2a3bb6922d
Closes #46 once deployed. The headless browser leaves the API stack and becomes its own compose unit (`chrome/docker-compose.yml`) intended for the home machine, reached over the tailnet. No fallback sidecar is left on the VPS. The backend needs no code change — `BROWSER_WS_URL` was already the only coupling. Its default is now empty rather than a pinned Docker IP, so an unconfigured or unreachable browser degrades exactly as it always has: plain-TLS libraries unaffected, kagane/novelfull logged and skipped, stored covers still served. ### What shipped - `chrome/docker-compose.yml` + `chrome/.env.example` — the browser unit, with the CDP port bound to `${BROWSER_BIND_ADDR}` (no default) and the resource limits from the epic: 512 MiB / 1 GiB memory+swap, `oom_score_adj 800`, halved CPU weight, shm 1 GiB -> 128 MiB. - API stack drops the service, its `depends_on` and the `browser` network. - `bookmark-api` gains the `default` network. Dropping `browser` had left it on `db` alone, which is `internal: true` — no published port and, worse, no egress for the poller at all. Caught by actually bringing the stack up. - ADR-0006 for the topology; `DEPLOY.md` §7 for first-time setup of the browser machine; `REDEPLOY.md` §8 for its independent update cadence; architecture diagrams, config tables and troubleshooting rows across README/AGENTS/env. ### Verified locally - Browser unit builds and runs: Chrome 151, UA carries no `HeadlessChrome`, all limits applied as declared. - **Live smoke passes through the new unit**: `TestSmokeKaganeImage` fetched 56710 bytes of `image/webp`, `TestSmokeKaganeGet` got a 200 with a real chapter list. The challenge cleared under the reduced 128 MiB shm. - Bind isolation proven: refused on the host's non-loopback address, accepted on the configured one. - 321 MiB peak of the 512 MiB cap after a full solve; 0 restarts, no OOM kill. - API stack comes up clean, `/healthz` 200; egress confirmed present on `default` and absent on `db`. - `go test ./...`, `go vet`, `gofmt` clean. ### Left to the operator Provisioning the home machine, the Tailscale ACL, setting `BROWSER_WS_URL` in production, and observing acceptance criteria 5-7 (covers with the machine off, several days of zero OOM/restarts, VPS memory improvement). `DEPLOY.md` §7 now carries the before/after `free -m` reading those need. Reviewed-on: #52 Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com> Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
29 lines
1.4 KiB
Bash
29 lines
1.4 KiB
Bash
# Copy to chrome/.env on the home machine. Never commit the real .env.
|
|
#
|
|
# This file configures the browser unit only. It is separate from the API
|
|
# stack's ../.env on purpose: the two run on different machines.
|
|
|
|
# The address the CDP port is published on — required, no default.
|
|
#
|
|
# Use this machine's **tailnet IP**, e.g. 100.x.y.z (`tailscale ip -4`). Not
|
|
# 0.0.0.0, not the LAN address: CDP has no authentication of its own, so
|
|
# anything that can reach this port has full control of the browser and a
|
|
# foothold on this host. Tailscale device identity plus an ACL is the access
|
|
# control; the bind address is what enforces it.
|
|
#
|
|
# For a throwaway local test, 127.0.0.1 is fine — but then only this machine
|
|
# can reach it, so the API must run here too.
|
|
# Left commented so `cp .env.example .env && docker compose up` fails with the
|
|
# variable's own message telling you what to set, rather than Docker rejecting
|
|
# "100.x.y.z" as an invalid IP.
|
|
# BROWSER_BIND_ADDR=100.x.y.z
|
|
|
|
# Clock zone the browser reports. Any real zone works and it need not match
|
|
# the egress IP's country — but it must not be UTC, which is itself the bot
|
|
# signal that stops the challenge clearing. The measurement is in entrypoint.sh.
|
|
#
|
|
# Unset falls back to the host's /etc/timezone, which is a real zone whenever
|
|
# the host clock is set to local time. Set this when the host runs UTC — a UTC
|
|
# server is exactly the case that fails.
|
|
# BROWSER_TZ=Asia/Jakarta
|