Repository navigation
docs(deployment): adiciona guia de deploy docker, headroom e acesso remoto - #23
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a1a9fc703e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| ### Step 2: Launch Stack | ||
|
|
||
| ```bash | ||
| docker compose -f docker-compose.example.yml up -d |
There was a problem hiding this comment.
Create the external network before launching Compose
On a fresh Docker host, this advertised production launch fails before starting any container because ominirtk-router always attaches to the external rtk-inference-net, despite the preceding text calling that network optional. Docker explicitly requires external networks to exist before compose up; use the repository's make setup target or document docker network create rtk-inference-net before this command. See Docker's external-network documentation.
Useful? React with 👍 / 👎.
| --name ominirtk-sync \ | ||
| --restart unless-stopped \ | ||
| -p 127.0.0.1:9092:9090 \ | ||
| -v omniroute_data:/app/data \ |
There was a problem hiding this comment.
Mount the gateway's actual data volume
When following this standalone quick start, -v omniroute_data:/app/data silently creates a new empty volume unless the existing gateway happens to use that exact global volume name; Compose-managed gateway volumes are normally project-prefixed, and a native or remote gateway will not use this Docker volume at all. OminiRTkSync reads storage.sqlite directly through DB_PATH, so the documented container remains DATABASE_NOT_READY; require the caller to mount the existing gateway data directory or its actual named volume rather than a generic new volume.
Useful? React with 👍 / 👎.
| -v "${HOME}:/root/host:ro" \ | ||
| -v ominirtksync_logs:/app/logs \ | ||
| -e DB_PATH=/app/data/storage.sqlite \ | ||
| -e OMNIROUTE_URL=http://host.docker.internal:20128 \ |
There was a problem hiding this comment.
Make host gateway resolution work on Linux Engine
For users running ordinary Docker Engine on Linux, host.docker.internal is not automatically populated as it is by Docker Desktop, so this standalone command cannot reach the host OmniRoute instance. Docker's documented Linux invocation adds --add-host host.docker.internal=host-gateway; include that flag or provide a platform-specific gateway address. See the docker run --add-host documentation.
Useful? React with 👍 / 👎.
| environment: | ||
| - UPSTREAM_URL=http://ominirtk-router:20128 | ||
| - PORT=8787 |
There was a problem hiding this comment.
Allow Headroom's container bind or configure a proxy token
Starting the headroom profile with the floating latest image now exits because the image binds to 0.0.0.0 internally while this environment supplies neither HEADROOM_PROXY_TOKEN nor HEADROOM_ALLOW_UNAUTHENTICATED_BIND=1. Headroom explicitly refuses an unauthenticated non-loopback bind; since the published host port is already loopback-only, add the acknowledgement variable, or configure a token and document how clients send it. See Headroom's Docker installation requirements.
Useful? React with 👍 / 👎.
| ports: | ||
| - "127.0.0.1:8787:8787" | ||
| environment: | ||
| - UPSTREAM_URL=http://ominirtk-router:20128 |
There was a problem hiding this comment.
Configure Headroom with its supported upstream variable
Even if the Headroom container starts, UPSTREAM_URL is not a Headroom setting, so requests are not automatically forwarded to OmniRoute as the new guide promises; OpenAI-format traffic retains Headroom's default upstream instead. Headroom documents OPENAI_TARGET_API_URL for a custom OpenAI-compatible target (and ANTHROPIC_TARGET_API_URL for Anthropic traffic), so configure the appropriate supported variable with the OmniRoute URL. See Headroom's proxy environment variables.
Useful? React with 👍 / 👎.
| ```bash | ||
| docker compose -f docker-compose.example.yml --profile tailnet up -d | ||
| ``` | ||
| 4. Access via MagicDNS at `http://ominirtk:20128` or Tailscale IP `100.x.y.z:20128`. |
There was a problem hiding this comment.
Provide a Tailscale Serve mapping before advertising access
After these steps, neither http://ominirtk:20128 nor the Tailscale-IP equivalent forwards to OmniRoute: the inspected ominirtk-tailnet service sets TS_SERVE_CONFIG=/config/serve.json, but mounts no /config directory and supplies no Serve mapping, while its userspace network namespace does not expose another container's port automatically. Tailscale requires the JSON configuration file to be mounted and to define the endpoint-to-backend mapping, as shown in its Docker parameter documentation; add that configuration or remove this access claim.
Useful? React with 👍 / 👎.
| > 1. `REQUIRE_LOGIN=true` (with a strong custom password) | ||
| > 2. `REQUIRE_API_KEY=true` (for coding tool authentication) |
There was a problem hiding this comment.
Make the remote-access flags configurable
When an operator follows the documented .env workflow and sets these flags before enabling the public tunnel, the values have no effect because docker-compose.example.yml passes literal REQUIRE_LOGIN=false and REQUIRE_API_KEY=false to OmniRoute, overriding the same variables in .env.example. The quick tunnel therefore exposes the gateway without either advertised protection despite the operator satisfying this prerequisite; interpolate both variables in Compose or explicitly instruct users to edit the Compose service itself.
Useful? React with 👍 / 👎.
| curl -fsSL https://tailscale.com/install.sh | sh | ||
| sudo tailscale up | ||
| tailscale ip -4 |
There was a problem hiding this comment.
Rebind the gateway when installing Tailscale on the host
Following this alternative only joins the host to the tailnet; it does not make the gateway reachable because docker-compose.example.yml publishes OmniRoute exclusively on 127.0.0.1:8082. Requests to the host's 100.x.y.z address therefore never reach that loopback-only listener. Document changing the port mapping to bind the discovered Tailscale IP (using host port 8082, not container port 20128) before presenting host-installed Tailscale as an equivalent remote-access path.
Useful? React with 👍 / 👎.
Adiciona guia completo de deploy com Docker, Headroom, Caveman, Cloudflare Tunnel e Tailscale.