mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-03 05:18:44 +00:00
Run each kernel under a scrubbed environment so untrusted code can never read the host's secrets. A custom 'docsgpt-python' kernelspec launches ipykernel through a wrapper that keeps only what the kernel needs (PATH, HOME, LANG, and the Jupyter runtime/data dirs), dropping API keys, tokens, the database URL, and the gateway token. The app selects this kernel by name via SANDBOX_KERNEL_NAME, so the distinct name is never shadowed by the stock python3 spec. Per-session workspaces are created mode 0700 (defense in depth under the shared uid). The README documents the runner as a single trust domain and points to the Daytona backend for per-tenant isolation.
162 lines
4.6 KiB
YAML
162 lines
4.6 KiB
YAML
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: docsgpt-api
|
|
spec:
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app: docsgpt-api
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: docsgpt-api
|
|
spec:
|
|
initContainers:
|
|
# Block pod start until Postgres accepts connections. The `postgres-init`
|
|
# Job is responsible for running alembic migrations; this container only
|
|
# waits for the server to be reachable.
|
|
- name: wait-for-postgres
|
|
image: postgres:16-alpine
|
|
command:
|
|
- sh
|
|
- -c
|
|
- |
|
|
until pg_isready -h postgres -p 5432 -U docsgpt -d docsgpt; do
|
|
echo "Waiting for postgres..."; sleep 2;
|
|
done
|
|
containers:
|
|
- name: docsgpt-api
|
|
image: arc53/docsgpt
|
|
ports:
|
|
- containerPort: 7091
|
|
resources:
|
|
limits:
|
|
memory: "4Gi"
|
|
cpu: "2"
|
|
requests:
|
|
memory: "2Gi"
|
|
cpu: "1"
|
|
envFrom:
|
|
- secretRef:
|
|
name: docsgpt-secrets
|
|
env:
|
|
- name: FLASK_APP
|
|
value: "application/app.py"
|
|
- name: DEPLOYMENT_TYPE
|
|
value: "cloud"
|
|
- name: POSTGRES_URI
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: docsgpt-secrets
|
|
key: POSTGRES_URI
|
|
# Disable in-app auto-bootstrap. The `postgres-init` Job under
|
|
# deployment/k8s/jobs/ owns schema creation and Alembic migrations,
|
|
# so application pods must not race with it on rollout.
|
|
- name: AUTO_MIGRATE
|
|
value: "false"
|
|
- name: AUTO_CREATE_DB
|
|
value: "false"
|
|
# Reach the always-on code-execution runner over HTTP + WebSocket.
|
|
- name: SANDBOX_GATEWAY_URL
|
|
value: "http://docsgpt-sandbox:8888"
|
|
# Select the runner's env-scrubbing kernelspec by its distinct name so
|
|
# it is never shadowed by the stock "python3" spec. MUST be set here:
|
|
# the runner only ships the kernelspec; the app (this pod) chooses it.
|
|
- name: SANDBOX_KERNEL_NAME
|
|
value: "docsgpt-python"
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: docsgpt-worker
|
|
spec:
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app: docsgpt-worker
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: docsgpt-worker
|
|
spec:
|
|
initContainers:
|
|
- name: wait-for-postgres
|
|
image: postgres:16-alpine
|
|
command:
|
|
- sh
|
|
- -c
|
|
- |
|
|
until pg_isready -h postgres -p 5432 -U docsgpt -d docsgpt; do
|
|
echo "Waiting for postgres..."; sleep 2;
|
|
done
|
|
containers:
|
|
- name: docsgpt-worker
|
|
image: arc53/docsgpt
|
|
command: ["celery", "-A", "application.app.celery", "worker", "-l", "INFO", "-n", "worker.%h"]
|
|
resources:
|
|
limits:
|
|
memory: "4Gi"
|
|
cpu: "2"
|
|
requests:
|
|
memory: "2Gi"
|
|
cpu: "1"
|
|
envFrom:
|
|
- secretRef:
|
|
name: docsgpt-secrets
|
|
env:
|
|
- name: API_URL
|
|
value: "http://<your-api-endpoint>"
|
|
- name: POSTGRES_URI
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: docsgpt-secrets
|
|
key: POSTGRES_URI
|
|
# Disable in-app auto-bootstrap. The `postgres-init` Job under
|
|
# deployment/k8s/jobs/ owns schema creation and Alembic migrations,
|
|
# so application pods must not race with it on rollout.
|
|
- name: AUTO_MIGRATE
|
|
value: "false"
|
|
- name: AUTO_CREATE_DB
|
|
value: "false"
|
|
# Reach the always-on code-execution runner over HTTP + WebSocket.
|
|
- name: SANDBOX_GATEWAY_URL
|
|
value: "http://docsgpt-sandbox:8888"
|
|
# Select the runner's env-scrubbing kernelspec by its distinct name so
|
|
# it is never shadowed by the stock "python3" spec. MUST be set here:
|
|
# the runner only ships the kernelspec; the app (this pod) chooses it.
|
|
- name: SANDBOX_KERNEL_NAME
|
|
value: "docsgpt-python"
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: docsgpt-frontend
|
|
spec:
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app: docsgpt-frontend
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: docsgpt-frontend
|
|
spec:
|
|
containers:
|
|
- name: docsgpt-frontend
|
|
image: arc53/docsgpt-fe
|
|
ports:
|
|
- containerPort: 5173
|
|
resources:
|
|
limits:
|
|
memory: "1Gi"
|
|
cpu: "1"
|
|
requests:
|
|
memory: "256Mi"
|
|
cpu: "100m"
|
|
env:
|
|
- name: VITE_API_HOST
|
|
value: "http://<your-api-endpoint>"
|
|
- name: VITE_API_STREAMING
|
|
value: "true"
|