Add versioned metric graph authority, owned browser evidence, paginated and all-tab traversal, deterministic sampling policies, and analyst-facing run inspection. Provision the DEV/PREPROD/PROD Superset, Gitea and million-row ClickHouse lab; retain reproducible lifecycle evidence and explicit incomplete-traversal limits.
120 lines
4.2 KiB
YAML
120 lines
4.2 KiB
YAML
# Isolated local DEV -> PREPROD -> PROD integration laboratory.
|
|
name: ss-tools-full-flow
|
|
x-superset: &superset
|
|
image: apache/superset:5.0.0-dev
|
|
entrypoint: ["/bin/sh", "/fixture/superset-entrypoint.sh"]
|
|
environment: &superset-env
|
|
SUPERSET_CONFIG_PATH: /fixture/superset_config.py
|
|
SUPERSET_SECRET_KEY: ${SUPERSET_SECRET_KEY:?Generate full-flow env}
|
|
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?Generate full-flow env}
|
|
FIXTURE_PASSWORD: ${FIXTURE_PASSWORD:?Generate full-flow env}
|
|
SUPERSET_METADATA_DB: superset_dev
|
|
volumes:
|
|
- ./docker/full-flow:/fixture:ro
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
healthcheck:
|
|
test: ["CMD", "curl", "-f", "http://localhost:8088/health"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
start_period: 120s
|
|
retries: 30
|
|
services:
|
|
db:
|
|
image: postgres:16-alpine
|
|
environment:
|
|
POSTGRES_USER: postgres
|
|
POSTGRES_DB: ss_tools
|
|
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?Generate full-flow env}
|
|
volumes:
|
|
- database:/var/lib/postgresql/data
|
|
- ./docker/full-flow/postgres-init.sh:/docker-entrypoint-initdb.d/full-flow.sh:ro
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U postgres -d ss_tools"]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 20
|
|
superset-dev:
|
|
<<: *superset
|
|
ports: ["127.0.0.1:18111:8088"]
|
|
superset-preprod:
|
|
<<: *superset
|
|
environment:
|
|
<<: *superset-env
|
|
SUPERSET_METADATA_DB: superset_preprod
|
|
ports: ["127.0.0.1:18112:8088"]
|
|
superset-prod:
|
|
<<: *superset
|
|
environment:
|
|
<<: *superset-env
|
|
SUPERSET_METADATA_DB: superset_prod
|
|
ports: ["127.0.0.1:18113:8088"]
|
|
gitea:
|
|
image: gitea/gitea:1.24.6-rootless
|
|
environment:
|
|
FIXTURE_PASSWORD: ${FIXTURE_PASSWORD:?Generate full-flow env}
|
|
GITEA__database__DB_TYPE: sqlite3
|
|
GITEA__security__INSTALL_LOCK: "true"
|
|
GITEA__server__ROOT_URL: http://gitea:3000/
|
|
GITEA__server__DOMAIN: gitea
|
|
GITEA__service__DISABLE_REGISTRATION: "true"
|
|
GITEA__server__DISABLE_SSH: "true"
|
|
ports: ["127.0.0.1:18300:3000"]
|
|
volumes:
|
|
- ./docker/full-flow:/fixture:ro
|
|
- gitea-data:/var/lib/gitea
|
|
- gitea-config:/etc/gitea
|
|
backend:
|
|
build:
|
|
context: .
|
|
dockerfile: docker/backend.Dockerfile
|
|
args:
|
|
INSTALL_PLAYWRIGHT_BROWSERS: "1"
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
environment:
|
|
DATABASE_URL: postgresql+psycopg2://postgres:${POSTGRES_PASSWORD}@db:5432/ss_tools
|
|
AUTH_SECRET_KEY: ${AUTH_SECRET_KEY:?Generate full-flow env}
|
|
ENCRYPTION_KEY: ${ENCRYPTION_KEY:?Generate full-flow env}
|
|
SERVICE_JWT: ${SERVICE_JWT:?Generate full-flow env}
|
|
# Operator-approved external provider hosts for this isolated laboratory.
|
|
LLM_NONLOCAL_ENDPOINT_ALLOWED_HOSTS: ${LLM_NONLOCAL_ENDPOINT_ALLOWED_HOSTS:-}
|
|
STORAGE_ROOT_PATH: /app/storage
|
|
INITIAL_ADMIN_CREATE: "true"
|
|
INITIAL_ADMIN_USERNAME: admin
|
|
INITIAL_ADMIN_PASSWORD: ${FIXTURE_PASSWORD:?Generate full-flow env}
|
|
PUBLISHED_CATALOG_GITEA_URL: ${PUBLISHED_CATALOG_GITEA_URL:-http://gitea:3000}
|
|
PUBLISHED_CATALOG_GITEA_TOKEN: ${PUBLISHED_CATALOG_GITEA_TOKEN:-}
|
|
PUBLISHED_CATALOG_REPO: ${PUBLISHED_CATALOG_REPO:-admin/baseline-catalogs}
|
|
PUBLISHED_CATALOG_REF: ${PUBLISHED_CATALOG_REF:-main}
|
|
FEATURES__DATASET_REVIEW: "true"
|
|
FEATURES__HEALTH_MONITOR: "true"
|
|
ports: ["127.0.0.1:18103:8000"]
|
|
volumes:
|
|
- storage:/app/storage
|
|
- baseline-repositories:/app/backend/git_repos
|
|
- ./specs/037-superset-baseline-engine/contracts:/app/specs/037-superset-baseline-engine/contracts:ro
|
|
- ./specs/038-dashboard-scenario-model/contracts:/app/specs/038-dashboard-scenario-model/contracts:ro
|
|
healthcheck:
|
|
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8000/api/ready', timeout=5)"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
start_period: 120s
|
|
retries: 30
|
|
frontend:
|
|
build:
|
|
context: .
|
|
dockerfile: docker/frontend.Dockerfile
|
|
depends_on:
|
|
backend:
|
|
condition: service_healthy
|
|
ports: ["127.0.0.1:18102:80"]
|
|
volumes:
|
|
database:
|
|
storage:
|
|
baseline-repositories:
|
|
gitea-data:
|
|
gitea-config:
|