mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-04 10:13:06 +00:00
182 lines
7.0 KiB
YAML
182 lines
7.0 KiB
YAML
name: docsgpt-oss
|
|
services:
|
|
frontend:
|
|
build: ../frontend
|
|
volumes:
|
|
- ../frontend/src:/app/src
|
|
environment:
|
|
- VITE_API_HOST=http://localhost:7091
|
|
- VITE_API_STREAMING=$VITE_API_STREAMING
|
|
- VITE_GOOGLE_CLIENT_ID=$VITE_GOOGLE_CLIENT_ID
|
|
ports:
|
|
- "5173:5173"
|
|
depends_on:
|
|
- backend
|
|
|
|
backend:
|
|
user: root
|
|
build: ../application
|
|
env_file:
|
|
- ../.env
|
|
environment:
|
|
# Override URLs to use docker service names
|
|
- CELERY_BROKER_URL=redis://redis:6379/0
|
|
- CELERY_RESULT_BACKEND=redis://redis:6379/1
|
|
- CACHE_REDIS_URL=redis://redis:6379/2
|
|
- POSTGRES_URI=postgresql://docsgpt:docsgpt@postgres:5432/docsgpt
|
|
# Code-execution runner reached over HTTP + WebSocket (no docker socket).
|
|
- SANDBOX_GATEWAY_URL=http://docsgpt-sandbox:8888
|
|
# Select the runner's env-scrubbing kernelspec (distinct name; never
|
|
# shadowed by the stock "python3" spec). Must match the kernel the
|
|
# docsgpt-sandbox image installs.
|
|
- SANDBOX_KERNEL_NAME=docsgpt-python
|
|
ports:
|
|
- "7091:7091"
|
|
networks:
|
|
# `default` reaches the internet (LLM APIs) + frontend/host; `data-net`
|
|
# reaches redis/postgres; `sandbox-net` reaches the code-exec runner over an
|
|
# internal-only net (so the runner needs no shared internet bridge to be
|
|
# reachable, and the egress overlay can cut its internet without severing
|
|
# this control path).
|
|
- default
|
|
- data-net
|
|
- sandbox-net
|
|
volumes:
|
|
- ../application/indexes:/app/indexes
|
|
- ../application/inputs:/app/inputs
|
|
- ../application/vectors:/app/vectors
|
|
depends_on:
|
|
redis:
|
|
condition: service_started
|
|
postgres:
|
|
condition: service_healthy
|
|
|
|
worker:
|
|
user: root
|
|
build: ../application
|
|
# Consumes the default queue AND the dedicated `parsing` queue (read_document /
|
|
# parse_document). Without `parsing` here the read_document await never resolves.
|
|
# For heavy/OCR parsing run a separate worker with `-Q parsing` (see
|
|
# deployment/sandbox/README.md).
|
|
command: celery -A application.app.celery worker -l INFO -B -Q docsgpt,parsing
|
|
networks:
|
|
# See backend: control-plane access to the code-exec runner over sandbox-net
|
|
# (workflow code nodes run in the worker).
|
|
- default
|
|
- data-net
|
|
- sandbox-net
|
|
env_file:
|
|
- ../.env
|
|
environment:
|
|
# Override URLs to use docker service names
|
|
- CELERY_BROKER_URL=redis://redis:6379/0
|
|
- CELERY_RESULT_BACKEND=redis://redis:6379/1
|
|
- API_URL=http://backend:7091
|
|
- CACHE_REDIS_URL=redis://redis:6379/2
|
|
- POSTGRES_URI=postgresql://docsgpt:docsgpt@postgres:5432/docsgpt
|
|
- SANDBOX_GATEWAY_URL=http://docsgpt-sandbox:8888
|
|
# Env-scrubbing kernelspec selected by name (see backend service).
|
|
- SANDBOX_KERNEL_NAME=docsgpt-python
|
|
volumes:
|
|
- ../application/indexes:/app/indexes
|
|
- ../application/inputs:/app/inputs
|
|
- ../application/vectors:/app/vectors
|
|
depends_on:
|
|
redis:
|
|
condition: service_started
|
|
postgres:
|
|
condition: service_healthy
|
|
|
|
# Opt-in code-execution runner (Jupyter Kernel Gateway). Started ONLY with
|
|
# `docker compose --profile sandbox up`: the `code_executor` tool is off by
|
|
# default (removed from DEFAULT_CHAT_TOOLS) and must be enabled per-agent in
|
|
# the agent tool picker, so a plain `up` does not start this service.
|
|
# Sessions are in-process kernels, never child containers; the Docker socket
|
|
# is NOT mounted. On an internal-only network — no host port is published, so
|
|
# the runner is reachable only from backend/worker, not from the
|
|
# host/internet. Egress/SSRF blocks, the gVisor `runsc` runtime, and seccomp
|
|
# profile come in the hardening slice.
|
|
#
|
|
# SINGLE TRUST DOMAIN: all sessions share this one container/uid and are
|
|
# isolated by working directory only (per-session cwd) — not by a kernel/OS
|
|
# boundary. The custom kernelspec scrubs secrets from the kernel env, but
|
|
# sibling workspaces are readable under the shared uid and kernels share one
|
|
# address space. Do NOT add `env_file: ../.env` here (the runner needs no app
|
|
# secrets). For cross-tenant / untrusted multi-tenant workloads use a
|
|
# per-session VM via SANDBOX_BACKEND=daytona instead.
|
|
docsgpt-sandbox:
|
|
build: ./sandbox
|
|
profiles: ["sandbox"]
|
|
mem_limit: ${SANDBOX_MEMORY:-1g}
|
|
cpus: ${SANDBOX_CPUS:-1.0}
|
|
pids_limit: 256
|
|
read_only: true
|
|
environment:
|
|
# Keep Jupyter's runtime/connection files on the writable tmpfs.
|
|
- JUPYTER_RUNTIME_DIR=/tmp/jupyter-runtime
|
|
- JUPYTER_DATA_DIR=/tmp/jupyter-data
|
|
tmpfs:
|
|
# Per-session workspaces (/tmp/docsgpt-sandbox/<session_id>) and Jupyter
|
|
# runtime files live on tmpfs; the root FS is read-only everywhere else.
|
|
- /tmp
|
|
networks:
|
|
# Reachable by backend/worker over the internal sandbox-net; internet
|
|
# egress (runtime pip install, etc.) via the dedicated sandbox-egress net.
|
|
# Deliberately NOT on `default`: the egress overlay cuts internet by
|
|
# flipping sandbox-egress to internal, without severing the control path.
|
|
- sandbox-net
|
|
- sandbox-egress
|
|
|
|
redis:
|
|
image: redis:6-alpine
|
|
# Data plane only: NOT reachable from the code-exec sandbox (which has no
|
|
# auth on this broker, so a reachable Redis = Celery task injection -> RCE).
|
|
networks:
|
|
- data-net
|
|
ports:
|
|
# Loopback only: the published port must NOT be reachable from the sandbox
|
|
# via the host/bridge gateway. Host-local dev tools still use localhost.
|
|
- 127.0.0.1:6379:6379
|
|
|
|
postgres:
|
|
image: postgres:16-alpine
|
|
# Data plane only (see redis): kept off the sandbox's networks.
|
|
networks:
|
|
- data-net
|
|
environment:
|
|
- POSTGRES_USER=docsgpt
|
|
- POSTGRES_PASSWORD=docsgpt
|
|
- POSTGRES_DB=docsgpt
|
|
ports:
|
|
# Loopback only (see redis): not reachable from the sandbox via the gateway.
|
|
- "127.0.0.1:5432:5432"
|
|
volumes:
|
|
- postgres_data:/var/lib/postgresql/data
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U docsgpt -d docsgpt"]
|
|
interval: 5s
|
|
timeout: 5s
|
|
retries: 10
|
|
|
|
networks:
|
|
# Control plane between backend/worker and the code-exec runner. internal:true
|
|
# => no internet route on this net; the runner egresses via sandbox-egress.
|
|
sandbox-net:
|
|
internal: true
|
|
# The runner's outbound internet route (runtime pip install, etc.). Kept
|
|
# internet-facing so the base stack works out of the box;
|
|
# deployment/optional/docker-compose.optional.sandbox-egress.yaml flips it to
|
|
# internal:true and forces egress through a deny-private proxy for full SSRF
|
|
# containment (blocking RFC1918 / link-local / cloud-metadata).
|
|
sandbox-egress: {}
|
|
# Internal-only data plane. redis (broker/cache) and postgres live here with
|
|
# backend/worker, but the code-exec sandbox is NOT attached, so arbitrary
|
|
# sandboxed code cannot reach the unauthenticated broker (Celery task
|
|
# injection -> worker RCE) or the database.
|
|
data-net:
|
|
internal: true
|
|
|
|
volumes:
|
|
postgres_data:
|
|
|