From bea144c91e06d785fdf347f040c525834550a743 Mon Sep 17 00:00:00 2001 From: Mikei386 <44135113+Mikei386@users.noreply.github.com> Date: Fri, 21 Aug 2026 14:03:32 +0200 Subject: [PATCH] Make fresh router startup reliable --- compose.yaml | 15 ++++++++++++--- install.sh | 15 ++++++++++++++- 2 files changed, 26 insertions(+), 4 deletions(-) diff --git a/compose.yaml b/compose.yaml index 1e5998d..a74cbd0 100644 --- a/compose.yaml +++ b/compose.yaml @@ -323,8 +323,15 @@ services: cap_drop: [ALL] # The entrypoint fixes ownership of fresh named volumes and immediately # drops to uid/gid 10002 via gosu before starting the router. Without this - # narrowly scoped capability a clean installation loops before startup. - cap_add: [CHOWN] + # narrowly scoped capabilities a clean installation cannot initialize the + # volumes and then switch to its unprivileged runtime identity. + cap_add: [CHOWN, SETUID, SETGID] + healthcheck: + test: [CMD, python, -c, "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8081/health', timeout=2)"] + interval: 5s + timeout: 3s + retries: 24 + start_period: 5s depends_on: profile-controller: condition: service_healthy @@ -351,7 +358,9 @@ services: - "${AI_BIND_ADDRESS:-127.0.0.1}:8080:8080" dns: ["${AI_DNS:-1.1.1.1}"] networks: [frontend, tools] - depends_on: [router] + depends_on: + router: + condition: service_healthy security_opt: ["no-new-privileges:true"] networks: diff --git a/install.sh b/install.sh index 47150c3..a6bb943 100755 --- a/install.sh +++ b/install.sh @@ -319,8 +319,21 @@ build_and_start() { docker compose --env-file "$SECRETS_DIR/stack.env" up -d --build \ profile-controller router open-webui + log "Auf gesunden Router warten" + local deadline=$((SECONDS + 180)) + until [ "$(docker inspect --format '{{if .State.Health}}{{.State.Health.Status}}{{else}}{{.State.Status}}{{end}}' mike-ai-router 2>/dev/null || true)" = "healthy" ]; do + if (( SECONDS >= deadline )); then + docker logs --tail 80 mike-ai-router >&2 || true + die "Router wurde nicht rechtzeitig gesund" + fi + sleep 2 + done + log "Fast-Profil aktivieren und Readiness prüfen" - docker compose --env-file "$SECRETS_DIR/stack.env" exec -T router python - <<'PY' + # Use docker exec directly here. Some Compose/Docker combinations return a + # transient HTTP 409 while upgrading the exec stream immediately after a + # freshly built service has been recreated. + docker exec -i mike-ai-router python - <<'PY' import json, os, time, urllib.request key = os.environ["ROUTER_API_KEY"] request = urllib.request.Request(