chore: ignore and untrack backup/context temp files
This commit is contained in:
@@ -1,15 +0,0 @@
|
|||||||
PUBLIC_HOST=stend.4mont.ru
|
|
||||||
LETSENCRYPT_EMAIL=admin@4mont.ru
|
|
||||||
|
|
||||||
POSTGRES_DB=portal
|
|
||||||
POSTGRES_USER=portal
|
|
||||||
POSTGRES_PASSWORD=change_me
|
|
||||||
|
|
||||||
SIGNING_KEY=replace_with_long_random_key
|
|
||||||
ADMIN_USERNAME=admin
|
|
||||||
ADMIN_PASSWORD=StrongAdminPassword!
|
|
||||||
SESSION_IDLE_SECONDS=300
|
|
||||||
PREWARM_POOL_SIZE=2
|
|
||||||
UNIVERSAL_POOL_SIZE=0
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER=4
|
|
||||||
LOG_LEVEL=INFO
|
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
PUBLIC_HOST=stend.4mont.ru
|
|
||||||
LETSENCRYPT_EMAIL=admin@4mont.ru
|
|
||||||
|
|
||||||
POSTGRES_DB=portal
|
|
||||||
POSTGRES_USER=portal
|
|
||||||
POSTGRES_PASSWORD=change_me
|
|
||||||
|
|
||||||
SIGNING_KEY=9a6d4b053a47ae24078e07587e69f344111652f153ba50eff31603e43c91f89b
|
|
||||||
ADMIN_USERNAME=admin
|
|
||||||
ADMIN_PASSWORD=StrongAdminPassword!
|
|
||||||
SESSION_IDLE_SECONDS=300
|
|
||||||
PREWARM_POOL_SIZE=2
|
|
||||||
UNIVERSAL_POOL_SIZE=0
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER=4
|
|
||||||
LOG_LEVEL=INFO
|
|
||||||
WEB_POOL_SIZE=20
|
|
||||||
WEB_POOL_BUFFER=2
|
|
||||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -1,124 +0,0 @@
|
|||||||
services:
|
|
||||||
traefik:
|
|
||||||
image: traefik:v3.2
|
|
||||||
command:
|
|
||||||
- --configFile=/etc/traefik/traefik.yml
|
|
||||||
ports:
|
|
||||||
- "0.0.0.0:8288:80"
|
|
||||||
- "0.0.0.0:2288:443"
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
||||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
|
||||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
|
||||||
- ./traefik/letsencrypt:/letsencrypt
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
db:
|
|
||||||
image: postgres:16
|
|
||||||
environment:
|
|
||||||
POSTGRES_DB: ${POSTGRES_DB}
|
|
||||||
POSTGRES_USER: ${POSTGRES_USER}
|
|
||||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
|
||||||
volumes:
|
|
||||||
- pg_data:/var/lib/postgresql/data
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
api:
|
|
||||||
build:
|
|
||||||
context: ./app
|
|
||||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "6"]
|
|
||||||
environment:
|
|
||||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
|
||||||
SIGNING_KEY: ${SIGNING_KEY}
|
|
||||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
|
||||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
|
||||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
|
||||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
|
||||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
|
||||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
|
||||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
|
||||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-10}
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
|
||||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
|
||||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 20
|
|
||||||
POOL_DISPATCH_RETRIES: 6
|
|
||||||
ENABLE_STARTUP_MAINTENANCE: 0
|
|
||||||
depends_on:
|
|
||||||
- db
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
- ./app/static/service-icons:/app/static/service-icons
|
|
||||||
labels:
|
|
||||||
- traefik.enable=true
|
|
||||||
- traefik.docker.network=portal_net
|
|
||||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
|
||||||
- traefik.http.routers.portal.entrypoints=websecure
|
|
||||||
- traefik.http.routers.portal.tls=true
|
|
||||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
|
||||||
- traefik.http.routers.portal.priority=1
|
|
||||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
|
||||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
|
|
||||||
maintenance:
|
|
||||||
build:
|
|
||||||
context: ./app
|
|
||||||
command: [python, maintenance_runner.py]
|
|
||||||
environment:
|
|
||||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
|
||||||
SIGNING_KEY: ${SIGNING_KEY}
|
|
||||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
|
||||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
|
||||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
|
||||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
|
||||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
|
||||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
|
||||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
|
||||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-10}
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
|
||||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
|
||||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 20
|
|
||||||
POOL_DISPATCH_RETRIES: 6
|
|
||||||
ENABLE_STARTUP_MAINTENANCE: 0
|
|
||||||
depends_on:
|
|
||||||
- db
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
- ./app/static/service-icons:/app/static/service-icons
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
kiosk-image:
|
|
||||||
image: portal-kiosk:latest
|
|
||||||
build:
|
|
||||||
context: ./kiosk
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
rdp-proxy-image:
|
|
||||||
image: portal-rdp-proxy:latest
|
|
||||||
build:
|
|
||||||
context: ./rdp-proxy
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
universal-runtime-image:
|
|
||||||
image: portal-universal-runtime:latest
|
|
||||||
build:
|
|
||||||
context: ./universal-runtime
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
networks:
|
|
||||||
portal_net:
|
|
||||||
name: portal_net
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
pg_data:
|
|
||||||
@@ -1,124 +0,0 @@
|
|||||||
services:
|
|
||||||
traefik:
|
|
||||||
image: traefik:v3.2
|
|
||||||
command:
|
|
||||||
- --configFile=/etc/traefik/traefik.yml
|
|
||||||
ports:
|
|
||||||
- "0.0.0.0:8288:80"
|
|
||||||
- "0.0.0.0:2288:443"
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
||||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
|
||||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
|
||||||
- ./traefik/letsencrypt:/letsencrypt
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
db:
|
|
||||||
image: postgres:16
|
|
||||||
environment:
|
|
||||||
POSTGRES_DB: ${POSTGRES_DB}
|
|
||||||
POSTGRES_USER: ${POSTGRES_USER}
|
|
||||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
|
||||||
volumes:
|
|
||||||
- pg_data:/var/lib/postgresql/data
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
api:
|
|
||||||
build:
|
|
||||||
context: ./app
|
|
||||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "18"]
|
|
||||||
environment:
|
|
||||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
|
||||||
SIGNING_KEY: ${SIGNING_KEY}
|
|
||||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
|
||||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
|
||||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
|
||||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
|
||||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
|
||||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
|
||||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
|
||||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
|
||||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
|
||||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
POOL_DISPATCH_RETRIES: 6
|
|
||||||
ENABLE_STARTUP_MAINTENANCE: 0
|
|
||||||
depends_on:
|
|
||||||
- db
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
- ./app/static/service-icons:/app/static/service-icons
|
|
||||||
labels:
|
|
||||||
- traefik.enable=true
|
|
||||||
- traefik.docker.network=portal_net
|
|
||||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
|
||||||
- traefik.http.routers.portal.entrypoints=websecure
|
|
||||||
- traefik.http.routers.portal.tls=true
|
|
||||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
|
||||||
- traefik.http.routers.portal.priority=1
|
|
||||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
|
||||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
|
|
||||||
maintenance:
|
|
||||||
build:
|
|
||||||
context: ./app
|
|
||||||
command: [python, maintenance_runner.py]
|
|
||||||
environment:
|
|
||||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
|
||||||
SIGNING_KEY: ${SIGNING_KEY}
|
|
||||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
|
||||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
|
||||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
|
||||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
|
||||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
|
||||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
|
||||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
|
||||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
|
||||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
|
||||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
POOL_DISPATCH_RETRIES: 6
|
|
||||||
ENABLE_STARTUP_MAINTENANCE: 0
|
|
||||||
depends_on:
|
|
||||||
- db
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
- ./app/static/service-icons:/app/static/service-icons
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
kiosk-image:
|
|
||||||
image: portal-kiosk:latest
|
|
||||||
build:
|
|
||||||
context: ./kiosk
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
rdp-proxy-image:
|
|
||||||
image: portal-rdp-proxy:latest
|
|
||||||
build:
|
|
||||||
context: ./rdp-proxy
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
universal-runtime-image:
|
|
||||||
image: portal-universal-runtime:latest
|
|
||||||
build:
|
|
||||||
context: ./universal-runtime
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
networks:
|
|
||||||
portal_net:
|
|
||||||
name: portal_net
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
pg_data:
|
|
||||||
@@ -1,124 +0,0 @@
|
|||||||
services:
|
|
||||||
traefik:
|
|
||||||
image: traefik:v3.2
|
|
||||||
command:
|
|
||||||
- --configFile=/etc/traefik/traefik.yml
|
|
||||||
ports:
|
|
||||||
- "0.0.0.0:8288:80"
|
|
||||||
- "0.0.0.0:2288:443"
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
||||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
|
||||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
|
||||||
- ./traefik/letsencrypt:/letsencrypt
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
db:
|
|
||||||
image: postgres:16
|
|
||||||
environment:
|
|
||||||
POSTGRES_DB: ${POSTGRES_DB}
|
|
||||||
POSTGRES_USER: ${POSTGRES_USER}
|
|
||||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
|
||||||
volumes:
|
|
||||||
- pg_data:/var/lib/postgresql/data
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
api:
|
|
||||||
build:
|
|
||||||
context: ./app
|
|
||||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "18"]
|
|
||||||
environment:
|
|
||||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
|
||||||
SIGNING_KEY: ${SIGNING_KEY}
|
|
||||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
|
||||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
|
||||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
|
||||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
|
||||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
|
||||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
|
||||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
|
||||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
|
||||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
|
||||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
POOL_DISPATCH_RETRIES: 6
|
|
||||||
ENABLE_STARTUP_MAINTENANCE: 0
|
|
||||||
depends_on:
|
|
||||||
- db
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
- ./app/static/service-icons:/app/static/service-icons
|
|
||||||
labels:
|
|
||||||
- traefik.enable=true
|
|
||||||
- traefik.docker.network=portal_net
|
|
||||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
|
||||||
- traefik.http.routers.portal.entrypoints=websecure
|
|
||||||
- traefik.http.routers.portal.tls=true
|
|
||||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
|
||||||
- traefik.http.routers.portal.priority=1
|
|
||||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
|
||||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
|
|
||||||
maintenance:
|
|
||||||
build:
|
|
||||||
context: ./app
|
|
||||||
command: [python, maintenance_runner.py]
|
|
||||||
environment:
|
|
||||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
|
||||||
SIGNING_KEY: ${SIGNING_KEY}
|
|
||||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
|
||||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
|
||||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
|
||||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
|
||||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
|
||||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
|
||||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
|
||||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
|
||||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
|
||||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
POOL_DISPATCH_RETRIES: 6
|
|
||||||
ENABLE_STARTUP_MAINTENANCE: 0
|
|
||||||
depends_on:
|
|
||||||
- db
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
- ./app/static/service-icons:/app/static/service-icons
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
kiosk-image:
|
|
||||||
image: portal-kiosk:latest
|
|
||||||
build:
|
|
||||||
context: ./kiosk
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
rdp-proxy-image:
|
|
||||||
image: portal-rdp-proxy:latest
|
|
||||||
build:
|
|
||||||
context: ./rdp-proxy
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
universal-runtime-image:
|
|
||||||
image: portal-universal-runtime:latest
|
|
||||||
build:
|
|
||||||
context: ./universal-runtime
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
networks:
|
|
||||||
portal_net:
|
|
||||||
name: portal_net
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
pg_data:
|
|
||||||
@@ -1,124 +0,0 @@
|
|||||||
services:
|
|
||||||
traefik:
|
|
||||||
image: traefik:v3.2
|
|
||||||
command:
|
|
||||||
- --configFile=/etc/traefik/traefik.yml
|
|
||||||
ports:
|
|
||||||
- "0.0.0.0:8288:80"
|
|
||||||
- "0.0.0.0:2288:443"
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
||||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
|
||||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
|
||||||
- ./traefik/letsencrypt:/letsencrypt
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
db:
|
|
||||||
image: postgres:16
|
|
||||||
environment:
|
|
||||||
POSTGRES_DB: ${POSTGRES_DB}
|
|
||||||
POSTGRES_USER: ${POSTGRES_USER}
|
|
||||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
|
||||||
volumes:
|
|
||||||
- pg_data:/var/lib/postgresql/data
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
api:
|
|
||||||
build:
|
|
||||||
context: ./app
|
|
||||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "18"]
|
|
||||||
environment:
|
|
||||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
|
||||||
SIGNING_KEY: ${SIGNING_KEY}
|
|
||||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
|
||||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
|
||||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
|
||||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
|
||||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
|
||||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
|
||||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
|
||||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
|
||||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
|
||||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
POOL_DISPATCH_RETRIES: 6
|
|
||||||
ENABLE_STARTUP_MAINTENANCE: 0
|
|
||||||
depends_on:
|
|
||||||
- db
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
- ./app/static/service-icons:/app/static/service-icons
|
|
||||||
labels:
|
|
||||||
- traefik.enable=true
|
|
||||||
- traefik.docker.network=portal_net
|
|
||||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
|
||||||
- traefik.http.routers.portal.entrypoints=websecure
|
|
||||||
- traefik.http.routers.portal.tls=true
|
|
||||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
|
||||||
- traefik.http.routers.portal.priority=1
|
|
||||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
|
||||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
|
|
||||||
maintenance:
|
|
||||||
build:
|
|
||||||
context: ./app
|
|
||||||
command: [python, maintenance_runner.py]
|
|
||||||
environment:
|
|
||||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
|
||||||
SIGNING_KEY: ${SIGNING_KEY}
|
|
||||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
|
||||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
|
||||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
|
||||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
|
||||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
|
||||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
|
||||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
|
||||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
|
||||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
|
||||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
|
||||||
POOL_DISPATCH_RETRIES: 6
|
|
||||||
ENABLE_STARTUP_MAINTENANCE: 0
|
|
||||||
depends_on:
|
|
||||||
- db
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
- ./app/static/service-icons:/app/static/service-icons
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
kiosk-image:
|
|
||||||
image: portal-kiosk:latest
|
|
||||||
build:
|
|
||||||
context: ./kiosk
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
rdp-proxy-image:
|
|
||||||
image: portal-rdp-proxy:latest
|
|
||||||
build:
|
|
||||||
context: ./rdp-proxy
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
universal-runtime-image:
|
|
||||||
image: portal-universal-runtime:latest
|
|
||||||
build:
|
|
||||||
context: ./universal-runtime
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
networks:
|
|
||||||
portal_net:
|
|
||||||
name: portal_net
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
pg_data:
|
|
||||||
@@ -1,87 +0,0 @@
|
|||||||
services:
|
|
||||||
traefik:
|
|
||||||
image: traefik:v3.2
|
|
||||||
command:
|
|
||||||
- --configFile=/etc/traefik/traefik.yml
|
|
||||||
ports:
|
|
||||||
- "0.0.0.0:8288:80"
|
|
||||||
- "0.0.0.0:2288:443"
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
||||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
|
||||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
|
||||||
- ./traefik/letsencrypt:/letsencrypt
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
db:
|
|
||||||
image: postgres:16
|
|
||||||
environment:
|
|
||||||
POSTGRES_DB: ${POSTGRES_DB}
|
|
||||||
POSTGRES_USER: ${POSTGRES_USER}
|
|
||||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
|
||||||
volumes:
|
|
||||||
- pg_data:/var/lib/postgresql/data
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
api:
|
|
||||||
build:
|
|
||||||
context: ./app
|
|
||||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "18"]
|
|
||||||
environment:
|
|
||||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
|
||||||
SIGNING_KEY: ${SIGNING_KEY}
|
|
||||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
|
||||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
|
||||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
|
||||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
|
||||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
|
||||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
|
||||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
|
||||||
depends_on:
|
|
||||||
- db
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
- ./app/static/service-icons:/app/static/service-icons
|
|
||||||
labels:
|
|
||||||
- traefik.enable=true
|
|
||||||
- traefik.docker.network=portal_net
|
|
||||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
|
||||||
- traefik.http.routers.portal.entrypoints=websecure
|
|
||||||
- traefik.http.routers.portal.tls=true
|
|
||||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
|
||||||
- traefik.http.routers.portal.priority=1
|
|
||||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
|
||||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
kiosk-image:
|
|
||||||
image: portal-kiosk:latest
|
|
||||||
build:
|
|
||||||
context: ./kiosk
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
rdp-proxy-image:
|
|
||||||
image: portal-rdp-proxy:latest
|
|
||||||
build:
|
|
||||||
context: ./rdp-proxy
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
universal-runtime-image:
|
|
||||||
image: portal-universal-runtime:latest
|
|
||||||
build:
|
|
||||||
context: ./universal-runtime
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
networks:
|
|
||||||
portal_net:
|
|
||||||
name: portal_net
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
pg_data:
|
|
||||||
@@ -1,87 +0,0 @@
|
|||||||
services:
|
|
||||||
traefik:
|
|
||||||
image: traefik:v3.2
|
|
||||||
command:
|
|
||||||
- --configFile=/etc/traefik/traefik.yml
|
|
||||||
ports:
|
|
||||||
- "0.0.0.0:8288:80"
|
|
||||||
- "0.0.0.0:2288:443"
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
||||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
|
||||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
|
||||||
- ./traefik/letsencrypt:/letsencrypt
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
db:
|
|
||||||
image: postgres:16
|
|
||||||
environment:
|
|
||||||
POSTGRES_DB: ${POSTGRES_DB}
|
|
||||||
POSTGRES_USER: ${POSTGRES_USER}
|
|
||||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
|
||||||
volumes:
|
|
||||||
- pg_data:/var/lib/postgresql/data
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
api:
|
|
||||||
build:
|
|
||||||
context: ./app
|
|
||||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "6"]
|
|
||||||
environment:
|
|
||||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
|
||||||
SIGNING_KEY: ${SIGNING_KEY}
|
|
||||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
|
||||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
|
||||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
|
||||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
|
||||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
|
||||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
|
||||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
|
||||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
|
||||||
depends_on:
|
|
||||||
- db
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
- ./app/static/service-icons:/app/static/service-icons
|
|
||||||
labels:
|
|
||||||
- traefik.enable=true
|
|
||||||
- traefik.docker.network=portal_net
|
|
||||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
|
||||||
- traefik.http.routers.portal.entrypoints=websecure
|
|
||||||
- traefik.http.routers.portal.tls=true
|
|
||||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
|
||||||
- traefik.http.routers.portal.priority=1
|
|
||||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
|
||||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
|
||||||
networks:
|
|
||||||
- portal_net
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
kiosk-image:
|
|
||||||
image: portal-kiosk:latest
|
|
||||||
build:
|
|
||||||
context: ./kiosk
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
rdp-proxy-image:
|
|
||||||
image: portal-rdp-proxy:latest
|
|
||||||
build:
|
|
||||||
context: ./rdp-proxy
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
universal-runtime-image:
|
|
||||||
image: portal-universal-runtime:latest
|
|
||||||
build:
|
|
||||||
context: ./universal-runtime
|
|
||||||
profiles: ["build-only"]
|
|
||||||
|
|
||||||
networks:
|
|
||||||
portal_net:
|
|
||||||
name: portal_net
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
pg_data:
|
|
||||||
@@ -1,58 +0,0 @@
|
|||||||
# CONTEXT_TEST
|
|
||||||
|
|
||||||
Обновлено: 2026-04-23 (Europe/Moscow)
|
|
||||||
|
|
||||||
## Цель
|
|
||||||
Продолжить нагрузочное тестирование маршрута `GET /go/{slug}` и стабилизировать поведение под конкуренцией.
|
|
||||||
|
|
||||||
## Что внедрено в API
|
|
||||||
|
|
||||||
1. Ограничение ожидания lock-ов:
|
|
||||||
- добавлен `LockTimeoutError`;
|
|
||||||
- `allocator_lock(...)` теперь поддерживает timeout через `pg_try_advisory_lock`;
|
|
||||||
- для user-lock в `go_service`: `GO_USER_LOCK_TIMEOUT_SECONDS` (default `2.0`);
|
|
||||||
- для pool-lock: `GO_POOL_LOCK_TIMEOUT_SECONDS` (default `5.0`).
|
|
||||||
|
|
||||||
2. Контролируемые ответы вместо долгого зависания:
|
|
||||||
- timeout user-lock -> `429`;
|
|
||||||
- timeout pool-lock -> `503`.
|
|
||||||
|
|
||||||
3. Фазовая телеметрия `go_service`:
|
|
||||||
- событие: `go_service_timing`;
|
|
||||||
- фиксируются времена фаз (wait lock, check existing/limit, ensure/acquire/dispatch/commit, total).
|
|
||||||
|
|
||||||
4. Ограничен dispatch runtime-пула:
|
|
||||||
- `POOL_DISPATCH_RETRIES` (default `4`),
|
|
||||||
- `POOL_DISPATCH_REQUEST_TIMEOUT_SECONDS` (default `2.0`),
|
|
||||||
- `POOL_DISPATCH_SLEEP_SECONDS` (default `0.3`).
|
|
||||||
|
|
||||||
## Что исправлено в тестовом контуре
|
|
||||||
|
|
||||||
1. В `.env` был пустой `SIGNING_KEY` -> заполнен, `api` перезапущен.
|
|
||||||
2. В k6-скрипте включено `noCookiesReset: true`, иначе возникал ложный вал `401`.
|
|
||||||
|
|
||||||
## Актуальные контрольные результаты
|
|
||||||
|
|
||||||
Контрольный тест (после правок):
|
|
||||||
- профиль: `5 VU`, `25s`, single-user;
|
|
||||||
- `http_req_failed = 0%`;
|
|
||||||
- `open_success = 1138`;
|
|
||||||
- `open_rejected = 0`;
|
|
||||||
- `p95 http_req_duration = 10.79ms`;
|
|
||||||
- по логам `/go/*`: `1138 x 303`, `1 x 503`.
|
|
||||||
|
|
||||||
Это подтверждает, что:
|
|
||||||
- долгие зависания заменены на быстрые контролируемые ответы;
|
|
||||||
- тестовый сценарий больше не искажается cookie-сбросом.
|
|
||||||
|
|
||||||
## Следующие шаги
|
|
||||||
|
|
||||||
1. Повторить multi-user `load` (30 VU, 5m) на этом же скрипте и зафиксировать:
|
|
||||||
- долю `303/429/503`,
|
|
||||||
- p95/p99,
|
|
||||||
- `go_service_timing` по фазам.
|
|
||||||
|
|
||||||
2. При необходимости тонко настроить:
|
|
||||||
- `GO_USER_LOCK_TIMEOUT_SECONDS`,
|
|
||||||
- `GO_POOL_LOCK_TIMEOUT_SECONDS`,
|
|
||||||
- `POOL_DISPATCH_*`.
|
|
||||||
Reference in New Issue
Block a user