From 13f9527a13988b2a4f4124f3b6c9aba58d5f5b07 Mon Sep 17 00:00:00 2001 From: Manish Kumar Date: Sun, 27 Sep 2026 01:25:25 -0500 Subject: [PATCH] pre-RMA emergency repository preservation --- docker-compose-release.yml | 19 ++++++++++--------- docker-compose.release.yml | 18 +++++++----------- docker-compose.yml | 28 ++++++++++++++++++++++++++-- 3 files changed, 43 insertions(+), 22 deletions(-) diff --git a/docker-compose-release.yml b/docker-compose-release.yml index 457520fc..84a3551c 100644 --- a/docker-compose-release.yml +++ b/docker-compose-release.yml @@ -175,9 +175,14 @@ services: # audit/identity.py::validate_identity_token both fell back to the # public literal "change-me" instead of the real secret. JWT_SECRET: ${AUTH_SECRET_KEY:?AUTH_SECRET_KEY must be set} + # Runtime API access is reader-only. Schema/admin operations use a + # separate explicitly provisioned maintenance path outside this service. + AUDIT_READER_DATABASE_URL: mysql+pymysql://audit_reader:${AUDIT_READER_DB_PASSWORD:?AUDIT_READER_DB_PASSWORD must be set}@mysql:3306/omnibioai_audit depends_on: redis: condition: service_healthy + mysql: + condition: service_healthy restart: on-failure # Phase I: ghcr.io/omnibioai/omnibioai-security-audit-worker is now @@ -187,14 +192,8 @@ services: # AuditConfig.EVENT_SIGNING_SECRET/DATABASE_URL consumers -- see # worker/main.py and db/session.py in that repo), just with this file's # required (:?) secret guards instead of dev's silently-defaulting ones. - # Note: unlike the security-audit (API) entry directly above, this - # worker entry includes AUDIT_DATABASE_URL and a mysql depends_on -- - # the worker is the process that actually writes audit_events rows - # (Sink.write() in consumers/sink.py), so it needs the DB connection - # regardless of whether the API entry in this particular file currently - # has it (a pre-existing gap between this file and docker-compose. - # release.yml's fuller security-audit block, not introduced or fixed - # here -- out of scope for this change). No ports: -- Dockerfile.worker + # The worker writes audit_events rows through its dedicated writer + # identity. No ports: -- Dockerfile.worker # doesn't EXPOSE anything, it's a Redis Streams consumer loop, not an # HTTP service. security-audit-worker: @@ -203,7 +202,9 @@ services: PYTHONUNBUFFERED: "1" REDIS_URL: redis://redis_audit_worker:${REDIS_AUDIT_WORKER_PASSWORD}@redis:6379/0 JWT_SECRET: ${AUTH_SECRET_KEY:?AUTH_SECRET_KEY must be set} - AUDIT_DATABASE_URL: mysql+pymysql://root:${MYSQL_ROOT_PASSWORD:?MYSQL_ROOT_PASSWORD must be set}@mysql:3306/omnibioai_audit + # Runtime ingestion is writer-only. Schema/admin operations use a + # separate explicitly provisioned maintenance path outside this service. + AUDIT_WRITER_DATABASE_URL: mysql+pymysql://audit_writer:${AUDIT_WRITER_DB_PASSWORD:?AUDIT_WRITER_DB_PASSWORD must be set}@mysql:3306/omnibioai_audit depends_on: redis: condition: service_healthy diff --git a/docker-compose.release.yml b/docker-compose.release.yml index 00b79237..3bdb522d 100644 --- a/docker-compose.release.yml +++ b/docker-compose.release.yml @@ -169,7 +169,7 @@ services: - "${HOST_IP:-0.0.0.0}:8004:8004" environment: PYTHONUNBUFFERED: "1" - REDIS_URL: redis://redis:6379 + REDIS_URL: redis://redis_audit_producer:${REDIS_AUDIT_PRODUCER_PASSWORD}@redis:6379/0 # SSO Phase 2 PR2 (JWT consumer audit): same shared secret # auth-service signs with and api-gateway/control-center already # verify with (all AUTH_SECRET_KEY) -- previously unset here, so @@ -177,15 +177,9 @@ services: # audit/identity.py::validate_identity_token both fell back to the # public literal "change-me" instead of the real secret. JWT_SECRET: ${AUTH_SECRET_KEY:?AUTH_SECRET_KEY must be set} - # PR-B0: same fix as docker-compose.yml -- GET /audit/events was - # falling back to an unreachable localhost DB URL. NOTE: this file - # intentionally does NOT add a security-audit-worker service (see - # docker-compose.yml's comment) -- no worker image is published by - # CI yet, and this image-only release file has no build: precedent - # to fall back on the way docker-compose.yml's billing-worker does. - # Flagged as an explicit follow-up in the PR-B0 report, not silently - # left broken. - AUDIT_DATABASE_URL: mysql+pymysql://root:${MYSQL_ROOT_PASSWORD:?MYSQL_ROOT_PASSWORD must be set}@mysql:3306/omnibioai_audit + # Runtime API access is reader-only. Schema/admin operations use a + # separate explicitly provisioned maintenance path outside this service. + AUDIT_READER_DATABASE_URL: mysql+pymysql://audit_reader:${AUDIT_READER_DB_PASSWORD:?AUDIT_READER_DB_PASSWORD must be set}@mysql:3306/omnibioai_audit depends_on: redis: condition: service_healthy @@ -209,7 +203,9 @@ services: PYTHONUNBUFFERED: "1" REDIS_URL: redis://redis_audit_worker:${REDIS_AUDIT_WORKER_PASSWORD}@redis:6379/0 JWT_SECRET: ${AUTH_SECRET_KEY:?AUTH_SECRET_KEY must be set} - AUDIT_DATABASE_URL: mysql+pymysql://root:${MYSQL_ROOT_PASSWORD:?MYSQL_ROOT_PASSWORD must be set}@mysql:3306/omnibioai_audit + # Runtime ingestion is writer-only. Schema/admin operations use a + # separate explicitly provisioned maintenance path outside this service. + AUDIT_WRITER_DATABASE_URL: mysql+pymysql://audit_writer:${AUDIT_WRITER_DB_PASSWORD:?AUDIT_WRITER_DB_PASSWORD must be set}@mysql:3306/omnibioai_audit depends_on: redis: condition: service_healthy diff --git a/docker-compose.yml b/docker-compose.yml index 2a2eee32..8a0d204c 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -130,6 +130,7 @@ services: PYTHONUNBUFFERED: "1" IAM_URL: http://auth-service:8001 AUDIT_URL: http://security-audit:8004 + TOOLSERVER_REGISTRATION_CLIENT_IDS: ${TES_TOOLSERVER_REGISTRATION_CLIENT_ID:?} # deploy-verify default (14d) is fine for this one -- no override. volumes: - ${WORKSPACE_HOST}:/workspace @@ -184,6 +185,10 @@ services: DB_USER: root DB_PASSWORD: ${MYSQL_ROOT_PASSWORD:-omnibioai} TOOLSERVER_BASE_URL: http://toolserver:9090 + TES_TOOLSERVER_REGISTRATION_CLIENT_ID: ${TES_TOOLSERVER_REGISTRATION_CLIENT_ID:?} + TES_TOOLSERVER_REGISTRATION_CLIENT_SECRET: ${TES_TOOLSERVER_REGISTRATION_CLIENT_SECRET:?} + TES_TOOLSERVER_CLIENT_ID: ${TES_TOOLSERVER_CLIENT_ID:?} + TES_TOOLSERVER_CLIENT_SECRET: ${TES_TOOLSERVER_CLIENT_SECRET:?} TES_TOOLS: /workspace/configs/tools TES_SERVERS: /workspace/configs/servers TMPDIR: /tmp/omnibioai_tes_runs @@ -754,6 +759,15 @@ services: RAG_BASE_URL: http://rag:8096 ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY:-} OPENAI_API_KEY: ${OPENAI_API_KEY:-} + # Licensed reference-database connectors (omnibioai-workbench plugins). + # Optional: each plugin reports not_configured when its variable is empty. + DRUGBANK_API_KEY: ${DRUGBANK_API_KEY:-} + ONCOKB_API_TOKEN: ${ONCOKB_API_TOKEN:-} + VARSOME_API_TOKEN: ${VARSOME_API_TOKEN:-} + VARSOME_API_ENVIRONMENT: ${VARSOME_API_ENVIRONMENT:-live} + MASTERMIND_API_TOKEN: ${MASTERMIND_API_TOKEN:-} + BIOCYC_EMAIL: ${BIOCYC_EMAIL:-} + BIOCYC_PASSWORD: ${BIOCYC_PASSWORD:-} CODE_LLM_MODEL: ${CODE_LLM_MODEL:-qwen2.5-coder:32b} REASONING_LLM_MODEL: ${REASONING_LLM_MODEL:-deepseek-r1:32b} RAG_LLM_MODEL: ${RAG_LLM_MODEL:-deepseek-r1:32b} @@ -967,6 +981,15 @@ services: OMNIBIOAI_MYSQL_PASSWORD: ${MYSQL_ROOT_PASSWORD:-omnibioai} ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY:-} OPENAI_API_KEY: ${OPENAI_API_KEY:-} + # Licensed reference-database connectors (omnibioai-workbench plugins). + # Optional: each plugin reports not_configured when its variable is empty. + DRUGBANK_API_KEY: ${DRUGBANK_API_KEY:-} + ONCOKB_API_TOKEN: ${ONCOKB_API_TOKEN:-} + VARSOME_API_TOKEN: ${VARSOME_API_TOKEN:-} + VARSOME_API_ENVIRONMENT: ${VARSOME_API_ENVIRONMENT:-live} + MASTERMIND_API_TOKEN: ${MASTERMIND_API_TOKEN:-} + BIOCYC_EMAIL: ${BIOCYC_EMAIL:-} + BIOCYC_PASSWORD: ${BIOCYC_PASSWORD:-} CODE_LLM_MODEL: ${CODE_LLM_MODEL:-qwen2.5-coder:32b} REASONING_LLM_MODEL: ${REASONING_LLM_MODEL:-deepseek-r1:32b} RAG_LLM_MODEL: ${RAG_LLM_MODEL:-deepseek-r1:32b} @@ -1505,8 +1528,9 @@ services: DB_HOST: mysql DB_PORT: "3306" DB_NAME: omnibioai - DB_USER: root - DB_PASSWORD: ${MYSQL_ROOT_PASSWORD:-omnibioai} + DB_USER: omnibioai_auth_runtime + DB_PASSWORD: ${AUTH_DB_PASSWORD:?AUTH_DB_PASSWORD must be set} + AUTH_AUDIT_INTEGRITY_KEY: ${AUTH_AUDIT_INTEGRITY_KEY:?AUTH_AUDIT_INTEGRITY_KEY must be set} SECRET_KEY: ${AUTH_SECRET_KEY:-change-me}