Document and configure isolated Athena frontend deployment

This commit is contained in:
Mikei386
2026-09-29 19:35:55 +02:00
parent 1333b0c36b
commit 043d5a3b6e
4 changed files with 88 additions and 0 deletions
+2
View File
@@ -10,6 +10,8 @@ CUDA, model downloads on startup, GPU access or Docker socket.**
This is the first web preview. Real Athena generation still needs an integration This is the first web preview. Real Athena generation still needs an integration
check; it is not yet a fully equivalent replacement for every desktop feature. check; it is not yet a fully equivalent replacement for every desktop feature.
Athena installation and operation: [deployment guide](docs/ATHENA_DEPLOYMENT.md).
See [limitations and architecture](docs/ARCHITECTURE.md) and [provenance](docs/PROVENANCE.md). See [limitations and architecture](docs/ARCHITECTURE.md) and [provenance](docs/PROVENANCE.md).
## Debian / Docker deployment ## Debian / Docker deployment
+13
View File
@@ -0,0 +1,13 @@
# Optional Athena override: host loopback reaches Deck without changing its networks.
# This GUI alone uses host networking and binds exclusively to 127.0.0.1.
services:
ltx-deskweb:
container_name: ltx-deskweb
network_mode: host
ports: !reset []
extra_hosts: !reset []
environment:
HOST: 127.0.0.1
LTX_BACKEND_URL: http://127.0.0.1:8120
cpus: 2
mem_limit: 1g
+61
View File
@@ -0,0 +1,61 @@
# Athena deployment
Deployment directory: `/opt/ltx-deskweb/source` on `192.168.1.212`.
Container: `ltx-deskweb`. Image: `ltx-deskweb:0.1.0`.
The additional `deploy/compose.athena.yaml` uses host networking **only for this
frontend**, binds its web server to `127.0.0.1:8118`, and connects to Deck at
`http://127.0.0.1:8120`. This avoids changing Deck's existing network or relying on
its current Docker IP. No Docker socket, GPU devices or inference packages are
mounted into the GUI. CPU and RAM limits: 2 CPUs / 1 GiB.
Filtered Deck inventory labels:
- `io.athena-deck.managed=true`
- `io.athena-deck.role=application`
Media mounts:
- `/data/video/ltx-desktop/LTXDesktop/remote-inputs/deskweb` → writable inputs.
A new isolated directory owned by UID/GID 1000; no recursive permission changes.
- `/data/video/ltx-desktop/LTXDesktop/outputs` → read-only outputs.
Backend-visible input path: `/data/LTXDesktop/remote-inputs/deskweb`.
The GUI and LTX backend see the same files through different bind mounts.
Credentials are outside Git in `source/secrets`. The Deck token is the existing
configured client token; it was not changed. GUI password is independently
randomized. Host secret files are readable only by UID 1000/root. If the Deck token
is rotated later, replace `secrets/ltx-token` and restart only the GUI container.
Never place secret contents in commands, Git, logs or screenshots.
## Access
From the Mac:
```sh
ssh -i /Users/mike_i386/.ssh/athena_key -o BatchMode=yes \
-o ExitOnForwardFailure=yes -N -L 8118:127.0.0.1:8118 root@192.168.1.212
```
Open `http://127.0.0.1:8118`. This is a tunnel to the container on Athena, not a Mac
application instance. PUBLIC_ORIGIN is set to this exact URL. For a different URL,
configure the origin accordingly. No WireGuard or firewall changes were made.
Local private copy of the GUI password:
`LTX-DeskWEB/secrets/web-password` (ignored by Git, mode 0600).
## Operation on Athena
```sh
cd /opt/ltx-deskweb/source
docker compose -p ltx-deskweb -f compose.yaml -f deploy/compose.athena.yaml up -d --no-deps ltx-deskweb
# Stop only this UI:
docker compose -p ltx-deskweb -f compose.yaml -f deploy/compose.athena.yaml stop ltx-deskweb
# Restart only this UI after changing its private configuration:
docker compose -p ltx-deskweb -f compose.yaml -f deploy/compose.athena.yaml restart ltx-deskweb
```
The GUI is available in LLM mode but reports that LTX is not ready. Activate Video
mode in Athena Deck when you want to generate. Deploying or starting this GUI does
not switch GPU mode or start the LTX model/backend.
+12
View File
@@ -21,3 +21,15 @@ No Athena service was started, stopped or reconfigured during this port.
The synthetic fixture uses a fixed public test password and isolated temporary The synthetic fixture uses a fixed public test password and isolated temporary
media storage on loopback port 18118. Never deploy that fixture as the real service. media storage on loopback port 18118. Never deploy that fixture as the real service.
Production start (`server/index.mjs`) requires an operator-provided password file. Production start (`server/index.mjs`) requires an operator-provided password file.
## Athena deployment — 2026-09-29
Docker image built successfully on Athena (Debian), including TypeScript and Vite
checks. `ltx-deskweb` starts with UID 1000, read-only root filesystem, no GPU or
Docker socket, 2 CPUs / 1 GiB limit, host-loopback binding on 8118.
Verified: GUI HTTP 200; login/session/logout; forwarding to Deck's health endpoint;
synthetic text upload and readback through shared input storage (test file removed);
Deck's actual Unix-socket helper inventory returns `ltx-deskweb` as `running`.
Existing Medium, TTS, WireGuard and Deck remain running; LTX remains stopped.
Real video generation was not requested or tested in this deployment.