Files
OpenViking/docker-compose.yml
T
Hao Zheandzhiheng.liu c61471ddc4 fix(deploy): harden bot and server deployment configuration (#3547)
* fix(bot): only require VKE credentials when the TOS storage path needs them

Sweep findings: C-14. Gate AK/SK validation on an actual TOS deployment and drop the unused cluster ID.

(cherry picked from commit 8790ba509f)

* fix(server): apply configured temp_upload.default_mode to uploads

Sweep findings: B-11, D-01. Apply the documented configured upload mode when requests omit it.

(cherry picked from commit a0dc2498e8)

* fix(bot): make one-click Docker deployment generate a working config and port mapping

Sweep findings: C-12. Generate the active ov.conf and keep gateway and Docker ports aligned.

(cherry picked from commit c22af83ab6)

* fix(server): make --bot work and propagate bot flags to workers

Sweep findings: B-09, B-15. Honor the public Bot alias and replay resolved Bot settings in worker processes.

(cherry picked from commit 32a898ca14)

* fix(docker): derive entrypoint/health port from configured server port

Sweep findings: F-06. Keep server startup and every container health check on the same effective port.

(cherry picked from commit 000795c7e3)

---------

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
2026-07-28 18:11:26 +08:00

70 lines
2.3 KiB
YAML

version: "3.8"
# Set OPENVIKING_PUBLIC_BASE_URL in a `.env` file next to this compose file
# when you need public HTTPS (OAuth, MCP clients on the internet).
#
# .env example for local-only (leave unset or empty):
# # no .env needed — just `docker compose up -d`
#
# .env example for a custom OpenViking port:
# OPENVIKING_SERVER_PORT=2000
#
# .env example for public HTTPS:
# OPENVIKING_PUBLIC_BASE_URL=https://ov.your-domain.com
# OV_ACME_EMAIL=admin@your-domain.com
#
# See docs/en/guides/12-public-access.md for the full walkthrough.
services:
openviking:
image: ghcr.io/volcengine/openviking:latest
container_name: openviking
# Direct access (optional — caddy:1934 is the recommended single entry
# point). Comment this out once Caddy is your only ingress.
ports:
- "${OPENVIKING_SERVER_PORT:-1933}:${OPENVIKING_SERVER_PORT:-1933}"
volumes:
- ~/.openviking:/app/.openviking
environment:
OPENVIKING_PUBLIC_BASE_URL: ${OPENVIKING_PUBLIC_BASE_URL:-}
OPENVIKING_SERVER_PORT: ${OPENVIKING_SERVER_PORT:-1933}
healthcheck:
test: ["CMD", "openviking-entrypoint", "--healthcheck"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
restart: unless-stopped
# Legacy reverse proxy — port 1934 is retained for existing deployments.
# New setups can connect directly to openviking:1933.
#
# For public HTTPS: edit the Caddyfile to add a domain block, set
# OPENVIKING_PUBLIC_BASE_URL in .env, uncomment the 80/443 port lines
# below, and add the caddy volumes at the bottom.
caddy:
image: caddy:2
container_name: openviking-caddy
restart: unless-stopped
ports:
- "1934:1934"
# Uncomment for public HTTPS (after adding a domain block to Caddyfile):
# - "80:80"
# - "443:443"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile:ro
# Uncomment for public HTTPS (Caddy stores certs here):
# - caddy_data:/data
# - caddy_config:/config
environment:
OPENVIKING_PUBLIC_BASE_URL: ${OPENVIKING_PUBLIC_BASE_URL:-}
OPENVIKING_SERVER_PORT: ${OPENVIKING_SERVER_PORT:-1933}
OV_ACME_EMAIL: ${OV_ACME_EMAIL:-}
depends_on:
- openviking
# Uncomment for public HTTPS:
# volumes:
# caddy_data:
# caddy_config: