# albok-service — the fleet knowledgebase service (vh/albok, packages/albok-service). The only # writer of the buildings-and-wings store. Requested by albok-dev 2026-10-02 (operator-approved). # # Deploy: scripts/elway infra-ops@10.100.50.40 --playbook playbooks/albok-service-host.yaml (host prep, config) # scripts/deploy-stack.sh nh3-docker albok-service (this file + conf/) # Image: built from a clean `git archive` of vh/albok, pushed to the pfi org (see README.md). # # ⚠ Host port 8392, NOT 8390: 8390 on nh3-docker is the althing post office. # ⚠ Exactly ONE instance per private root: a second one exits 75 on the lease. Never scale this. # ⚠ Nothing else may mount /srv/albok/store read-write. Viewers mount it :ro with group_add by gid # (1510 albok-read, 1511 albok-personal) and need GIT_OPTIONAL_LOCKS=0 + a safe.directory entry. services: albok-service: image: gitea.phasefinal.com/pfi/albok-service:0.1.0@sha256:9ae2c94e39917d690aef2361e47abceff863f25338fd0ea2848b651bcb145ab6 container_name: albok-service restart: unless-stopped ports: - "8392:8390" # Membership the service needs to chgrp wing dirs to the read groups (it runs as uid 1500, not root). group_add: - "1510" - "1511" volumes: - /srv/albok/store:/srv/albok/store - /srv/albok/private:/srv/albok/private - /srv/albok/etc/albok.yaml:/etc/albok/albok.yaml:ro # the read groups must RESOLVE BY NAME inside the container (layout.py uses grp.getgrnam) - /opt/docker/conf/albok-service/group:/etc/group:ro mem_limit: 4g healthcheck: test: ["CMD", "python", "-c", "import urllib.request,sys; sys.exit(0 if urllib.request.urlopen('http://127.0.0.1:8390/health', timeout=5).status == 200 else 1)"] interval: 30s timeout: 10s retries: 3 start_period: 60s networks: - tnet labels: - homepage.group=Agents (no UI) - homepage.name=Albok - homepage.icon=mdi-book-search - homepage.description=Fleet knowledgebase service (albok-service) on nh3-docker - homepage.href=http://10.100.50.40:8392/health networks: tnet: name: traefik-net external: true