Files
CASAN/infra/local-prod/docker-compose.yml
T
thanhnvandClaude Opus 4.8 36a4812ef3 refactor(structure): promote app to repo root + remove redundant workspace cruft
Standard production layout: the OKR app (was nested under AINative_OKR_CASAN5/) is now
the repository root. No more wrapper directory.

- Promote AINative_OKR_CASAN5/* -> repo root (backend/ frontend/ packages/ apps/
  .specify/ docs/ infra/ nginx/ scripts/ + configs). Merge tool dirs: .gitea (kept the
  active deploy ci.yml, added harness-ci.yml + runbooks), .claude (agents/commands +
  launch.json), .github moved up.
- Remove redundant: 00_SUBMISSION_PACKAGE, scattered root notes (FPT_CASAN_Full.md,
  tu-tuong-casan.md, casan-tu-sinh..., casan_harness_assessment.md, source-review...,
  README_CASAN5_REFINED.md), casan-next-plans/ and optimize-docs/ (competition/planning
  artifacts — roadmap + design history preserved in git log / commit messages).
- Update all references to the old layout:
  - .gitea/workflows/{ci,harness-ci}.yml, .github/workflows/{ci,deploy}.yml:
    working-directory .; drop AINative_OKR_CASAN5/ prefix; .specify/{tests,scripts}
    -> packages/casan-harness/... (.specify/logs state kept)
  - .claude/launch.json, .gitea/*-runbook.md: path prefixes
  - CLAUDE.md, README.md: docs/input -> apps/okr/domain/input
  - policy-bundle.yaml: 8 policy paths -> packages/casan-harness/...; manifest re-signed
- secrets-scan.sh: fixture excludes -> new package/domain paths.

Full gate from the new root: PASS=64 FAIL=0 SKIP=3.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-08 13:26:36 +09:00

141 lines
3.8 KiB
YAML

name: casan-local-prod
services:
vault:
image: hashicorp/vault:1.15
cap_add:
- IPC_LOCK
environment:
VAULT_DEV_ROOT_TOKEN_ID: root
VAULT_DEV_LISTEN_ADDRESS: 0.0.0.0:8200
ports:
- "18200:8200"
healthcheck:
test: ["CMD", "wget", "-q", "-O", "-", "http://127.0.0.1:8200/v1/sys/health"]
interval: 5s
timeout: 3s
retries: 20
idp:
build:
context: ./idp
environment:
CASAN_IDP_PORT: "8080"
CASAN_IDP_ISSUER: http://127.0.0.1:18081
ports:
- "18081:8080"
healthcheck:
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8080/healthz', timeout=2)"]
interval: 5s
timeout: 3s
retries: 20
minio:
image: minio/minio:RELEASE.2025-09-07T16-13-09Z
command: server /data --console-address ":9001"
environment:
MINIO_ROOT_USER: casanadmin
MINIO_ROOT_PASSWORD: casanadmin123
MINIO_BROWSER_REDIRECT_URL: http://127.0.0.1:19091
ports:
- "19090:9000"
- "19091:9001"
volumes:
- minio-data:/data
healthcheck:
test: ["CMD", "curl", "-fsS", "http://127.0.0.1:9000/minio/health/live"]
interval: 5s
timeout: 3s
retries: 20
minio-init:
image: minio/mc:RELEASE.2025-08-13T08-35-41Z
depends_on:
minio:
condition: service_healthy
entrypoint: /bin/sh
command:
- -c
- |
set -eu
mc alias set local http://minio:9000 casanadmin casanadmin123
mc mb --ignore-existing --with-lock local/casan-worm
mc retention set --default COMPLIANCE 1d local/casan-worm
mc anonymous set none local/casan-worm
echo MINIO_WORM_READY bucket=casan-worm mode=COMPLIANCE retention=1d
minio-mc:
image: minio/mc:RELEASE.2025-08-13T08-35-41Z
profiles: ["tools"]
depends_on:
minio:
condition: service_healthy
entrypoint: /bin/sh
alert-webhook:
build:
context: ./mock-http
command: ["python", "/app/mock_http.py", "alert"]
environment:
CASAN_MOCK_PORT: "8080"
ports:
- "19092:8080"
healthcheck:
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8080/healthz', timeout=2)"]
interval: 5s
timeout: 3s
retries: 20
billing-api:
build:
context: ./mock-http
command: ["python", "/app/mock_http.py", "billing"]
environment:
CASAN_MOCK_PORT: "8080"
ports:
- "19093:8080"
healthcheck:
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8080/healthz', timeout=2)"]
interval: 5s
timeout: 3s
retries: 20
dashboard:
image: python:3.12-slim
working_dir: /workspace
command: ["python", "packages/casan-harness/scripts/bash/dashboard-server.py", "8787"]
environment:
CASAN_DASHBOARD_BIND: 0.0.0.0
CASAN_DASHBOARD_STALE_S: "315360000"
CASAN_DASHBOARD_METRICS: /workspace/.specify/logs/cost/metrics.jsonl
CASAN_DASHBOARD_HTML: /workspace/docs/output/casan/central-agentops-dashboard.html
CASAN_DASHBOARD_ALERTS: /workspace/.specify/agentops/alerts.log
volumes:
- ../..:/workspace:ro
expose:
- "8787"
healthcheck:
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8787/healthz', timeout=2)"]
interval: 5s
timeout: 3s
retries: 20
dashboard-nginx:
image: nginx:1.27-alpine
depends_on:
dashboard:
condition: service_healthy
ports:
- "18080:80"
volumes:
- ./nginx/default.conf:/etc/nginx/conf.d/default.conf:ro
- ./nginx/htpasswd:/etc/nginx/.htpasswd:ro
healthcheck:
test: ["CMD", "wget", "-q", "-O", "-", "http://127.0.0.1/healthz"]
interval: 5s
timeout: 3s
retries: 20
volumes:
minio-data: