From 32b1415a6d30dd662b59f4a0f4313d16b3df49c7 Mon Sep 17 00:00:00 2001 From: thulasiraman S Date: Fri, 28 Aug 2026 02:26:42 +0530 Subject: [PATCH] WeLe Agentic AI with Docker deployment --- .dockerignore | 24 +++++++++ .gitattributes | 19 +++++++ DEPLOY.md | 128 +++++++++++++++++++++++++++++++++++++++++++++ Dockerfile | 39 ++++++++++++++ docker-compose.yml | 76 +++++++++++++++++++++++++++ 5 files changed, 286 insertions(+) create mode 100644 .dockerignore create mode 100644 .gitattributes create mode 100644 DEPLOY.md create mode 100644 Dockerfile create mode 100644 docker-compose.yml diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..2600c89 --- /dev/null +++ b/.dockerignore @@ -0,0 +1,24 @@ +# Keep the build context small and secrets out of the image. +node_modules +.git +.gitignore +.env +.env.* +!.env.example + +# The voice service is not part of this image (needs a GPU). +voice-service/ + +# Local-only +scripts/ +storage/artifacts/* +logs/ +*.log +.claude/ +.vscode/ +.idea/ +README.md +DEPLOY.md +Dockerfile +docker-compose.yml +*.md diff --git a/.gitattributes b/.gitattributes new file mode 100644 index 0000000..33d7c30 --- /dev/null +++ b/.gitattributes @@ -0,0 +1,19 @@ +# Normalise to LF in the repository. +* text=auto eol=lf + +# These are consumed by Linux inside containers — CRLF breaks them outright +# (a shebang followed by \r is not a valid interpreter path). +Dockerfile text eol=lf +*.sh text eol=lf +*.yml text eol=lf +*.yaml text eol=lf +.dockerignore text eol=lf +.env.example text eol=lf + +# Binary — never touch. +*.png binary +*.jpg binary +*.pdf binary +*.wav binary +*.onnx binary +*.safetensors binary diff --git a/DEPLOY.md b/DEPLOY.md new file mode 100644 index 0000000..dc98bf0 --- /dev/null +++ b/DEPLOY.md @@ -0,0 +1,128 @@ +# Deploying to AWS + +Target: `ubuntu@52.66.12.133`, Ubuntu 24.04, Docker 29.7.2 / Compose v5.4.0. + +The service runs **alongside** the existing CRM stack, attaching to its network +so it can reach `redis` and `whatsapp-api` by name. It does not modify the CRM. + +> **Do not clone into `/opt/wele/whatsapp-crm`.** That directory is the live +> CRM's own git repo — cloning over it would destroy the running deployment. +> This project gets its own directory next to it. + +## What is *not* deployed + +`voice-service/` stays off this host. It needs a CUDA GPU and ~5 GB of RAM; +the instance has **no GPU, 2 vCPU and 3.7 GB total** (~2.3 GB free with the CRM +running). Attempting it would OOM the box and take the CRM down with it. + +Voice needs a GPU instance (e.g. `g4dn.xlarge`) before it can be deployed. + +## First deploy + +```bash +ssh -i wele-product-aws.pem ubuntu@52.66.12.133 + +sudo mkdir -p /opt/wele/agentic-ai && sudo chown ubuntu:ubuntu /opt/wele/agentic-ai +git clone https://gitea.wele.in/Thulasiraman/Agentic-AI.git /opt/wele/agentic-ai +cd /opt/wele/agentic-ai + +cp .env.example .env +nano .env # fill in the values in the table below + +sudo docker compose up --build -d +sudo docker compose logs -f agentic-ai +``` + +### Required in `.env` + +| Variable | Value | +|---|---| +| `MONGODB_URI` | same connection string the CRM uses | +| `CRM_JWT_SECRET` | **must equal** the CRM's `JWT_SECRET`, or every login is rejected here | +| `GMI_API_KEY` | GMI Cloud key | +| `OPENROUTER_API_KEY` | OpenRouter key (failover) | +| `PUBLIC_BASE_URL` | `https://crm.wele.in` — used in artifact download links | + +`REDIS_*` and `CRM_API_BASE` are set by compose and should be left alone. + +Compose fails fast with a named error if `MONGODB_URI` or `CRM_JWT_SECRET` is +missing, rather than starting a container that cannot authenticate anyone. + +## Updating + +```bash +cd /opt/wele/agentic-ai +git pull origin main +sudo docker compose up --build -d +``` + +## Verify + +```bash +curl -s localhost:4000/health | jq +``` + +Expect `mongo: connected`, `redis: redis`, `crm_api: reachable`, and the model +chains. `redis: memory` means it fell back to an in-process store — check that +the container really joined `whatsapp-crm_default`. + +## Frontend + +The chat UI lives in the **CRM** repo (`frontend/src/pages/AIAssistant.jsx`), +so it deploys with the CRM, not with this service. It needs to know where this +service is: + +```bash +# in the CRM repo, frontend/.env.production +VITE_AGENT_URL=https://crm.wele.in/agent +``` + +Then add a reverse-proxy rule so that path reaches port 4000. Nginx: + +```nginx +location /agent/ { + proxy_pass http://127.0.0.1:4000/; + proxy_http_version 1.1; + + # Required for SSE streaming and the voice WebSocket. + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_set_header Host $host; + proxy_buffering off; + proxy_read_timeout 300s; # a turn can take 45s; the default 60s is too tight +} +``` + +`proxy_buffering off` matters — with it on, nginx holds the SSE stream and the +UI shows nothing until the turn finishes, which looks like a hang. + +## Ports + +| Port | Service | Published | +|---|---|---| +| 3000 | CRM (`wele-whatsapp-api`) | yes | +| 4000 | **this service** | yes | +| 4000 | CRM `chat-service` | no — container-internal only, so no clash | +| 6379 | Redis (shared) | yes | +| 19530 | Milvus | yes | + +## Resource notes + +The container is capped at **768 MB**. On a 3.7 GB box already running the CRM, +chat-service, Redis and Milvus, an uncapped Node process having a bad turn can +starve the CRM. Raise it only if you see OOM kills: + +```bash +sudo docker inspect wele-agentic-ai --format '{{.State.OOMKilled}}' +``` + +## Rollback + +```bash +cd /opt/wele/agentic-ai +git log --oneline -5 +git checkout +sudo docker compose up --build -d +``` + +The CRM is a separate stack and is unaffected by anything here. diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..2cca1a9 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,39 @@ +# ============================================ +# WeLe Agentic AI — production image +# +# Node service only. The voice service is deliberately NOT in this image: it +# needs a CUDA GPU and several GB of RAM, and the target host has neither. +# See DEPLOY.md. +# ============================================ + +FROM node:20-alpine AS deps +WORKDIR /app +COPY package*.json ./ +# `npm ci` builds exactly the lockfile, so a deploy can never silently pick up +# a different dependency tree than the one that was tested. +RUN npm ci --omit=dev + +FROM node:20-alpine +WORKDIR /app + +# Run unprivileged. The base image already ships a `node` user. +ENV NODE_ENV=production \ + PORT=4000 + +COPY --from=deps /app/node_modules ./node_modules +COPY package.json ./ +COPY src/ ./src/ + +# Generated reports are written here. Owned by `node` so the unprivileged +# process can write, and a volume is mounted over it in compose so files +# survive a rebuild. +RUN mkdir -p /app/storage/artifacts && chown -R node:node /app/storage + +USER node +EXPOSE 4000 + +# Compose owns restart policy; this is the in-container liveness signal. +HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \ + CMD node -e "fetch('http://127.0.0.1:'+(process.env.PORT||4000)+'/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))" + +CMD ["node", "src/server.js"] diff --git a/docker-compose.yml b/docker-compose.yml new file mode 100644 index 0000000..3f81949 --- /dev/null +++ b/docker-compose.yml @@ -0,0 +1,76 @@ +# ============================================ +# WeLe Agentic AI — deployment +# +# Runs alongside the existing CRM stack rather than inside it. Joining the +# CRM's network (`whatsapp-crm_default`) lets this service reach `redis` and +# `whatsapp-api` by name, without publishing anything extra or duplicating a +# Redis on a 3.7 GB box. +# +# The voice service is not here on purpose — it needs a CUDA GPU. See DEPLOY.md. +# ============================================ + +services: + agentic-ai: + build: . + image: wele/agentic-ai:latest + container_name: wele-agentic-ai + restart: always + + # Host 4000 is free. The CRM's chat-service also listens on 4000, but only + # inside its own container — it publishes nothing, so there is no clash. + ports: + - "4000:4000" + + env_file: + - .env + + environment: + - NODE_ENV=production + - PORT=4000 + + # Reuse the CRM's Redis by service name on the shared network. + # Keys are namespaced with REDIS_PREFIX, so the two never collide. + - REDIS_ENABLED=true + - REDIS_HOST=redis + - REDIS_PORT=6379 + - REDIS_PREFIX=agentic: + + # Writes go through the CRM's own REST routes so its lead scoring, + # socket events and audit trail still fire. Reached over the shared + # network, so this never leaves the host. + - CRM_API_BASE=http://whatsapp-api:3000 + + # Must match the CRM's JWT_SECRET — that is how a CRM login is accepted + # here with the same role and permissions. Sourced from .env so the + # secret is never written into this file. + - CRM_JWT_SECRET=${CRM_JWT_SECRET:?set CRM_JWT_SECRET in .env — must equal the CRM JWT_SECRET} + - MONGODB_URI=${MONGODB_URI:?set MONGODB_URI in .env} + + volumes: + # Generated xlsx/pdf/pptx survive rebuilds; swept on a TTL by the app. + - artifacts:/app/storage/artifacts + + # A 2 vCPU / 3.7 GB host already runs the CRM, chat-service, Redis and + # Milvus. Capping this container keeps a runaway turn from starving them. + deploy: + resources: + limits: + memory: 768M + + logging: + driver: json-file + options: + max-size: "10m" + max-file: "3" + + networks: + - crm + +networks: + crm: + # Created by the CRM's own compose project; we attach, never own it. + name: whatsapp-crm_default + external: true + +volumes: + artifacts: