Skip to content

docs(deployment): adiciona guia de deploy docker, headroom e acesso remoto - #23

Merged
elielsousa-pathbit merged 1 commit into
masterfrom
feat/docker-deployment-guide
Oct 7, 2026
Merged

elielsousa-pathbit merged 1 commit into
masterfrom
feat/docker-deployment-guide

Conversation

@elielsousa-pathbit

Copy link
Copy Markdown
Contributor

Adiciona guia completo de deploy com Docker, Headroom, Caveman, Cloudflare Tunnel e Tailscale.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T23:55:35.493169Z a1a9fc7 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@elielsousa-pathbit
elielsousa-pathbit merged commit 90b4158 into master Oct 7, 2026
6 checks passed
@elielsousa-pathbit
elielsousa-pathbit deleted the feat/docker-deployment-guide branch October 7, 2026 23:52

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a1a9fc703e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

### Step 2: Launch Stack

```bash
docker compose -f docker-compose.example.yml up -d

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Create the external network before launching Compose

On a fresh Docker host, this advertised production launch fails before starting any container because ominirtk-router always attaches to the external rtk-inference-net, despite the preceding text calling that network optional. Docker explicitly requires external networks to exist before compose up; use the repository's make setup target or document docker network create rtk-inference-net before this command. See Docker's external-network documentation.

Useful? React with 👍 / 👎.

--name ominirtk-sync \
--restart unless-stopped \
-p 127.0.0.1:9092:9090 \
-v omniroute_data:/app/data \

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Mount the gateway's actual data volume

When following this standalone quick start, -v omniroute_data:/app/data silently creates a new empty volume unless the existing gateway happens to use that exact global volume name; Compose-managed gateway volumes are normally project-prefixed, and a native or remote gateway will not use this Docker volume at all. OminiRTkSync reads storage.sqlite directly through DB_PATH, so the documented container remains DATABASE_NOT_READY; require the caller to mount the existing gateway data directory or its actual named volume rather than a generic new volume.

Useful? React with 👍 / 👎.

-v "${HOME}:/root/host:ro" \
-v ominirtksync_logs:/app/logs \
-e DB_PATH=/app/data/storage.sqlite \
-e OMNIROUTE_URL=http://host.docker.internal:20128 \

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Make host gateway resolution work on Linux Engine

For users running ordinary Docker Engine on Linux, host.docker.internal is not automatically populated as it is by Docker Desktop, so this standalone command cannot reach the host OmniRoute instance. Docker's documented Linux invocation adds --add-host host.docker.internal=host-gateway; include that flag or provide a platform-specific gateway address. See the docker run --add-host documentation.

Useful? React with 👍 / 👎.

Comment on lines +204 to +206
environment:
- UPSTREAM_URL=http://ominirtk-router:20128
- PORT=8787

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Allow Headroom's container bind or configure a proxy token

Starting the headroom profile with the floating latest image now exits because the image binds to 0.0.0.0 internally while this environment supplies neither HEADROOM_PROXY_TOKEN nor HEADROOM_ALLOW_UNAUTHENTICATED_BIND=1. Headroom explicitly refuses an unauthenticated non-loopback bind; since the published host port is already loopback-only, add the acknowledgement variable, or configure a token and document how clients send it. See Headroom's Docker installation requirements.

Useful? React with 👍 / 👎.

ports:
- "127.0.0.1:8787:8787"
environment:
- UPSTREAM_URL=http://ominirtk-router:20128

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Configure Headroom with its supported upstream variable

Even if the Headroom container starts, UPSTREAM_URL is not a Headroom setting, so requests are not automatically forwarded to OmniRoute as the new guide promises; OpenAI-format traffic retains Headroom's default upstream instead. Headroom documents OPENAI_TARGET_API_URL for a custom OpenAI-compatible target (and ANTHROPIC_TARGET_API_URL for Anthropic traffic), so configure the appropriate supported variable with the OmniRoute URL. See Headroom's proxy environment variables.

Useful? React with 👍 / 👎.

```bash
docker compose -f docker-compose.example.yml --profile tailnet up -d
```
4. Access via MagicDNS at `http://ominirtk:20128` or Tailscale IP `100.x.y.z:20128`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Provide a Tailscale Serve mapping before advertising access

After these steps, neither http://ominirtk:20128 nor the Tailscale-IP equivalent forwards to OmniRoute: the inspected ominirtk-tailnet service sets TS_SERVE_CONFIG=/config/serve.json, but mounts no /config directory and supplies no Serve mapping, while its userspace network namespace does not expose another container's port automatically. Tailscale requires the JSON configuration file to be mounted and to define the endpoint-to-backend mapping, as shown in its Docker parameter documentation; add that configuration or remove this access claim.

Useful? React with 👍 / 👎.

Comment on lines +140 to +141
> 1. `REQUIRE_LOGIN=true` (with a strong custom password)
> 2. `REQUIRE_API_KEY=true` (for coding tool authentication)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Make the remote-access flags configurable

When an operator follows the documented .env workflow and sets these flags before enabling the public tunnel, the values have no effect because docker-compose.example.yml passes literal REQUIRE_LOGIN=false and REQUIRE_API_KEY=false to OmniRoute, overriding the same variables in .env.example. The quick tunnel therefore exposes the gateway without either advertised protection despite the operator satisfying this prerequisite; interpolate both variables in Compose or explicitly instruct users to edit the Compose service itself.

Useful? React with 👍 / 👎.

Comment on lines +190 to +192
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up
tailscale ip -4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Rebind the gateway when installing Tailscale on the host

Following this alternative only joins the host to the tailnet; it does not make the gateway reachable because docker-compose.example.yml publishes OmniRoute exclusively on 127.0.0.1:8082. Requests to the host's 100.x.y.z address therefore never reach that loopback-only listener. Document changing the port mapping to bind the discovered Tailscale IP (using host port 8082, not container port 20128) before presenting host-installed Tailscale as an equivalent remote-access path.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant