mirror of
https://github.com/R0m1k3/Loki.git
synced 2026-10-11 17:26:57 +02:00
Phases 5 & 8 : onglet Logs, durcissement Docker et documentation
Phase 5 (fin) : - PreviewPanel : onglet Logs (journal d'activité des outils de la session, compteur dynamique, statuts ✓/✕/⏸/…) Phase 8 : - .dockerignore - Dockerfile : utilisateur non-root (uid 10001), HEALTHCHECK via curl, dossiers de runtime détenus par l'utilisateur - docker-compose : healthcheck, variable SEARX_URL optionnelle - .env.example : SEARX_URL - README : sections Utilisation, Outils de l'agent, Sécurité (confinement, validation run_shell, non-root) ; feuille de route complète Validation : config docker compose OK ; build d'image non exécutable ici (démon Docker absent de l'environnement). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SVay7z3y7q2gEe54ByAE6N
This commit is contained in:
1 parent
de2befe31e
commit
66be893ea6
6 files changed
+159
-14
No files matched your search
+13
-1
@@ -16,6 +16,10 @@ ENV PYTHONUNBUFFERED=1 \
|
||||
DATA_DIR=/data \
|
||||
PORT=8080
|
||||
|
||||
# curl pour le HEALTHCHECK
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends curl \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
COPY backend/requirements.txt ./
|
||||
RUN pip install --no-cache-dir -r requirements.txt
|
||||
|
||||
@@ -23,8 +27,16 @@ COPY backend/ ./backend/
|
||||
# Frontend compilé servi en statique par FastAPI
|
||||
COPY --from=frontend /app/frontend/dist ./backend/static
|
||||
|
||||
RUN mkdir -p /workspace /data
|
||||
# Utilisateur non-root + dossiers de runtime lui appartenant
|
||||
RUN useradd --create-home --uid 10001 loki \
|
||||
&& mkdir -p /workspace /data \
|
||||
&& chown -R loki:loki /workspace /data /app
|
||||
USER loki
|
||||
|
||||
EXPOSE 8080
|
||||
WORKDIR /app/backend
|
||||
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
|
||||
CMD curl -fsS "http://localhost:${PORT}/api/health" || exit 1
|
||||
|
||||
CMD ["sh", "-c", "uvicorn app.main:app --host 0.0.0.0 --port ${PORT}"]
|
||||
Reference in new issue
Block a user