fix(resume): add ENCRYPTION_SECRET + redis so the AI tab loads
The v5 rewrite gates AI features behind two new env vars we never had. Opening the AI Integrations tab calls aiProviders.list, which runs assertCredentialEncryptionConfigured() and throws AI_CREDENTIAL_ENCRYPTION_UNAVAILABLE when ENCRYPTION_SECRET is unset -- so the tab errored on mount instead of rendering. The agent workspace has a second gate: isAgentEnvironmentConfigured() requires ENCRYPTION_SECRET *and* REDIS_URL, so add a dedicated redis to the stack rather than leaving the agent half-broken. Every other redis on the host is on another stack's private network. ENCRYPTION_SECRET encrypts stored provider API keys at rest (schema requires >=32 chars); rotating it makes saved keys undecryptable, so it is pinned like AUTH_SECRET. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
2bbc693b74
commit
fb0b692f83
2 files changed
+27
No files matched your search
@@ -3,6 +3,7 @@
|
|||||||
# Volume -> bind-mount conversions (tiered per density policy):
|
# Volume -> bind-mount conversions (tiered per density policy):
|
||||||
# postgres data -> /config/resume/postgres (SSD; DB, low density)
|
# postgres data -> /config/resume/postgres (SSD; DB, low density)
|
||||||
# minio data -> /storage1/labdata/resume/minio (ZFS; object store, blobs)
|
# minio data -> /storage1/labdata/resume/minio (ZFS; object store, blobs)
|
||||||
|
# redis data -> /config/resume/redis (SSD; AI agent stream state)
|
||||||
# app uploads -> /storage1/labdata/resume/data (ZFS; blobs, see app below)
|
# app uploads -> /storage1/labdata/resume/data (ZFS; blobs, see app below)
|
||||||
# The Chrome service is stateless. app + resume-minio join edge (resume.ginnoir.com,
|
# The Chrome service is stateless. app + resume-minio join edge (resume.ginnoir.com,
|
||||||
# storage.j-costa.com, minio.ginnoir.com); postgres stays private.
|
# storage.j-costa.com, minio.ginnoir.com); postgres stays private.
|
||||||
@@ -69,6 +70,22 @@ services:
|
|||||||
- EXIT_ON_HEALTH_FAILURE=true
|
- EXIT_ON_HEALTH_FAILURE=true
|
||||||
- PRE_REQUEST_HEALTH_CHECK=true
|
- PRE_REQUEST_HEALTH_CHECK=true
|
||||||
|
|
||||||
|
redis:
|
||||||
|
container_name: redis_resume
|
||||||
|
image: redis:7-alpine
|
||||||
|
restart: unless-stopped
|
||||||
|
labels:
|
||||||
|
- "com.centurylabs.watchtower.enable=false"
|
||||||
|
networks: [resume]
|
||||||
|
command: --save 60 1 --loglevel warning
|
||||||
|
volumes:
|
||||||
|
- /config/resume/redis:/data
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "redis-cli", "ping"]
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 5
|
||||||
|
|
||||||
app:
|
app:
|
||||||
container_name: resume
|
container_name: resume
|
||||||
image: amruthpillai/reactive-resume:latest
|
image: amruthpillai/reactive-resume:latest
|
||||||
@@ -88,6 +105,8 @@ services:
|
|||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
resume-minio:
|
resume-minio:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
chrome:
|
chrome:
|
||||||
condition: service_started
|
condition: service_started
|
||||||
env_file:
|
env_file:
|
||||||
|
|||||||
@@ -28,3 +28,11 @@ STORAGE_SECRET_KEY=minioadmin
|
|||||||
AUTH_SECRET=1b7e96f61f080d04d4bf673d9ea1d9349eb7693cddee5772b6c3f153c88032db5b97efd8570087bc6f340d2cd874aabc1e5c681bc22889921240d6a23738bc7f
|
AUTH_SECRET=1b7e96f61f080d04d4bf673d9ea1d9349eb7693cddee5772b6c3f153c88032db5b97efd8570087bc6f340d2cd874aabc1e5c681bc22889921240d6a23738bc7f
|
||||||
OAUTH_CLIENT_ID=YpMFNp9q5mGbN8ADM5rUol0ERHmSiTDClJKIVOxK
|
OAUTH_CLIENT_ID=YpMFNp9q5mGbN8ADM5rUol0ERHmSiTDClJKIVOxK
|
||||||
OAUTH_CLIENT_SECRET=mzwjSt0Xtibo156km61T7VYerT48K6ZTa79cEek4mgdky6t1Sjaddlshw2QcJL8727N6qWzddi2ihxNGSpUVMXUBbjNgx4jtkHAy5xtmvqdk9ouIFclyhCgXh9fzjMCA
|
OAUTH_CLIENT_SECRET=mzwjSt0Xtibo156km61T7VYerT48K6ZTa79cEek4mgdky6t1Sjaddlshw2QcJL8727N6qWzddi2ihxNGSpUVMXUBbjNgx4jtkHAy5xtmvqdk9ouIFclyhCgXh9fzjMCA
|
||||||
|
|
||||||
|
# AI features (v5). ENCRYPTION_SECRET encrypts stored AI provider API keys at
|
||||||
|
# rest (schema requires >=32 chars); without it the AI Integrations tab throws
|
||||||
|
# AI_CREDENTIAL_ENCRYPTION_UNAVAILABLE. Rotating it makes every saved provider
|
||||||
|
# key undecryptable, so pin it like AUTH_SECRET. Generate: openssl rand -hex 32
|
||||||
|
# REDIS_URL is additionally required by the AI agent workspace (streaming).
|
||||||
|
ENCRYPTION_SECRET=2310384c2befea91af4bb6cdc5dc0eea2b1e492c0ac61003b64356abecad7a61
|
||||||
|
REDIS_URL=redis://redis_resume:6379
|
||||||
Reference in new issue
Block a user