COMPOSE_PROJECT_NAME=model-platform-develop SCHEDULE_EVENT_NAMESPACE=model-platform-develop # External port of the Nginx gateway. Only Nginx is exposed to the host # (architecture §2.2); backend/runtime/schedule stay on the Docker internal # network. Override here to expose Nginx on a different host port. GATEWAY_PORT=8890 # External MySQL. URL-encode reserved characters in DATABASE_URL. MYSQL_HOST=127.0.0.1 MYSQL_PORT=3306 MYSQL_USER=root MYSQL_PASSWORD=change-me MYSQL_DATABASE=model_platform DATABASE_URL=mysql+asyncmy://root:change-me@127.0.0.1:3306/model_platform?charset=utf8mb4 # 运维模块独立库;省略时后端自动复用 DATABASE_URL 的账号和主机, # 仅将数据库名切换为 model_operations。 OPERATIONS_DATABASE_URL=mysql+asyncmy://root:change-me@127.0.0.1:3306/model_operations?charset=utf8mb4 # 运维模块访问另外两库时使用专用只读 Session;生产建议配置 DBA # 创建的只读账号,不要复用 root。 PLATFORM_READ_DATABASE_URL=mysql+asyncmy://readonly:change-me@127.0.0.1:3306/model_platform?charset=utf8mb4 DEPLOY_DATABASE_URL=mysql+asyncmy://readonly:change-me@127.0.0.1:3306/model_deploy?charset=utf8mb4 # Redis is an optional accelerator: cache + Streams only. MySQL Outbox remains # the reliable source of truth when Redis is unavailable. REDIS_URL=redis://127.0.0.1:6379/0 OPERATIONS_CACHE_TTL_SECONDS=300 OPERATIONS_REDIS_PREFIX=model-platform:operations OPERATIONS_EVENT_STREAM=model-platform:operations:events OPERATIONS_EVENT_STREAM_MAXLEN=10000 JWT_SECRET=change-this-development-secret # AES-256 configuration decryption key used only when a value is wrapped in ENC(...). # Replace before deployment; keep the same value across all four services. APP_CONFIG_SECRET_KEY=change-this-config-secret-key # Force the Secure flag on the session cookie even when the inbound request # scheme is plain HTTP. Enable behind a TLS-terminating reverse proxy that # strips/rewrites X-Forwarded-Proto — otherwise the cookie is written without # Secure and browsers refuse to send it back over HTTPS. COOKIE_FORCE_SECURE=false # Service label surfaced in lifespan / health checks. SERVICE_NAME=service # Force the Secure flag on the session cookie even when the inbound request # scheme is plain HTTP. Enable behind a TLS-terminating reverse proxy that # strips/rewrites X-Forwarded-Proto — otherwise the cookie is written without # Secure and browsers refuse to send it back over HTTPS. COOKIE_FORCE_SECURE=false # Service label surfaced in lifespan / health checks. SERVICE_NAME=service # ============================================================================ # CRITICAL: must set BEFORE first run. The initial admin user is seeded by # the deployment bootstrap. Never keep the development default in production. # ============================================================================ INITIAL_ADMIN_PASSWORD=admin12345 # Backend loguru stderr sink level. One of DEBUG / INFO / WARNING / ERROR # / CRITICAL. Anything else (e.g. lowercase) falls back to INFO inside # configure_logging(). Change to DEBUG to see request bodies in # runtime_client._jupyter_request. LOG_LEVEL=INFO # Audit log (backend HTTP interface compliance log). One line per HTTP # request, written to data/logs/audit/audit-YYYY-MM-DD.log (one file per # day). AUDIT_LOG_DIR is relative to the backend process cwd (/app in the # container). AUDIT_LOG_RETENTION_DAYS=0 disables cleanup of old files. AUDIT_LOG_DIR= AUDIT_LOG_RETENTION_DAYS=30 # Exact paths excluded from the audit line (health/root probes carry no # business value but fire every second from K8s/LB). The default already # covers /health/live /health/ready /api/v1/health / /health/storage; # leave empty to keep the default. Comma-separated, e.g. /health/live,/api/v1/health. AUDIT_EXCLUDED_PATHS= # Object storage. Two modes are supported: # STORAGE_BACKEND=s3 — connects to an S3-compatible service (MinIO, # RustFS, SeaweedFS, AWS S3, …). Requires the # S3_* block below. # STORAGE_BACKEND=local — stores objects on the local filesystem under # LOCAL_STORAGE_BASE_DIR. Backend and runtime # share this directory via a Docker volume # (docker-compose.yml mounts `local-storage`). # Useful for dev, single-node, air-gapped. STORAGE_BACKEND=s3 LOCAL_STORAGE_BASE_DIR=/data # Object storage (S3-compatible). Only used when STORAGE_BACKEND=s3. # S3_ENDPOINT is the single upstream URL consumed by all 4 services: # - nginx (via scripts/nginx-entrypoint.sh, which parses host + port) # - backend / runtime / schedule (passed through to boto3 / rclone) # S3_ACCESS_KEY / S3_SECRET_KEY are read by Python code in # backend/ and schedule/ (boto3 credentials). # # S3 buckets are purpose-named: # S3_WORKSPACE_BUCKET — workspace files (notebooks, scripts, working # copies); layout is ``s3:////...``. # S3_VERSION_BUCKET — immutable script-version artifacts. # S3_RUN_LOG_BUCKET — schedule run logs and execution results. # S3_TRASH_BUCKET — soft-deleted objects; source bucket key is preserved # as a prefix so restore is a same-key move. S3_HOST=127.0.0.1 S3_PORT=9000 S3_ENDPOINT=http://127.0.0.1:9000 S3_ACCESS_KEY=change-me S3_SECRET_KEY=change-me S3_WORKSPACE_BUCKET=workspace S3_VERSION_BUCKET=version S3_RUN_LOG_BUCKET=run-log S3_TRASH_BUCKET=trash S3_TRASH_RETENTION_DAYS=30 # rclone RC (HTTP control API). The runtime container starts rclone with # `--rc --rc-addr 0.0.0.0:5572 --rc-no-auth` (see runtime/src/runtime/mount.py), # so the backend can POST /vfs/refresh here to invalidate the FUSE dir-cache # after writing new workspace files. Default points at the runtime service # over the compose network. RCLONE_RC_URL=http://runtime:5572 # Backend → Runtime HTTP endpoint (Jupyter contents API, file ops). RUNTIME_API_URL=http://runtime:8000 # Public base URL for the runtime container (surfaced to clients for # Jupyter access tickets / embedded URLs). PUBLIC_BASE_URL=http://runtime # ============================================================================ # Service-to-service auth (P0-1 fix). # Backend's /internal/v1/* storage control plane requires this shared secret. # The schedule worker reads the same value and sends it as the # ``X-Internal-Service-Token`` header. Value MUST match between backend and # schedule. Generate a random 64-char string for any non-dev deployment: # python -c "import secrets; print(secrets.token_urlsafe(48))" # ============================================================================ INTERNAL_SERVICE_TOKEN=change-me-internal-service-token # Schedule → Backend HTTP base URL (cron post-back / status callbacks). BACKEND_API_URL=http://backend:8000 # Max concurrent notebooks running in the schedule worker. Each notebook is # dispatched as an asyncio task bounded by a semaphore; the polling loop is # never blocked. SCHEDULE_EXECUTION_CONCURRENCY=4 # Readiness probe targets. Comma-separated host:port list checked by # /health/ready; empty disables the check. e.g. mysql:3306,s3:9000 READINESS_TARGETS=