# Athena deployment Deployment directory: `/opt/ltx-deskweb/source` on `192.168.1.212`. Container: `ltx-deskweb`. Image: `ltx-deskweb:0.1.0`. The additional `deploy/compose.athena.yaml` uses host networking **only for this frontend**, binds its web server to `127.0.0.1:8118`, and connects to Deck at `http://127.0.0.1:8120`. This avoids changing Deck's existing network or relying on its current Docker IP. No Docker socket, GPU devices or inference packages are mounted into the GUI. CPU and RAM limits: 2 CPUs / 1 GiB. GUI identity: UID 1000 / GID 0; this supplies shared-file read access, not root UID or Linux capabilities. Filtered Deck inventory labels: - `io.athena-deck.managed=true` - `io.athena-deck.role=application` Media mounts: - `/data/video/ltx-desktop/LTXDesktop/remote-inputs/deskweb` → writable inputs. A new isolated directory owned by UID 1000 / GID 0, mode 2750; no changes to other LTX directories. Files use mode 0640. The existing LTX backend runs with GID 0 and dropped capabilities, so group-read/traverse permission is required even for its root UID. - `/data/video/ltx-desktop/LTXDesktop/outputs` → read-only outputs. Backend-visible input path: `/data/LTXDesktop/remote-inputs/deskweb`. The GUI and LTX backend see the same files through different bind mounts. Credentials are outside Git in `source/secrets`. The Deck token is the existing configured client token; it was not changed. GUI password is independently randomized. Host secret files are readable only by UID 1000/root. If the Deck token is rotated later, replace `secrets/ltx-token` and restart only the GUI container. Never place secret contents in commands, Git, logs or screenshots. ## Access From the Mac: ```sh ssh -i /Users/mike_i386/.ssh/athena_key -o BatchMode=yes \ -o ExitOnForwardFailure=yes -N -L 8118:127.0.0.1:8118 root@192.168.1.212 ``` Open `http://127.0.0.1:8118`. This is a tunnel to the container on Athena, not a Mac application instance. PUBLIC_ORIGIN is set to this exact URL. For a different URL, configure the origin accordingly. No WireGuard or firewall changes were made. Local private copy of the GUI password: `LTX-DeskWEB/secrets/web-password` (ignored by Git, mode 0600). ## Operation on Athena ```sh cd /opt/ltx-deskweb/source docker compose -p ltx-deskweb -f compose.yaml -f deploy/compose.athena.yaml up -d --no-deps ltx-deskweb # Stop only this UI: docker compose -p ltx-deskweb -f compose.yaml -f deploy/compose.athena.yaml stop ltx-deskweb # Restart only this UI after changing its private configuration: docker compose -p ltx-deskweb -f compose.yaml -f deploy/compose.athena.yaml restart ltx-deskweb ``` The GUI is available in LLM mode but reports that LTX is not ready. Activate Video mode in Athena Deck when you want to generate. Deploying or starting this GUI does not switch GPU mode or start the LTX model/backend.