sheet upload fix

This commit is contained in:
Suriyakumarvijayanayagam
2026-08-28 11:22:53 +05:30
parent 0e75d32f61
commit 52f5d3be1d
41 changed files with 2056 additions and 1507 deletions

View File

@@ -119,17 +119,68 @@ AUTH_LOCKOUT_SECONDS=300
AUTH_ALLOW_ANY_LOGIN=true
# Machine consumers of api.<domain> - scripts, partner integrations, your own
# backends. Format: name:role:secret, comma-separated, role is admin or user.
# backends. Format: name:role:secret, comma-separated. Role is one of:
#
# admin everything, including system/init and model training
# user catalog write access (add products, upload inventory)
# uploader ONE verb: POST /api/uploads/catalog. Nothing else - it cannot
# read the catalog, cannot see another caller's submissions, and
# cannot cancel or resume anything. This is the role to issue to
# an outside party who needs to send you spreadsheets.
#
# Callers send the secret as an X-API-Key header.
#
# One entry per consumer, always: a shared key cannot be revoked for one caller
# without breaking every other. Mint them with:
# python scripts/make_auth_secrets.py --api-key partner-x:user
# python scripts/make_auth_secrets.py --api-key catalog-drop:uploader
#
# NAME THE KEY FOR ITS FUNCTION, NOT THE PERSON HOLDING IT. /api/health is
# public and reports {name, role, fingerprint} for every configured key. The
# secret is never exposed, but the NAME is - so `catalog-drop:uploader:...` is
# right and `priya-laptop:uploader:...` publishes a colleague's name to anyone
# who curls the health endpoint.
#
# Leave empty if only the web app calls the API - it signs in through
# /api/auth/login instead, and a key nobody needs is only risk.
API_KEYS=
# ---------------------------------------------------------------------------
# Catalog batch ingestion
# ---------------------------------------------------------------------------
# Used by both spreadsheet ingestion routes - the admin one
# (POST /api/admin/catalog-batch/ingest) and the API-client one
# (POST /api/uploads/catalog). Every ceiling is enforced in the application,
# not at the proxy: in production the caller reaches mcp.nearle.ai.in directly,
# so neither nginx's client_max_body_size nor Caddy's request_body cap is in
# front of these endpoints.
#
# Per-file limits are fixed in code at 10MB / 2000 rows, matching the
# single-file upload path. These bound the BATCH on top of that.
BATCH_MAX_FILES=20
BATCH_MAX_TOTAL_BYTES=52428800
BATCH_MAX_TOTAL_ROWS=20000
# Where staged uploads live. Under DATA_DIR because that path is already a
# declared volume, which is what lets a batch survive a container restart.
# BATCH_UPLOAD_DIR=/app/data/batch_uploads
# Batches allowed to wait behind the one running. One worker thread runs a
# single batch at a time; past this depth the endpoints answer 429 rather than
# accepting work they have no intention of starting soon. This queue is the
# only thing bounding what an uploader key can cost in CPU - raise it with care
# on a one-vCPU host.
BATCH_QUEUE_MAX=4
# Staged files are deleted this many days after the batch was created.
BATCH_RETENTION_DAYS=7
# Deliberately false. A batch a restart cut short is marked "interrupted" and
# waits for someone to press Resume. Auto-resuming means a container stuck in a
# restart loop re-runs the heaviest work in the app on every boot, which is how
# a slow start becomes an unrecoverable spiral.
BATCH_AUTO_RESUME=false
USE_OLLAMA=true
OLLAMA_BASE_URL=http://localhost:11434
OLLAMA_MODEL_NAME=qwen2.5:1.5b