feat/cathou-serve: supervised dashboard-cathou + all secrets into age (public-repo-safe) #61

Merged
gortium merged 2 commits from feat/cathou-serve into master 2026-09-18 20:48:34 +00:00
5 changed files with 31 additions and 2 deletions

View File

@@ -23,9 +23,15 @@ services:
- ROCR_VISIBLE_DEVICES=0,1 - ROCR_VISIBLE_DEVICES=0,1
- HSA_ENABLE_SDMA=0 - HSA_ENABLE_SDMA=0
- TZ=America/Montreal - TZ=America/Montreal
- CATHOU_SERVE_PASSWORD=${CATHOU_SERVE_PASSWORD:?must be set}
- CATHOU_SERVE_SECRET=${CATHOU_SERVE_SECRET:?must be set}
- HERMES_DASHBOARD_BASIC_AUTH_USERNAME=thierry
- HERMES_DASHBOARD_BASIC_AUTH_PASSWORD=${HERMES_DASHBOARD_BASIC_AUTH_PASSWORD:?must be set}
- HERMES_DASHBOARD_BASIC_AUTH_SECRET=${HERMES_DASHBOARD_BASIC_AUTH_SECRET:?must be set}
volumes: volumes:
- /mnt/HoardingCow_docker_data/Hermes/data:/opt/data - /mnt/HoardingCow_docker_data/Hermes/data:/opt/data
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/opt/data/ExoKortex - /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/opt/data/ExoKortex
- ./s6/dashboard-cathou:/etc/s6-overlay/s6-rc.d/dashboard-cathou:ro
devices: devices:
- /dev/kfd:/dev/kfd - /dev/kfd:/dev/kfd
- /dev/dri:/dev/dri - /dev/dri:/dev/dri
@@ -138,7 +144,7 @@ services:
container_name: honcho container_name: honcho
restart: unless-stopped restart: unless-stopped
environment: environment:
- DB_CONNECTION_URI=postgresql+psycopg://honcho:honcho_pass@honcho-db:5432/honcho - DB_CONNECTION_URI=postgresql+psycopg://honcho:${HONCHO_DB_PASSWORD:?HONCHO_DB_PASSWORD must be set}@honcho-db:5432/honcho
- CACHE_URL=redis://honcho-redis:6379/0 - CACHE_URL=redis://honcho-redis:6379/0
- CACHE_ENABLED=true - CACHE_ENABLED=true
- EMBEDDING_VECTOR_DIMENSIONS=1024 - EMBEDDING_VECTOR_DIMENSIONS=1024
@@ -179,7 +185,7 @@ services:
environment: environment:
- POSTGRES_DB=honcho - POSTGRES_DB=honcho
- POSTGRES_USER=honcho - POSTGRES_USER=honcho
- POSTGRES_PASSWORD=honcho_pass - POSTGRES_PASSWORD=${HONCHO_DB_PASSWORD:?HONCHO_DB_PASSWORD must be set}
- PGDATA=/var/lib/postgresql/data/pgdata - PGDATA=/var/lib/postgresql/data/pgdata
volumes: volumes:
- /mnt/HoardingCow_docker_data/Honcho/postgres:/var/lib/postgresql/data - /mnt/HoardingCow_docker_data/Honcho/postgres:/var/lib/postgresql/data

View File

@@ -0,0 +1 @@
base

View File

@@ -0,0 +1,4 @@
#!/command/with-contenv sh
# Always restart on exit (exit != 125). Crash-loop with a bad auth
# config is the intended fail-closed signal.
exit 0

View File

@@ -0,0 +1,17 @@
#!/command/with-contenv sh
# Personal dashboard serve (:9120) for cathou — same machinery as the
# main dashboard service, but runs the command directly so its OWN
# with-contenv shebang can't wipe our env (a second with-contenv reset
# would drop the port + auth variables). Supervised by s6: restarts on crash.
export HERMES_DASHBOARD_PORT=9120
export HERMES_DASHBOARD_BASIC_AUTH_USERNAME=cathou
export HERMES_DASHBOARD_BASIC_AUTH_PASSWORD="${CATHOU_SERVE_PASSWORD:-}"
export HERMES_DASHBOARD_BASIC_AUTH_SECRET="${CATHOU_SERVE_SECRET:-}"
export HOME=/opt/data
cd /opt/data
# shellcheck disable=SC1091
. /opt/hermes/.venv/bin/activate
# Fail-closed: missing password => provider won't register => serve fails
# => s6 crash-loop surfaces it, never a silent unauthenticated bind.
[ "$(id -u)" = 0 ] || exec hermes dashboard --host 0.0.0.0 --port 9120 --no-open
exec s6-setuidgid hermes hermes dashboard --host 0.0.0.0 --port 9120 --no-open

View File

@@ -0,0 +1 @@
longrun