Files
LTX-DeskWEB/docs/ATHENA_DEPLOYMENT.md
T

65 lines
2.8 KiB
Markdown

# Athena deployment
Deployment directory: `/opt/ltx-deskweb/source` on `192.168.1.212`.
Container: `ltx-deskweb`. Image: `ltx-deskweb:0.1.0`.
The additional `deploy/compose.athena.yaml` uses host networking **only for this
frontend**, binds its web server to `127.0.0.1:8118`, and connects to Deck at
`http://127.0.0.1:8120`. This avoids changing Deck's existing network or relying on
its current Docker IP. No Docker socket, GPU devices or inference packages are
mounted into the GUI. CPU and RAM limits: 2 CPUs / 1 GiB. GUI identity: UID 1000 / GID 0;
this supplies shared-file read access, not root UID or Linux capabilities.
Filtered Deck inventory labels:
- `io.athena-deck.managed=true`
- `io.athena-deck.role=application`
Media mounts:
- `/data/video/ltx-desktop/LTXDesktop/remote-inputs/deskweb` → writable inputs.
A new isolated directory owned by UID 1000 / GID 0, mode 2750; no changes to other LTX directories.
Files use mode 0640. The existing LTX backend runs with GID 0 and dropped
capabilities, so group-read/traverse permission is required even for its root UID.
- `/data/video/ltx-desktop/LTXDesktop/outputs` → read-only outputs.
Backend-visible input path: `/data/LTXDesktop/remote-inputs/deskweb`.
The GUI and LTX backend see the same files through different bind mounts.
Credentials are outside Git in `source/secrets`. The Deck token is the existing
configured client token; it was not changed. GUI password is independently
randomized. Host secret files are readable only by UID 1000/root. If the Deck token
is rotated later, replace `secrets/ltx-token` and restart only the GUI container.
Never place secret contents in commands, Git, logs or screenshots.
## Access
From the Mac:
```sh
ssh -i /Users/mike_i386/.ssh/athena_key -o BatchMode=yes \
-o ExitOnForwardFailure=yes -N -L 8118:127.0.0.1:8118 root@192.168.1.212
```
Open `http://127.0.0.1:8118`. This is a tunnel to the container on Athena, not a Mac
application instance. PUBLIC_ORIGIN is set to this exact URL. For a different URL,
configure the origin accordingly. No WireGuard or firewall changes were made.
Local private copy of the GUI password:
`LTX-DeskWEB/secrets/web-password` (ignored by Git, mode 0600).
## Operation on Athena
```sh
cd /opt/ltx-deskweb/source
docker compose -p ltx-deskweb -f compose.yaml -f deploy/compose.athena.yaml up -d --no-deps ltx-deskweb
# Stop only this UI:
docker compose -p ltx-deskweb -f compose.yaml -f deploy/compose.athena.yaml stop ltx-deskweb
# Restart only this UI after changing its private configuration:
docker compose -p ltx-deskweb -f compose.yaml -f deploy/compose.athena.yaml restart ltx-deskweb
```
The GUI is available in LLM mode but reports that LTX is not ready. Activate Video
mode in Athena Deck when you want to generate. Deploying or starting this GUI does
not switch GPU mode or start the LTX model/backend.