Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 10 additions & 9 deletions docker-compose-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -175,9 +175,14 @@ services:
# audit/identity.py::validate_identity_token both fell back to the
# public literal "change-me" instead of the real secret.
JWT_SECRET: ${AUTH_SECRET_KEY:?AUTH_SECRET_KEY must be set}
# Runtime API access is reader-only. Schema/admin operations use a
# separate explicitly provisioned maintenance path outside this service.
AUDIT_READER_DATABASE_URL: mysql+pymysql://audit_reader:${AUDIT_READER_DB_PASSWORD:?AUDIT_READER_DB_PASSWORD must be set}@mysql:3306/omnibioai_audit
depends_on:
redis:
condition: service_healthy
mysql:
condition: service_healthy
restart: on-failure

# Phase I: ghcr.io/omnibioai/omnibioai-security-audit-worker is now
Expand All @@ -187,14 +192,8 @@ services:
# AuditConfig.EVENT_SIGNING_SECRET/DATABASE_URL consumers -- see
# worker/main.py and db/session.py in that repo), just with this file's
# required (:?) secret guards instead of dev's silently-defaulting ones.
# Note: unlike the security-audit (API) entry directly above, this
# worker entry includes AUDIT_DATABASE_URL and a mysql depends_on --
# the worker is the process that actually writes audit_events rows
# (Sink.write() in consumers/sink.py), so it needs the DB connection
# regardless of whether the API entry in this particular file currently
# has it (a pre-existing gap between this file and docker-compose.
# release.yml's fuller security-audit block, not introduced or fixed
# here -- out of scope for this change). No ports: -- Dockerfile.worker
# The worker writes audit_events rows through its dedicated writer
# identity. No ports: -- Dockerfile.worker
# doesn't EXPOSE anything, it's a Redis Streams consumer loop, not an
# HTTP service.
security-audit-worker:
Expand All @@ -203,7 +202,9 @@ services:
PYTHONUNBUFFERED: "1"
REDIS_URL: redis://redis_audit_worker:${REDIS_AUDIT_WORKER_PASSWORD}@redis:6379/0
JWT_SECRET: ${AUTH_SECRET_KEY:?AUTH_SECRET_KEY must be set}
AUDIT_DATABASE_URL: mysql+pymysql://root:${MYSQL_ROOT_PASSWORD:?MYSQL_ROOT_PASSWORD must be set}@mysql:3306/omnibioai_audit
# Runtime ingestion is writer-only. Schema/admin operations use a
# separate explicitly provisioned maintenance path outside this service.
AUDIT_WRITER_DATABASE_URL: mysql+pymysql://audit_writer:${AUDIT_WRITER_DB_PASSWORD:?AUDIT_WRITER_DB_PASSWORD must be set}@mysql:3306/omnibioai_audit
depends_on:
redis:
condition: service_healthy
Expand Down
18 changes: 7 additions & 11 deletions docker-compose.release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -169,23 +169,17 @@ services:
- "${HOST_IP:-0.0.0.0}:8004:8004"
environment:
PYTHONUNBUFFERED: "1"
REDIS_URL: redis://redis:6379
REDIS_URL: redis://redis_audit_producer:${REDIS_AUDIT_PRODUCER_PASSWORD}@redis:6379/0
# SSO Phase 2 PR2 (JWT consumer audit): same shared secret
# auth-service signs with and api-gateway/control-center already
# verify with (all AUTH_SECRET_KEY) -- previously unset here, so
# api/deps.py::require_platform_admin and
# audit/identity.py::validate_identity_token both fell back to the
# public literal "change-me" instead of the real secret.
JWT_SECRET: ${AUTH_SECRET_KEY:?AUTH_SECRET_KEY must be set}
# PR-B0: same fix as docker-compose.yml -- GET /audit/events was
# falling back to an unreachable localhost DB URL. NOTE: this file
# intentionally does NOT add a security-audit-worker service (see
# docker-compose.yml's comment) -- no worker image is published by
# CI yet, and this image-only release file has no build: precedent
# to fall back on the way docker-compose.yml's billing-worker does.
# Flagged as an explicit follow-up in the PR-B0 report, not silently
# left broken.
AUDIT_DATABASE_URL: mysql+pymysql://root:${MYSQL_ROOT_PASSWORD:?MYSQL_ROOT_PASSWORD must be set}@mysql:3306/omnibioai_audit
# Runtime API access is reader-only. Schema/admin operations use a
# separate explicitly provisioned maintenance path outside this service.
AUDIT_READER_DATABASE_URL: mysql+pymysql://audit_reader:${AUDIT_READER_DB_PASSWORD:?AUDIT_READER_DB_PASSWORD must be set}@mysql:3306/omnibioai_audit
depends_on:
redis:
condition: service_healthy
Expand All @@ -209,7 +203,9 @@ services:
PYTHONUNBUFFERED: "1"
REDIS_URL: redis://redis_audit_worker:${REDIS_AUDIT_WORKER_PASSWORD}@redis:6379/0
JWT_SECRET: ${AUTH_SECRET_KEY:?AUTH_SECRET_KEY must be set}
AUDIT_DATABASE_URL: mysql+pymysql://root:${MYSQL_ROOT_PASSWORD:?MYSQL_ROOT_PASSWORD must be set}@mysql:3306/omnibioai_audit
# Runtime ingestion is writer-only. Schema/admin operations use a
# separate explicitly provisioned maintenance path outside this service.
AUDIT_WRITER_DATABASE_URL: mysql+pymysql://audit_writer:${AUDIT_WRITER_DB_PASSWORD:?AUDIT_WRITER_DB_PASSWORD must be set}@mysql:3306/omnibioai_audit
depends_on:
redis:
condition: service_healthy
Expand Down
28 changes: 26 additions & 2 deletions docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -130,6 +130,7 @@ services:
PYTHONUNBUFFERED: "1"
IAM_URL: http://auth-service:8001
AUDIT_URL: http://security-audit:8004
TOOLSERVER_REGISTRATION_CLIENT_IDS: ${TES_TOOLSERVER_REGISTRATION_CLIENT_ID:?}
# deploy-verify default (14d) is fine for this one -- no override.
volumes:
- ${WORKSPACE_HOST}:/workspace
Expand Down Expand Up @@ -184,6 +185,10 @@ services:
DB_USER: root
DB_PASSWORD: ${MYSQL_ROOT_PASSWORD:-omnibioai}
TOOLSERVER_BASE_URL: http://toolserver:9090
TES_TOOLSERVER_REGISTRATION_CLIENT_ID: ${TES_TOOLSERVER_REGISTRATION_CLIENT_ID:?}
TES_TOOLSERVER_REGISTRATION_CLIENT_SECRET: ${TES_TOOLSERVER_REGISTRATION_CLIENT_SECRET:?}
TES_TOOLSERVER_CLIENT_ID: ${TES_TOOLSERVER_CLIENT_ID:?}
TES_TOOLSERVER_CLIENT_SECRET: ${TES_TOOLSERVER_CLIENT_SECRET:?}
TES_TOOLS: /workspace/configs/tools
TES_SERVERS: /workspace/configs/servers
TMPDIR: /tmp/omnibioai_tes_runs
Expand Down Expand Up @@ -754,6 +759,15 @@ services:
RAG_BASE_URL: http://rag:8096
ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY:-}
OPENAI_API_KEY: ${OPENAI_API_KEY:-}
# Licensed reference-database connectors (omnibioai-workbench plugins).
# Optional: each plugin reports not_configured when its variable is empty.
DRUGBANK_API_KEY: ${DRUGBANK_API_KEY:-}
ONCOKB_API_TOKEN: ${ONCOKB_API_TOKEN:-}
VARSOME_API_TOKEN: ${VARSOME_API_TOKEN:-}
VARSOME_API_ENVIRONMENT: ${VARSOME_API_ENVIRONMENT:-live}
MASTERMIND_API_TOKEN: ${MASTERMIND_API_TOKEN:-}
BIOCYC_EMAIL: ${BIOCYC_EMAIL:-}
BIOCYC_PASSWORD: ${BIOCYC_PASSWORD:-}
CODE_LLM_MODEL: ${CODE_LLM_MODEL:-qwen2.5-coder:32b}
REASONING_LLM_MODEL: ${REASONING_LLM_MODEL:-deepseek-r1:32b}
RAG_LLM_MODEL: ${RAG_LLM_MODEL:-deepseek-r1:32b}
Expand Down Expand Up @@ -967,6 +981,15 @@ services:
OMNIBIOAI_MYSQL_PASSWORD: ${MYSQL_ROOT_PASSWORD:-omnibioai}
ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY:-}
OPENAI_API_KEY: ${OPENAI_API_KEY:-}
# Licensed reference-database connectors (omnibioai-workbench plugins).
# Optional: each plugin reports not_configured when its variable is empty.
DRUGBANK_API_KEY: ${DRUGBANK_API_KEY:-}
ONCOKB_API_TOKEN: ${ONCOKB_API_TOKEN:-}
VARSOME_API_TOKEN: ${VARSOME_API_TOKEN:-}
VARSOME_API_ENVIRONMENT: ${VARSOME_API_ENVIRONMENT:-live}
MASTERMIND_API_TOKEN: ${MASTERMIND_API_TOKEN:-}
BIOCYC_EMAIL: ${BIOCYC_EMAIL:-}
BIOCYC_PASSWORD: ${BIOCYC_PASSWORD:-}
CODE_LLM_MODEL: ${CODE_LLM_MODEL:-qwen2.5-coder:32b}
REASONING_LLM_MODEL: ${REASONING_LLM_MODEL:-deepseek-r1:32b}
RAG_LLM_MODEL: ${RAG_LLM_MODEL:-deepseek-r1:32b}
Expand Down Expand Up @@ -1505,8 +1528,9 @@ services:
DB_HOST: mysql
DB_PORT: "3306"
DB_NAME: omnibioai
DB_USER: root
DB_PASSWORD: ${MYSQL_ROOT_PASSWORD:-omnibioai}
DB_USER: omnibioai_auth_runtime
DB_PASSWORD: ${AUTH_DB_PASSWORD:?AUTH_DB_PASSWORD must be set}
AUTH_AUDIT_INTEGRITY_KEY: ${AUTH_AUDIT_INTEGRITY_KEY:?AUTH_AUDIT_INTEGRITY_KEY must be set}

SECRET_KEY: ${AUTH_SECRET_KEY:-change-me}

Expand Down
Loading