chore: ignore and untrack backup/context temp files
This commit is contained in:
@@ -1,15 +0,0 @@
|
||||
PUBLIC_HOST=stend.4mont.ru
|
||||
LETSENCRYPT_EMAIL=admin@4mont.ru
|
||||
|
||||
POSTGRES_DB=portal
|
||||
POSTGRES_USER=portal
|
||||
POSTGRES_PASSWORD=change_me
|
||||
|
||||
SIGNING_KEY=replace_with_long_random_key
|
||||
ADMIN_USERNAME=admin
|
||||
ADMIN_PASSWORD=StrongAdminPassword!
|
||||
SESSION_IDLE_SECONDS=300
|
||||
PREWARM_POOL_SIZE=2
|
||||
UNIVERSAL_POOL_SIZE=0
|
||||
MAX_ACTIVE_SERVICES_PER_USER=4
|
||||
LOG_LEVEL=INFO
|
||||
@@ -1,17 +0,0 @@
|
||||
PUBLIC_HOST=stend.4mont.ru
|
||||
LETSENCRYPT_EMAIL=admin@4mont.ru
|
||||
|
||||
POSTGRES_DB=portal
|
||||
POSTGRES_USER=portal
|
||||
POSTGRES_PASSWORD=change_me
|
||||
|
||||
SIGNING_KEY=9a6d4b053a47ae24078e07587e69f344111652f153ba50eff31603e43c91f89b
|
||||
ADMIN_USERNAME=admin
|
||||
ADMIN_PASSWORD=StrongAdminPassword!
|
||||
SESSION_IDLE_SECONDS=300
|
||||
PREWARM_POOL_SIZE=2
|
||||
UNIVERSAL_POOL_SIZE=0
|
||||
MAX_ACTIVE_SERVICES_PER_USER=4
|
||||
LOG_LEVEL=INFO
|
||||
WEB_POOL_SIZE=20
|
||||
WEB_POOL_BUFFER=2
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -1,124 +0,0 @@
|
||||
services:
|
||||
traefik:
|
||||
image: traefik:v3.2
|
||||
command:
|
||||
- --configFile=/etc/traefik/traefik.yml
|
||||
ports:
|
||||
- "0.0.0.0:8288:80"
|
||||
- "0.0.0.0:2288:443"
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
||||
- ./traefik/letsencrypt:/letsencrypt
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
db:
|
||||
image: postgres:16
|
||||
environment:
|
||||
POSTGRES_DB: ${POSTGRES_DB}
|
||||
POSTGRES_USER: ${POSTGRES_USER}
|
||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
||||
volumes:
|
||||
- pg_data:/var/lib/postgresql/data
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
api:
|
||||
build:
|
||||
context: ./app
|
||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "6"]
|
||||
environment:
|
||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
||||
SIGNING_KEY: ${SIGNING_KEY}
|
||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-10}
|
||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 20
|
||||
POOL_DISPATCH_RETRIES: 6
|
||||
ENABLE_STARTUP_MAINTENANCE: 0
|
||||
depends_on:
|
||||
- db
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./app/static/service-icons:/app/static/service-icons
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.docker.network=portal_net
|
||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
||||
- traefik.http.routers.portal.entrypoints=websecure
|
||||
- traefik.http.routers.portal.tls=true
|
||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
||||
- traefik.http.routers.portal.priority=1
|
||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
|
||||
maintenance:
|
||||
build:
|
||||
context: ./app
|
||||
command: [python, maintenance_runner.py]
|
||||
environment:
|
||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
||||
SIGNING_KEY: ${SIGNING_KEY}
|
||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-10}
|
||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 20
|
||||
POOL_DISPATCH_RETRIES: 6
|
||||
ENABLE_STARTUP_MAINTENANCE: 0
|
||||
depends_on:
|
||||
- db
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./app/static/service-icons:/app/static/service-icons
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
kiosk-image:
|
||||
image: portal-kiosk:latest
|
||||
build:
|
||||
context: ./kiosk
|
||||
profiles: ["build-only"]
|
||||
|
||||
rdp-proxy-image:
|
||||
image: portal-rdp-proxy:latest
|
||||
build:
|
||||
context: ./rdp-proxy
|
||||
profiles: ["build-only"]
|
||||
|
||||
universal-runtime-image:
|
||||
image: portal-universal-runtime:latest
|
||||
build:
|
||||
context: ./universal-runtime
|
||||
profiles: ["build-only"]
|
||||
|
||||
networks:
|
||||
portal_net:
|
||||
name: portal_net
|
||||
|
||||
volumes:
|
||||
pg_data:
|
||||
@@ -1,124 +0,0 @@
|
||||
services:
|
||||
traefik:
|
||||
image: traefik:v3.2
|
||||
command:
|
||||
- --configFile=/etc/traefik/traefik.yml
|
||||
ports:
|
||||
- "0.0.0.0:8288:80"
|
||||
- "0.0.0.0:2288:443"
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
||||
- ./traefik/letsencrypt:/letsencrypt
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
db:
|
||||
image: postgres:16
|
||||
environment:
|
||||
POSTGRES_DB: ${POSTGRES_DB}
|
||||
POSTGRES_USER: ${POSTGRES_USER}
|
||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
||||
volumes:
|
||||
- pg_data:/var/lib/postgresql/data
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
api:
|
||||
build:
|
||||
context: ./app
|
||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "18"]
|
||||
environment:
|
||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
||||
SIGNING_KEY: ${SIGNING_KEY}
|
||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
||||
POOL_DISPATCH_RETRIES: 6
|
||||
ENABLE_STARTUP_MAINTENANCE: 0
|
||||
depends_on:
|
||||
- db
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./app/static/service-icons:/app/static/service-icons
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.docker.network=portal_net
|
||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
||||
- traefik.http.routers.portal.entrypoints=websecure
|
||||
- traefik.http.routers.portal.tls=true
|
||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
||||
- traefik.http.routers.portal.priority=1
|
||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
|
||||
maintenance:
|
||||
build:
|
||||
context: ./app
|
||||
command: [python, maintenance_runner.py]
|
||||
environment:
|
||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
||||
SIGNING_KEY: ${SIGNING_KEY}
|
||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
||||
POOL_DISPATCH_RETRIES: 6
|
||||
ENABLE_STARTUP_MAINTENANCE: 0
|
||||
depends_on:
|
||||
- db
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./app/static/service-icons:/app/static/service-icons
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
kiosk-image:
|
||||
image: portal-kiosk:latest
|
||||
build:
|
||||
context: ./kiosk
|
||||
profiles: ["build-only"]
|
||||
|
||||
rdp-proxy-image:
|
||||
image: portal-rdp-proxy:latest
|
||||
build:
|
||||
context: ./rdp-proxy
|
||||
profiles: ["build-only"]
|
||||
|
||||
universal-runtime-image:
|
||||
image: portal-universal-runtime:latest
|
||||
build:
|
||||
context: ./universal-runtime
|
||||
profiles: ["build-only"]
|
||||
|
||||
networks:
|
||||
portal_net:
|
||||
name: portal_net
|
||||
|
||||
volumes:
|
||||
pg_data:
|
||||
@@ -1,124 +0,0 @@
|
||||
services:
|
||||
traefik:
|
||||
image: traefik:v3.2
|
||||
command:
|
||||
- --configFile=/etc/traefik/traefik.yml
|
||||
ports:
|
||||
- "0.0.0.0:8288:80"
|
||||
- "0.0.0.0:2288:443"
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
||||
- ./traefik/letsencrypt:/letsencrypt
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
db:
|
||||
image: postgres:16
|
||||
environment:
|
||||
POSTGRES_DB: ${POSTGRES_DB}
|
||||
POSTGRES_USER: ${POSTGRES_USER}
|
||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
||||
volumes:
|
||||
- pg_data:/var/lib/postgresql/data
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
api:
|
||||
build:
|
||||
context: ./app
|
||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "18"]
|
||||
environment:
|
||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
||||
SIGNING_KEY: ${SIGNING_KEY}
|
||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
||||
POOL_DISPATCH_RETRIES: 6
|
||||
ENABLE_STARTUP_MAINTENANCE: 0
|
||||
depends_on:
|
||||
- db
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./app/static/service-icons:/app/static/service-icons
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.docker.network=portal_net
|
||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
||||
- traefik.http.routers.portal.entrypoints=websecure
|
||||
- traefik.http.routers.portal.tls=true
|
||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
||||
- traefik.http.routers.portal.priority=1
|
||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
|
||||
maintenance:
|
||||
build:
|
||||
context: ./app
|
||||
command: [python, maintenance_runner.py]
|
||||
environment:
|
||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
||||
SIGNING_KEY: ${SIGNING_KEY}
|
||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
||||
POOL_DISPATCH_RETRIES: 6
|
||||
ENABLE_STARTUP_MAINTENANCE: 0
|
||||
depends_on:
|
||||
- db
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./app/static/service-icons:/app/static/service-icons
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
kiosk-image:
|
||||
image: portal-kiosk:latest
|
||||
build:
|
||||
context: ./kiosk
|
||||
profiles: ["build-only"]
|
||||
|
||||
rdp-proxy-image:
|
||||
image: portal-rdp-proxy:latest
|
||||
build:
|
||||
context: ./rdp-proxy
|
||||
profiles: ["build-only"]
|
||||
|
||||
universal-runtime-image:
|
||||
image: portal-universal-runtime:latest
|
||||
build:
|
||||
context: ./universal-runtime
|
||||
profiles: ["build-only"]
|
||||
|
||||
networks:
|
||||
portal_net:
|
||||
name: portal_net
|
||||
|
||||
volumes:
|
||||
pg_data:
|
||||
@@ -1,124 +0,0 @@
|
||||
services:
|
||||
traefik:
|
||||
image: traefik:v3.2
|
||||
command:
|
||||
- --configFile=/etc/traefik/traefik.yml
|
||||
ports:
|
||||
- "0.0.0.0:8288:80"
|
||||
- "0.0.0.0:2288:443"
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
||||
- ./traefik/letsencrypt:/letsencrypt
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
db:
|
||||
image: postgres:16
|
||||
environment:
|
||||
POSTGRES_DB: ${POSTGRES_DB}
|
||||
POSTGRES_USER: ${POSTGRES_USER}
|
||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
||||
volumes:
|
||||
- pg_data:/var/lib/postgresql/data
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
api:
|
||||
build:
|
||||
context: ./app
|
||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "18"]
|
||||
environment:
|
||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
||||
SIGNING_KEY: ${SIGNING_KEY}
|
||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
||||
POOL_DISPATCH_RETRIES: 6
|
||||
ENABLE_STARTUP_MAINTENANCE: 0
|
||||
depends_on:
|
||||
- db
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./app/static/service-icons:/app/static/service-icons
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.docker.network=portal_net
|
||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
||||
- traefik.http.routers.portal.entrypoints=websecure
|
||||
- traefik.http.routers.portal.tls=true
|
||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
||||
- traefik.http.routers.portal.priority=1
|
||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
|
||||
maintenance:
|
||||
build:
|
||||
context: ./app
|
||||
command: [python, maintenance_runner.py]
|
||||
environment:
|
||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
||||
SIGNING_KEY: ${SIGNING_KEY}
|
||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
||||
WEB_POOL_SIZE: ${WEB_POOL_SIZE:-20}
|
||||
WEB_POOL_BUFFER: ${WEB_POOL_BUFFER:-2}
|
||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
||||
GO_USER_LOCK_TIMEOUT_SECONDS: 8
|
||||
GO_POOL_LOCK_TIMEOUT_SECONDS: 8
|
||||
POOL_DISPATCH_RETRIES: 6
|
||||
ENABLE_STARTUP_MAINTENANCE: 0
|
||||
depends_on:
|
||||
- db
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./app/static/service-icons:/app/static/service-icons
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
kiosk-image:
|
||||
image: portal-kiosk:latest
|
||||
build:
|
||||
context: ./kiosk
|
||||
profiles: ["build-only"]
|
||||
|
||||
rdp-proxy-image:
|
||||
image: portal-rdp-proxy:latest
|
||||
build:
|
||||
context: ./rdp-proxy
|
||||
profiles: ["build-only"]
|
||||
|
||||
universal-runtime-image:
|
||||
image: portal-universal-runtime:latest
|
||||
build:
|
||||
context: ./universal-runtime
|
||||
profiles: ["build-only"]
|
||||
|
||||
networks:
|
||||
portal_net:
|
||||
name: portal_net
|
||||
|
||||
volumes:
|
||||
pg_data:
|
||||
@@ -1,87 +0,0 @@
|
||||
services:
|
||||
traefik:
|
||||
image: traefik:v3.2
|
||||
command:
|
||||
- --configFile=/etc/traefik/traefik.yml
|
||||
ports:
|
||||
- "0.0.0.0:8288:80"
|
||||
- "0.0.0.0:2288:443"
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
||||
- ./traefik/letsencrypt:/letsencrypt
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
db:
|
||||
image: postgres:16
|
||||
environment:
|
||||
POSTGRES_DB: ${POSTGRES_DB}
|
||||
POSTGRES_USER: ${POSTGRES_USER}
|
||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
||||
volumes:
|
||||
- pg_data:/var/lib/postgresql/data
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
api:
|
||||
build:
|
||||
context: ./app
|
||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "18"]
|
||||
environment:
|
||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
||||
SIGNING_KEY: ${SIGNING_KEY}
|
||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
||||
depends_on:
|
||||
- db
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./app/static/service-icons:/app/static/service-icons
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.docker.network=portal_net
|
||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
||||
- traefik.http.routers.portal.entrypoints=websecure
|
||||
- traefik.http.routers.portal.tls=true
|
||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
||||
- traefik.http.routers.portal.priority=1
|
||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
kiosk-image:
|
||||
image: portal-kiosk:latest
|
||||
build:
|
||||
context: ./kiosk
|
||||
profiles: ["build-only"]
|
||||
|
||||
rdp-proxy-image:
|
||||
image: portal-rdp-proxy:latest
|
||||
build:
|
||||
context: ./rdp-proxy
|
||||
profiles: ["build-only"]
|
||||
|
||||
universal-runtime-image:
|
||||
image: portal-universal-runtime:latest
|
||||
build:
|
||||
context: ./universal-runtime
|
||||
profiles: ["build-only"]
|
||||
|
||||
networks:
|
||||
portal_net:
|
||||
name: portal_net
|
||||
|
||||
volumes:
|
||||
pg_data:
|
||||
@@ -1,87 +0,0 @@
|
||||
services:
|
||||
traefik:
|
||||
image: traefik:v3.2
|
||||
command:
|
||||
- --configFile=/etc/traefik/traefik.yml
|
||||
ports:
|
||||
- "0.0.0.0:8288:80"
|
||||
- "0.0.0.0:2288:443"
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
- ./traefik/traefik.yml:/etc/traefik/traefik.yml:ro
|
||||
- ./traefik/dynamic:/etc/traefik/dynamic
|
||||
- ./traefik/letsencrypt:/letsencrypt
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
db:
|
||||
image: postgres:16
|
||||
environment:
|
||||
POSTGRES_DB: ${POSTGRES_DB}
|
||||
POSTGRES_USER: ${POSTGRES_USER}
|
||||
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
|
||||
volumes:
|
||||
- pg_data:/var/lib/postgresql/data
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
api:
|
||||
build:
|
||||
context: ./app
|
||||
command: ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "6"]
|
||||
environment:
|
||||
DATABASE_URL: postgresql+psycopg2://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}
|
||||
SIGNING_KEY: ${SIGNING_KEY}
|
||||
PUBLIC_HOST: ${PUBLIC_HOST}
|
||||
ADMIN_USERNAME: ${ADMIN_USERNAME}
|
||||
ADMIN_PASSWORD: ${ADMIN_PASSWORD}
|
||||
SESSION_IDLE_SECONDS: ${SESSION_IDLE_SECONDS:-300}
|
||||
PREWARM_POOL_SIZE: ${PREWARM_POOL_SIZE:-2}
|
||||
UNIVERSAL_POOL_SIZE: ${UNIVERSAL_POOL_SIZE:-0}
|
||||
MAX_ACTIVE_SERVICES_PER_USER: ${MAX_ACTIVE_SERVICES_PER_USER:-4}
|
||||
LOG_LEVEL: ${LOG_LEVEL:-INFO}
|
||||
depends_on:
|
||||
- db
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./app/static/service-icons:/app/static/service-icons
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.docker.network=portal_net
|
||||
- traefik.http.routers.portal.rule=Host(`${PUBLIC_HOST}`)
|
||||
- traefik.http.routers.portal.entrypoints=websecure
|
||||
- traefik.http.routers.portal.tls=true
|
||||
- traefik.http.routers.portal.tls.certresolver=letsencrypt
|
||||
- traefik.http.routers.portal.priority=1
|
||||
- traefik.http.services.portal.loadbalancer.server.port=8000
|
||||
- traefik.http.routers.portal.middlewares=secure-headers@file
|
||||
networks:
|
||||
- portal_net
|
||||
restart: unless-stopped
|
||||
|
||||
kiosk-image:
|
||||
image: portal-kiosk:latest
|
||||
build:
|
||||
context: ./kiosk
|
||||
profiles: ["build-only"]
|
||||
|
||||
rdp-proxy-image:
|
||||
image: portal-rdp-proxy:latest
|
||||
build:
|
||||
context: ./rdp-proxy
|
||||
profiles: ["build-only"]
|
||||
|
||||
universal-runtime-image:
|
||||
image: portal-universal-runtime:latest
|
||||
build:
|
||||
context: ./universal-runtime
|
||||
profiles: ["build-only"]
|
||||
|
||||
networks:
|
||||
portal_net:
|
||||
name: portal_net
|
||||
|
||||
volumes:
|
||||
pg_data:
|
||||
@@ -1,58 +0,0 @@
|
||||
# CONTEXT_TEST
|
||||
|
||||
Обновлено: 2026-04-23 (Europe/Moscow)
|
||||
|
||||
## Цель
|
||||
Продолжить нагрузочное тестирование маршрута `GET /go/{slug}` и стабилизировать поведение под конкуренцией.
|
||||
|
||||
## Что внедрено в API
|
||||
|
||||
1. Ограничение ожидания lock-ов:
|
||||
- добавлен `LockTimeoutError`;
|
||||
- `allocator_lock(...)` теперь поддерживает timeout через `pg_try_advisory_lock`;
|
||||
- для user-lock в `go_service`: `GO_USER_LOCK_TIMEOUT_SECONDS` (default `2.0`);
|
||||
- для pool-lock: `GO_POOL_LOCK_TIMEOUT_SECONDS` (default `5.0`).
|
||||
|
||||
2. Контролируемые ответы вместо долгого зависания:
|
||||
- timeout user-lock -> `429`;
|
||||
- timeout pool-lock -> `503`.
|
||||
|
||||
3. Фазовая телеметрия `go_service`:
|
||||
- событие: `go_service_timing`;
|
||||
- фиксируются времена фаз (wait lock, check existing/limit, ensure/acquire/dispatch/commit, total).
|
||||
|
||||
4. Ограничен dispatch runtime-пула:
|
||||
- `POOL_DISPATCH_RETRIES` (default `4`),
|
||||
- `POOL_DISPATCH_REQUEST_TIMEOUT_SECONDS` (default `2.0`),
|
||||
- `POOL_DISPATCH_SLEEP_SECONDS` (default `0.3`).
|
||||
|
||||
## Что исправлено в тестовом контуре
|
||||
|
||||
1. В `.env` был пустой `SIGNING_KEY` -> заполнен, `api` перезапущен.
|
||||
2. В k6-скрипте включено `noCookiesReset: true`, иначе возникал ложный вал `401`.
|
||||
|
||||
## Актуальные контрольные результаты
|
||||
|
||||
Контрольный тест (после правок):
|
||||
- профиль: `5 VU`, `25s`, single-user;
|
||||
- `http_req_failed = 0%`;
|
||||
- `open_success = 1138`;
|
||||
- `open_rejected = 0`;
|
||||
- `p95 http_req_duration = 10.79ms`;
|
||||
- по логам `/go/*`: `1138 x 303`, `1 x 503`.
|
||||
|
||||
Это подтверждает, что:
|
||||
- долгие зависания заменены на быстрые контролируемые ответы;
|
||||
- тестовый сценарий больше не искажается cookie-сбросом.
|
||||
|
||||
## Следующие шаги
|
||||
|
||||
1. Повторить multi-user `load` (30 VU, 5m) на этом же скрипте и зафиксировать:
|
||||
- долю `303/429/503`,
|
||||
- p95/p99,
|
||||
- `go_service_timing` по фазам.
|
||||
|
||||
2. При необходимости тонко настроить:
|
||||
- `GO_USER_LOCK_TIMEOUT_SECONDS`,
|
||||
- `GO_POOL_LOCK_TIMEOUT_SECONDS`,
|
||||
- `POOL_DISPATCH_*`.
|
||||
Reference in New Issue
Block a user