Files
AgapHost/openai/docker-compose.yml
alvis 544637c073 Move adolf config to agap_git root (kb#65)
Relocate the OpenClaw gateway config from openai/adolf/ to adolf/ at
the repo root, since it's shared config rather than part of the
openai/ compose project's own tree. Update the docker-compose.yml
bind-mount path (./adolf/openclaw.json -> ../adolf/openclaw.json) and
comments, plus README.md references, to match. Verified: adolf
container recreated healthy with the new bind-mount source resolving
to /home/alvis/agap_git/adolf/openclaw.json, and a fresh
openclaw.json.last-good snapshot confirms the config was accepted.
2026-07-07 08:58:30 +00:00

305 lines
11 KiB
YAML

services:
litellm-db:
image: postgres:16-alpine
container_name: litellm-db
environment:
- POSTGRES_DB=litellm
- POSTGRES_USER=litellm
- POSTGRES_PASSWORD=litellm
volumes:
- /mnt/ssd/dbs/litellm/postgres:/var/lib/postgresql/data
restart: always
litellm:
image: ghcr.io/berriai/litellm:main-latest
container_name: litellm
ports:
- "4000:4000"
volumes:
- ./litellm-config.yaml:/app/config.yaml
environment:
- DATABASE_URL=postgresql://litellm:litellm@litellm-db:5432/litellm
- LITELLM_MASTER_KEY=sk-fjQC1BxAiGFSMs
- LANGFUSE_PUBLIC_KEY=${LANGFUSE_PUBLIC_KEY:-changeme}
- LANGFUSE_SECRET_KEY=${LANGFUSE_SECRET_KEY:-changeme}
- LANGFUSE_HOST=http://langfuse:3000
- OPENROUTER_API_KEY=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
command: ["--config", "/app/config.yaml", "--port", "4000"]
extra_hosts:
- "host.docker.internal:host-gateway"
depends_on:
- litellm-db
- langfuse
restart: always
kimi-agent:
build: ./kimi-agent
container_name: kimi-agent
volumes:
- /home/alvis/kimi-workspace:/workspace
- kimi-agent-home:/root/.kimi-code
restart: unless-stopped
langfuse-db:
image: postgres:16-alpine
container_name: langfuse-db
environment:
- POSTGRES_DB=langfuse
- POSTGRES_USER=langfuse
- POSTGRES_PASSWORD=langfuse
volumes:
- /mnt/ssd/dbs/langfuse/postgres:/var/lib/postgresql/data
restart: always
langfuse:
image: ghcr.io/langfuse/langfuse:2
container_name: langfuse
ports:
- "3200:3000"
environment:
- DATABASE_URL=postgresql://langfuse:langfuse@langfuse-db:5432/langfuse
- NEXTAUTH_URL=https://lf.alogins.net
- NEXTAUTH_SECRET=532a746b24ac40afa39f9d317031cab94d4d6881107ea3b1209b28020f1a9761
- SALT=7927b3b0092afe4542274940b557becea6418a5fed79f7acd25c3a789349fdc9
- AUTH_DISABLE_SIGNUP=true
depends_on:
- langfuse-db
restart: always
qdrant:
image: qdrant/qdrant
container_name: qdrant
ports:
- "6333:6333"
- "6334:6334"
restart: always
volumes:
- /mnt/ssd/dbs/qdrant:/qdrant/storage:z
faster-whisper:
image: fedirz/faster-whisper-server:latest-cuda
container_name: faster-whisper
runtime: nvidia
ports:
- "8880:8000"
environment:
- WHISPER__MODEL=deepdml/faster-whisper-large-v3-turbo-ct2
- WHISPER__INFERENCE_DEVICE=cuda
- WHISPER__COMPUTE_TYPE=int8
- WHISPER__LANGUAGE=ru
- NVIDIA_VISIBLE_DEVICES=all
- NVIDIA_DRIVER_CAPABILITIES=compute,utility
volumes:
- /mnt/ssd/ai/faster-whisper:/root/.cache/huggingface
restart: always
silero-tts:
build: ./silero-tts
container_name: silero-tts
ports:
- "8881:8881"
volumes:
- /mnt/ssd/ai/silero-tts:/cache/torch
restart: always
pipecat:
build: ./pipecat
container_name: pipecat
ports:
- "8882:8882"
environment:
- LIVEKIT_URL=ws://host.docker.internal:7880
- LIVEKIT_PUBLIC_URL=wss://lk.alogins.net
- LIVEKIT_API_KEY=devkey
- LIVEKIT_SECRET=ef3ef4b903ca8469b09b2dd7ab6af529c4d2f3c95668f53832fc351cf67777a9
- ADOLF_URL=http://host.docker.internal:8000/v1
- STT_URL=http://host.docker.internal:8880/v1
- TTS_URL=http://host.docker.internal:8881/v1
- STT_MODEL=deepdml/faster-whisper-large-v3-turbo-ct2
- TTS_VOICE=onyx
extra_hosts:
- "host.docker.internal:host-gateway"
restart: unless-stopped
# Adolf — OpenClaw fork (Matrix-first personal assistant). The OpenClaw
# gateway config (Matrix channel + allow-list, model provider ->
# adolf-llm:8010, MCP registry, gateway.tools.allow for cron/nodes) is
# version-controlled at agap_git/adolf/openclaw.json (repo root, alongside
# this openai/ project, not nested inside it) and bind-mounted read-only
# over the adolf-state volume (see volumes below), so git is the single
# source of truth — not a hand-edited volume file. The volume still
# holds runtime state only (Matrix crypto/devices, credentials, sessions,
# workspace/SOUL.md, logs). Matrix creds and ADOLF_KEY come from
# openai/.env (gitignored, never committed). Source tree: /home/alvis/adolf.
# To change config: edit ../adolf/openclaw.json + restart adolf.
adolf:
build:
context: ../../adolf
# Matrix is opt-in at build time (see adolf/Dockerfile); without this,
# the gateway logs "no-channel-owner" and channels.matrix is inert.
args:
OPENCLAW_EXTENSIONS: matrix
image: adolf:local
container_name: adolf
environment:
- HOME=/home/node
- OPENCLAW_HOME=/home/node
- OPENCLAW_STATE_DIR=/home/node/.openclaw
- OPENCLAW_CONFIG_PATH=/home/node/.openclaw/openclaw.json
- OPENCLAW_CONFIG_DIR=/home/node/.openclaw
- OPENCLAW_WORKSPACE_DIR=/home/node/.openclaw/workspace
- OPENCLAW_GATEWAY_TOKEN=${ADOLF_GATEWAY_TOKEN:-}
- ADOLF_KEY=${ADOLF_KEY:-}
- MATRIX_HOMESERVER=${MATRIX_HOMESERVER:-}
- MATRIX_USER_ID=${MATRIX_USER_ID:-}
- MATRIX_PASSWORD=${MATRIX_PASSWORD:-}
- MATRIX_DEVICE_NAME=${MATRIX_DEVICE_NAME:-Adolf OpenClaw Gateway}
# marketplace-mcp bearer token (kb task #61) -- referenced by
# openclaw.json's mcp.servers.marketplace.headers.Authorization via
# ${MARKETPLACE_MCP_TOKEN} substitution; never inlined into that file.
- MARKETPLACE_MCP_TOKEN=${MARKETPLACE_MCP_TOKEN:-}
- TZ=Europe/Riga
volumes:
# Runtime state only (Matrix crypto/devices, credentials, sessions,
# workspace, logs). The gateway config file itself is overlaid below.
- adolf-state:/home/node/.openclaw
# Version-controlled OpenClaw gateway config, mounted read-only on top
# of the state volume so it is the single source of truth. The gateway
# reads this JSONC file and snapshots its own .last-good/.rejected
# copies into the volume dir (writable) — it never rewrites this file,
# so read-only is safe. Edit the tracked file + restart to change config;
# runtime/UI edits are intentionally disabled by the ro mount.
- ../adolf/openclaw.json:/home/node/.openclaw/openclaw.json:ro
extra_hosts:
- "host.docker.internal:host-gateway"
# mtx.alogins.net's public A record can't hairpin-NAT back through the
# router from inside a container; route it to the host gateway instead,
# matching matrix/docker-compose.yml's lk-jwt-service (same problem,
# same fix). Caddy on the host terminates TLS on :443 and proxies to
# synapse:8008.
- "mtx.alogins.net:host-gateway"
cap_drop:
- NET_RAW
- NET_ADMIN
security_opt:
- no-new-privileges:true
init: true
ports:
- "18789:18789"
- "18790:18790"
command:
["node", "dist/index.js", "gateway", "--bind", "lan", "--port", "18789"]
restart: unless-stopped
# cognee-llm — stateless one-shot Kimi-CLI wrapper for Cognee's batch cognify
# (P3). Opposite policy to kimi-agent: no resume, non-streaming, text-only.
# Note (SPIKE-FINDINGS gate 5): Cognee should DEFAULT its LLM to LiteLLM; this
# is the optional low-volume path. Needs `kimi login` in its own volume.
cognee-llm:
build: ./cognee-llm
container_name: cognee-llm
ports:
- "8011:8011"
volumes:
- cognee-llm-home:/root/.kimi-code
restart: unless-stopped
# adolf-llm — conversational Kimi-CLI wrapper (:8010), the model backend for
# the Adolf OpenClaw gateway (P2). Real streaming (SSE), chat_id session-keying
# + 1:1 kimi resume, media, per-session .mcp.json sourced from the shared
# shared-mcp.json contract (cognee-mcp P4, openclaw-tools P5). Needs
# `kimi login` in adolf-llm-home.
adolf-llm:
build: ./adolf-llm
container_name: adolf-llm
ports:
- "8010:8010"
volumes:
- adolf-llm-workspace:/workspace
- adolf-llm-home:/root/.kimi-code
- ./shared-mcp.json:/shared-mcp.json:ro
restart: unless-stopped
# cognee — Adolf's memory backend (P4). FastAPI + embedded Kuzu graph +
# Qdrant vectors. LLM via cognee-llm:8011 (Kimi CLI wrapper), embeddings via
# ollama directly (host.docker.internal:11436, separate compose project —
# hence extra_hosts below). Sole owner of the on-disk Kuzu/SQLite files
# under /mnt/ssd/dbs/cognee/ (Kuzu is not safe for concurrent multi-process
# access) — never run a second process against those files.
cognee:
build: ./cognee
container_name: cognee
restart: unless-stopped
environment:
# Real OS env var, not just the mounted .env file: the qdrant vector
# adapter's registration hook (cognee/Dockerfile's sitecustomize.py)
# gates on os.environ.get("VECTOR_DB_PROVIDER") at Python interpreter
# start, which only sees actual container env vars — pydantic-settings'
# env_file=".env" parsing (used for the rest of cognee.env) never
# populates os.environ itself. Without this, cognee raises
# "Unsupported vector database provider: qdrant" at startup even though
# cognee.env sets VECTOR_DB_PROVIDER=qdrant. Verified 2026-07-05.
- VECTOR_DB_PROVIDER=qdrant
volumes:
- ./cognee/cognee.env:/app/.env
- /mnt/ssd/dbs/cognee/data:/data
- /mnt/ssd/dbs/cognee/system:/system
extra_hosts:
- "host.docker.internal:host-gateway"
# Not published to the host — only cognee-mcp (same compose network)
# needs to reach it. Uncomment for local debugging:
# ports:
# - "8000:8000"
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:8000/health"]
interval: 30s
timeout: 10s
retries: 3
start_period: 40s
# cognee-mcp — thin MCP-to-HTTP proxy in API mode (API_URL=cognee:8000).
# Never opens the graph/vector files itself, so it's safe to run alongside
# `cognee` without a second writer on the same Kuzu database. Exposes 3
# tools: remember / recall / forget.
cognee-mcp:
image: cognee/cognee-mcp:1.2.2
container_name: cognee-mcp
restart: unless-stopped
environment:
- ENV=local
- LOG_LEVEL=INFO
- PYTHONUNBUFFERED=1
- TRANSPORT_MODE=http
- API_URL=http://cognee:8000
- MCP_ALLOWED_HOSTS=cognee-mcp:*
ports:
- "8001:8000"
depends_on:
- cognee
# openclaw-tools — MCP bridge (P5) exposing a minimal slice of the Adolf
# OpenClaw gateway's agent tools (message/cron/nodes/browser) over MCP
# Streamable HTTP, so Kimi CLI sessions (adolf-llm) can call them instead of
# bypassing OpenClaw entirely. Proxies each MCP tool call to the gateway's
# `POST /tools/invoke` HTTP surface (http://adolf:18789). NOTE: `cron` and
# `nodes` are hard-denied on that surface by default until P6 adds them to
# `gateway.tools.allow` in the adolf openclaw.json — see openclaw-tools/
# server.js for the full gate writeup. Not useful until `adolf` (P6) is
# configured and running; safe to build/run standalone before that.
openclaw-tools:
build: ./openclaw-tools
container_name: openclaw-tools
environment:
- OPENCLAW_GATEWAY_URL=http://adolf:18789
- OPENCLAW_GATEWAY_TOKEN=${ADOLF_GATEWAY_TOKEN:-}
ports:
- "8020:8020"
restart: unless-stopped
volumes:
kimi-agent-home:
adolf-state:
cognee-llm-home:
adolf-llm-workspace:
adolf-llm-home: