependency eliminated; file ops bind the shared basedir input/output - named local-disk volumes for the gallery SQLite (arbo_db, restic-backed) and hero images (arbo_heroes); catalog as a ro git-checkout mount (D2) - ENGINE_TOKEN + GRANITE_KEY via on-host .env; GRANITE via the LiteLLM gateway - Q5 catalog-pull: manual day-1, ytvc-style webhook follow-on Image build, /healthz, catalog in-container path, and non-root UID are comfy-dev's to confirm (CONFIRM items in README).
This commit is contained in:
@@ -0,0 +1,86 @@
|
||||
# Arbo (catalog) engine — FastAPI sidecar that drives ComfyUI from a
|
||||
# versioned workflow catalog. Serves the SPA + /workflows + /run.
|
||||
#
|
||||
# Co-located on irv-ml1 BESIDE the comfyui stack (ADR-0001 / D3). This
|
||||
# collapses the engine<->ComfyUI link to the shared traefik-net + the
|
||||
# local filesystem and ELIMINATES the old SSH/WireGuard dependency:
|
||||
# - generation : COMFYUI_URL=http://comfyui:8188 (container DNS on
|
||||
# traefik-net — the "localhost-equivalent"; no scp, no WG hop)
|
||||
# - file ops : ARBO_COMFY_INPUT_DIR / ARBO_COMFY_OUTPUT_DIR bind the
|
||||
# SAME host dirs comfyui mounts (/worktank/comfyui/basedir/{input,
|
||||
# output}), so to-input / upload-input / artifact-wipe are local fs
|
||||
# ops. ARBO_COMFY_SSH_HOST is left UNSET on purpose → the engine's
|
||||
# local-cp/shutil path (comfy-dev's D3 follow-on) takes over.
|
||||
#
|
||||
# State that MUST survive restarts (named volumes, local disk — NOT NFS,
|
||||
# per the DB-off-NFS rule; SQLite-on-NFS locking is a known foot-gun):
|
||||
# - arbo_db -> the gallery/history SQLite (ARBO_DB)
|
||||
# - arbo_heroes -> runtime hero images (ARBO_HEROES_DIR)
|
||||
# The catalog is a comfy-dev git checkout bind-mounted read-only (D2):
|
||||
# a workflow update = `git pull` on the host + restart, no image rebuild.
|
||||
#
|
||||
# IMAGE + CATALOG TARGET are owned by comfy-dev (they build the image +
|
||||
# add /healthz). Two items marked CONFIRM below need their image layout.
|
||||
# All tunables live in .env — edit that, not this file.
|
||||
|
||||
services:
|
||||
engine:
|
||||
image: ${ARBO_IMAGE} # CONFIRM: gitea.phasefinal.com/vh/arbo:<tag>, comfy-dev builds
|
||||
container_name: arbo
|
||||
restart: unless-stopped
|
||||
# Run as the host owner of /worktank (1000:1000 = lkraven) so writes
|
||||
# into comfyui's basedir/input + the named volumes land with the
|
||||
# right ownership (matches the comfyui stack's WANTED_UID posture).
|
||||
user: "${ARBO_UID:-1000}:${ARBO_GID:-1000}"
|
||||
ports:
|
||||
- "${ARBO_BIND:-0.0.0.0}:${ARBO_PORT:-8200}:8200"
|
||||
env_file: .env
|
||||
environment:
|
||||
- ARBO_HOST=0.0.0.0
|
||||
- ARBO_PORT=8200
|
||||
- ARBO_DB=/data/gallery.sqlite
|
||||
- ARBO_HEROES_DIR=/heroes
|
||||
# engine<->ComfyUI over the shared network (no SSH):
|
||||
- COMFYUI_URL=http://comfyui:8188
|
||||
- ARBO_COMFY_INPUT_DIR=/comfy/input
|
||||
- ARBO_COMFY_OUTPUT_DIR=/comfy/output
|
||||
# ARBO_COMFY_SSH_HOST intentionally UNSET -> local-cp path (D3 follow-on)
|
||||
# LiteLLM gateway for the granite hero/metadata calls:
|
||||
- GRANITE_ENDPOINT=http://10.250.50.70:4000/v1
|
||||
- GRANITE_KEY=${GRANITE_KEY} # arbo-prompt-enhance scoped vkey (.env)
|
||||
- ENGINE_TOKEN=${ENGINE_TOKEN} # real bearer — closes today's open auth (.env)
|
||||
volumes:
|
||||
- arbo_db:/data
|
||||
- arbo_heroes:/heroes
|
||||
# comfyui's input/output, shared on the host (rw: upload-input writes
|
||||
# input, artifact-wipe deletes output):
|
||||
- /worktank/comfyui/basedir/input:/comfy/input
|
||||
- /worktank/comfyui/basedir/output:/comfy/output
|
||||
# catalog checkout (comfy-dev clone on the host), read-only:
|
||||
- ${ARBO_CATALOG_DIR:-/worktank/arbo/repo}/catalog:/app/catalog:ro # CONFIRM in-container path vs image layout
|
||||
- ${ARBO_CATALOG_DIR:-/worktank/arbo/repo}/graphs:/app/graphs:ro # CONFIRM in-container path vs image layout
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "curl -fsS http://localhost:8200/healthz >/dev/null || exit 1"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
start_period: 30s
|
||||
networks:
|
||||
- tnet
|
||||
labels:
|
||||
- homepage.group=AI Systems
|
||||
- homepage.name=Arbo
|
||||
- homepage.icon=mdi-image-multiple-outline
|
||||
- homepage.description=Catalog-driven ComfyUI engine (irv-ml1)
|
||||
- homepage.href=http://10.100.79.3:${ARBO_PORT:-8200}
|
||||
|
||||
volumes:
|
||||
arbo_db:
|
||||
name: arbo_db
|
||||
arbo_heroes:
|
||||
name: arbo_heroes
|
||||
|
||||
networks:
|
||||
tnet:
|
||||
name: traefik-net
|
||||
external: true
|
||||
Reference in New Issue
Block a user