M0-M7 已完成:核心网关(身份/RBAC/TOTP/OIDC/SAML/Provider/配额/路由/内容策略/审计/定价)+ 资源市场(MCP/Skills/数字员工)。 含 22 个 PostgreSQL 迁移、管理端/门户端前端源码、OpenAPI 契约、部署 compose。 Co-Authored-By: Claude <noreply@anthropic.com>
2.3 KiB
Production deployment
This bundle builds the Go services and both Art Design Pro applications from source. PostgreSQL and two Redis roles are included; MinIO/S3 and ClickHouse are not required.
Prerequisites
- Docker Engine with Compose v2
- At least 4 CPU cores, 8 GiB RAM and 30 GiB free disk for an initial build
- An external TLS reverse proxy or load balancer
- A backup destination for the PostgreSQL volume
First deployment
Run all commands from the repository root:
cp deploy/production.env.example deploy/production.env
chmod 600 deploy/production.env
# Edit deploy/production.env and replace every CHANGE_ME value.
docker compose \
--env-file deploy/production.env \
-f deploy/docker-compose.production.yml \
config --quiet
docker compose \
--env-file deploy/production.env \
-f deploy/docker-compose.production.yml \
up -d --build
Create the initial administrator once:
docker compose \
--env-file deploy/production.env \
-f deploy/docker-compose.production.yml \
--profile tools run --rm bootstrap-admin
Then remove BOOTSTRAP_ADMIN_PASSWORD from deploy/production.env and use the
admin UI to create database-backed gateway API keys.
Endpoints
- API and OpenAI-compatible gateway:
127.0.0.1:8080 - Admin UI:
http://127.0.0.1:8081/admin/ - Portal UI:
http://127.0.0.1:8082/portal/ - Liveness/readiness:
/healthzand/readyz
Ports bind to loopback by default. Terminate TLS at a reverse proxy and forward
to these endpoints. Change *_BIND_IP only when the host firewall and network
policy are already in place.
Operations
Check status and logs:
docker compose --env-file deploy/production.env -f deploy/docker-compose.production.yml ps
docker compose --env-file deploy/production.env -f deploy/docker-compose.production.yml logs --tail=200 gateway-api
curl --fail http://127.0.0.1:8080/readyz
For upgrades, back up PostgreSQL first, change GATEWAY_VERSION, then run the
same up -d --build command. The one-shot migrator applies forward migrations
before the API starts. Do not use docker compose down -v in production because
it removes persistent data.
The bundled database URLs use sslmode=disable only for the private Compose
network. When using an external PostgreSQL or Redis service, require TLS and use
sslmode=verify-full / rediss:// as supported by that service.