3.1 KiB
3.1 KiB
Local and Server Docker Deployment Implementation Plan
For Codex: execute this plan in the current isolated worktree; keep runtime credentials out of Git.
Goal: Configure and verify a Docker Desktop deployment using GLM 5.2 and the existing PSD workspace, while retaining a portable server deployment contract.
Architecture: The base Compose file builds two applications and consumes only generic environment values and a Docker secret bundle. A tracked GLM Pi registry is mounted read-only in the core container. A Git-ignored local override supplies Mac-specific PSD workspace and CA mounts; server operators supply equivalent server runtime values separately.
Tech Stack: Docker Compose v2, Node 22, Python 3.12, Pi RPC, Fastify, nginx.
Task 1: Add the non-secret GLM Pi registry
Files:
- Create:
deploy/pi/models.json - Modify:
docker/core.Dockerfile - Modify:
compose.yaml - Test: Compose configuration and Pi model discovery
- Define the
zai/glm-5.2OpenAI-compatible model registry without a credential. - Create the Pi user configuration directory in the core image and mount the registry read-only.
- Verify that
get_available_modelsreturnszai/glm-5.2when the bundle supplies the model key.
Task 2: Add generic PSD-compatible runtime templates
Files:
- Create:
deploy/workspaces/psd.yaml.example - Create:
deploy/compose.psd-local.yaml.example - Modify:
deploy/env.example - Modify:
README.md
- Define a relative
/data/workspaces/psdworkspace configuration with external REST DWH/vector adapters. - Document required non-secret environment values and the local/server boundary.
- Keep host paths and credential values out of all tracked files.
Task 3: Materialize local runtime configuration securely
Files (ignored):
- Create:
.env - Create:
deploy/secrets/thothii.secrets - Create:
deploy/compose.psd-local.yaml - Create:
deploy/workspaces/psd.yaml
- Transfer only required values from the existing local configuration without writing them to logs.
- Set
PI_PROVIDER=zai,PI_MODEL=glm-5.2, and the Docker Desktop host gateway for Ollama. - Bind-mount the PSD workspace and private CA read-only where appropriate; sessions remain writable.
- Enforce restricted modes on the secret bundle.
Task 4: Build and verify the Docker deployment
Commands:
docker compose config --quietdocker compose builddocker compose up -d- health/API/model/session smoke checks
- Validate rendered Compose configuration without exposing secrets.
- Build the core and frontend images.
- Verify secret mount, core and frontend health, and model listing.
- Start a PSD session using GLM 5.2 and verify Pi emits a workflow event or gate.
- Capture sanitized diagnostics and stop only disposable test resources; leave the validated local stack running unless it fails.
Task 5: Record the deployment result
Files:
- Modify:
README.mdor deployment documentation
- Record the exact local startup command and server-equivalent configuration steps.
- State verified endpoints, model, and session-start result without secret values.