mirror of
https://github.com/simstudioai/sim.git
synced 2026-08-30 17:05:18 +08:00
3de63c94e3
* feat(self-host): align Docker Compose with Helm and overhaul self-hosting docs Docker Compose shipped no scheduler, so scheduled workflows, every polling trigger, connector syncs, the outbox, and data drains silently never ran. Adds a cron service running the same 18 jobs the Helm chart schedules as CronJobs, and closes the remaining behavioral gaps between the two paths: bundled Redis in the chart, no hosted plan caps in chart defaults, pinned image tags, and fail-fast secrets. A CI check keeps the schedulers in sync. Also rewrites the self-hosting docs: 14 new pages, 8 updated, reorganized into Install / Configure / Operate. * fix(self-host): drop bun install from chart CI, remove air-gapped and backup docs The scheduler-parity check pulled a full dependency install into the chart-validation job, which fails building isolated-vm on that runner. Rewritten to use only node builtins so the job installs nothing. Also removes the air-gapped and backup/restore pages, and stops pinning a concrete release in the docs so the examples do not go stale each release. * fix(helm): bundle Redis in secret-manager modes unless the URL is supplied Suppressing Redis whenever a secret mode was active left those deployments with no Redis at all — REDIS_URL is optional there and both shipped examples omit it. The chart now steps aside only on a detectable signal: an explicit app.env.REDIS_URL, an ESO remoteRefs.app.REDIS_URL mapping, or the new redis.provideUrl=false opt-out for a pre-created Secret it cannot read. * fix(compose): derive realtime BETTER_AUTH_URL from NEXT_PUBLIC_APP_URL realtime read BETTER_AUTH_URL directly and fell back to localhost while simstudio derived it from NEXT_PUBLIC_APP_URL, so setting only the public origin left realtime authenticating against http://localhost:3000. * fix(helm): deliver bundled REDIS_URL via ConfigMap so an operator value always wins Injecting REDIS_URL as an inline container env made it beat every envFrom source, so a REDIS_URL held in a pre-created Secret or synced by External Secrets was silently shadowed and traffic moved to a fresh in-cluster Redis. Kubernetes resolves duplicate envFrom keys by letting the last source win, so the bundled URL now ships as a ConfigMap listed before the app Secret. Any operator-supplied value overrides it without the chart needing to read it, which also removes the redis.provideUrl flag the previous attempt required. * docs(helm): spell out the egress rule external datastores need The default NetworkPolicy allows 443 plus the bundled Postgres and Redis by pod selector. Anything you run outside the chart on another port needs its own rule, which is easiest to miss when REDIS_URL arrives via a Secret the chart cannot inspect. Adds a copyable example to the production checklist and the security guide. * feat(helm): add networkPolicy.allowExternalEgress for managed datastores The default policy allows 443 plus the bundled Postgres and Redis by pod selector, so a managed datastore on another port needs a hand-written CIDR rule — awkward when REDIS_URL arrives via a Secret the chart cannot inspect. Adds an opt-in switch that drops the port restriction while still blocking the cloud metadata endpoints. Defaults to false, keeping this chart stricter than the common chart default of unrestricted egress.
173 lines
7.4 KiB
YAML
173 lines
7.4 KiB
YAML
services:
|
|
simstudio:
|
|
env_file:
|
|
- path: .env
|
|
required: false
|
|
# app, realtime and migrations share a database schema and must move together,
|
|
# so one variable drives all three. Set SIM_VERSION in .env to upgrade.
|
|
image: ghcr.io/simstudioai/simstudio:${SIM_VERSION:-latest}
|
|
restart: unless-stopped
|
|
ports:
|
|
- '3000:3000'
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 8G
|
|
environment:
|
|
- NODE_ENV=production
|
|
- DATABASE_URL=postgresql://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@db:5432/${POSTGRES_DB:-simstudio}
|
|
- BETTER_AUTH_URL=${NEXT_PUBLIC_APP_URL:-http://localhost:3000}
|
|
- NEXT_PUBLIC_APP_URL=${NEXT_PUBLIC_APP_URL:-http://localhost:3000}
|
|
# TRUSTED_ORIGINS: comma-separated public origins to trust for auth in
|
|
# addition to NEXT_PUBLIC_APP_URL. Use when serving from multiple domains
|
|
# (apex + www, alias hostnames, reverse-proxy IPs). Empty by default.
|
|
- TRUSTED_ORIGINS=${TRUSTED_ORIGINS:-}
|
|
# AUTH_TRUSTED_PROXIES: comma-separated reverse-proxy IPs or CIDR ranges in
|
|
# front of the app (ingress, load balancer). Better Auth walks
|
|
# x-forwarded-for right to left, skips these hops, and uses the first
|
|
# untrusted address as the client IP. Required for correct session IPs and
|
|
# rate-limit keying behind a multi-hop proxy chain. Empty by default.
|
|
- AUTH_TRUSTED_PROXIES=${AUTH_TRUSTED_PROXIES:-}
|
|
# Required. Compose aborts with this message rather than starting the app
|
|
# with an empty secret, which would silently corrupt stored credentials.
|
|
- 'BETTER_AUTH_SECRET=${BETTER_AUTH_SECRET:?is required. Create a .env file next to docker-compose.prod.yml and set it to the output of: openssl rand -hex 32}'
|
|
- 'ENCRYPTION_KEY=${ENCRYPTION_KEY:?is required. Set it in .env to the output of: openssl rand -hex 32. It cannot be changed later without losing stored credentials.}'
|
|
- 'INTERNAL_API_SECRET=${INTERNAL_API_SECRET:?is required. Set it in .env to the output of: openssl rand -hex 32}'
|
|
- API_ENCRYPTION_KEY=${API_ENCRYPTION_KEY:-}
|
|
# Authenticates the cron service against the background job endpoints.
|
|
- CRON_SECRET=${CRON_SECRET:-}
|
|
- REDIS_URL=${REDIS_URL:-redis://redis:6379}
|
|
- COPILOT_API_KEY=${COPILOT_API_KEY:-}
|
|
- NEXT_PUBLIC_CHAT_DISABLED=${NEXT_PUBLIC_CHAT_DISABLED:-}
|
|
- SIM_AGENT_API_URL=${SIM_AGENT_API_URL:-}
|
|
- OLLAMA_URL=${OLLAMA_URL:-http://localhost:11434}
|
|
- SOCKET_SERVER_URL=${SOCKET_SERVER_URL:-http://realtime:3002}
|
|
# NEXT_PUBLIC_SOCKET_URL is read by the browser. Leave it unset for this
|
|
# stack: the client already falls back to localhost:3002 for a localhost
|
|
# page, and a proxied deployment needs the page-origin fallback that an
|
|
# explicit value would suppress. Set it only when realtime is on a
|
|
# different host:port (e.g. wss://socket.example.com).
|
|
- NEXT_PUBLIC_SOCKET_URL=${NEXT_PUBLIC_SOCKET_URL:-}
|
|
- ADMISSION_GATE_MAX_INFLIGHT=${ADMISSION_GATE_MAX_INFLIGHT:-500}
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
redis:
|
|
condition: service_healthy
|
|
migrations:
|
|
condition: service_completed_successfully
|
|
realtime:
|
|
condition: service_healthy
|
|
healthcheck:
|
|
test: ['CMD', 'curl', '-fsS', 'http://127.0.0.1:3000']
|
|
interval: 90s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 10s
|
|
|
|
realtime:
|
|
env_file:
|
|
- path: .env
|
|
required: false
|
|
image: ghcr.io/simstudioai/realtime:${SIM_VERSION:-latest}
|
|
restart: unless-stopped
|
|
ports:
|
|
- '3002:3002'
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 1G
|
|
environment:
|
|
- NODE_ENV=production
|
|
- DATABASE_URL=postgresql://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@db:5432/${POSTGRES_DB:-simstudio}
|
|
- NEXT_PUBLIC_APP_URL=${NEXT_PUBLIC_APP_URL:-http://localhost:3000}
|
|
# Derived from NEXT_PUBLIC_APP_URL, matching the simstudio service — a
|
|
# single public-origin variable keeps the two from disagreeing.
|
|
- BETTER_AUTH_URL=${NEXT_PUBLIC_APP_URL:-http://localhost:3000}
|
|
- 'BETTER_AUTH_SECRET=${BETTER_AUTH_SECRET:?is required and must match the value used by the simstudio service}'
|
|
- 'INTERNAL_API_SECRET=${INTERNAL_API_SECRET:?is required and must match the value used by the simstudio service}'
|
|
- REDIS_URL=${REDIS_URL:-redis://redis:6379}
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
redis:
|
|
condition: service_healthy
|
|
healthcheck:
|
|
test: ['CMD', 'curl', '-fsS', 'http://127.0.0.1:3002/health']
|
|
interval: 90s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 10s
|
|
|
|
migrations:
|
|
image: ghcr.io/simstudioai/migrations:${SIM_VERSION:-latest}
|
|
working_dir: /app/packages/db
|
|
environment:
|
|
- DATABASE_URL=postgresql://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@db:5432/${POSTGRES_DB:-simstudio}
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
command: ['bun', 'run', 'db:migrate']
|
|
restart: 'no'
|
|
|
|
# Backs pub/sub (live Chat task-status and table events) and the shared caches.
|
|
# The app falls back to PostgreSQL for storage when REDIS_URL is unset, but the
|
|
# pub/sub channels have no fallback — without Redis, live status never streams.
|
|
# Not published to the host: only the app and realtime containers need it, and
|
|
# binding 6379 would collide with a Redis already running locally.
|
|
redis:
|
|
image: redis:7-alpine
|
|
restart: unless-stopped
|
|
healthcheck:
|
|
test: ['CMD', 'redis-cli', 'ping']
|
|
interval: 5s
|
|
timeout: 5s
|
|
retries: 5
|
|
|
|
# Runs the background jobs the Helm chart schedules as Kubernetes CronJobs:
|
|
# scheduled workflows, polling triggers, connector syncs, the transactional
|
|
# outbox, subscription renewal, and data drains. Without it none of those run.
|
|
# Schedules live in docker/crontab and mirror helm/sim/values.yaml cronjobs.jobs.
|
|
cron:
|
|
# Deliberately NOT pinned to SIM_VERSION: the scheduler only makes HTTP calls
|
|
# and shares no database schema with the app, so it does not need to move in
|
|
# lockstep — and no cron tag exists for releases that predate it.
|
|
image: ghcr.io/simstudioai/cron:${SIM_CRON_VERSION:-latest}
|
|
# Built from the repo when the published image is not available locally, so a
|
|
# fresh `git clone && docker compose up -d` works before the first release
|
|
# that publishes it.
|
|
build:
|
|
context: .
|
|
dockerfile: docker/cron.Dockerfile
|
|
# on-failure, not unless-stopped: with no CRON_SECRET the container exits 0
|
|
# after explaining why, and stays stopped instead of crash-looping. Upgrades
|
|
# from a compose file that predates this service therefore still come up.
|
|
restart: on-failure
|
|
environment:
|
|
- SIM_URL=http://simstudio:3000
|
|
- CRON_SECRET=${CRON_SECRET:-}
|
|
- TZ=${TZ:-UTC}
|
|
depends_on:
|
|
simstudio:
|
|
condition: service_healthy
|
|
|
|
db:
|
|
image: pgvector/pgvector:pg17
|
|
restart: unless-stopped
|
|
ports:
|
|
- '${POSTGRES_PORT:-5432}:5432'
|
|
environment:
|
|
- POSTGRES_USER=${POSTGRES_USER:-postgres}
|
|
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-postgres}
|
|
- POSTGRES_DB=${POSTGRES_DB:-simstudio}
|
|
volumes:
|
|
- postgres_data:/var/lib/postgresql/data
|
|
healthcheck:
|
|
test: ['CMD-SHELL', 'pg_isready -U postgres']
|
|
interval: 5s
|
|
timeout: 5s
|
|
retries: 5
|
|
|
|
volumes:
|
|
postgres_data:
|