Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
117 lines (114 loc) · 5.32 KB
/
Copy pathdocker-compose.yml
File metadata and controls
117 lines (114 loc) · 5.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
# DB + App deployment (production-ready): a stock-timeplusd `db` container and
# a pure-Python `app` container (chat agent + web UI + ingest + MCP). The two
# talk over the network (TIMEPLUS_HOST: db). This is the recommended shape for
# anything beyond a quick local run.
#
# For a single-container test/local runner, use the all-in-one file instead:
# docker compose -f docker-compose.allinone.yml up -d
#
# cp .env.example .env # put your API keys + GITHUB_TOKEN there
# docker compose up -d
# docker compose exec app tpk ingest
# docker compose exec app tpk status
# claude mcp add timeplus-knowledge -- docker compose exec -T app tpk-mcp
# open http://localhost:8000 # chat agent + web UI
#
# Repos are fetched from GitHub at the tags pinned in repos.toml (the
# tpk-checkouts volume caches them so citations can quote source).
# GITHUB_TOKEN is required for private repos.
#
# Variables (set in .env or the shell):
# TIMEPLUS_PASSWORD required; provisions the `tpk` DB user and locks the
# `default` user with the same password
# GITHUB_TOKEN fetch private corpus repos; also used by ingest/reindex
# jobs submitted through the management API
# ANTHROPIC_API_KEY semantic extraction (claude backend) + agent chat
# OPENAI_API_KEY semantic extraction (openai backend) + agent chat
# ANTHROPIC_MODEL / OPENAI_MODEL extraction model overrides
# ANTHROPIC_BASE_URL / OPENAI_BASE_URL custom endpoints / gateways
# TPK_AGENT_PROVIDER chat agent LLM backend (anthropic/openai)
# TPK_AGENT_MODEL chat agent model override
# TPK_CHAT_AUDIT set to 0 to disable chat support-history auditing
services:
db:
# Stock timeplusd, no custom build. The two things we add — the dev
# small-segments override and the users.d provisioning (dedicated `tpk`
# user + password-locked `default`) — are bind-mounted and applied by an
# entrypoint override, so this tracks upstream timeplusd exactly (bump the
# tag; no rebuild) and swapping to OSS proton is a one-line image change.
image: docker.timeplus.com/timeplus/timeplusd:latest
container_name: tpk-db
entrypoint:
- /bin/bash
- -c
# users.d ships read-only even to its owner (UID 101, the runtime user);
# the owner can still chmod it. Run render-users via `bash` so the
# bind-mounted script needs no execute bit.
- "chmod u+w /etc/timeplusd-server/users.d && bash /opt/tpk/render-users.sh && exec /entrypoint.sh"
ports:
- "8123:8123" # SQL over HTTP (ClickHouse-compatible)
- "3218:3218" # REST ingest API
volumes:
- tpk-data:/var/lib/timeplusd
- ./deploy/timeplusd-dev/small-segments.yaml:/etc/timeplusd-server/config.d/small-segments.yaml:ro
- ./deploy/docker/render-users.sh:/opt/tpk/render-users.sh:ro
environment:
TIMEPLUS_PASSWORD: ${TIMEPLUS_PASSWORD:?TIMEPLUS_PASSWORD must be set in .env}
restart: unless-stopped
# timeplusd answers HTTP on `/` (200) before it accepts SQL; the app also
# retries the connection (db.connect_with_retry). This healthcheck gates
# `depends_on` so the app doesn't start into a refused connection on `up`.
# `/ping` is not implemented by timeplusd. wget-or-curl fallback so a
# base-image change dropping either tool can't silently wedge the app.
healthcheck:
test: ["CMD-SHELL", "wget -q -O /dev/null http://localhost:8123/ || curl -sf http://localhost:8123/ -o /dev/null || exit 1"]
interval: 5s
timeout: 3s
retries: 30
start_period: 5s
app:
build:
context: .
dockerfile: deploy/docker/Dockerfile
target: app
image: timeplus/tpk-app:dev
container_name: tpk-app
depends_on:
db:
condition: service_healthy
command: ["serve", "--host", "0.0.0.0", "--port", "8000"]
ports:
- "8000:8000"
volumes:
- tpk-checkouts:/opt/tpk/.checkouts
environment:
TIMEPLUS_HOST: db
TIMEPLUS_USER: tpk
TIMEPLUS_PASSWORD: ${TIMEPLUS_PASSWORD:?TIMEPLUS_PASSWORD must be set in .env}
TPK_AGENT_PROVIDER: ${TPK_AGENT_PROVIDER:-}
TPK_AGENT_MODEL: ${TPK_AGENT_MODEL:-}
TPK_AGENT_REASONING_EFFORT: ${TPK_AGENT_REASONING_EFFORT:-}
TPK_CHAT_AUDIT: ${TPK_CHAT_AUDIT:-}
# Global fallback daily token budget for non-admin chat (0 = unlimited);
# a role's own daily_token_limit (Users -> Roles) overrides it.
TPK_DAILY_TOKEN_LIMIT: ${TPK_DAILY_TOKEN_LIMIT:-}
TPK_ANONYMOUS_ACCESS: ${TPK_ANONYMOUS_ACCESS:-}
TPK_ANONYMOUS_DAILY_TOKEN_LIMIT: ${TPK_ANONYMOUS_DAILY_TOKEN_LIMIT:-}
TPK_MCP_HTTP_ENABLED: ${TPK_MCP_HTTP_ENABLED:-}
TPK_MCP_ALLOWED_HOSTS: ${TPK_MCP_ALLOWED_HOSTS:-}
# Semantic-extraction (graphify) backend: openai|claude|auto. `auto` is
# ambiguous when both API keys are set; model comes from OPENAI_MODEL /
# ANTHROPIC_MODEL.
TPK_EXTRACTION_BACKEND: ${TPK_EXTRACTION_BACKEND:-}
TPK_EXTRACTION_MODEL: ${TPK_EXTRACTION_MODEL:-}
ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY:-}
ANTHROPIC_BASE_URL: ${ANTHROPIC_BASE_URL:-}
ANTHROPIC_MODEL: ${ANTHROPIC_MODEL:-}
OPENAI_API_KEY: ${OPENAI_API_KEY:-}
OPENAI_BASE_URL: ${OPENAI_BASE_URL:-}
OPENAI_MODEL: ${OPENAI_MODEL:-}
GITHUB_TOKEN: ${GITHUB_TOKEN:-}
restart: unless-stopped
volumes:
tpk-data:
tpk-checkouts: