update
mega-ci / static-release-gates (push) Failing after 11s
release-tag / release-image (push) Successful in 6m46s
mega-ci / go-quality (services/control) (push) Successful in 10m7s
mega-ci / go-quality (platform/neuroforge) (push) Successful in 10m20s
mega-ci / go-quality (services/agent) (push) Successful in 11m1s
mega-ci / go-quality (services/knowledge) (push) Successful in 11m13s
mega-ci / docker-build (push) Has been skipped

This commit is contained in:
2026-09-09 11:10:31 +02:00
parent 9a4370e4df
commit e0bf42bf32
85 changed files with 8035 additions and 1138 deletions
+24 -11
View File
@@ -1,16 +1,29 @@
# Distributed Deployment Kits (v1.6.0)
# Deployment Kits — GLPI NeuroForge Mega v1.6.2
This directory contains three independent deployment kits:
This repository intentionally supports both the complete NeuroForge platform and stripped standalone operation.
- `master/` - authoritative NeuroForge Master plus Agent, Knowledge, Control, optional SearXNG and optional Prometheus/Grafana.
- `cpu-subagent/` - CPU worker for `vector.relink` / graph convergence.
- `gpu-subagent/` - GPU worker plus local Ollama for `model.chat` and `model.embed`.
## Complete / distributed platform
The generated `NEUROFORGE_WORKER_TOKEN` is identical in all three `.env` files. Replace the RFC 5737 example IP addresses (`192.0.2.x`) with real reachable addresses before starting.
- `master/` — authoritative NeuroForge Master plus GLPI Agent, Knowledge, Control, optional SearXNG, Prometheus and Grafana. Remote CPU/GPU workers connect to this node.
- `cpu-subagent/` — disposable CPU worker with `cpu,vector.relink` capabilities.
- `gpu-subagent/` — disposable GPU worker plus Ollama with `gpu,model.chat,model.embed` capabilities.
Recommended order:
1. GPU subagent: `docker compose --profile monitoring up -d`
2. CPU subagent: `docker compose --profile monitoring up -d`
3. Master: fill GLPI credentials, then `docker compose --profile research --profile monitoring up -d`
The Master is the only authoritative owner of NeuroForge state. CPU/GPU workers use leases, heartbeats and fenced job completion.
Only the Master holds authoritative NeuroForge state. Workers are disposable execution nodes.
## Standalone core operation
- `agent/` — GLPI Agent with local Knowledge vector backend; no NeuroForge, Control or Research dependency.
- `knowledge/` — standalone Knowledge editor/service.
- `ollama/` — standalone Ollama runtime.
- `combined/` — Agent + Knowledge + Ollama on one host, still without NeuroForge.
The standalone Agent and Knowledge kits share `runtime/knowledge` by default. The Agent mounts it read-only; Knowledge mounts it read-write.
## Release rules
- Project images are pinned by `IMAGE_TAG=1.6.2`; production compose files do not require `latest`.
- Replace every `CHANGE_ME_...` placeholder before startup.
- Never use `docker compose down -v` during an in-place upgrade unless loss of persistent state is intended.
- For a v1.6.0/v1.6.1 NeuroForge data volume, keep the volume: v1.6.2 includes the v1.6.1 recovery/OOM hotfixes and startup compaction path.
See each role's README/preflight and the root `README.md` for startup order.
@@ -0,0 +1,10 @@
services:
agent-data-init:
image: glpi-ai-agent-data-init-local:1.6.2
build:
context: ../../services/agent
target: data-init
agent:
image: glpi-ai-agent-local:1.6.2
build:
context: ../../services/agent
+62
View File
@@ -0,0 +1,62 @@
name: glpi-ai-agent-core
services:
agent-data-init:
image: ${AGENT_DATA_INIT_IMAGE:-git.send.nrw/sendnrw/glpi-neuroforge-mega-agent-data-init:${IMAGE_TAG:-1.6.2}}
restart: "no"
user: "0:0"
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/agent-data:/app/data
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
cap_add:
- CHOWN
- FOWNER
agent:
image: ${AGENT_IMAGE:-git.send.nrw/sendnrw/glpi-neuroforge-mega-agent:${IMAGE_TAG:-1.6.2}}
restart: unless-stopped
env_file:
- .env
environment:
HTTP_ADDR: :8080
DATA_DIR: /app/data
KNOWLEDGE_DIR: /app/knowledge
KNOWLEDGE_VECTOR_BACKEND: local
OUTCOME_LEARNING_ENABLED: "false"
OUTCOME_RETRIEVAL_ENABLED: "false"
BRAIN_ACTIVITY_URL: ""
BRAIN_ACTIVITY_API_KEY: ""
NEUROFORGE_URL: ""
NEUROFORGE_API_KEY: ""
CONTROL_READ_TOKEN: ""
ports:
- ${AGENT_BIND_IP:-127.0.0.1}:${AGENT_HOST_PORT:-9980}:8080
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/agent-data:/app/data
- ${CORE_DATA_ROOT:-../../runtime}/knowledge:/app/knowledge:ro
depends_on:
agent-data-init:
condition: service_completed_successfully
networks:
- core
read_only: true
tmpfs:
- /tmp:size=64m,mode=1777
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
healthcheck:
test: ["CMD", "/app/glpi-ai-agent", "healthcheck"]
interval: 15s
timeout: 3s
retries: 8
start_period: 10s
stop_grace_period: 20s
networks:
core:
external: true
name: ${CORE_NETWORK:-glpi-ai-core}
+99
View File
@@ -0,0 +1,99 @@
name: glpi-ai-core
services:
ollama:
image: ${OLLAMA_IMAGE:-ollama/ollama:0.33.2}
restart: unless-stopped
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/ollama:/root/.ollama
ports:
- ${OLLAMA_BIND_IP:-127.0.0.1}:${OLLAMA_HOST_PORT:-11434}:11434
networks:
core:
aliases: [ollama]
security_opt:
- no-new-privileges:true
agent-data-init:
image: ${AGENT_DATA_INIT_IMAGE:-git.send.nrw/sendnrw/glpi-neuroforge-mega-agent-data-init:${IMAGE_TAG:-1.6.1}}
restart: "no"
user: "0:0"
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/agent-data:/app/data
security_opt:
- no-new-privileges:true
cap_drop: [ALL]
cap_add: [CHOWN, FOWNER]
agent:
image: ${AGENT_IMAGE:-git.send.nrw/sendnrw/glpi-neuroforge-mega-agent:${IMAGE_TAG:-1.6.1}}
restart: unless-stopped
env_file: [.env]
environment:
HTTP_ADDR: :8080
DATA_DIR: /app/data
KNOWLEDGE_DIR: /app/knowledge
OLLAMA_URL: http://ollama:11434
OLLAMA_URLS: http://ollama:11434
KNOWLEDGE_VECTOR_BACKEND: local
OUTCOME_LEARNING_ENABLED: "false"
OUTCOME_RETRIEVAL_ENABLED: "false"
BRAIN_ACTIVITY_URL: ""
BRAIN_ACTIVITY_API_KEY: ""
NEUROFORGE_URL: ""
NEUROFORGE_API_KEY: ""
CONTROL_READ_TOKEN: ""
ports:
- ${AGENT_BIND_IP:-127.0.0.1}:${AGENT_HOST_PORT:-9980}:8080
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/agent-data:/app/data
- ${CORE_DATA_ROOT:-../../runtime}/knowledge:/app/knowledge:ro
depends_on:
agent-data-init:
condition: service_completed_successfully
ollama:
condition: service_started
networks: [core]
read_only: true
tmpfs: [/tmp:size=64m,mode=1777]
security_opt: [no-new-privileges:true]
cap_drop: [ALL]
healthcheck:
test: ["CMD", "/app/glpi-ai-agent", "healthcheck"]
interval: 15s
timeout: 3s
retries: 8
start_period: 10s
stop_grace_period: 20s
knowledge:
image: ${KNOWLEDGE_IMAGE:-git.send.nrw/sendnrw/glpi-neuroforge-mega-knowledge:${IMAGE_TAG:-1.6.1}}
restart: unless-stopped
env_file: [.env]
environment:
APP_MODE: ${KB_APP_MODE:-editor}
DATA_DIR: /data/knowledge
BACKUP_DIR: /data/backups
STAGING_DIR: /data/staging
LISTEN_ADDR: :8080
OLLAMA_BASE_URL: http://ollama:11434
BRAIN_ACTIVITY_URL: ""
BRAIN_ACTIVITY_API_KEY: ""
ports:
- ${KNOWLEDGE_BIND_IP:-127.0.0.1}:${KNOWLEDGE_HOST_PORT:-9981}:8080
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/knowledge:/data/knowledge:rw
- ${CORE_DATA_ROOT:-../../runtime}/staging:/data/staging:rw
- ${CORE_DATA_ROOT:-../../runtime}/backups:/data/backups:rw
depends_on:
ollama:
condition: service_started
networks: [core]
read_only: true
tmpfs: [/tmp:size=32m,mode=1777]
security_opt: [no-new-privileges:true]
cap_drop: [ALL]
stop_grace_period: 35s
networks:
core:
name: ${CORE_NETWORK:-glpi-ai-core}
+14
View File
@@ -0,0 +1,14 @@
services:
agent-data-init:
image: glpi-ai-agent-data-init-local:1.6.1
build:
context: ../../services/agent
target: data-init
agent:
image: glpi-ai-agent-local:1.6.1
build:
context: ../../services/agent
knowledge:
image: glpi-ai-knowledge-local:1.6.1
build:
context: ../../services/knowledge
@@ -0,0 +1,14 @@
services:
agent-data-init:
image: glpi-ai-agent-data-init-local:1.6.2
build:
context: ../../services/agent
target: data-init
agent:
image: glpi-ai-agent-local:1.6.2
build:
context: ../../services/agent
knowledge:
image: glpi-ai-knowledge-local:1.6.2
build:
context: ../../services/knowledge
+99
View File
@@ -0,0 +1,99 @@
name: glpi-ai-core
services:
ollama:
image: ${OLLAMA_IMAGE:-ollama/ollama:0.33.2}
restart: unless-stopped
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/ollama:/root/.ollama
ports:
- ${OLLAMA_BIND_IP:-127.0.0.1}:${OLLAMA_HOST_PORT:-11434}:11434
networks:
core:
aliases: [ollama]
security_opt:
- no-new-privileges:true
agent-data-init:
image: ${AGENT_DATA_INIT_IMAGE:-git.send.nrw/sendnrw/glpi-neuroforge-mega-agent-data-init:${IMAGE_TAG:-1.6.2}}
restart: "no"
user: "0:0"
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/agent-data:/app/data
security_opt:
- no-new-privileges:true
cap_drop: [ALL]
cap_add: [CHOWN, FOWNER]
agent:
image: ${AGENT_IMAGE:-git.send.nrw/sendnrw/glpi-neuroforge-mega-agent:${IMAGE_TAG:-1.6.2}}
restart: unless-stopped
env_file: [.env]
environment:
HTTP_ADDR: :8080
DATA_DIR: /app/data
KNOWLEDGE_DIR: /app/knowledge
OLLAMA_URL: http://ollama:11434
OLLAMA_URLS: http://ollama:11434
KNOWLEDGE_VECTOR_BACKEND: local
OUTCOME_LEARNING_ENABLED: "false"
OUTCOME_RETRIEVAL_ENABLED: "false"
BRAIN_ACTIVITY_URL: ""
BRAIN_ACTIVITY_API_KEY: ""
NEUROFORGE_URL: ""
NEUROFORGE_API_KEY: ""
CONTROL_READ_TOKEN: ""
ports:
- ${AGENT_BIND_IP:-127.0.0.1}:${AGENT_HOST_PORT:-9980}:8080
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/agent-data:/app/data
- ${CORE_DATA_ROOT:-../../runtime}/knowledge:/app/knowledge:ro
depends_on:
agent-data-init:
condition: service_completed_successfully
ollama:
condition: service_started
networks: [core]
read_only: true
tmpfs: [/tmp:size=64m,mode=1777]
security_opt: [no-new-privileges:true]
cap_drop: [ALL]
healthcheck:
test: ["CMD", "/app/glpi-ai-agent", "healthcheck"]
interval: 15s
timeout: 3s
retries: 8
start_period: 10s
stop_grace_period: 20s
knowledge:
image: ${KNOWLEDGE_IMAGE:-git.send.nrw/sendnrw/glpi-neuroforge-mega-knowledge:${IMAGE_TAG:-1.6.2}}
restart: unless-stopped
env_file: [.env]
environment:
APP_MODE: ${KB_APP_MODE:-editor}
DATA_DIR: /data/knowledge
BACKUP_DIR: /data/backups
STAGING_DIR: /data/staging
LISTEN_ADDR: :8080
OLLAMA_BASE_URL: http://ollama:11434
BRAIN_ACTIVITY_URL: ""
BRAIN_ACTIVITY_API_KEY: ""
ports:
- ${KNOWLEDGE_BIND_IP:-127.0.0.1}:${KNOWLEDGE_HOST_PORT:-9981}:8080
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/knowledge:/data/knowledge:rw
- ${CORE_DATA_ROOT:-../../runtime}/staging:/data/staging:rw
- ${CORE_DATA_ROOT:-../../runtime}/backups:/data/backups:rw
depends_on:
ollama:
condition: service_started
networks: [core]
read_only: true
tmpfs: [/tmp:size=32m,mode=1777]
security_opt: [no-new-privileges:true]
cap_drop: [ALL]
stop_grace_period: 35s
networks:
core:
name: ${CORE_NETWORK:-glpi-ai-core}
+8 -4
View File
@@ -1,7 +1,11 @@
#!/usr/bin/env sh
set -eu
for k in NEUROFORGE_MASTER_URL NEUROFORGE_WORKER_TOKEN NEUROFORGE_CPU_WORKER_ID; do v=$(grep -E "^${k}=" .env | head -1 | cut -d= -f2- || true); [ -n "$v" ] || { echo "FEHLT: $k"; exit 1; }; echo "$v" | grep -q '192\.0\.2\.' && { echo "SETZEN: $k"; exit 1; } || true; done
command -v docker >/dev/null 2>&1 || { echo "FEHLT: docker"; exit 1; }
docker compose version >/dev/null
[ -f .env ] || { echo 'missing .env'; exit 1; }
for k in IMAGE_TAG NEUROFORGE_MASTER_URL NEUROFORGE_WORKER_TOKEN NEUROFORGE_CPU_WORKER_ID; do
v=$(awk -F= -v key="$k" '$1==key {sub(/^[^=]*=/,""); print; exit}' .env)
[ -n "$v" ] || { echo "missing: $k"; exit 1; }
done
if grep -Eq '192\.0\.2\.|example\.invalid|CHANGE_ME|YOUR-' .env; then echo 'placeholder/example values remain in .env'; exit 1; fi
[ "$(awk -F= '$1=="IMAGE_TAG"{print $2}' .env)" = "1.6.2" ] || { echo 'IMAGE_TAG must be 1.6.2'; exit 1; }
docker compose --profile monitoring config >/dev/null
echo "CPU subagent preflight: OK"
echo 'cpu subagent preflight: OK'
+8 -5
View File
@@ -1,8 +1,11 @@
#!/usr/bin/env sh
set -eu
for k in NEUROFORGE_MASTER_URL NEUROFORGE_WORKER_TOKEN NEUROFORGE_GPU_WORKER_ID OLLAMA_MODEL OLLAMA_EMBEDDING_MODEL; do v=$(grep -E "^${k}=" .env | head -1 | cut -d= -f2- || true); [ -n "$v" ] || { echo "FEHLT: $k"; exit 1; }; echo "$v" | grep -q '192\.0\.2\.' && { echo "SETZEN: $k"; exit 1; } || true; done
command -v docker >/dev/null 2>&1 || { echo "FEHLT: docker"; exit 1; }
docker compose version >/dev/null
[ -f .env ] || { echo 'missing .env'; exit 1; }
for k in IMAGE_TAG NEUROFORGE_MASTER_URL NEUROFORGE_WORKER_TOKEN NEUROFORGE_GPU_WORKER_ID OLLAMA_MODEL OLLAMA_EMBEDDING_MODEL; do
v=$(awk -F= -v key="$k" '$1==key {sub(/^[^=]*=/,""); print; exit}' .env)
[ -n "$v" ] || { echo "missing: $k"; exit 1; }
done
if grep -Eq '192\.0\.2\.|example\.invalid|CHANGE_ME|YOUR-' .env; then echo 'placeholder/example values remain in .env'; exit 1; fi
[ "$(awk -F= '$1=="IMAGE_TAG"{print $2}' .env)" = "1.6.2" ] || { echo 'IMAGE_TAG must be 1.6.2'; exit 1; }
docker compose --profile monitoring config >/dev/null
command -v nvidia-smi >/dev/null 2>&1 || echo "WARNUNG: nvidia-smi nicht gefunden; NVIDIA Host/Toolkit prüfen."
echo "GPU subagent preflight: OK"
echo 'gpu subagent preflight: OK'
@@ -0,0 +1,5 @@
services:
knowledge:
image: glpi-ai-knowledge-local:1.6.2
build:
context: ../../services/knowledge
+36
View File
@@ -0,0 +1,36 @@
name: glpi-ai-knowledge-core
services:
knowledge:
image: ${KNOWLEDGE_IMAGE:-git.send.nrw/sendnrw/glpi-neuroforge-mega-knowledge:${IMAGE_TAG:-1.6.2}}
restart: unless-stopped
env_file:
- .env
environment:
APP_MODE: ${KB_APP_MODE:-editor}
DATA_DIR: /data/knowledge
BACKUP_DIR: /data/backups
STAGING_DIR: /data/staging
LISTEN_ADDR: :8080
BRAIN_ACTIVITY_URL: ""
BRAIN_ACTIVITY_API_KEY: ""
ports:
- ${KNOWLEDGE_BIND_IP:-127.0.0.1}:${KNOWLEDGE_HOST_PORT:-9981}:8080
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/knowledge:/data/knowledge:rw
- ${CORE_DATA_ROOT:-../../runtime}/staging:/data/staging:rw
- ${CORE_DATA_ROOT:-../../runtime}/backups:/data/backups:rw
networks:
- core
read_only: true
tmpfs:
- /tmp:size=32m,mode=1777
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
stop_grace_period: 35s
networks:
core:
external: true
name: ${CORE_NETWORK:-glpi-ai-core}
+11 -10
View File
@@ -23,7 +23,7 @@ services:
- ALL
neuroforge:
image: git.send.nrw/sendnrw/glpi-neuroforge-mega-neuroforge:${IMAGE_TAG:?Set IMAGE_TAG
to an immutable release tag, for example 1.6.0}
to an immutable release tag, for example 1.6.2}
command:
- -data
- /app/data
@@ -57,14 +57,15 @@ services:
NEUROFORGE_WORKER_DEFAULT_MAX_ATTEMPTS: ${NEUROFORGE_WORKER_DEFAULT_MAX_ATTEMPTS:-3}
NEUROFORGE_WORKER_RETRY_BACKOFF_SECONDS: ${NEUROFORGE_WORKER_RETRY_BACKOFF_SECONDS:-15}
NEUROFORGE_WORKER_MAX_QUEUED_JOBS: ${NEUROFORGE_WORKER_MAX_QUEUED_JOBS:-5000}
NEUROFORGE_WORKER_MAX_QUEUED_PAYLOAD_MB: ${NEUROFORGE_WORKER_MAX_QUEUED_PAYLOAD_MB:-128}
NEUROFORGE_WORKER_MASTER_APPLY_MAX_ATTEMPTS: ${NEUROFORGE_WORKER_MASTER_APPLY_MAX_ATTEMPTS:-5}
NEUROFORGE_WORKER_MASTER_APPLY_BACKOFF_SECONDS: ${NEUROFORGE_WORKER_MASTER_APPLY_BACKOFF_SECONDS:-5}
NEUROFORGE_WORKER_JOB_RETENTION_HOURS: ${NEUROFORGE_WORKER_JOB_RETENTION_HOURS:-168}
NEUROFORGE_WORKER_MAX_TERMINAL_JOBS: ${NEUROFORGE_WORKER_MAX_TERMINAL_JOBS:-20000}
NEUROFORGE_WORKER_JOB_RETENTION_HOURS: ${NEUROFORGE_WORKER_JOB_RETENTION_HOURS:-24}
NEUROFORGE_WORKER_MAX_TERMINAL_JOBS: ${NEUROFORGE_WORKER_MAX_TERMINAL_JOBS:-2000}
NEUROFORGE_GRAPH_BACKFILL_ENABLED: ${NEUROFORGE_GRAPH_BACKFILL_ENABLED:-true}
NEUROFORGE_GRAPH_BACKFILL_INTERVAL_SECONDS: ${NEUROFORGE_GRAPH_BACKFILL_INTERVAL_SECONDS:-10}
NEUROFORGE_GRAPH_BACKFILL_BATCH_SIZE: ${NEUROFORGE_GRAPH_BACKFILL_BATCH_SIZE:-64}
NEUROFORGE_GRAPH_BACKFILL_MAX_QUEUED: ${NEUROFORGE_GRAPH_BACKFILL_MAX_QUEUED:-256}
NEUROFORGE_GRAPH_BACKFILL_BATCH_SIZE: ${NEUROFORGE_GRAPH_BACKFILL_BATCH_SIZE:-16}
NEUROFORGE_GRAPH_BACKFILL_MAX_QUEUED: ${NEUROFORGE_GRAPH_BACKFILL_MAX_QUEUED:-64}
NEUROFORGE_GRAPH_BACKFILL_MIN_DEGREE: ${NEUROFORGE_GRAPH_BACKFILL_MIN_DEGREE:-3}
NEUROFORGE_GRAPH_CANDIDATE_MULTIPLIER: ${NEUROFORGE_GRAPH_CANDIDATE_MULTIPLIER:-6}
NEUROFORGE_GRAPH_RETRY_AFTER_MINUTES: ${NEUROFORGE_GRAPH_RETRY_AFTER_MINUTES:-360}
@@ -137,7 +138,7 @@ services:
stop_grace_period: 35s
agent-data-init:
image: git.send.nrw/sendnrw/glpi-neuroforge-mega-agent-data-init:${IMAGE_TAG:?Set
IMAGE_TAG to an immutable release tag, for example 1.6.0}
IMAGE_TAG to an immutable release tag, for example 1.6.2}
restart: 'no'
user: 0:0
volumes:
@@ -151,7 +152,7 @@ services:
- FOWNER
agent:
image: git.send.nrw/sendnrw/glpi-neuroforge-mega-agent:${IMAGE_TAG:?Set IMAGE_TAG
to an immutable release tag, for example 1.6.0}
to an immutable release tag, for example 1.6.2}
restart: unless-stopped
environment:
AI_CONTENT_LABEL_ENABLED: ${AI_CONTENT_LABEL_ENABLED:-}
@@ -373,7 +374,7 @@ services:
stop_grace_period: 20s
knowledge:
image: git.send.nrw/sendnrw/glpi-neuroforge-mega-knowledge:${IMAGE_TAG:?Set IMAGE_TAG
to an immutable release tag, for example 1.6.0}
to an immutable release tag, for example 1.6.2}
restart: unless-stopped
environment:
APP_MODE: ${KB_APP_MODE:-editor}
@@ -414,7 +415,7 @@ services:
stop_grace_period: 35s
control:
image: git.send.nrw/sendnrw/glpi-neuroforge-mega-control:${IMAGE_TAG:?Set IMAGE_TAG
to an immutable release tag, for example 1.6.0}
to an immutable release tag, for example 1.6.2}
restart: unless-stopped
environment:
CONTROL_ADDR: :8070
@@ -543,7 +544,7 @@ services:
- prometheus-secrets:/etc/prometheus-secrets:ro
depends_on:
neuroforge:
condition: service_healthy
condition: service_started
prometheus-secrets-init:
condition: service_completed_successfully
prometheus-config-init:
@@ -9,7 +9,7 @@
],
"timezone": "browser",
"schemaVersion": 41,
"version": 1,
"version": 2,
"refresh": "15s",
"time": {
"from": "now-6h",
@@ -1443,6 +1443,45 @@
"sort": "desc"
}
}
},
{
"id": 26,
"title": "Durable Job Payload Bytes",
"type": "timeseries",
"datasource": {
"type": "prometheus",
"uid": "prometheus"
},
"gridPos": {
"x": 0,
"y": 56,
"w": 24,
"h": 8
},
"fieldConfig": {
"defaults": {
"unit": "bytes"
},
"overrides": []
},
"options": {
"legend": {
"displayMode": "list",
"placement": "bottom",
"showLegend": true
},
"tooltip": {
"mode": "multi",
"sort": "none"
}
},
"targets": [
{
"expr": "neuroforge_job_payload_bytes",
"legendFormat": "{{state}}",
"refId": "A"
}
]
}
]
}
@@ -0,0 +1,12 @@
apiVersion: 1
providers:
- name: NeuroForge
orgId: 1
folder: NeuroForge
type: file
disableDeletion: true
updateIntervalSeconds: 30
allowUiUpdates: false
options:
path: /var/lib/grafana/dashboards
@@ -1,4 +1,5 @@
apiVersion: 1
datasources:
- name: Prometheus
uid: prometheus
@@ -56,3 +56,19 @@ groups:
annotations:
summary: "Knowledge graph remains highly isolated"
description: "More than 80% of memories are still isolated after 30 minutes."
- alert: NeuroForgePendingPayloadHigh
expr: neuroforge_job_payload_bytes{state="pending"} > 104857600
for: 5m
labels: {severity: warning}
annotations:
summary: "NeuroForge pending job payload memory is high"
description: "Pending durable job payload/result bytes exceed 100 MiB for 5 minutes; backfill should remain below the v1.6.2 safety budget."
- alert: NeuroForgeTerminalPayloadHigh
expr: neuroforge_job_payload_bytes{state="terminal"} > 67108864
for: 10m
labels: {severity: warning}
annotations:
summary: "NeuroForge terminal job payload retention is high"
description: "Terminal job payload/result bytes exceed 64 MiB. Completed vector.relink jobs should be compacted automatically in v1.6.2."
+11 -12
View File
@@ -1,15 +1,14 @@
#!/usr/bin/env sh
set -eu
bad=0
check() { key="$1"; val=$(grep -E "^${key}=" .env | head -1 | cut -d= -f2- || true); if [ -z "$val" ] || echo "$val" | grep -Eq 'CHANGE_ME|example\.invalid|192\.0\.2\.'; then echo "SETZEN: $key"; bad=1; fi; }
for k in GLPI_URL GLPI_CLIENT_ID GLPI_CLIENT_SECRET GLPI_USERNAME GLPI_PASSWORD OLLAMA_BASE_URL OLLAMA_URLS; do check "$k"; done
if [ "$bad" -ne 0 ]; then echo "Preflight fehlgeschlagen: Platzhalter ersetzen."; exit 1; fi
command -v docker >/dev/null 2>&1 || { echo "FEHLT: docker"; exit 1; }
docker compose version >/dev/null
[ -f .env ] || { echo 'missing .env'; exit 1; }
required='IMAGE_TAG NEUROFORGE_ADMIN_TOKEN NEUROFORGE_APP_API_KEY NEUROFORGE_INTEGRATION_TOKEN NEUROFORGE_CONTROL_READ_TOKEN NEUROFORGE_WORKER_TOKEN NEUROFORGE_METRICS_TOKEN KB_INTEGRATION_TOKEN CONTROL_READ_TOKEN GLPI_URL GLPI_CLIENT_ID GLPI_CLIENT_SECRET GLPI_USERNAME GLPI_PASSWORD GRAFANA_ADMIN_PASSWORD'
for k in $required; do
v=$(awk -F= -v key="$k" '$1==key {sub(/^[^=]*=/,""); print; exit}' .env)
[ -n "$v" ] || { echo "missing: $k"; exit 1; }
done
if grep -Eq '(^|=)(https?://)?192\.0\.2\.|example\.invalid|CHANGE_ME|YOUR-' .env; then
echo 'placeholder/example values remain in .env'; exit 1
fi
[ "$(awk -F= '$1=="IMAGE_TAG"{print $2}' .env)" = "1.6.2" ] || { echo 'IMAGE_TAG must be 1.6.2'; exit 1; }
docker compose --profile research --profile monitoring config >/dev/null
[ -f monitoring/prometheus/prometheus.yml.template ]
[ -f monitoring/prometheus/alerts.yml ]
[ -f monitoring/grafana/dashboards/neuroforge-master-subagents.json ]
mkdir -p knowledge staging backups
./monitoring/validate.sh
echo "Master preflight: OK"
echo 'master preflight: OK'
+20
View File
@@ -0,0 +1,20 @@
name: glpi-ai-ollama-core
services:
ollama:
image: ${OLLAMA_IMAGE:-ollama/ollama:0.33.2}
restart: unless-stopped
ports:
- ${OLLAMA_BIND_IP:-127.0.0.1}:${OLLAMA_HOST_PORT:-11434}:11434
volumes:
- ${CORE_DATA_ROOT:-../../runtime}/ollama:/root/.ollama
networks:
core:
aliases:
- ollama
security_opt:
- no-new-privileges:true
networks:
core:
external: true
name: ${CORE_NETWORK:-glpi-ai-core}
+9
View File
@@ -0,0 +1,9 @@
#!/usr/bin/env sh
set -eu
[ -f .env ] && set -a && . ./.env && set +a
: "${OLLAMA_MODEL:=gemma4}"
: "${OLLAMA_EMBEDDING_MODEL:=embeddinggemma}"
docker compose exec ollama ollama pull "$OLLAMA_MODEL"
docker compose exec ollama ollama pull "$OLLAMA_EMBEDDING_MODEL"
echo "Modelle vorhanden:"
docker compose exec ollama ollama list