Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
35 lines (35 loc) · 2.02 KB
/
Copy pathdocker-compose.yml
File metadata and controls
35 lines (35 loc) · 2.02 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
# Runnable version of the snippet in docs/INSTALLATION_GUIDE.md's Docker section.
#
# docker compose up
#
# Serves the repo this file lives in. Set REPO_PATH to point at a different
# one, e.g. `REPO_PATH=/path/to/other/repo docker compose up`.
services:
trelix:
image: ghcr.io/sairam0424/trelix:latest
# --host 0.0.0.0 is required INSIDE the container for published ports to reach the
# process; it is not the exposure decision. The `ports` mapping below is.
command: ["serve", "/repo", "--host", "0.0.0.0", "--port", "8765"]
ports:
# Bound to loopback deliberately. `"8765:8765"` publishes on every host interface,
# and the API is open by design when no token is set (see api/app.py's authenticate
# "3./4." branch) — so the previous mapping served unauthenticated code search over
# the bind-mounted repository below to anything that could reach the host.
# Change to "8765:8765" only together with TRELIX_API_AUTH_TOKEN. Publishing on
# another interface also needs the hostname clients will use added to
# TRELIX_API_ALLOWED_HOSTS below, or the Host check answers 403.
- "127.0.0.1:8765:8765"
volumes:
- "${REPO_PATH:-.}:/repo"
environment:
- OPENAI_API_KEY=${OPENAI_API_KEY:-}
- TRELIX_EMBEDDER_PROVIDER=${TRELIX_EMBEDDER_PROVIDER:-openai}
# Unset by default, which leaves every route open — matching the CLI. Listed here
# so it is discoverable rather than something you have to know exists: set it before
# widening the port mapping above.
- TRELIX_API_AUTH_TOKEN=${TRELIX_API_AUTH_TOKEN:-}
# Host/Origin check against DNS rebinding and drive-by requests from web pages. The
# port is published on host loopback only, so these are the names a browser uses.
# Add a hostname (comma-separated) to serve under another name; `*` disables the
# check. It does not replace TRELIX_API_AUTH_TOKEN. GET /health is always exempt.
- TRELIX_API_ALLOWED_HOSTS=${TRELIX_API_ALLOWED_HOSTS:-localhost,127.0.0.1,[::1]}