Files
kubernetes/docker-compose.yml
Suriya 91dd240431 Fix worker/gateway logic bugs and duplicate CORS headers
worker.py (both the ConfigMap copy and conf/worker.py):
- Set an explicit ack_wait=60s on the JetStream pull consumer. It was
  previously left at the implicit default (~30s), the same ballpark
  as the outbound HTTP timeout - a slow-but-legitimate external call
  could cause JetStream to redeliver the message to another worker
  while the first was still mid-request, double-processing a
  non-idempotent call (e.g. duplicate order creation).
- Track in-flight tasks and drain them (bounded wait) before closing
  the NATS/HTTP connections on shutdown, instead of cutting them off
  immediately - avoids dropped/duplicated messages on pod restarts.
- Generic exception handler now does nak(delay=5) instead of an
  undelayed nak(), avoiding a tight redelivery loop on a persistent
  bug.
- Missing 'data' field in a message now explicitly drops with a log
  line instead of silently forwarding the entire internal envelope.
- Removed the hardcoded NATS password fallback baked into the source
  (every deployment already supplies it via a Secret at runtime, so
  this was a redundant plaintext copy sitting in a ConfigMap).

app.py (both the ConfigMap copy and conf/app.py):
- Fixed "NATS by connected" typo -> "NATS not connected".
- Same hardcoded-password-fallback removal as worker.py.

CORS:
- conf/nginx-jupiter.conf and the in-cluster jupiter-cors-proxy nginx
  config both add their own CORS headers without stripping any the
  upstream might set, unlike nginx-queue-proxy.conf which does this
  correctly. Added proxy_hide_header for the ACA-* headers in both -
  browsers reject a response with duplicate Access-Control-* values.

docker-compose.yml:
- Added the missing doormile-proxy service (doormile.com -> :8206 ->
  NodePort 30830). nginx-doormile.conf existed but had no service
  wiring it into Traefik, unlike every other app.
2026-07-18 16:07:49 +05:30

134 lines
4.4 KiB
YAML

services:
# Queue API Proxy - Routes queue.workolik.com (Traefik on host:443) to Kubernetes LoadBalancer (FastAPI)
queue-api-proxy:
image: nginx:alpine
container_name: queue-api-proxy
restart: unless-stopped
ports:
- "8202:8201" # Internal port for Traefik to reach nginx
volumes:
- ./conf/nginx-queue-proxy.conf:/etc/nginx/nginx.conf:ro
extra_hosts:
- "host.docker.internal:host-gateway"
networks:
- web
labels:
- "traefik.enable=true"
- "traefik.docker.network=web"
# Router for queue.workolik.com with CORS (proxying to K8s LoadBalancer)
- "traefik.http.routers.queue-api.rule=Host(`queue.workolik.com`)"
- "traefik.http.routers.queue-api.tls=true"
- "traefik.http.routers.queue-api.tls.certresolver=letsencrypt"
- "traefik.http.routers.queue-api.priority=100"
- "traefik.http.services.queue-api.loadbalancer.server.port=8201"
# Kubernetes dashboard proxy (kube.workolik.com ? K8s dashboard)
k8s-dashboard-proxy:
image: nginx:alpine
container_name: k8s-dashboard-proxy
restart: unless-stopped
ports:
- "8083:8083"
volumes:
- ./conf/nginx-k8s-dashboard.conf:/etc/nginx/nginx.conf:ro
extra_hosts:
- "host.docker.internal:host-gateway"
networks:
- web
labels:
- "traefik.enable=true"
- "traefik.http.routers.k8s-dashboard.rule=Host(`kube.workolik.com`)"
- "traefik.http.routers.k8s-dashboard.tls=true"
- "traefik.http.routers.k8s-dashboard.tls.certresolver=letsencrypt"
- "traefik.http.services.k8s-dashboard.loadbalancer.server.port=8083"
- "traefik.docker.network=web"
# Jupiter API Proxy (jupiter.nearle.app ? K8s Gateway)
jupiter-proxy:
image: nginx:alpine
container_name: jupiter-proxy
restart: unless-stopped
ports:
- "8203:8203"
volumes:
- ./conf/nginx-jupiter.conf:/etc/nginx/nginx.conf:ro
extra_hosts:
- "host.docker.internal:host-gateway"
networks:
- web
labels:
- "traefik.enable=true"
- "traefik.docker.network=web"
- "traefik.http.routers.jupiter-api.rule=Host(`jupiter.nearle.app`)"
- "traefik.http.routers.jupiter-api.tls=true"
- "traefik.http.routers.jupiter-api.tls.certresolver=letsencrypt"
- "traefik.http.services.jupiter-api.loadbalancer.server.port=8203"
# Fiesta API Proxy (fiesta.nearle.app ? K8s NodePort 30823)
fiesta-proxy:
image: nginx:alpine
container_name: fiesta-proxy
restart: unless-stopped
ports:
- "8204:8204"
volumes:
- ./conf/nginx-fiesta.conf:/etc/nginx/nginx.conf:ro
extra_hosts:
- "host.docker.internal:host-gateway"
networks:
- web
labels:
- "traefik.enable=true"
- "traefik.docker.network=web"
- "traefik.http.routers.fiesta-api.rule=Host(`fiesta.nearle.app`)"
- "traefik.http.routers.fiesta-api.tls=true"
- "traefik.http.routers.fiesta-api.tls.certresolver=letsencrypt"
- "traefik.http.services.fiesta-api.loadbalancer.server.port=8204"
# Atlantis API Proxy (atlantis.nearle.app ? K8s NodePort 30825)
atlantis-proxy:
image: nginx:alpine
container_name: atlantis-proxy
restart: unless-stopped
ports:
- "8205:8205"
volumes:
- ./conf/nginx-atlantis.conf:/etc/nginx/nginx.conf:ro
extra_hosts:
- "host.docker.internal:host-gateway"
networks:
- web
labels:
- "traefik.enable=true"
- "traefik.docker.network=web"
- "traefik.http.routers.atlantis-api.rule=Host(`atlantis.nearle.app`)"
- "traefik.http.routers.atlantis-api.tls=true"
- "traefik.http.routers.atlantis-api.tls.certresolver=letsencrypt"
- "traefik.http.services.atlantis-api.loadbalancer.server.port=8205"
# Doormile API Proxy (doormile.com -> K8s NodePort 30830)
doormile-proxy:
image: nginx:alpine
container_name: doormile-proxy
restart: unless-stopped
ports:
- "8206:8206"
volumes:
- ./conf/nginx-doormile.conf:/etc/nginx/nginx.conf:ro
extra_hosts:
- "host.docker.internal:host-gateway"
networks:
- web
labels:
- "traefik.enable=true"
- "traefik.docker.network=web"
- "traefik.http.routers.doormile-api.rule=Host(`doormile.com`)"
- "traefik.http.routers.doormile-api.tls=true"
- "traefik.http.routers.doormile-api.tls.certresolver=letsencrypt"
- "traefik.http.services.doormile-api.loadbalancer.server.port=8206"
networks:
web:
external: true