- UX audit Fix 1-5: actionable MCP HandoffSurface (endpoint/discovery/onboarding), reachable approval loop (sidebar section + waiting-for-me badge), honest MCP entry labels, ROUTES SSOT for dashboard-testing/load-testing (+ link-integrity coverage) - scenario registry hub (/dashboard-testing/scenarios) built on ScenarioRegistryModel - admin MCP governance: read-only GET /api/admin/mcp/catalog (catalog x roles + DCR clients) + /admin/mcp page/model/api + ROUTES.admin.mcp + sidebar entry - full i18n sweep of dashboard-testing routes and scenario-* component trees (ru/en) - accumulated workspace: MCP OAuth/DCR, automation idempotency migration, docker/nginx, specs
67 lines
2.2 KiB
YAML
67 lines
2.2 KiB
YAML
services:
|
|
db:
|
|
image: ${POSTGRES_IMAGE:-postgres:16-alpine}
|
|
restart: unless-stopped
|
|
# Compatibility workaround for legacy Docker/libseccomp hosts running PostgreSQL 16.
|
|
security_opt:
|
|
- seccomp=unconfined
|
|
environment:
|
|
POSTGRES_DB: ss_tools
|
|
POSTGRES_USER: postgres
|
|
POSTGRES_PASSWORD: postgres
|
|
ports:
|
|
- "${POSTGRES_HOST_PORT:-5432}:5432"
|
|
volumes:
|
|
- postgres_data:/var/lib/postgresql/data
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U postgres -d ss_tools"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 10
|
|
|
|
backend:
|
|
build:
|
|
context: .
|
|
dockerfile: docker/backend.Dockerfile
|
|
restart: unless-stopped
|
|
env_file:
|
|
- ./backend/.env
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
environment:
|
|
DATABASE_URL: postgresql+psycopg2://postgres:postgres@db:5432/ss_tools
|
|
STORAGE_ROOT_PATH: /app/storage
|
|
RESET_DATABASE_SCHEMA: ${RESET_DATABASE_SCHEMA:-false}
|
|
BACKEND_PORT: 8000
|
|
ALLOWED_ORIGINS: ${ALLOWED_ORIGINS:-}
|
|
MCP_ALLOWED_HOSTS: ${MCP_ALLOWED_HOSTS:-127.0.0.1:*,localhost:*,[::1]:*}
|
|
MCP_ALLOWED_ORIGINS: ${MCP_ALLOWED_ORIGINS:-http://127.0.0.1:*,http://localhost:*,http://[::1]:*}
|
|
# Trust the internal nginx proxy; bind the direct backend port to loopback below.
|
|
FORWARDED_ALLOW_IPS: ${FORWARDED_ALLOW_IPS:-*}
|
|
INITIAL_ADMIN_CREATE: ${INITIAL_ADMIN_CREATE:-false}
|
|
INITIAL_ADMIN_USERNAME: ${INITIAL_ADMIN_USERNAME:-admin}
|
|
INITIAL_ADMIN_PASSWORD: ${INITIAL_ADMIN_PASSWORD:-}
|
|
FEATURES__DATASET_REVIEW: ${FEATURES__DATASET_REVIEW:-true}
|
|
FEATURES__HEALTH_MONITOR: ${FEATURES__HEALTH_MONITOR:-true}
|
|
SERVICE_JWT: ${SERVICE_JWT:?Set SERVICE_JWT in .env — do not use a public default for the service secret}
|
|
LLM_CA_CERT_URLS: ${LLM_CA_CERT_URLS:-}
|
|
ports:
|
|
- "127.0.0.1:${BACKEND_HOST_PORT:-8001}:8000"
|
|
volumes:
|
|
- ./storage:/app/storage
|
|
- ${CERTS_PATH:-./certs}:/opt/certs:ro
|
|
|
|
frontend:
|
|
build:
|
|
context: .
|
|
dockerfile: docker/frontend.Dockerfile
|
|
restart: unless-stopped
|
|
depends_on:
|
|
- backend
|
|
ports:
|
|
- "${FRONTEND_HOST_PORT:-8000}:80"
|
|
|
|
volumes:
|
|
postgres_data:
|