Make fresh router startup reliable
This commit is contained in:
+12
-3
@@ -323,8 +323,15 @@ services:
|
|||||||
cap_drop: [ALL]
|
cap_drop: [ALL]
|
||||||
# The entrypoint fixes ownership of fresh named volumes and immediately
|
# The entrypoint fixes ownership of fresh named volumes and immediately
|
||||||
# drops to uid/gid 10002 via gosu before starting the router. Without this
|
# drops to uid/gid 10002 via gosu before starting the router. Without this
|
||||||
# narrowly scoped capability a clean installation loops before startup.
|
# narrowly scoped capabilities a clean installation cannot initialize the
|
||||||
cap_add: [CHOWN]
|
# volumes and then switch to its unprivileged runtime identity.
|
||||||
|
cap_add: [CHOWN, SETUID, SETGID]
|
||||||
|
healthcheck:
|
||||||
|
test: [CMD, python, -c, "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8081/health', timeout=2)"]
|
||||||
|
interval: 5s
|
||||||
|
timeout: 3s
|
||||||
|
retries: 24
|
||||||
|
start_period: 5s
|
||||||
depends_on:
|
depends_on:
|
||||||
profile-controller:
|
profile-controller:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
@@ -351,7 +358,9 @@ services:
|
|||||||
- "${AI_BIND_ADDRESS:-127.0.0.1}:8080:8080"
|
- "${AI_BIND_ADDRESS:-127.0.0.1}:8080:8080"
|
||||||
dns: ["${AI_DNS:-1.1.1.1}"]
|
dns: ["${AI_DNS:-1.1.1.1}"]
|
||||||
networks: [frontend, tools]
|
networks: [frontend, tools]
|
||||||
depends_on: [router]
|
depends_on:
|
||||||
|
router:
|
||||||
|
condition: service_healthy
|
||||||
security_opt: ["no-new-privileges:true"]
|
security_opt: ["no-new-privileges:true"]
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
|
|||||||
+14
-1
@@ -319,8 +319,21 @@ build_and_start() {
|
|||||||
docker compose --env-file "$SECRETS_DIR/stack.env" up -d --build \
|
docker compose --env-file "$SECRETS_DIR/stack.env" up -d --build \
|
||||||
profile-controller router open-webui
|
profile-controller router open-webui
|
||||||
|
|
||||||
|
log "Auf gesunden Router warten"
|
||||||
|
local deadline=$((SECONDS + 180))
|
||||||
|
until [ "$(docker inspect --format '{{if .State.Health}}{{.State.Health.Status}}{{else}}{{.State.Status}}{{end}}' mike-ai-router 2>/dev/null || true)" = "healthy" ]; do
|
||||||
|
if (( SECONDS >= deadline )); then
|
||||||
|
docker logs --tail 80 mike-ai-router >&2 || true
|
||||||
|
die "Router wurde nicht rechtzeitig gesund"
|
||||||
|
fi
|
||||||
|
sleep 2
|
||||||
|
done
|
||||||
|
|
||||||
log "Fast-Profil aktivieren und Readiness prüfen"
|
log "Fast-Profil aktivieren und Readiness prüfen"
|
||||||
docker compose --env-file "$SECRETS_DIR/stack.env" exec -T router python - <<'PY'
|
# Use docker exec directly here. Some Compose/Docker combinations return a
|
||||||
|
# transient HTTP 409 while upgrading the exec stream immediately after a
|
||||||
|
# freshly built service has been recreated.
|
||||||
|
docker exec -i mike-ai-router python - <<'PY'
|
||||||
import json, os, time, urllib.request
|
import json, os, time, urllib.request
|
||||||
key = os.environ["ROUTER_API_KEY"]
|
key = os.environ["ROUTER_API_KEY"]
|
||||||
request = urllib.request.Request(
|
request = urllib.request.Request(
|
||||||
|
|||||||
Reference in New Issue
Block a user