Files
tao.chen 60ab745d58 Merge branch 'develop'
# Conflicts:
#	CLAUDE.md
#	backend/src/backend/api/platform/members.py
#	backend/src/backend/main.py
#	common/src/common/config.py
#	frontend/app/app.css
#	frontend/app/components/common/Topbar.tsx
#	frontend/app/components/ui/table.tsx
#	frontend/app/features/admin/PermissionCheckboxList.tsx
#	frontend/app/features/admin/UserFormDialog.tsx
#	frontend/app/features/platform/DashboardRoute.tsx
#	frontend/app/features/platform/PythonEditor.tsx
#	frontend/app/features/platform/ScriptWorkspace.tsx
#	frontend/app/routes.ts
#	frontend/app/routes/platform.navigation.tsx
#	frontend/app/routes/platform.tsx
#	frontend/app/services/api/_shared.ts
#	frontend/app/services/api/boundApi.ts
#	frontend/app/services/api/fileLocks.ts
#	frontend/app/services/api/platformEmployees.ts
#	frontend/app/services/api/resources.ts
#	frontend/app/services/api/schedules.ts
#	frontend/app/services/api/scripts.ts
#	frontend/app/services/api/workspaceMembers.ts
#	frontend/app/services/api/workspaces.ts
#	frontend/package.json
#	frontend/pnpm-lock.yaml
#	frontend/vite.config.ts
2026-09-04 16:09:50 +08:00

151 lines
7.1 KiB
Bash

COMPOSE_PROJECT_NAME=model-platform-develop
SCHEDULE_EVENT_NAMESPACE=model-platform-develop
# External port of the Nginx gateway. Only Nginx is exposed to the host
# (architecture §2.2); backend/runtime/schedule stay on the Docker internal
# network. Override here to expose Nginx on a different host port.
GATEWAY_PORT=8890
# External MySQL. URL-encode reserved characters in DATABASE_URL.
MYSQL_HOST=127.0.0.1
MYSQL_PORT=3306
MYSQL_USER=root
MYSQL_PASSWORD=change-me
MYSQL_DATABASE=model_platform
DATABASE_URL=mysql+asyncmy://root:change-me@127.0.0.1:3306/model_platform?charset=utf8mb4
# 运维模块独立库;省略时后端自动复用 DATABASE_URL 的账号和主机,
# 仅将数据库名切换为 model_operations。
OPERATIONS_DATABASE_URL=mysql+asyncmy://root:change-me@127.0.0.1:3306/model_operations?charset=utf8mb4
# 运维模块访问另外两库时使用专用只读 Session;生产建议配置 DBA
# 创建的只读账号,不要复用 root。
PLATFORM_READ_DATABASE_URL=mysql+asyncmy://readonly:change-me@127.0.0.1:3306/model_platform?charset=utf8mb4
DEPLOY_DATABASE_URL=mysql+asyncmy://readonly:change-me@127.0.0.1:3306/model_deploy?charset=utf8mb4
# Redis is an optional accelerator: cache + Streams only. MySQL Outbox remains
# the reliable source of truth when Redis is unavailable.
REDIS_URL=redis://127.0.0.1:6379/0
OPERATIONS_CACHE_TTL_SECONDS=300
OPERATIONS_REDIS_PREFIX=model-platform:operations
OPERATIONS_EVENT_STREAM=model-platform:operations:events
OPERATIONS_EVENT_STREAM_MAXLEN=10000
JWT_SECRET=change-this-development-secret
# AES-256 configuration decryption key used only when a value is wrapped in ENC(...).
# Replace before deployment; keep the same value across all four services.
APP_CONFIG_SECRET_KEY=change-this-config-secret-key
# Force the Secure flag on the session cookie even when the inbound request
# scheme is plain HTTP. Enable behind a TLS-terminating reverse proxy that
# strips/rewrites X-Forwarded-Proto — otherwise the cookie is written without
# Secure and browsers refuse to send it back over HTTPS.
COOKIE_FORCE_SECURE=false
# Service label surfaced in lifespan / health checks.
SERVICE_NAME=service
# Force the Secure flag on the session cookie even when the inbound request
# scheme is plain HTTP. Enable behind a TLS-terminating reverse proxy that
# strips/rewrites X-Forwarded-Proto — otherwise the cookie is written without
# Secure and browsers refuse to send it back over HTTPS.
COOKIE_FORCE_SECURE=false
# Service label surfaced in lifespan / health checks.
SERVICE_NAME=service
# ============================================================================
# CRITICAL: must set BEFORE first run. The initial admin user is seeded by
# the deployment bootstrap. Never keep the development default in production.
# ============================================================================
INITIAL_ADMIN_PASSWORD=admin12345
# Backend loguru stderr sink level. One of DEBUG / INFO / WARNING / ERROR
# / CRITICAL. Anything else (e.g. lowercase) falls back to INFO inside
# configure_logging(). Change to DEBUG to see request bodies in
# runtime_client._jupyter_request.
LOG_LEVEL=INFO
# Audit log (backend HTTP interface compliance log). One line per HTTP
# request, written to data/logs/audit/audit-YYYY-MM-DD.log (one file per
# day). AUDIT_LOG_DIR is relative to the backend process cwd (/app in the
# container). AUDIT_LOG_RETENTION_DAYS=0 disables cleanup of old files.
AUDIT_LOG_DIR=
AUDIT_LOG_RETENTION_DAYS=30
# Exact paths excluded from the audit line (health/root probes carry no
# business value but fire every second from K8s/LB). The default already
# covers /health/live /health/ready /api/v1/health / /health/storage;
# leave empty to keep the default. Comma-separated, e.g. /health/live,/api/v1/health.
AUDIT_EXCLUDED_PATHS=
# Object storage. Two modes are supported:
# STORAGE_BACKEND=s3 — connects to an S3-compatible service (MinIO,
# RustFS, SeaweedFS, AWS S3, …). Requires the
# S3_* block below.
# STORAGE_BACKEND=local — stores objects on the local filesystem under
# LOCAL_STORAGE_BASE_DIR. Backend and runtime
# share this directory via a Docker volume
# (docker-compose.yml mounts `local-storage`).
# Useful for dev, single-node, air-gapped.
STORAGE_BACKEND=s3
LOCAL_STORAGE_BASE_DIR=/data
# Object storage (S3-compatible). Only used when STORAGE_BACKEND=s3.
# S3_ENDPOINT is the single upstream URL consumed by all 4 services:
# - nginx (via scripts/nginx-entrypoint.sh, which parses host + port)
# - backend / runtime / schedule (passed through to boto3 / rclone)
# S3_ACCESS_KEY / S3_SECRET_KEY are read by Python code in
# backend/ and schedule/ (boto3 credentials).
#
# S3 buckets are purpose-named:
# S3_WORKSPACE_BUCKET — workspace files (notebooks, scripts, working
# copies); layout is ``s3://<bucket>/<workspace_id>/...``.
# S3_VERSION_BUCKET — immutable script-version artifacts.
# S3_RUN_LOG_BUCKET — schedule run logs and execution results.
# S3_TRASH_BUCKET — soft-deleted objects; source bucket key is preserved
# as a prefix so restore is a same-key move.
S3_HOST=127.0.0.1
S3_PORT=9000
S3_ENDPOINT=http://127.0.0.1:9000
S3_ACCESS_KEY=change-me
S3_SECRET_KEY=change-me
S3_WORKSPACE_BUCKET=workspace
S3_VERSION_BUCKET=version
S3_RUN_LOG_BUCKET=run-log
S3_TRASH_BUCKET=trash
S3_TRASH_RETENTION_DAYS=30
# rclone RC (HTTP control API). The runtime container starts rclone with
# `--rc --rc-addr 0.0.0.0:5572 --rc-no-auth` (see runtime/src/runtime/mount.py),
# so the backend can POST /vfs/refresh here to invalidate the FUSE dir-cache
# after writing new workspace files. Default points at the runtime service
# over the compose network.
RCLONE_RC_URL=http://runtime:5572
# Backend → Runtime HTTP endpoint (Jupyter contents API, file ops).
RUNTIME_API_URL=http://runtime:8000
# Public base URL for the runtime container (surfaced to clients for
# Jupyter access tickets / embedded URLs).
PUBLIC_BASE_URL=http://runtime
# ============================================================================
# Service-to-service auth (P0-1 fix).
# Backend's /internal/v1/* storage control plane requires this shared secret.
# The schedule worker reads the same value and sends it as the
# ``X-Internal-Service-Token`` header. Value MUST match between backend and
# schedule. Generate a random 64-char string for any non-dev deployment:
# python -c "import secrets; print(secrets.token_urlsafe(48))"
# ============================================================================
INTERNAL_SERVICE_TOKEN=change-me-internal-service-token
# Schedule → Backend HTTP base URL (cron post-back / status callbacks).
BACKEND_API_URL=http://backend:8000
# Max concurrent notebooks running in the schedule worker. Each notebook is
# dispatched as an asyncio task bounded by a semaphore; the polling loop is
# never blocked.
SCHEDULE_EXECUTION_CONCURRENCY=4
# Readiness probe targets. Comma-separated host:port list checked by
# /health/ready; empty disables the check. e.g. mysql:3306,s3:9000
READINESS_TARGETS=