WeLe Agentic AI with Docker deployment
This commit is contained in:
@@ -0,0 +1,24 @@
|
|||||||
|
# Keep the build context small and secrets out of the image.
|
||||||
|
node_modules
|
||||||
|
.git
|
||||||
|
.gitignore
|
||||||
|
.env
|
||||||
|
.env.*
|
||||||
|
!.env.example
|
||||||
|
|
||||||
|
# The voice service is not part of this image (needs a GPU).
|
||||||
|
voice-service/
|
||||||
|
|
||||||
|
# Local-only
|
||||||
|
scripts/
|
||||||
|
storage/artifacts/*
|
||||||
|
logs/
|
||||||
|
*.log
|
||||||
|
.claude/
|
||||||
|
.vscode/
|
||||||
|
.idea/
|
||||||
|
README.md
|
||||||
|
DEPLOY.md
|
||||||
|
Dockerfile
|
||||||
|
docker-compose.yml
|
||||||
|
*.md
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
# Normalise to LF in the repository.
|
||||||
|
* text=auto eol=lf
|
||||||
|
|
||||||
|
# These are consumed by Linux inside containers — CRLF breaks them outright
|
||||||
|
# (a shebang followed by \r is not a valid interpreter path).
|
||||||
|
Dockerfile text eol=lf
|
||||||
|
*.sh text eol=lf
|
||||||
|
*.yml text eol=lf
|
||||||
|
*.yaml text eol=lf
|
||||||
|
.dockerignore text eol=lf
|
||||||
|
.env.example text eol=lf
|
||||||
|
|
||||||
|
# Binary — never touch.
|
||||||
|
*.png binary
|
||||||
|
*.jpg binary
|
||||||
|
*.pdf binary
|
||||||
|
*.wav binary
|
||||||
|
*.onnx binary
|
||||||
|
*.safetensors binary
|
||||||
@@ -0,0 +1,128 @@
|
|||||||
|
# Deploying to AWS
|
||||||
|
|
||||||
|
Target: `ubuntu@52.66.12.133`, Ubuntu 24.04, Docker 29.7.2 / Compose v5.4.0.
|
||||||
|
|
||||||
|
The service runs **alongside** the existing CRM stack, attaching to its network
|
||||||
|
so it can reach `redis` and `whatsapp-api` by name. It does not modify the CRM.
|
||||||
|
|
||||||
|
> **Do not clone into `/opt/wele/whatsapp-crm`.** That directory is the live
|
||||||
|
> CRM's own git repo — cloning over it would destroy the running deployment.
|
||||||
|
> This project gets its own directory next to it.
|
||||||
|
|
||||||
|
## What is *not* deployed
|
||||||
|
|
||||||
|
`voice-service/` stays off this host. It needs a CUDA GPU and ~5 GB of RAM;
|
||||||
|
the instance has **no GPU, 2 vCPU and 3.7 GB total** (~2.3 GB free with the CRM
|
||||||
|
running). Attempting it would OOM the box and take the CRM down with it.
|
||||||
|
|
||||||
|
Voice needs a GPU instance (e.g. `g4dn.xlarge`) before it can be deployed.
|
||||||
|
|
||||||
|
## First deploy
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh -i wele-product-aws.pem ubuntu@52.66.12.133
|
||||||
|
|
||||||
|
sudo mkdir -p /opt/wele/agentic-ai && sudo chown ubuntu:ubuntu /opt/wele/agentic-ai
|
||||||
|
git clone https://gitea.wele.in/Thulasiraman/Agentic-AI.git /opt/wele/agentic-ai
|
||||||
|
cd /opt/wele/agentic-ai
|
||||||
|
|
||||||
|
cp .env.example .env
|
||||||
|
nano .env # fill in the values in the table below
|
||||||
|
|
||||||
|
sudo docker compose up --build -d
|
||||||
|
sudo docker compose logs -f agentic-ai
|
||||||
|
```
|
||||||
|
|
||||||
|
### Required in `.env`
|
||||||
|
|
||||||
|
| Variable | Value |
|
||||||
|
|---|---|
|
||||||
|
| `MONGODB_URI` | same connection string the CRM uses |
|
||||||
|
| `CRM_JWT_SECRET` | **must equal** the CRM's `JWT_SECRET`, or every login is rejected here |
|
||||||
|
| `GMI_API_KEY` | GMI Cloud key |
|
||||||
|
| `OPENROUTER_API_KEY` | OpenRouter key (failover) |
|
||||||
|
| `PUBLIC_BASE_URL` | `https://crm.wele.in` — used in artifact download links |
|
||||||
|
|
||||||
|
`REDIS_*` and `CRM_API_BASE` are set by compose and should be left alone.
|
||||||
|
|
||||||
|
Compose fails fast with a named error if `MONGODB_URI` or `CRM_JWT_SECRET` is
|
||||||
|
missing, rather than starting a container that cannot authenticate anyone.
|
||||||
|
|
||||||
|
## Updating
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cd /opt/wele/agentic-ai
|
||||||
|
git pull origin main
|
||||||
|
sudo docker compose up --build -d
|
||||||
|
```
|
||||||
|
|
||||||
|
## Verify
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -s localhost:4000/health | jq
|
||||||
|
```
|
||||||
|
|
||||||
|
Expect `mongo: connected`, `redis: redis`, `crm_api: reachable`, and the model
|
||||||
|
chains. `redis: memory` means it fell back to an in-process store — check that
|
||||||
|
the container really joined `whatsapp-crm_default`.
|
||||||
|
|
||||||
|
## Frontend
|
||||||
|
|
||||||
|
The chat UI lives in the **CRM** repo (`frontend/src/pages/AIAssistant.jsx`),
|
||||||
|
so it deploys with the CRM, not with this service. It needs to know where this
|
||||||
|
service is:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# in the CRM repo, frontend/.env.production
|
||||||
|
VITE_AGENT_URL=https://crm.wele.in/agent
|
||||||
|
```
|
||||||
|
|
||||||
|
Then add a reverse-proxy rule so that path reaches port 4000. Nginx:
|
||||||
|
|
||||||
|
```nginx
|
||||||
|
location /agent/ {
|
||||||
|
proxy_pass http://127.0.0.1:4000/;
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
|
||||||
|
# Required for SSE streaming and the voice WebSocket.
|
||||||
|
proxy_set_header Upgrade $http_upgrade;
|
||||||
|
proxy_set_header Connection "upgrade";
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_buffering off;
|
||||||
|
proxy_read_timeout 300s; # a turn can take 45s; the default 60s is too tight
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
`proxy_buffering off` matters — with it on, nginx holds the SSE stream and the
|
||||||
|
UI shows nothing until the turn finishes, which looks like a hang.
|
||||||
|
|
||||||
|
## Ports
|
||||||
|
|
||||||
|
| Port | Service | Published |
|
||||||
|
|---|---|---|
|
||||||
|
| 3000 | CRM (`wele-whatsapp-api`) | yes |
|
||||||
|
| 4000 | **this service** | yes |
|
||||||
|
| 4000 | CRM `chat-service` | no — container-internal only, so no clash |
|
||||||
|
| 6379 | Redis (shared) | yes |
|
||||||
|
| 19530 | Milvus | yes |
|
||||||
|
|
||||||
|
## Resource notes
|
||||||
|
|
||||||
|
The container is capped at **768 MB**. On a 3.7 GB box already running the CRM,
|
||||||
|
chat-service, Redis and Milvus, an uncapped Node process having a bad turn can
|
||||||
|
starve the CRM. Raise it only if you see OOM kills:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo docker inspect wele-agentic-ai --format '{{.State.OOMKilled}}'
|
||||||
|
```
|
||||||
|
|
||||||
|
## Rollback
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cd /opt/wele/agentic-ai
|
||||||
|
git log --oneline -5
|
||||||
|
git checkout <previous-sha>
|
||||||
|
sudo docker compose up --build -d
|
||||||
|
```
|
||||||
|
|
||||||
|
The CRM is a separate stack and is unaffected by anything here.
|
||||||
+39
@@ -0,0 +1,39 @@
|
|||||||
|
# ============================================
|
||||||
|
# WeLe Agentic AI — production image
|
||||||
|
#
|
||||||
|
# Node service only. The voice service is deliberately NOT in this image: it
|
||||||
|
# needs a CUDA GPU and several GB of RAM, and the target host has neither.
|
||||||
|
# See DEPLOY.md.
|
||||||
|
# ============================================
|
||||||
|
|
||||||
|
FROM node:20-alpine AS deps
|
||||||
|
WORKDIR /app
|
||||||
|
COPY package*.json ./
|
||||||
|
# `npm ci` builds exactly the lockfile, so a deploy can never silently pick up
|
||||||
|
# a different dependency tree than the one that was tested.
|
||||||
|
RUN npm ci --omit=dev
|
||||||
|
|
||||||
|
FROM node:20-alpine
|
||||||
|
WORKDIR /app
|
||||||
|
|
||||||
|
# Run unprivileged. The base image already ships a `node` user.
|
||||||
|
ENV NODE_ENV=production \
|
||||||
|
PORT=4000
|
||||||
|
|
||||||
|
COPY --from=deps /app/node_modules ./node_modules
|
||||||
|
COPY package.json ./
|
||||||
|
COPY src/ ./src/
|
||||||
|
|
||||||
|
# Generated reports are written here. Owned by `node` so the unprivileged
|
||||||
|
# process can write, and a volume is mounted over it in compose so files
|
||||||
|
# survive a rebuild.
|
||||||
|
RUN mkdir -p /app/storage/artifacts && chown -R node:node /app/storage
|
||||||
|
|
||||||
|
USER node
|
||||||
|
EXPOSE 4000
|
||||||
|
|
||||||
|
# Compose owns restart policy; this is the in-container liveness signal.
|
||||||
|
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \
|
||||||
|
CMD node -e "fetch('http://127.0.0.1:'+(process.env.PORT||4000)+'/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"
|
||||||
|
|
||||||
|
CMD ["node", "src/server.js"]
|
||||||
@@ -0,0 +1,76 @@
|
|||||||
|
# ============================================
|
||||||
|
# WeLe Agentic AI — deployment
|
||||||
|
#
|
||||||
|
# Runs alongside the existing CRM stack rather than inside it. Joining the
|
||||||
|
# CRM's network (`whatsapp-crm_default`) lets this service reach `redis` and
|
||||||
|
# `whatsapp-api` by name, without publishing anything extra or duplicating a
|
||||||
|
# Redis on a 3.7 GB box.
|
||||||
|
#
|
||||||
|
# The voice service is not here on purpose — it needs a CUDA GPU. See DEPLOY.md.
|
||||||
|
# ============================================
|
||||||
|
|
||||||
|
services:
|
||||||
|
agentic-ai:
|
||||||
|
build: .
|
||||||
|
image: wele/agentic-ai:latest
|
||||||
|
container_name: wele-agentic-ai
|
||||||
|
restart: always
|
||||||
|
|
||||||
|
# Host 4000 is free. The CRM's chat-service also listens on 4000, but only
|
||||||
|
# inside its own container — it publishes nothing, so there is no clash.
|
||||||
|
ports:
|
||||||
|
- "4000:4000"
|
||||||
|
|
||||||
|
env_file:
|
||||||
|
- .env
|
||||||
|
|
||||||
|
environment:
|
||||||
|
- NODE_ENV=production
|
||||||
|
- PORT=4000
|
||||||
|
|
||||||
|
# Reuse the CRM's Redis by service name on the shared network.
|
||||||
|
# Keys are namespaced with REDIS_PREFIX, so the two never collide.
|
||||||
|
- REDIS_ENABLED=true
|
||||||
|
- REDIS_HOST=redis
|
||||||
|
- REDIS_PORT=6379
|
||||||
|
- REDIS_PREFIX=agentic:
|
||||||
|
|
||||||
|
# Writes go through the CRM's own REST routes so its lead scoring,
|
||||||
|
# socket events and audit trail still fire. Reached over the shared
|
||||||
|
# network, so this never leaves the host.
|
||||||
|
- CRM_API_BASE=http://whatsapp-api:3000
|
||||||
|
|
||||||
|
# Must match the CRM's JWT_SECRET — that is how a CRM login is accepted
|
||||||
|
# here with the same role and permissions. Sourced from .env so the
|
||||||
|
# secret is never written into this file.
|
||||||
|
- CRM_JWT_SECRET=${CRM_JWT_SECRET:?set CRM_JWT_SECRET in .env — must equal the CRM JWT_SECRET}
|
||||||
|
- MONGODB_URI=${MONGODB_URI:?set MONGODB_URI in .env}
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
# Generated xlsx/pdf/pptx survive rebuilds; swept on a TTL by the app.
|
||||||
|
- artifacts:/app/storage/artifacts
|
||||||
|
|
||||||
|
# A 2 vCPU / 3.7 GB host already runs the CRM, chat-service, Redis and
|
||||||
|
# Milvus. Capping this container keeps a runaway turn from starving them.
|
||||||
|
deploy:
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: 768M
|
||||||
|
|
||||||
|
logging:
|
||||||
|
driver: json-file
|
||||||
|
options:
|
||||||
|
max-size: "10m"
|
||||||
|
max-file: "3"
|
||||||
|
|
||||||
|
networks:
|
||||||
|
- crm
|
||||||
|
|
||||||
|
networks:
|
||||||
|
crm:
|
||||||
|
# Created by the CRM's own compose project; we attach, never own it.
|
||||||
|
name: whatsapp-crm_default
|
||||||
|
external: true
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
artifacts:
|
||||||
Reference in New Issue
Block a user