services: kb-query: build: # Repo-root context (not the usual `.` = this dir) so the Dockerfile can # `COPY packages/kb-retrieval/` — the packages/ Dockerfile convention from # CLAUDE.md. scripts/deploy/deploy.sh's gate and deploy-node.sh's # `docker compose ... up --build` both resolve this the same way. context: ../.. dockerfile: services/kb-query/Dockerfile container_name: kb-query restart: unless-stopped ports: # LAN-only bind, never 0.0.0.0 — same convention as paperless/nextcloud # (exposure: private). npm@PIHA vhost + OIDC are a later step (plan §8); # this bind is what that vhost will eventually proxy to. # Requires .env (from env.example) next to this file at deploy. - "${LAN_BIND_IP}:8230:8080" environment: - KB_DSN=${KB_DSN} - OLLAMA_URL=${OLLAMA_URL:-http://solaria:11434} - OLLAMA_PIHA_URL=${OLLAMA_PIHA_URL:-http://localhost:11434} - EMBED_MODEL=${EMBED_MODEL:-bge-m3} - SUMMARY_MODEL=${SUMMARY_MODEL:-claude-haiku-4-5} # python:3.12-slim has no curl/wget; same in-container check pattern as llm-gateway. healthcheck: test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8080/healthz', timeout=3).read()"] interval: 30s timeout: 10s retries: 5 start_period: 10s