Add dynamic AI Workspace run profiles
This commit is contained in:
+6
-1
@@ -59,9 +59,14 @@ AI_WORKSPACE_PG_USER=nodedc_ai_workspace
|
||||
AI_WORKSPACE_PG_PASS=change-me-generate-with-infra-scripts-init-dev-env
|
||||
AI_WORKSPACE_ASSISTANT_TOKEN=change-me-generate-with-infra-scripts-init-dev-env
|
||||
NODEDC_AI_WORKSPACE_ASSISTANT_URL=http://ai-workspace-assistant:18082
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_URL=http://host.docker.internal:4100/api/internal/v1/ai-workspace/entitlements
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN=replace-with-ops-agent-gateway-internal-token
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_REQUIRED=false
|
||||
|
||||
# AI Workspace Hub for downloaded Codex workers.
|
||||
# Default local development uses the deployed relay. Override these only for offline Hub development.
|
||||
# Default local development uses the deployed relay and is a hybrid-prod-bridge topology:
|
||||
# local UI/services can be tested, but live Codex worker write-path e2e is not proven.
|
||||
# For true local/tunnel e2e, change both Hub URLs and Ops Gateway public URL deliberately.
|
||||
AI_WORKSPACE_HUB_TOKEN=change-me-generate-with-infra-scripts-init-dev-env
|
||||
AI_WORKSPACE_HUB_HOST_BIND=127.0.0.1:18081
|
||||
AI_WORKSPACE_HUB_PUBLIC_URL=wss://ai-hub.nodedc.ru/api/ai-workspace/hub
|
||||
|
||||
+146
@@ -0,0 +1,146 @@
|
||||
#!/usr/bin/env sh
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR=$(CDPATH= cd -- "$(dirname -- "$0")" && pwd)
|
||||
PLATFORM_ROOT=$(CDPATH= cd -- "$SCRIPT_DIR/../.." && pwd)
|
||||
OPS_GATEWAY_REPO="${OPS_GATEWAY_REPO:-$PLATFORM_ROOT/../../data/NODEDC_TASKMANAGER_CODEXAPI}"
|
||||
ENGINE_REPO="${ENGINE_REPO:-$PLATFORM_ROOT/../NODEDC_ENGINE_INFRA}"
|
||||
PLATFORM_ENV="${PLATFORM_ENV:-$PLATFORM_ROOT/infra/.env}"
|
||||
|
||||
passed=0
|
||||
failed=0
|
||||
warnings=0
|
||||
|
||||
section() {
|
||||
printf '\n== %s ==\n' "$1"
|
||||
}
|
||||
|
||||
pass() {
|
||||
passed=$((passed + 1))
|
||||
printf 'PASS %s\n' "$1"
|
||||
}
|
||||
|
||||
fail() {
|
||||
failed=$((failed + 1))
|
||||
printf 'FAIL %s\n' "$1" >&2
|
||||
}
|
||||
|
||||
warn() {
|
||||
warnings=$((warnings + 1))
|
||||
printf 'WARN %s\n' "$1" >&2
|
||||
}
|
||||
|
||||
require_file() {
|
||||
file="$1"
|
||||
label="$2"
|
||||
if [ -f "$file" ]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label (missing file: $file)"
|
||||
fi
|
||||
}
|
||||
|
||||
require_contains() {
|
||||
file="$1"
|
||||
needle="$2"
|
||||
label="$3"
|
||||
if [ ! -f "$file" ]; then
|
||||
fail "$label (missing file: $file)"
|
||||
return 0
|
||||
fi
|
||||
if grep -Fq "$needle" "$file"; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label (missing: $needle)"
|
||||
fi
|
||||
}
|
||||
|
||||
read_env() {
|
||||
file="$1"
|
||||
key="$2"
|
||||
if [ ! -f "$file" ]; then
|
||||
return 0
|
||||
fi
|
||||
awk -F= -v key="$key" '
|
||||
$0 ~ "^[[:space:]]*#" { next }
|
||||
$1 == key {
|
||||
value = substr($0, index($0, "=") + 1)
|
||||
gsub(/^[[:space:]]+|[[:space:]]+$/, "", value)
|
||||
gsub(/^"|"$/, "", value)
|
||||
print value
|
||||
exit
|
||||
}
|
||||
' "$file"
|
||||
}
|
||||
|
||||
require_env_value() {
|
||||
file="$1"
|
||||
key="$2"
|
||||
expected="$3"
|
||||
label="$4"
|
||||
actual=$(read_env "$file" "$key" || true)
|
||||
if [ "$actual" = "$expected" ]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label (expected $key=$expected, got ${actual:-<missing>})"
|
||||
fi
|
||||
}
|
||||
|
||||
section "Required files"
|
||||
require_file "$PLATFORM_ROOT/infra/.env.example" "Platform local env example exists"
|
||||
require_file "$PLATFORM_ROOT/infra/synology/.env.synology.example" "Platform Synology env example exists"
|
||||
require_file "$PLATFORM_ROOT/infra/docker-compose.dev.yml" "Platform local compose exists"
|
||||
require_file "$PLATFORM_ROOT/infra/synology/docker-compose.platform-http.yml" "Platform Synology compose exists"
|
||||
require_file "$OPS_GATEWAY_REPO/.env.example" "Ops Gateway local env example exists"
|
||||
require_file "$OPS_GATEWAY_REPO/.env.synology.example" "Ops Gateway Synology env example exists"
|
||||
require_file "$OPS_GATEWAY_REPO/docker-compose.local.yml" "Ops Gateway local compose exists"
|
||||
require_file "$OPS_GATEWAY_REPO/docker-compose.synology.yml" "Ops Gateway Synology compose exists"
|
||||
require_file "$ENGINE_REPO/docker-compose.yml" "Engine compose exists"
|
||||
|
||||
section "Platform local contract"
|
||||
require_env_value "$PLATFORM_ROOT/infra/.env.example" "AI_WORKSPACE_OPS_ENTITLEMENT_URL" "http://host.docker.internal:4100/api/internal/v1/ai-workspace/entitlements" "Local Platform example points Ops entitlement to local Gateway"
|
||||
require_env_value "$PLATFORM_ROOT/infra/.env.example" "AI_WORKSPACE_HUB_PUBLIC_URL" "wss://ai-hub.nodedc.ru/api/ai-workspace/hub" "Local Platform example keeps deployed Hub as hybrid worker relay by default"
|
||||
require_env_value "$PLATFORM_ROOT/infra/.env.example" "AI_WORKSPACE_HUB_INTERNAL_URL" "https://ai-hub.nodedc.ru" "Local Platform example has explicit Hub internal URL"
|
||||
require_contains "$PLATFORM_ROOT/infra/scripts/init-dev-env.sh" "AI_WORKSPACE_OPS_ENTITLEMENT_URL=http://host.docker.internal:4100/api/internal/v1/ai-workspace/entitlements" "Local env generator emits local Ops entitlement URL"
|
||||
require_contains "$PLATFORM_ROOT/infra/scripts/init-dev-env.sh" "AI_WORKSPACE_HUB_INTERNAL_URL=https://ai-hub.nodedc.ru" "Local env generator emits explicit Hub internal URL"
|
||||
|
||||
section "Platform Synology contract"
|
||||
require_env_value "$PLATFORM_ROOT/infra/synology/.env.synology.example" "NODEDC_AI_WORKSPACE_ASSISTANT_URL" "http://ai-workspace-assistant:18082" "Synology Platform exposes Assistant to app services on compose network"
|
||||
require_env_value "$PLATFORM_ROOT/infra/synology/.env.synology.example" "AI_WORKSPACE_OPS_ENTITLEMENT_URL" "http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements" "Synology Platform points Ops entitlement to Synology Gateway"
|
||||
require_env_value "$PLATFORM_ROOT/infra/synology/.env.synology.example" "AI_WORKSPACE_HUB_PUBLIC_URL" "wss://ai-hub.nodedc.ru/api/ai-workspace/hub" "Synology Platform worker-facing Hub URL is public relay"
|
||||
require_env_value "$PLATFORM_ROOT/infra/synology/.env.synology.example" "AI_WORKSPACE_HUB_INTERNAL_URL" "https://ai-hub.nodedc.ru" "Synology Platform backend Hub URL is explicit"
|
||||
require_contains "$PLATFORM_ROOT/infra/synology/verify-current-runtime.sh" 'AI_WORKSPACE_OPS_ENTITLEMENT_URL" = "http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements"' "Synology verify checks Ops entitlement URL"
|
||||
|
||||
section "Ops Gateway contract"
|
||||
require_env_value "$OPS_GATEWAY_REPO/.env.example" "NODEDC_AGENT_GATEWAY_PUBLIC_URL" "https://ops-agents.nodedc.ru" "Ops Gateway local example keeps worker-facing MCP URL explicit"
|
||||
require_env_value "$OPS_GATEWAY_REPO/.env.example" "NODEDC_TASKER_INTERNAL_URL" "http://task.local.nodedc" "Ops Gateway local example points downstream to local Tasker"
|
||||
require_env_value "$OPS_GATEWAY_REPO/.env.synology.example" "NODEDC_AGENT_GATEWAY_PUBLIC_URL" "https://ops-agents.nodedc.ru" "Ops Gateway Synology public MCP URL is public relay"
|
||||
require_env_value "$OPS_GATEWAY_REPO/.env.synology.example" "NODEDC_TASKER_INTERNAL_URL" "http://172.22.0.222:18090" "Ops Gateway Synology downstream points to Synology Tasker"
|
||||
require_contains "$OPS_GATEWAY_REPO/docker-compose.synology.yml" '${HOST_BIND:-172.22.0.222}:${HOST_PORT:-18190}:${PORT:-4100}' "Ops Gateway Synology compose binds expected internal port"
|
||||
require_contains "$OPS_GATEWAY_REPO/README.md" "The response uses the AI Workspace adapter contract" "Ops Gateway README documents AI Workspace adapter contract"
|
||||
|
||||
section "Engine contract"
|
||||
require_contains "$ENGINE_REPO/docker-compose.yml" 'NODEDC_AI_WORKSPACE_ASSISTANT_URL: ${NODEDC_AI_WORKSPACE_ASSISTANT_URL:-http://ai-workspace-assistant:18082}' "Engine compose accepts configurable Assistant URL"
|
||||
require_contains "$ENGINE_REPO/docker-compose.yml" 'NDC_AI_WORKSPACE_HUB_URL: ${NDC_AI_WORKSPACE_HUB_URL:-wss://ai-hub.nodedc.ru/api/ai-workspace/hub}' "Engine compose accepts configurable worker-facing Hub URL"
|
||||
require_contains "$ENGINE_REPO/docker-compose.yml" 'NDC_AI_WORKSPACE_HUB_HTTP_URL: ${NDC_AI_WORKSPACE_HUB_HTTP_URL:-https://ai-hub.nodedc.ru}' "Engine compose accepts configurable Hub HTTP URL"
|
||||
require_contains "$ENGINE_REPO/nodedc-source/server/aiWorkspace/assistantRegistryClient.js" "'X-NODEDC-User-Role': role" "Engine forwards user role to Assistant"
|
||||
require_contains "$ENGINE_REPO/nodedc-source/server/aiWorkspace/assistantRegistryClient.js" "'X-NODEDC-User-Groups': groups.join(',')" "Engine forwards user groups to Assistant"
|
||||
|
||||
section "Current local env warnings"
|
||||
if [ -f "$PLATFORM_ENV" ]; then
|
||||
local_ops_entitlement=$(read_env "$PLATFORM_ENV" AI_WORKSPACE_OPS_ENTITLEMENT_URL || true)
|
||||
if [ -z "$local_ops_entitlement" ]; then
|
||||
warn "Current Platform env has no AI_WORKSPACE_OPS_ENTITLEMENT_URL; current Mac remains hybrid/contract-only until env is deliberately updated."
|
||||
else
|
||||
pass "Current Platform env has AI_WORKSPACE_OPS_ENTITLEMENT_URL"
|
||||
fi
|
||||
else
|
||||
warn "Current Platform env not found: $PLATFORM_ENV"
|
||||
fi
|
||||
|
||||
section "Summary"
|
||||
printf 'passed=%s failed=%s warnings=%s\n' "$passed" "$failed" "$warnings"
|
||||
|
||||
if [ "$failed" -ne 0 ]; then
|
||||
exit 1
|
||||
fi
|
||||
+123
@@ -0,0 +1,123 @@
|
||||
#!/usr/bin/env sh
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR=$(CDPATH= cd -- "$(dirname -- "$0")" && pwd)
|
||||
PLATFORM_ROOT=$(CDPATH= cd -- "$SCRIPT_DIR/../.." && pwd)
|
||||
AI_ASSISTANT_DIR="$PLATFORM_ROOT/services/ai-workspace-assistant"
|
||||
|
||||
OPS_GATEWAY_REPO="${OPS_GATEWAY_REPO:-$PLATFORM_ROOT/../../data/NODEDC_TASKMANAGER_CODEXAPI}"
|
||||
ENGINE_REPO="${ENGINE_REPO:-$PLATFORM_ROOT/../NODEDC_ENGINE_INFRA}"
|
||||
|
||||
RUN_GATEWAY_SMOKE="${RUN_GATEWAY_SMOKE:-1}"
|
||||
GATEWAY_DATABASE_URL="${GATEWAY_DATABASE_URL:-postgres://nodedc_agent_gateway:replace-with-local-postgres-password@localhost:54100/nodedc_agent_gateway}"
|
||||
GATEWAY_INTERNAL_TOKEN="${GATEWAY_INTERNAL_TOKEN:-replace-with-gateway-internal-token}"
|
||||
GATEWAY_RUN_TOKEN_TTL_SECONDS="${GATEWAY_RUN_TOKEN_TTL_SECONDS:-43200}"
|
||||
|
||||
passed=0
|
||||
failed=0
|
||||
skipped=0
|
||||
|
||||
section() {
|
||||
printf '\n== %s ==\n' "$1"
|
||||
}
|
||||
|
||||
pass() {
|
||||
passed=$((passed + 1))
|
||||
printf 'PASS %s\n' "$1"
|
||||
}
|
||||
|
||||
fail() {
|
||||
failed=$((failed + 1))
|
||||
printf 'FAIL %s\n' "$1" >&2
|
||||
}
|
||||
|
||||
skip() {
|
||||
skipped=$((skipped + 1))
|
||||
printf 'SKIP %s\n' "$1"
|
||||
}
|
||||
|
||||
run_in() {
|
||||
dir="$1"
|
||||
label="$2"
|
||||
command="$3"
|
||||
|
||||
if [ ! -d "$dir" ]; then
|
||||
fail "$label (missing directory: $dir)"
|
||||
return 0
|
||||
fi
|
||||
|
||||
printf '\n$ %s\n' "$label"
|
||||
set +e
|
||||
(cd "$dir" && sh -lc "$command")
|
||||
status=$?
|
||||
set -e
|
||||
|
||||
if [ "$status" -eq 0 ]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label (exit $status)"
|
||||
fi
|
||||
}
|
||||
|
||||
section "AI Workspace topology classification"
|
||||
run_in "$PLATFORM_ROOT" \
|
||||
"Classify current topology" \
|
||||
"infra/scripts/check-ai-workspace-topology.sh"
|
||||
|
||||
section "Platform static and contract gates"
|
||||
run_in "$PLATFORM_ROOT" \
|
||||
"Platform shell syntax" \
|
||||
"sh -n infra/scripts/init-dev-env.sh infra/scripts/check-ai-workspace-topology.sh infra/scripts/check-ai-workspace-config-contract.sh infra/scripts/check-ai-workspace-release-gates.sh infra/synology/check-ai-workspace-apply-plan.sh infra/synology/prepare-ai-workspace-env.sh infra/synology/deploy-current.sh infra/synology/verify-current-runtime.sh infra/synology/apply-current-runtime.sh infra/synology/backup-current.sh"
|
||||
run_in "$PLATFORM_ROOT" \
|
||||
"AI Workspace config contract" \
|
||||
"infra/scripts/check-ai-workspace-config-contract.sh"
|
||||
run_in "$AI_ASSISTANT_DIR" \
|
||||
"AI Workspace Assistant server syntax" \
|
||||
"node --check src/server.mjs"
|
||||
run_in "$AI_ASSISTANT_DIR" \
|
||||
"AI Workspace run profile smoke" \
|
||||
"npm run smoke:run-profile"
|
||||
run_in "$PLATFORM_ROOT" \
|
||||
"Platform diff hygiene" \
|
||||
"git diff --check"
|
||||
|
||||
section "Ops Gateway static and vertical gates"
|
||||
if [ -d "$OPS_GATEWAY_REPO" ]; then
|
||||
run_in "$OPS_GATEWAY_REPO" \
|
||||
"Ops Gateway TypeScript check" \
|
||||
"npm run check"
|
||||
run_in "$OPS_GATEWAY_REPO" \
|
||||
"Ops Gateway build" \
|
||||
"npm run build"
|
||||
if [ "$RUN_GATEWAY_SMOKE" = "1" ]; then
|
||||
run_in "$OPS_GATEWAY_REPO" \
|
||||
"Ops Gateway smoke" \
|
||||
"DATABASE_URL='$GATEWAY_DATABASE_URL' NODEDC_AGENT_GATEWAY_INTERNAL_TOKEN='$GATEWAY_INTERNAL_TOKEN' NODEDC_AI_WORKSPACE_RUN_TOKEN_TTL_SECONDS='$GATEWAY_RUN_TOKEN_TTL_SECONDS' npm run smoke:gateway"
|
||||
else
|
||||
skip "Ops Gateway smoke (RUN_GATEWAY_SMOKE=$RUN_GATEWAY_SMOKE)"
|
||||
fi
|
||||
run_in "$OPS_GATEWAY_REPO" \
|
||||
"Ops Gateway diff hygiene" \
|
||||
"git diff --check"
|
||||
else
|
||||
fail "Ops Gateway repo not found: $OPS_GATEWAY_REPO"
|
||||
fi
|
||||
|
||||
section "Engine static gates"
|
||||
if [ -d "$ENGINE_REPO" ]; then
|
||||
run_in "$ENGINE_REPO" \
|
||||
"Engine AI Workspace client syntax" \
|
||||
"node --check nodedc-source/server/aiWorkspace/assistantRegistryClient.js"
|
||||
run_in "$ENGINE_REPO" \
|
||||
"Engine diff hygiene" \
|
||||
"git diff --check"
|
||||
else
|
||||
fail "Engine repo not found: $ENGINE_REPO"
|
||||
fi
|
||||
|
||||
section "Summary"
|
||||
printf 'passed=%s failed=%s skipped=%s\n' "$passed" "$failed" "$skipped"
|
||||
|
||||
if [ "$failed" -ne 0 ]; then
|
||||
exit 1
|
||||
fi
|
||||
Executable
+194
@@ -0,0 +1,194 @@
|
||||
#!/usr/bin/env sh
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR=$(CDPATH= cd -- "$(dirname -- "$0")" && pwd)
|
||||
INFRA_DIR=$(CDPATH= cd -- "$SCRIPT_DIR/.." && pwd)
|
||||
PLATFORM_ENV="${PLATFORM_ENV:-$INFRA_DIR/.env}"
|
||||
|
||||
ASSISTANT_URL="${ASSISTANT_URL:-http://127.0.0.1:18082}"
|
||||
HUB_URL="${HUB_URL:-http://127.0.0.1:18081}"
|
||||
GATEWAY_URL="${GATEWAY_URL:-http://127.0.0.1:4100}"
|
||||
TASK_URL="${TASK_URL:-http://task.local.nodedc/}"
|
||||
ENGINE_URL="${ENGINE_URL:-http://127.0.0.1:5300/}"
|
||||
|
||||
read_env() {
|
||||
file="$1"
|
||||
key="$2"
|
||||
if [ ! -f "$file" ]; then
|
||||
return 0
|
||||
fi
|
||||
awk -F= -v key="$key" '
|
||||
$0 ~ "^[[:space:]]*#" { next }
|
||||
$1 == key {
|
||||
value = substr($0, index($0, "=") + 1)
|
||||
gsub(/^[[:space:]]+|[[:space:]]+$/, "", value)
|
||||
gsub(/^"|"$/, "", value)
|
||||
print value
|
||||
exit
|
||||
}
|
||||
' "$file"
|
||||
}
|
||||
|
||||
http_status() {
|
||||
url="$1"
|
||||
curl -k -sS -o /dev/null -w "%{http_code}" --max-time 3 "$url" 2>/dev/null || true
|
||||
}
|
||||
|
||||
http_body() {
|
||||
url="$1"
|
||||
curl -k -sS --max-time 3 "$url" 2>/dev/null || true
|
||||
}
|
||||
|
||||
ok_status() {
|
||||
code="$1"
|
||||
case "$code" in
|
||||
2*|3*) printf true ;;
|
||||
*) printf false ;;
|
||||
esac
|
||||
}
|
||||
|
||||
json_number() {
|
||||
key="$1"
|
||||
sed -n "s/.*\"$key\"[[:space:]]*:[[:space:]]*\\([0-9][0-9]*\\).*/\\1/p" | head -n 1
|
||||
}
|
||||
|
||||
url_kind() {
|
||||
value="$1"
|
||||
case "$value" in
|
||||
"")
|
||||
printf missing
|
||||
;;
|
||||
*127.0.0.1*|*localhost*|*host.docker.internal*|*".local.nodedc"*|*ai-workspace-hub*|*agent-gateway*)
|
||||
printf local
|
||||
;;
|
||||
*100.[6-9][0-9].*|*100.1[01][0-9].*|*100.12[0-7].*|*.ts.net*)
|
||||
printf tailscale
|
||||
;;
|
||||
*172.22.0.222*|*".nas.nodedc"*)
|
||||
printf synology-lan
|
||||
;;
|
||||
*ai-hub.nodedc.ru*|*ops-agents.nodedc.ru*|*hub.nodedc.ru*|*ops.nodedc.ru*)
|
||||
printf prod-public
|
||||
;;
|
||||
http://172.*|http://192.168.*|http://10.*)
|
||||
printf lan
|
||||
;;
|
||||
*)
|
||||
printf custom
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
bool_and() {
|
||||
left="$1"
|
||||
right="$2"
|
||||
if [ "$left" = true ] && [ "$right" = true ]; then
|
||||
printf true
|
||||
else
|
||||
printf false
|
||||
fi
|
||||
}
|
||||
|
||||
assistant_code=$(http_status "$ASSISTANT_URL/healthz")
|
||||
hub_body=$(http_body "$HUB_URL/healthz")
|
||||
hub_code=000
|
||||
if [ -n "$hub_body" ]; then
|
||||
hub_code=$(http_status "$HUB_URL/healthz")
|
||||
fi
|
||||
gateway_code=$(http_status "$GATEWAY_URL/readyz")
|
||||
task_code=$(http_status "$TASK_URL")
|
||||
engine_code=$(http_status "$ENGINE_URL")
|
||||
|
||||
assistant_ok=$(ok_status "$assistant_code")
|
||||
hub_ok=$(ok_status "$hub_code")
|
||||
gateway_ok=$(ok_status "$gateway_code")
|
||||
task_ok=$(ok_status "$task_code")
|
||||
engine_ok=$(ok_status "$engine_code")
|
||||
|
||||
agents_online=$(printf "%s" "$hub_body" | json_number agentsOnline)
|
||||
case "$agents_online" in
|
||||
""|*[!0-9]*) agents_online=0 ;;
|
||||
esac
|
||||
|
||||
hub_public=$(read_env "$PLATFORM_ENV" AI_WORKSPACE_HUB_PUBLIC_URL || true)
|
||||
hub_internal=$(read_env "$PLATFORM_ENV" AI_WORKSPACE_HUB_INTERNAL_URL || true)
|
||||
ops_entitlement=$(read_env "$PLATFORM_ENV" AI_WORKSPACE_OPS_ENTITLEMENT_URL || true)
|
||||
|
||||
hub_public_kind=$(url_kind "$hub_public")
|
||||
hub_internal_kind=$(url_kind "$hub_internal")
|
||||
ops_entitlement_kind=$(url_kind "$ops_entitlement")
|
||||
|
||||
local_services_ok=$(bool_and "$(bool_and "$assistant_ok" "$hub_ok")" "$(bool_and "$gateway_ok" "$task_ok")")
|
||||
worker_on_local_hub=false
|
||||
if [ "$agents_online" -gt 0 ]; then
|
||||
worker_on_local_hub=true
|
||||
fi
|
||||
|
||||
hub_runtime_kind=custom
|
||||
case "$hub_public_kind:$hub_internal_kind" in
|
||||
local:local|local:missing|missing:local) hub_runtime_kind=local ;;
|
||||
tailscale:local|tailscale:tailscale|tailscale:missing) hub_runtime_kind=tailscale ;;
|
||||
prod-public:prod-public|prod-public:missing|missing:prod-public) hub_runtime_kind=prod-public ;;
|
||||
*) hub_runtime_kind=mixed ;;
|
||||
esac
|
||||
|
||||
classification=contract-only
|
||||
if [ "$local_services_ok" = true ]; then
|
||||
if [ "$engine_ok" = true ] \
|
||||
&& [ "$worker_on_local_hub" = true ] \
|
||||
&& [ "$ops_entitlement_kind" = local ] \
|
||||
&& [ "$hub_runtime_kind" = local ]; then
|
||||
classification=true-local-e2e
|
||||
elif [ "$engine_ok" = true ] \
|
||||
&& [ "$worker_on_local_hub" = true ] \
|
||||
&& { [ "$ops_entitlement_kind" = tailscale ] || [ "$hub_runtime_kind" = tailscale ]; }; then
|
||||
classification=tunnel-local-e2e
|
||||
elif [ "$hub_runtime_kind" = prod-public ] || [ "$worker_on_local_hub" = false ]; then
|
||||
classification=hybrid-prod-bridge
|
||||
else
|
||||
classification=local-ops-vertical
|
||||
fi
|
||||
elif [ "$gateway_ok" = true ] && [ "$task_ok" = true ]; then
|
||||
classification=local-ops-vertical
|
||||
elif [ "$task_ok" = true ] || [ "$engine_ok" = true ]; then
|
||||
classification=local-ui-only
|
||||
fi
|
||||
|
||||
cat <<EOF
|
||||
classification=$classification
|
||||
platform_env=$PLATFORM_ENV
|
||||
assistant_health=$assistant_ok status=$assistant_code url=$ASSISTANT_URL/healthz
|
||||
hub_health=$hub_ok status=$hub_code url=$HUB_URL/healthz agents_online=$agents_online
|
||||
gateway_health=$gateway_ok status=$gateway_code url=$GATEWAY_URL/readyz
|
||||
task_health=$task_ok status=$task_code url=$TASK_URL
|
||||
engine_health=$engine_ok status=$engine_code url=$ENGINE_URL
|
||||
hub_public_kind=$hub_public_kind
|
||||
hub_internal_kind=$hub_internal_kind
|
||||
hub_runtime_kind=$hub_runtime_kind
|
||||
ops_entitlement_kind=$ops_entitlement_kind
|
||||
EOF
|
||||
|
||||
case "$classification" in
|
||||
true-local-e2e|tunnel-local-e2e)
|
||||
echo "meaning=local write-path e2e can be interpreted if the worker can reach returned MCP URLs"
|
||||
;;
|
||||
hybrid-prod-bridge)
|
||||
echo "meaning=do not treat UI dialog as local write-path proof; worker/HUB/MCP topology is mixed"
|
||||
;;
|
||||
local-ops-vertical)
|
||||
echo "meaning=Gateway and Tasker local vertical checks are valid, but no live Codex worker e2e is proven"
|
||||
;;
|
||||
local-ui-only)
|
||||
echo "meaning=local UI/proxy is reachable, but AI Workspace write path is not proven"
|
||||
;;
|
||||
*)
|
||||
echo "meaning=contract tests only; no runtime topology is proven"
|
||||
;;
|
||||
esac
|
||||
|
||||
if [ "${REQUIRE_TRUE_E2E:-0}" = "1" ]; then
|
||||
case "$classification" in
|
||||
true-local-e2e|tunnel-local-e2e) exit 0 ;;
|
||||
*) exit 2 ;;
|
||||
esac
|
||||
fi
|
||||
@@ -60,14 +60,20 @@ NODEDC_INTERNAL_ACCESS_TOKEN=$(openssl rand -hex 48 | tr -d '\n')
|
||||
COOKIE_DOMAIN=.local.nodedc
|
||||
COOKIE_SECURE=false
|
||||
|
||||
# AI Workspace shared registry and Hub
|
||||
# AI Workspace shared registry and Hub.
|
||||
# Generated local env uses the deployed relay by default. This is suitable for
|
||||
# UI/contract smoke, not proof of local live-worker write-path e2e.
|
||||
AI_WORKSPACE_PG_DB=nodedc_ai_workspace
|
||||
AI_WORKSPACE_PG_USER=nodedc_ai_workspace
|
||||
AI_WORKSPACE_PG_PASS=$(rand 36)
|
||||
AI_WORKSPACE_ASSISTANT_TOKEN=$(openssl rand -hex 48 | tr -d '\n')
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_URL=http://host.docker.internal:4100/api/internal/v1/ai-workspace/entitlements
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN=replace-with-ops-agent-gateway-internal-token
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_REQUIRED=false
|
||||
AI_WORKSPACE_HUB_TOKEN=$(openssl rand -hex 48 | tr -d '\n')
|
||||
AI_WORKSPACE_HUB_HOST_BIND=127.0.0.1:18081
|
||||
AI_WORKSPACE_HUB_PUBLIC_URL=wss://ai-hub.nodedc.ru/api/ai-workspace/hub
|
||||
AI_WORKSPACE_HUB_INTERNAL_URL=https://ai-hub.nodedc.ru
|
||||
AI_WORKSPACE_HUB_FALLBACK_URLS=
|
||||
EOF
|
||||
|
||||
|
||||
@@ -62,6 +62,9 @@ AI_WORKSPACE_PG_USER=nodedc_ai_workspace
|
||||
AI_WORKSPACE_PG_PASS=replace-with-random-synology-secret
|
||||
AI_WORKSPACE_ASSISTANT_TOKEN=replace-with-random-synology-secret
|
||||
NODEDC_AI_WORKSPACE_ASSISTANT_URL=http://ai-workspace-assistant:18082
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_URL=http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN=replace-with-ops-agent-gateway-internal-token
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_REQUIRED=false
|
||||
|
||||
AI_WORKSPACE_HUB_TOKEN=replace-with-random-synology-secret
|
||||
AI_WORKSPACE_HUB_HOST_BIND=0.0.0.0:18081
|
||||
|
||||
@@ -47,6 +47,14 @@ AI_WORKSPACE_HUB_FALLBACK_URLS=
|
||||
|
||||
Server-side Hub API calls, including executor status checks, use `AI_WORKSPACE_HUB_INTERNAL_URL` and require a token accepted by Hub: `AI_WORKSPACE_HUB_TOKEN`, `NDC_AI_WORKSPACE_HUB_TOKEN`, or the shared `NODEDC_INTERNAL_ACCESS_TOKEN` where that token is intentionally common across platform services.
|
||||
|
||||
AI Workspace Assistant also calls product entitlement adapters before every Codex run. Ops uses the Agent Gateway internal endpoint; the token must match `NODEDC_AGENT_GATEWAY_INTERNAL_TOKEN` from the Ops Agent Gateway deployment:
|
||||
|
||||
```env
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_URL=http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN=<same value as Ops NODEDC_AGENT_GATEWAY_INTERNAL_TOKEN>
|
||||
AI_WORKSPACE_OPS_ENTITLEMENT_REQUIRED=false
|
||||
```
|
||||
|
||||
## Локальные домены для первичной проверки
|
||||
|
||||
На Mac для первичной проверки добавить в `/etc/hosts`:
|
||||
@@ -137,6 +145,8 @@ GATEWAY_REPO=/Users/dcconstructions/Downloads/mnt/data/NODEDC_TASKMANAGER_CODEXA
|
||||
|
||||
Скрипт не запускает Docker сам: на NAS `sudo` интерактивный, поэтому команды применения печатаются в конце.
|
||||
|
||||
По умолчанию sync source-копий на SMB/NAS не сохраняет owner/group/perms/times. Для Docker build важен контент, а macOS/Synology metadata может падать на `utimensat Operation timed out`. Если metadata действительно нужно сохранить для отдельного ручного случая, запускать с `RSYNC_PRESERVE_METADATA=1`.
|
||||
|
||||
Что синхронизируется:
|
||||
|
||||
- Platform compose/Caddy.
|
||||
|
||||
@@ -57,6 +57,10 @@ echo "== ai workspace assistant hub target check =="
|
||||
"${DOCKER_BIN}" exec nodedc-platform-ai-workspace-assistant-1 sh -lc \
|
||||
'test "$AI_WORKSPACE_HUB_PUBLIC_URL" = "wss://ai-hub.nodedc.ru/api/ai-workspace/hub" && test -z "$AI_WORKSPACE_HUB_FALLBACK_URLS" && echo ai-workspace-prod-hub-target-ok'
|
||||
|
||||
echo "== ai workspace assistant Ops entitlement adapter check =="
|
||||
"${DOCKER_BIN}" exec nodedc-platform-ai-workspace-assistant-1 sh -lc \
|
||||
'test "$AI_WORKSPACE_OPS_ENTITLEMENT_URL" = "http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements" && test -n "$AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN" && echo ai-workspace-ops-entitlement-env-ok'
|
||||
|
||||
echo "== clear authentik global brand css =="
|
||||
DOCKER_BIN="${DOCKER_BIN}" bash "${PLATFORM_DIR}/clear-authentik-brand-css.sh"
|
||||
|
||||
|
||||
@@ -46,6 +46,7 @@ rsync_dir "${NAS_ROOT}/authentik/custom-templates/" "${BACKUP_DIR}/files/authent
|
||||
rsync_dir "${NAS_ROOT}/platform/authentik/" "${BACKUP_DIR}/files/platform/authentik/"
|
||||
rsync_dir "${NAS_ROOT}/platform/notification-core/" "${BACKUP_DIR}/files/platform/notification-core/"
|
||||
rsync_dir "${NAS_ROOT}/platform/ai-workspace-hub/" "${BACKUP_DIR}/files/platform/ai-workspace-hub/"
|
||||
rsync_dir "${NAS_ROOT}/platform/ai-workspace-assistant/" "${BACKUP_DIR}/files/platform/ai-workspace-assistant/"
|
||||
|
||||
rsync_file "${NAS_ROOT}/platform/.env.synology" "${BACKUP_DIR}/files/platform/"
|
||||
rsync_file "${NAS_ROOT}/platform/.env.synology.example" "${BACKUP_DIR}/files/platform/"
|
||||
@@ -73,6 +74,7 @@ Contains:
|
||||
- Platform runtime config: platform/.env.synology, compose, Caddyfile
|
||||
- Notification Core source/config: platform/notification-core, platform compose/env
|
||||
- AI Workspace Hub source/config: platform/ai-workspace-hub, platform compose/env
|
||||
- AI Workspace Assistant source/config: platform/ai-workspace-assistant, platform compose/env
|
||||
- Tasker runtime config: tasker/plane-app/.env.synology, compose, Synology override
|
||||
- Ops Agents Gateway runtime config: ops-agents/.env, compose
|
||||
|
||||
@@ -101,8 +103,24 @@ sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file "${ENV_FILE}" \\
|
||||
-f "${COMPOSE_FILE}" \\
|
||||
exec -T postgresql-authentik \\
|
||||
sh -lc 'pg_restore --list /dev/stdin >/dev/null' \\
|
||||
< "\${BACKUP_DIR}/authentik-postgres.dump"
|
||||
rm -f /tmp/authentik-postgres.dump
|
||||
|
||||
sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file "${ENV_FILE}" \\
|
||||
-f "${COMPOSE_FILE}" \\
|
||||
cp "\${BACKUP_DIR}/authentik-postgres.dump" postgresql-authentik:/tmp/authentik-postgres.dump
|
||||
|
||||
sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file "${ENV_FILE}" \\
|
||||
-f "${COMPOSE_FILE}" \\
|
||||
exec -T postgresql-authentik \\
|
||||
pg_restore --list /tmp/authentik-postgres.dump >/dev/null
|
||||
|
||||
sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file "${ENV_FILE}" \\
|
||||
-f "${COMPOSE_FILE}" \\
|
||||
exec -T postgresql-authentik \\
|
||||
rm -f /tmp/authentik-postgres.dump
|
||||
|
||||
if command -v sha256sum >/dev/null 2>&1; then
|
||||
(cd "\${BACKUP_DIR}" && sha256sum authentik-postgres.dump > SHA256SUMS)
|
||||
@@ -132,8 +150,24 @@ sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file "${ENV_FILE}" \\
|
||||
-f "${COMPOSE_FILE}" \\
|
||||
exec -T notification-postgres \\
|
||||
sh -lc 'pg_restore --list /dev/stdin >/dev/null' \\
|
||||
< "\${BACKUP_DIR}/notification-postgres.dump"
|
||||
rm -f /tmp/notification-postgres.dump
|
||||
|
||||
sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file "${ENV_FILE}" \\
|
||||
-f "${COMPOSE_FILE}" \\
|
||||
cp "\${BACKUP_DIR}/notification-postgres.dump" notification-postgres:/tmp/notification-postgres.dump
|
||||
|
||||
sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file "${ENV_FILE}" \\
|
||||
-f "${COMPOSE_FILE}" \\
|
||||
exec -T notification-postgres \\
|
||||
pg_restore --list /tmp/notification-postgres.dump >/dev/null
|
||||
|
||||
sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file "${ENV_FILE}" \\
|
||||
-f "${COMPOSE_FILE}" \\
|
||||
exec -T notification-postgres \\
|
||||
rm -f /tmp/notification-postgres.dump
|
||||
|
||||
echo "notification-db-dump-ok: \${BACKUP_DIR}/notification-postgres.dump"
|
||||
EOF
|
||||
@@ -158,8 +192,18 @@ sudo "${DOCKER_BIN}" "\${compose_args[@]}" \\
|
||||
|
||||
sudo "${DOCKER_BIN}" "\${compose_args[@]}" \\
|
||||
exec -T plane-db \\
|
||||
sh -lc 'pg_restore --list /dev/stdin >/dev/null' \\
|
||||
< "\${BACKUP_DIR}/tasker-postgres.dump"
|
||||
rm -f /tmp/tasker-postgres.dump
|
||||
|
||||
sudo "${DOCKER_BIN}" "\${compose_args[@]}" \\
|
||||
cp "\${BACKUP_DIR}/tasker-postgres.dump" plane-db:/tmp/tasker-postgres.dump
|
||||
|
||||
sudo "${DOCKER_BIN}" "\${compose_args[@]}" \\
|
||||
exec -T plane-db \\
|
||||
pg_restore --list /tmp/tasker-postgres.dump >/dev/null
|
||||
|
||||
sudo "${DOCKER_BIN}" "\${compose_args[@]}" \\
|
||||
exec -T plane-db \\
|
||||
rm -f /tmp/tasker-postgres.dump
|
||||
|
||||
echo "tasker-db-dump-ok: \${BACKUP_DIR}/tasker-postgres.dump"
|
||||
EOF
|
||||
@@ -183,8 +227,24 @@ sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file .env \\
|
||||
-f docker-compose.synology.yml \\
|
||||
exec -T postgres \\
|
||||
sh -lc 'pg_restore --list /dev/stdin >/dev/null' \\
|
||||
< "\${BACKUP_DIR}/ops-agents-postgres.dump"
|
||||
rm -f /tmp/ops-agents-postgres.dump
|
||||
|
||||
sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file .env \\
|
||||
-f docker-compose.synology.yml \\
|
||||
cp "\${BACKUP_DIR}/ops-agents-postgres.dump" postgres:/tmp/ops-agents-postgres.dump
|
||||
|
||||
sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file .env \\
|
||||
-f docker-compose.synology.yml \\
|
||||
exec -T postgres \\
|
||||
pg_restore --list /tmp/ops-agents-postgres.dump >/dev/null
|
||||
|
||||
sudo "${DOCKER_BIN}" compose \\
|
||||
--env-file .env \\
|
||||
-f docker-compose.synology.yml \\
|
||||
exec -T postgres \\
|
||||
rm -f /tmp/ops-agents-postgres.dump
|
||||
|
||||
echo "ops-agents-db-dump-ok: \${BACKUP_DIR}/ops-agents-postgres.dump"
|
||||
EOF
|
||||
|
||||
+190
@@ -0,0 +1,190 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
SCRIPT_DIR="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)"
|
||||
PLATFORM_REPO="$(cd -- "${SCRIPT_DIR}/../.." && pwd)"
|
||||
NAS_ROOT="${NAS_ROOT:-/Volumes/docker/nodedc-platform}"
|
||||
GATEWAY_REPO="${GATEWAY_REPO:-${PLATFORM_REPO}/../../data/NODEDC_TASKMANAGER_CODEXAPI}"
|
||||
ENGINE_REPO="${ENGINE_REPO:-${PLATFORM_REPO}/../NODEDC_ENGINE_INFRA}"
|
||||
|
||||
NAS_PLATFORM_ENV="${NAS_PLATFORM_ENV:-${NAS_ROOT}/platform/.env.synology}"
|
||||
NAS_GATEWAY_ENV="${NAS_GATEWAY_ENV:-${NAS_ROOT}/ops-agents/.env}"
|
||||
|
||||
passed=0
|
||||
failed=0
|
||||
warnings=0
|
||||
|
||||
section() {
|
||||
printf '\n== %s ==\n' "$1"
|
||||
}
|
||||
|
||||
pass() {
|
||||
passed=$((passed + 1))
|
||||
printf 'PASS %s\n' "$1"
|
||||
}
|
||||
|
||||
fail() {
|
||||
failed=$((failed + 1))
|
||||
printf 'FAIL %s\n' "$1" >&2
|
||||
}
|
||||
|
||||
warn() {
|
||||
warnings=$((warnings + 1))
|
||||
printf 'WARN %s\n' "$1" >&2
|
||||
}
|
||||
|
||||
read_env() {
|
||||
local file="$1"
|
||||
local key="$2"
|
||||
[[ -f "${file}" ]] || return 0
|
||||
awk -F= -v key="${key}" '
|
||||
$0 ~ "^[[:space:]]*#" { next }
|
||||
$1 == key {
|
||||
value = substr($0, index($0, "=") + 1)
|
||||
gsub(/^[[:space:]]+|[[:space:]]+$/, "", value)
|
||||
gsub(/^"|"$/, "", value)
|
||||
print value
|
||||
exit
|
||||
}
|
||||
' "${file}"
|
||||
}
|
||||
|
||||
require_path() {
|
||||
local path="$1"
|
||||
local label="$2"
|
||||
if [[ -e "${path}" ]]; then
|
||||
pass "${label}"
|
||||
else
|
||||
fail "${label} (missing: ${path})"
|
||||
fi
|
||||
}
|
||||
|
||||
require_file_contains() {
|
||||
local file="$1"
|
||||
local needle="$2"
|
||||
local label="$3"
|
||||
if [[ ! -f "${file}" ]]; then
|
||||
fail "${label} (missing file: ${file})"
|
||||
return
|
||||
fi
|
||||
if grep -Fq "${needle}" "${file}"; then
|
||||
pass "${label}"
|
||||
else
|
||||
fail "${label} (missing: ${needle})"
|
||||
fi
|
||||
}
|
||||
|
||||
require_env_value() {
|
||||
local file="$1"
|
||||
local key="$2"
|
||||
local expected="$3"
|
||||
local label="$4"
|
||||
local actual
|
||||
actual="$(read_env "${file}" "${key}" || true)"
|
||||
if [[ "${actual}" == "${expected}" ]]; then
|
||||
pass "${label}"
|
||||
else
|
||||
fail "${label} (expected ${key}=${expected}, got ${actual:-<missing>})"
|
||||
fi
|
||||
}
|
||||
|
||||
require_env_nonempty() {
|
||||
local file="$1"
|
||||
local key="$2"
|
||||
local label="$3"
|
||||
local actual
|
||||
actual="$(read_env "${file}" "${key}" || true)"
|
||||
if [[ -n "${actual}" && "${actual}" != replace-with-* && "${actual}" != change-me-* ]]; then
|
||||
pass "${label}"
|
||||
else
|
||||
fail "${label} (${key} missing or placeholder)"
|
||||
fi
|
||||
}
|
||||
|
||||
section "Local prerequisites"
|
||||
require_path "${NAS_ROOT}" "NAS mount exists"
|
||||
require_path "${GATEWAY_REPO}" "Ops Gateway repo exists"
|
||||
require_path "${ENGINE_REPO}" "Engine repo exists"
|
||||
require_path "${PLATFORM_REPO}/infra/scripts/check-ai-workspace-release-gates.sh" "Predeploy gate runner exists"
|
||||
require_path "${PLATFORM_REPO}/infra/scripts/check-ai-workspace-config-contract.sh" "Config contract checker exists"
|
||||
require_path "${PLATFORM_REPO}/infra/synology/backup-current.sh" "Synology backup script exists"
|
||||
require_path "${PLATFORM_REPO}/infra/synology/apply-current-runtime.sh" "Synology apply script exists"
|
||||
require_path "${PLATFORM_REPO}/infra/synology/verify-current-runtime.sh" "Synology verify script exists"
|
||||
|
||||
section "Source and migration audit"
|
||||
require_path "${PLATFORM_REPO}/services/ai-workspace-assistant/src/server.mjs" "AI Workspace Assistant source present"
|
||||
require_path "${PLATFORM_REPO}/services/ai-workspace-assistant/src/templates/install-windows.ps1" "Worker installer template present"
|
||||
require_path "${GATEWAY_REPO}/migrations/004_run_grants.sql" "Ops Gateway token-scoped run grants migration present"
|
||||
require_file_contains "${GATEWAY_REPO}/docker-entrypoint.sh" "npm run migrate:dist" "Ops Gateway image applies migrations on startup"
|
||||
require_file_contains "${PLATFORM_REPO}/infra/synology/backup-current.sh" "ai-workspace-assistant" "Backup includes AI Workspace Assistant source"
|
||||
require_file_contains "${PLATFORM_REPO}/infra/synology/deploy-current.sh" "RSYNC_METADATA_ARGS" "Deploy sync avoids fragile NAS metadata by default"
|
||||
require_file_contains "${PLATFORM_REPO}/infra/synology/apply-current-runtime.sh" "ai-workspace-ops-entitlement-env-ok" "Apply verifies Ops entitlement env"
|
||||
require_file_contains "${PLATFORM_REPO}/infra/synology/verify-current-runtime.sh" "ai-workspace-ops-entitlement-env-ok" "Verify checks Ops entitlement env"
|
||||
|
||||
section "NAS env readiness"
|
||||
if [[ -f "${NAS_PLATFORM_ENV}" ]]; then
|
||||
pass "NAS Platform env exists"
|
||||
require_env_value "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_HUB_PUBLIC_URL" "wss://ai-hub.nodedc.ru/api/ai-workspace/hub" "NAS Platform worker-facing Hub URL"
|
||||
require_env_value "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_HUB_INTERNAL_URL" "https://ai-hub.nodedc.ru" "NAS Platform internal Hub URL"
|
||||
require_env_value "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_HUB_FALLBACK_URLS" "" "NAS Platform Hub fallback URLs disabled"
|
||||
require_env_value "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_OPS_ENTITLEMENT_URL" "http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements" "NAS Platform Ops entitlement URL"
|
||||
require_env_nonempty "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN" "NAS Platform Ops entitlement token configured"
|
||||
require_env_nonempty "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_ASSISTANT_TOKEN" "NAS Platform Assistant token configured"
|
||||
require_env_nonempty "${NAS_PLATFORM_ENV}" "AI_WORKSPACE_HUB_TOKEN" "NAS Platform Hub token configured"
|
||||
else
|
||||
fail "NAS Platform env missing: ${NAS_PLATFORM_ENV}"
|
||||
fi
|
||||
|
||||
if [[ -f "${NAS_GATEWAY_ENV}" ]]; then
|
||||
pass "NAS Ops Gateway env exists"
|
||||
require_env_value "${NAS_GATEWAY_ENV}" "NODEDC_AGENT_GATEWAY_PUBLIC_URL" "https://ops-agents.nodedc.ru" "NAS Gateway worker-facing MCP URL"
|
||||
require_env_value "${NAS_GATEWAY_ENV}" "NODEDC_TASKER_INTERNAL_URL" "http://172.22.0.222:18090" "NAS Gateway downstream Tasker URL"
|
||||
require_env_value "${NAS_GATEWAY_ENV}" "NODEDC_AI_WORKSPACE_RUN_TOKEN_TTL_SECONDS" "43200" "NAS Gateway AI Workspace run token TTL"
|
||||
require_env_nonempty "${NAS_GATEWAY_ENV}" "NODEDC_AGENT_GATEWAY_INTERNAL_TOKEN" "NAS Gateway internal token configured"
|
||||
require_env_nonempty "${NAS_GATEWAY_ENV}" "NODEDC_INTERNAL_ACCESS_TOKEN" "NAS Gateway Tasker internal token configured"
|
||||
require_env_nonempty "${NAS_GATEWAY_ENV}" "POSTGRES_PASSWORD" "NAS Gateway Postgres password configured"
|
||||
else
|
||||
fail "NAS Ops Gateway env missing: ${NAS_GATEWAY_ENV}"
|
||||
fi
|
||||
|
||||
section "Controlled apply order"
|
||||
cat <<EOF
|
||||
1. Run local predeploy gate:
|
||||
cd ${PLATFORM_REPO}
|
||||
infra/scripts/check-ai-workspace-release-gates.sh
|
||||
|
||||
2. Create file backup from mounted NAS share:
|
||||
cd ${PLATFORM_REPO}
|
||||
NAS_ROOT=${NAS_ROOT} infra/synology/backup-current.sh
|
||||
|
||||
3. On Synology, run DB dumps from the backup folder:
|
||||
bash /volume1/docker/nodedc-platform/backups/<backup-id>/run-authentik-db-dump-on-synology.sh
|
||||
bash /volume1/docker/nodedc-platform/backups/<backup-id>/run-notification-db-dump-on-synology.sh
|
||||
bash /volume1/docker/nodedc-platform/backups/<backup-id>/run-ops-agents-db-dump-on-synology.sh
|
||||
# Tasker DB dump only if Tasker backend/schema changes are included:
|
||||
bash /volume1/docker/nodedc-platform/backups/<backup-id>/run-tasker-db-dump-on-synology.sh
|
||||
|
||||
4. Sync source to NAS mount:
|
||||
cd ${PLATFORM_REPO}
|
||||
NAS_ROOT=${NAS_ROOT} GATEWAY_REPO=${GATEWAY_REPO} infra/synology/deploy-current.sh
|
||||
|
||||
5. Apply Ops Gateway first on Synology:
|
||||
cd /volume1/docker/nodedc-platform/ops-agents
|
||||
sudo /usr/local/bin/docker compose --env-file .env -f docker-compose.synology.yml up -d --build --force-recreate
|
||||
curl -fsS http://172.22.0.222:18190/readyz
|
||||
|
||||
6. Apply Platform AI Workspace services on Synology:
|
||||
cd /volume1/docker/nodedc-platform/platform
|
||||
sudo bash apply-current-runtime.sh
|
||||
|
||||
7. Verify runtime:
|
||||
cd /volume1/docker/nodedc-platform/platform
|
||||
sudo bash verify-current-runtime.sh
|
||||
EOF
|
||||
|
||||
section "Summary"
|
||||
printf 'passed=%s failed=%s warnings=%s\n' "${passed}" "${failed}" "${warnings}"
|
||||
|
||||
if [[ "${failed}" -ne 0 ]]; then
|
||||
exit 1
|
||||
fi
|
||||
@@ -11,6 +11,11 @@ TASKER_CHANGED_BASE="${TASKER_CHANGED_BASE:-}"
|
||||
GATEWAY_REPO="${GATEWAY_REPO:-}"
|
||||
SYNC_AUTHENTIK_TEMPLATES="${SYNC_AUTHENTIK_TEMPLATES:-0}"
|
||||
|
||||
RSYNC_METADATA_ARGS=()
|
||||
if [[ "${RSYNC_PRESERVE_METADATA:-0}" != "1" ]]; then
|
||||
RSYNC_METADATA_ARGS=(--no-times --no-perms --no-owner --no-group)
|
||||
fi
|
||||
|
||||
if [[ ! -d "${NAS_ROOT}" ]]; then
|
||||
echo "NAS_ROOT not found: ${NAS_ROOT}" >&2
|
||||
echo "Set NAS_ROOT=/path/to/nodedc-platform when the Synology share is mounted elsewhere." >&2
|
||||
@@ -19,15 +24,15 @@ fi
|
||||
|
||||
mkdir -p "${NAS_ROOT}/platform"
|
||||
|
||||
rsync -av \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" \
|
||||
"${PLATFORM_REPO}/infra/synology/docker-compose.platform-http.yml" \
|
||||
"${NAS_ROOT}/platform/docker-compose.platform-http.yml"
|
||||
|
||||
rsync -av \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" \
|
||||
"${PLATFORM_REPO}/infra/synology/Caddyfile.http" \
|
||||
"${NAS_ROOT}/platform/Caddyfile.http"
|
||||
|
||||
rsync -av \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" \
|
||||
"${PLATFORM_REPO}/infra/synology/deploy-current.sh" \
|
||||
"${PLATFORM_REPO}/infra/synology/backup-current.sh" \
|
||||
"${PLATFORM_REPO}/infra/synology/apply-current-runtime.sh" \
|
||||
@@ -36,7 +41,7 @@ rsync -av \
|
||||
"${NAS_ROOT}/platform/"
|
||||
|
||||
mkdir -p "${NAS_ROOT}/platform/notification-core"
|
||||
rsync -av --delete \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \
|
||||
--exclude='node_modules/' \
|
||||
--exclude='.env' \
|
||||
--exclude='.env.*' \
|
||||
@@ -44,7 +49,7 @@ rsync -av --delete \
|
||||
"${NAS_ROOT}/platform/notification-core/"
|
||||
|
||||
mkdir -p "${NAS_ROOT}/platform/ai-workspace-hub"
|
||||
rsync -av --delete \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \
|
||||
--exclude='node_modules/' \
|
||||
--exclude='.env' \
|
||||
--exclude='.env.*' \
|
||||
@@ -52,7 +57,7 @@ rsync -av --delete \
|
||||
"${NAS_ROOT}/platform/ai-workspace-hub/"
|
||||
|
||||
mkdir -p "${NAS_ROOT}/platform/ai-workspace-assistant"
|
||||
rsync -av --delete \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \
|
||||
--exclude='node_modules/' \
|
||||
--exclude='.env' \
|
||||
--exclude='.env.*' \
|
||||
@@ -61,7 +66,7 @@ rsync -av --delete \
|
||||
|
||||
if [[ "${SYNC_AUTHENTIK_TEMPLATES}" == "1" ]]; then
|
||||
mkdir -p "${NAS_ROOT}/authentik/custom-templates"
|
||||
rsync -av --delete \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \
|
||||
"${PLATFORM_REPO}/infra/authentik/custom-templates/" \
|
||||
"${NAS_ROOT}/authentik/custom-templates/"
|
||||
else
|
||||
@@ -75,7 +80,7 @@ if [[ -n "${LAUNCHER_REPO}" ]]; then
|
||||
fi
|
||||
|
||||
mkdir -p "${NAS_ROOT}/launcher/source"
|
||||
rsync -av --delete \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \
|
||||
--exclude='.git/' \
|
||||
--exclude='node_modules/' \
|
||||
--exclude='dist/' \
|
||||
@@ -95,7 +100,7 @@ if [[ -n "${TASKER_REPO}" ]]; then
|
||||
|
||||
mkdir -p "${NAS_ROOT}/tasker/plane-src" "${NAS_ROOT}/tasker/plane-app"
|
||||
|
||||
rsync -av \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" \
|
||||
"${TASKER_REPO}/plane-app/docker-compose.yaml" \
|
||||
"${NAS_ROOT}/tasker/plane-app/docker-compose.yaml"
|
||||
|
||||
@@ -121,14 +126,14 @@ if [[ -n "${TASKER_REPO}" ]]; then
|
||||
|
||||
if [[ -f "${source_path}" ]]; then
|
||||
mkdir -p "$(dirname -- "${target_path}")"
|
||||
rsync -av "${source_path}" "${target_path}"
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" "${source_path}" "${target_path}"
|
||||
else
|
||||
echo "skip deleted Tasker file in changed sync: ${changed_file}"
|
||||
fi
|
||||
done
|
||||
elif [[ "${TASKER_SYNC_SOURCE}" == "1" ]]; then
|
||||
echo "TASKER_SYNC_SOURCE=1: syncing full Tasker source without delete"
|
||||
rsync -av \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" \
|
||||
--exclude='.git/' \
|
||||
--exclude='node_modules/' \
|
||||
--exclude='.pnpm-store/' \
|
||||
@@ -153,7 +158,7 @@ if [[ -n "${TASKER_REPO}" ]]; then
|
||||
fi
|
||||
|
||||
if [[ -f "${TASKER_REPO}/plane-app/docker-compose.synology.override.yml" ]]; then
|
||||
rsync -av \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" \
|
||||
"${TASKER_REPO}/plane-app/docker-compose.synology.override.yml" \
|
||||
"${NAS_ROOT}/tasker/plane-app/docker-compose.synology.override.yml"
|
||||
else
|
||||
@@ -170,7 +175,7 @@ if [[ -n "${GATEWAY_REPO}" ]]; then
|
||||
fi
|
||||
|
||||
mkdir -p "${NAS_ROOT}/ops-agents"
|
||||
rsync -av --delete \
|
||||
rsync -av "${RSYNC_METADATA_ARGS[@]}" --delete \
|
||||
--exclude='.git/' \
|
||||
--exclude='node_modules/' \
|
||||
--exclude='dist/' \
|
||||
|
||||
Executable
+98
@@ -0,0 +1,98 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
NAS_ROOT="${NAS_ROOT:-/Volumes/docker/nodedc-platform}"
|
||||
PLATFORM_ENV="${PLATFORM_ENV:-${NAS_ROOT}/platform/.env.synology}"
|
||||
GATEWAY_ENV="${GATEWAY_ENV:-${NAS_ROOT}/ops-agents/.env}"
|
||||
BACKUP_ROOT="${BACKUP_ROOT:-${NAS_ROOT}/backups/env-prep}"
|
||||
TIMESTAMP="${TIMESTAMP:-$(date +%Y%m%d-%H%M%S)}"
|
||||
BACKUP_DIR="${BACKUP_DIR:-${BACKUP_ROOT}/${TIMESTAMP}}"
|
||||
|
||||
mkdir -p "${BACKUP_DIR}"
|
||||
|
||||
read_env() {
|
||||
local file="$1"
|
||||
local key="$2"
|
||||
[[ -f "${file}" ]] || return 0
|
||||
awk -F= -v key="${key}" '
|
||||
$0 ~ "^[[:space:]]*#" { next }
|
||||
$1 == key {
|
||||
value = substr($0, index($0, "=") + 1)
|
||||
gsub(/^[[:space:]]+|[[:space:]]+$/, "", value)
|
||||
gsub(/^"|"$/, "", value)
|
||||
print value
|
||||
exit
|
||||
}
|
||||
' "${file}"
|
||||
}
|
||||
|
||||
backup_file() {
|
||||
local file="$1"
|
||||
local label="$2"
|
||||
if [[ ! -f "${file}" ]]; then
|
||||
echo "missing ${label}: ${file}" >&2
|
||||
exit 1
|
||||
fi
|
||||
local backup_path="${BACKUP_DIR}/$(basename "${file}").${label}.bak"
|
||||
if ! COPYFILE_DISABLE=1 cp -X "${file}" "${backup_path}" 2>/dev/null; then
|
||||
cat "${file}" > "${backup_path}"
|
||||
fi
|
||||
chmod 600 "${backup_path}"
|
||||
}
|
||||
|
||||
set_env_value() {
|
||||
local file="$1"
|
||||
local key="$2"
|
||||
local value="$3"
|
||||
local tmp
|
||||
tmp="$(mktemp)"
|
||||
if grep -qE "^${key}=" "${file}"; then
|
||||
awk -v key="${key}" -v value="${value}" '
|
||||
BEGIN { replaced = 0 }
|
||||
$0 ~ "^[[:space:]]*#" { print; next }
|
||||
index($0, key "=") == 1 {
|
||||
print key "=" value
|
||||
replaced = 1
|
||||
next
|
||||
}
|
||||
{ print }
|
||||
END {
|
||||
if (!replaced) {
|
||||
print key "=" value
|
||||
}
|
||||
}
|
||||
' "${file}" > "${tmp}"
|
||||
else
|
||||
cat "${file}" > "${tmp}"
|
||||
printf '\n%s=%s\n' "${key}" "${value}" >> "${tmp}"
|
||||
fi
|
||||
cat "${tmp}" > "${file}"
|
||||
rm -f "${tmp}"
|
||||
chmod 600 "${file}"
|
||||
}
|
||||
|
||||
gateway_internal_token="$(read_env "${GATEWAY_ENV}" NODEDC_AGENT_GATEWAY_INTERNAL_TOKEN || true)"
|
||||
if [[ -z "${gateway_internal_token}" || "${gateway_internal_token}" == replace-with-* || "${gateway_internal_token}" == change-me-* ]]; then
|
||||
echo "Gateway NODEDC_AGENT_GATEWAY_INTERNAL_TOKEN is missing or placeholder in ${GATEWAY_ENV}" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
backup_file "${PLATFORM_ENV}" platform
|
||||
backup_file "${GATEWAY_ENV}" ops-agents
|
||||
|
||||
set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_HUB_PUBLIC_URL "wss://ai-hub.nodedc.ru/api/ai-workspace/hub"
|
||||
set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_HUB_INTERNAL_URL "https://ai-hub.nodedc.ru"
|
||||
set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_HUB_FALLBACK_URLS ""
|
||||
set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_OPS_ENTITLEMENT_URL "http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements"
|
||||
set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN "${gateway_internal_token}"
|
||||
set_env_value "${PLATFORM_ENV}" AI_WORKSPACE_OPS_ENTITLEMENT_REQUIRED "false"
|
||||
|
||||
set_env_value "${GATEWAY_ENV}" NODEDC_AI_WORKSPACE_RUN_TOKEN_TTL_SECONDS "43200"
|
||||
|
||||
cat <<EOF
|
||||
ai-workspace-env-prep-ok
|
||||
backup_dir=${BACKUP_DIR}
|
||||
updated_platform_env=${PLATFORM_ENV}
|
||||
updated_gateway_env=${GATEWAY_ENV}
|
||||
secrets_printed=false
|
||||
EOF
|
||||
@@ -67,6 +67,10 @@ echo "== ai workspace assistant hub target check =="
|
||||
"${DOCKER_BIN}" exec nodedc-platform-ai-workspace-assistant-1 sh -lc \
|
||||
'test "$AI_WORKSPACE_HUB_PUBLIC_URL" = "wss://ai-hub.nodedc.ru/api/ai-workspace/hub" && test -z "$AI_WORKSPACE_HUB_FALLBACK_URLS" && echo ai-workspace-prod-hub-target-ok'
|
||||
|
||||
echo "== ai workspace assistant Ops entitlement adapter check =="
|
||||
"${DOCKER_BIN}" exec nodedc-platform-ai-workspace-assistant-1 sh -lc \
|
||||
'test "$AI_WORKSPACE_OPS_ENTITLEMENT_URL" = "http://172.22.0.222:18190/api/internal/v1/ai-workspace/entitlements" && test -n "$AI_WORKSPACE_OPS_ENTITLEMENT_TOKEN" && echo ai-workspace-ops-entitlement-env-ok'
|
||||
|
||||
echo "== auth flow check =="
|
||||
auth_flow="$(fetch_with_retry https://id.nodedc.ru/if/flow/default-authentication-flow/)"
|
||||
printf '%s' "$auth_flow" \
|
||||
|
||||
Reference in New Issue
Block a user