-
-
Notifications
You must be signed in to change notification settings - Fork 44
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
70 lines (67 loc) · 2.55 KB
/
Copy pathdocker-compose.yml
File metadata and controls
70 lines (67 loc) · 2.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
services:
# ──────────────────────────────────────────────
# OmniParser (Gradio UI parser server)
# First run downloads ~4GB model weights
# ──────────────────────────────────────────────
omniparser:
build:
context: .
dockerfile: docker/omniparser/Dockerfile
container_name: omniparser-server
volumes:
- omniparser-weights:/app/OmniParser/weights
ports:
- "7861:7861"
environment:
- HF_HUB_ENABLE_HF_TRANSFER=1
healthcheck:
test: ["CMD-SHELL", "python -c \"import urllib.request; urllib.request.urlopen('http://localhost:7861')\" || exit 1"]
interval: 15s
timeout: 10s
retries: 30
start_period: 120s
restart: unless-stopped
networks:
- agent-net
# ──────────────────────────────────────────────
# Main Agent (Python)
# ──────────────────────────────────────────────
agent:
build:
context: .
dockerfile: Dockerfile
container_name: craftbot
env_file:
- .env
environment:
- OMNIPARSER_BASE_URL=http://omniparser-server:7861
- USE_OMNIPARSER=${USE_OMNIPARSER:-True}
# The image runs as UID 10001 (see Dockerfile). Bind-mounted host
# directories keep their host ownership, so chown them to match once:
# sudo chown -R 10001:10001 ./workspace
volumes:
# /var/run/docker.sock was mounted here and is deliberately gone. It is
# the host's Docker control plane: a container holding it can start a
# privileged container and take the host. Nothing in the codebase used
# it (no `docker exec`, no docker SDK, no DOCKER_HOST), and this
# container runs commands the model chooses, so it was pure blast
# radius. Do not add it back without a scoped proxy in front.
- ./workspace:/app/workspace
- ./config.json:/app/config.json
security_opt:
# A process inside cannot gain privileges it did not start with
# (blocks setuid escalation paths).
- no-new-privileges:true
depends_on:
omniparser:
condition: service_healthy
stdin_open: true
tty: true
restart: unless-stopped
networks:
- agent-net
volumes:
omniparser-weights:
networks:
agent-net:
driver: bridge