5759c1862e
M0-M7 已完成:核心网关(身份/RBAC/TOTP/OIDC/SAML/Provider/配额/路由/内容策略/审计/定价)+ 资源市场(MCP/Skills/数字员工)。 含 22 个 PostgreSQL 迁移、管理端/门户端前端源码、OpenAPI 契约、部署 compose。 Co-Authored-By: Claude <noreply@anthropic.com>
75 lines
2.3 KiB
Markdown
75 lines
2.3 KiB
Markdown
# Production deployment
|
|
|
|
This bundle builds the Go services and both Art Design Pro applications from
|
|
source. PostgreSQL and two Redis roles are included; MinIO/S3 and ClickHouse are
|
|
not required.
|
|
|
|
## Prerequisites
|
|
|
|
- Docker Engine with Compose v2
|
|
- At least 4 CPU cores, 8 GiB RAM and 30 GiB free disk for an initial build
|
|
- An external TLS reverse proxy or load balancer
|
|
- A backup destination for the PostgreSQL volume
|
|
|
|
## First deployment
|
|
|
|
Run all commands from the repository root:
|
|
|
|
```bash
|
|
cp deploy/production.env.example deploy/production.env
|
|
chmod 600 deploy/production.env
|
|
# Edit deploy/production.env and replace every CHANGE_ME value.
|
|
|
|
docker compose \
|
|
--env-file deploy/production.env \
|
|
-f deploy/docker-compose.production.yml \
|
|
config --quiet
|
|
|
|
docker compose \
|
|
--env-file deploy/production.env \
|
|
-f deploy/docker-compose.production.yml \
|
|
up -d --build
|
|
```
|
|
|
|
Create the initial administrator once:
|
|
|
|
```bash
|
|
docker compose \
|
|
--env-file deploy/production.env \
|
|
-f deploy/docker-compose.production.yml \
|
|
--profile tools run --rm bootstrap-admin
|
|
```
|
|
|
|
Then remove `BOOTSTRAP_ADMIN_PASSWORD` from `deploy/production.env` and use the
|
|
admin UI to create database-backed gateway API keys.
|
|
|
|
## Endpoints
|
|
|
|
- API and OpenAI-compatible gateway: `127.0.0.1:8080`
|
|
- Admin UI: `http://127.0.0.1:8081/admin/`
|
|
- Portal UI: `http://127.0.0.1:8082/portal/`
|
|
- Liveness/readiness: `/healthz` and `/readyz`
|
|
|
|
Ports bind to loopback by default. Terminate TLS at a reverse proxy and forward
|
|
to these endpoints. Change `*_BIND_IP` only when the host firewall and network
|
|
policy are already in place.
|
|
|
|
## Operations
|
|
|
|
Check status and logs:
|
|
|
|
```bash
|
|
docker compose --env-file deploy/production.env -f deploy/docker-compose.production.yml ps
|
|
docker compose --env-file deploy/production.env -f deploy/docker-compose.production.yml logs --tail=200 gateway-api
|
|
curl --fail http://127.0.0.1:8080/readyz
|
|
```
|
|
|
|
For upgrades, back up PostgreSQL first, change `GATEWAY_VERSION`, then run the
|
|
same `up -d --build` command. The one-shot migrator applies forward migrations
|
|
before the API starts. Do not use `docker compose down -v` in production because
|
|
it removes persistent data.
|
|
|
|
The bundled database URLs use `sslmode=disable` only for the private Compose
|
|
network. When using an external PostgreSQL or Redis service, require TLS and use
|
|
`sslmode=verify-full` / `rediss://` as supported by that service.
|