Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
121 lines (116 loc) · 4.17 KB
/
Copy pathdocker-compose.yml
File metadata and controls
121 lines (116 loc) · 4.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
# closegate — drop-in self-hosted deployment.
#
# Brings up three services from a single shared image:
#
# engine — the policy gate + MCP server (auto-seeds on first run)
# agent — the FastAPI agent loop + HITL API (publicly exposed)
# web — the Vue workspace UI (publicly exposed; proxies /api → agent)
#
# Usage:
# cp .env.example .env # edit if you want a different pack / LLM key
# docker compose up # build + start; first run takes ~3 min
# open http://localhost:5173 # the workspace
#
# docker compose down # stop, keep data
# docker compose down -v # stop + wipe the SQLite volume
#
# For SSO via a reverse proxy (SAML, mTLS), see
# `docker-compose.proxy.yml` overlay and documentation/integrations/sso-*.md.
name: closegate
services:
engine:
build:
context: .
dockerfile: deploy/Dockerfile
image: closegate:local
container_name: closegate-engine
restart: unless-stopped
environment:
SERVICE: engine
CLOSEGATE_ENV: ${CLOSEGATE_ENV:-dev}
CLOSEGATE_DB_PATH: /data/recon.db
CLOSEGATE_SEED_DIR: /app/seed
CLOSEGATE_SEED_PACK: ${CLOSEGATE_SEED_PACK:-saas}
CLOSEGATE_ENGINE_PORT: 8001
CLOSEGATE_MCP_TRANSPORT: http
CLOSEGATE_MCP_PORT: 8001
# The agent container reaches the engine by its compose service name, so
# the MCP transport must accept the `engine` Host header (FastMCP's
# DNS-rebinding guard otherwise 421s any non-localhost host).
CLOSEGATE_MCP_ALLOWED_HOSTS: ${CLOSEGATE_MCP_ALLOWED_HOSTS:-engine:*}
volumes:
- closegate-data:/data
# Engine is NOT publicly routed in production. Expose only for local
# debugging (`curl localhost:8001/healthz`); remove this in real
# deployments behind a load balancer.
ports:
- "127.0.0.1:8001:8001"
healthcheck:
test: ["CMD", "curl", "--fail", "http://127.0.0.1:8001/healthz"]
interval: 10s
timeout: 3s
start_period: 30s
retries: 5
agent:
image: closegate:local
container_name: closegate-agent
restart: unless-stopped
depends_on:
engine:
condition: service_healthy
environment:
SERVICE: agent
CLOSEGATE_ENV: ${CLOSEGATE_ENV:-dev}
CLOSEGATE_AGENT_DB_PATH: /data/agent.db
CLOSEGATE_AGENT_PORT: 8000
# Cross-container DNS: services reach each other by compose name.
CLOSEGATE_ENGINE_MCP_URL: http://engine:8001/mcp
# Live LLM is opt-in. Default to canned-response mode so the demo
# boots without an API key.
CLOSEGATE_LIVE_LLM: ${CLOSEGATE_LIVE_LLM:-0}
ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY:-}
# SSO — header-trust by default (trusts an upstream reverse proxy).
# Switch to 'oidc' + fill in CLOSEGATE_OIDC_* to validate IdP tokens.
CLOSEGATE_AUTH_BACKEND: ${CLOSEGATE_AUTH_BACKEND:-header-trust}
CLOSEGATE_OIDC_ISSUER: ${CLOSEGATE_OIDC_ISSUER:-}
CLOSEGATE_OIDC_CLIENT_ID: ${CLOSEGATE_OIDC_CLIENT_ID:-}
CLOSEGATE_OIDC_CLIENT_SECRET: ${CLOSEGATE_OIDC_CLIENT_SECRET:-}
CLOSEGATE_OIDC_REDIRECT_URI: ${CLOSEGATE_OIDC_REDIRECT_URI:-}
CLOSEGATE_SESSION_SECRET: ${CLOSEGATE_SESSION_SECRET:-}
volumes:
- closegate-data:/data
ports:
- "8000:8000"
healthcheck:
test: ["CMD", "curl", "--fail", "http://127.0.0.1:8000/healthz"]
interval: 10s
timeout: 3s
start_period: 20s
retries: 5
web:
image: closegate:local
container_name: closegate-web
restart: unless-stopped
depends_on:
agent:
condition: service_healthy
environment:
SERVICE: web
CLOSEGATE_ENV: ${CLOSEGATE_ENV:-dev}
CLOSEGATE_WEB_PORT: 5173
# Vite preview proxies /api/* — point it at the agent container.
VITE_AGENT_HOST: agent
VITE_AGENT_PORT: 8000
ports:
- "5173:5173"
healthcheck:
# `vite preview` serves the built site immediately; no /healthz endpoint
# on the web side, so we probe the index instead.
test: ["CMD", "curl", "--fail", "http://127.0.0.1:5173/"]
interval: 10s
timeout: 3s
start_period: 15s
retries: 5
volumes:
closegate-data:
name: closegate-data