Add a tiny privileged sidecar (vision-manager/) that polls the analysis backlog in Postgres and starts/stops the mangalord-vision container by name: start when analyze_page jobs are pending, stop after STOP_DEBOUNCE idle. It is the single owner of the vision lifecycle and the only component with Docker access — scoped through tecnativa/docker-socket-proxy (CONTAINERS+POST only) on an internal-only network, so the internet-facing backend never touches the socket. Both helpers sit behind `profiles: [ai]` (vanilla `compose up` is unaffected). The manager debounces the stop, gates the first request on GET /health==200 after a cold start, honours a crawl RAM-mutex on the 8 GiB box, and owns its own idle timer (leak-safe if the backend dies). Backlog query uses the real schema (state + payload->>'kind'); a read-only DB role (readonly-role.sql) keeps it off the backend creds. Bump 0.80.0 -> 0.81.0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
18 lines
707 B
Docker
18 lines
707 B
Docker
# vision-manager — tiny sidecar that starts/stops mangalord-vision by name
|
|
# according to the analysis backlog. See manager.sh and VISION-AUTOSCALE.md.
|
|
FROM alpine:3.20
|
|
|
|
# bash (the script uses arrays/arithmetic), curl (/health probe),
|
|
# postgresql-client (psql backlog query), docker-cli (start/stop via the
|
|
# socket-proxy). No daemon, no compiled build.
|
|
RUN apk add --no-cache bash curl postgresql-client docker-cli
|
|
|
|
COPY manager.sh /usr/local/bin/manager.sh
|
|
RUN chmod +x /usr/local/bin/manager.sh
|
|
|
|
# Run unprivileged: the container only needs to reach the socket-proxy over
|
|
# TCP and Postgres — it never touches the host socket directly.
|
|
USER nobody
|
|
|
|
ENTRYPOINT ["bash", "/usr/local/bin/manager.sh"]
|