gitoriaLog in with ident

antcolony

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commita6af7883a6af7883tracker: worker box sees calendar.worldapi.org (login to copy)mrea6af7883/docker-compose.yml

5.1 KB

  1. # antcolony-scheduler — permanent `./colony run --live` on Loreana (mission 028, ticket antcolony#1).
  2. # README "Operations" says how to start / stop / read logs / change settings.
  3. #
  4. # How: a tiny busybox container that bind-mounts the HOST's / and pivot_roots into it (docker/pivot.sh), then drops to
  5. # uid 1000 (mre) and runs docker/entrypoint.sh → ./colony run. The scheduler and its workers therefore see exactly the
  6. # host's toolchain (claude + ~/.claude login, node, google-chrome-stable, rsync, ssh, /media/STORAGE/projects, the token)
  7. # — nothing is installed in an image. Root only exists for the three mount calls in pivot.sh.
  8. # Settings: environment below, overridden by a `.env` beside this file (see .env.example — never commit a .env).
  9. services:
  10. scheduler:
  11. image: busybox:1.37-musl@sha256:5cec3fc171c87218698e85a52af7087de727372aae264a787b8112901a5b0092
  12. container_name: antcolony-scheduler
  13. restart: unless-stopped # starts with the docker daemon (enabled at boot); `docker stop` keeps it stopped
  14. network_mode: host # same network as the host (workers' dev servers, tickets, Claude API)
  15. pid: host # same /proc as the host fs: lib/cleanup.sh reads /proc + ss, PIDs must match
  16. cap_add: [SYS_ADMIN] # pivot.sh: mount --make-rprivate + pivot_root (dropped with the switch to uid 1000)
  17. security_opt:
  18. - seccomp=unconfined # pivot_root, and Chrome's sandbox (user namespaces) like on the host
  19. stop_grace_period: 75s # docker stop: finish window (COLONY_STOP_FINISH_SECONDS, 20) + park, < systemd's 90 s at shutdown
  20. volumes:
  21. - /:/host # recursive bind; propagation rprivate (docker default)
  22. entrypoint: ["sh", "/host/media/STORAGE/projects/antcolony-scheduler/docker/pivot.sh"]
  23. logging:
  24. driver: json-file
  25. options: { max-size: "10m", max-file: "3" }
  26. environment:
  27. COLONY_LIVE: ${COLONY_LIVE:-1} # 1 → `run --live` (the live tickets server)
  28. COLONY_TICKETS_URL: ${COLONY_TICKETS_URL:-https://tickets.worldapi.org}
  29. COLONY_TOKEN_FILE: ${COLONY_TOKEN_FILE:-/home/mre/.config/antcolony/tickets-token}
  30. CLAUDE_CONFIG_DIR: ${CLAUDE_CONFIG_DIR:-} # empty = the host's ~/.claude (mre's own subscription); e.g. /home/mre/.claude-colony = a separate login for the workers
  31. COLONY_QUOTA_RESERVE: ${COLONY_RESERVE:-70} # no start at/above this % of the 5 h window; 100 = off
  32. COLONY_WEEK_LIMIT: ${COLONY_WEEK_LIMIT:-84} # no start while the weekly usage is above; 100 = off
  33. COLONY_RUN_INTERVAL: ${COLONY_RUN_INTERVAL:-60} # seconds between iterations
  34. COLONY_PARALLEL: ${COLONY_PARALLEL:-1} # sessions at once
  35. COLONY_MODEL: ${COLONY_MODEL:-sonnet}
  36. COLONY_SANDBOX: ${COLONY_SANDBOX:-} # antcolony#18: on (default) | off — every Claude session in a bubblewrap box (README "Sandbox")
  37. COLONY_SANDBOX_RO: ${COLONY_SANDBOX_RO:-} # extra read-only paths, ':'-separated (default /media/STORAGE/projects/antcolony-docs)
  38. COLONY_MAX_TURNS: ${COLONY_MAX_TURNS:-40}
  39. COLONY_WORK_TIMEOUT: ${COLONY_WORK_TIMEOUT:-3600}
  40. COLONY_CONTROLLER_MODEL: ${COLONY_CONTROLLER_MODEL:-sonnet}
  41. COLONY_CONTROLLER_MAX_TURNS: ${COLONY_CONTROLLER_MAX_TURNS:-20}
  42. COLONY_CONTROLLER_TIMEOUT: ${COLONY_CONTROLLER_TIMEOUT:-900}
  43. COLONY_MAX_BUDGET_USD: ${COLONY_MAX_BUDGET_USD:-} # empty = no --max-budget-usd
  44. COLONY_PORT_POOL: ${COLONY_PORT_POOL:-8700-8799}
  45. COLONY_PORTS_PER_SESSION: ${COLONY_PORTS_PER_SESSION:-10}
  46. COLONY_RUN_ARGS: ${COLONY_RUN_ARGS:-} # extra `run` options, e.g. "--lease-ttl 7200"
  47. COLONY_STOP_FINISH_SECONDS: ${COLONY_STOP_FINISH_SECONDS:-20} # docker stop: let sessions finish this long, then park
  48. COLONY_LOG_MAX_BYTES: ${COLONY_LOG_MAX_BYTES:-10485760} # logs/colony.log rotates at this size
  49. COLONY_LOG_KEEP: ${COLONY_LOG_KEEP:-5} # rotated files kept (colony.log.1 … .5)
  50. COLONY_LIBRARIAN: ${COLONY_LIBRARIAN:-} # mission 029: on (default) | off — the librarian FIRST in every iteration
  51. COLONY_LIBRARIAN_MODEL: ${COLONY_LIBRARIAN_MODEL:-} # its model (default sonnet)
  52. COLONY_LIBRARIAN_FALLBACK: ${COLONY_LIBRARIAN_FALLBACK:-} # antcolony#20: where a text goes when the local model cannot answer (default sonnet)
  53. COLONY_LOCAL_URL: ${COLONY_LOCAL_URL:-} # antcolony#20: OpenAI-compatible endpoint of the local model (default http://127.0.0.1:8080/v1)
  54. COLONY_LOCAL_TIMEOUT: ${COLONY_LOCAL_TIMEOUT:-} # seconds per local call (default 120)
  55. COLONY_LIBRARIAN_MAX: ${COLONY_LIBRARIAN_MAX:-} # creator texts classified per iteration (default 0 = all; a text left over → no start that iteration)
  56. COLONY_CREATOR_NAMES: ${COLONY_CREATOR_NAMES:-} # the creator's display names in tickets (default Caramboleyo,creator)
  57. COLONY_CREATOR_TOKEN_FILE: ${COLONY_CREATOR_TOKEN_FILE:-} # optional: the creator's tickets token, lets /confirm and /reject in comments work

Branches

Latest commits

  • a6af7883tracker: worker box sees calendar.worldapi.org (login to copy)mre
  • c613d26btemplates: bridges to external components (login.js for ident's selector) are allowed (creator 2026-09-27)mre
  • 9062978ctracker: worker box sees /media/STORAGE/projects/old-tracker read-only (tracker#2 source data)mre
  • 7f9660eeState of 2026-09-27, before the move to gitoriamre