服务器实测可经 Cloudflare 443 访问 Gitea 且 git 协议正常(此前我只测了 13000 端口就断言不可达,是错的),因此不再需要 tar + SFTP。 - docker-compose: 增加 user: "1000:1000"。容器此前以 root 运行,写进挂载目录的每轮 jsonl 产物都是 root 属主,导致宿主用户连自己的部署目录都挪不动 —— 这在把部署迁到 /mnt/data 时实际发生了 - deploy.sh: 一条命令走完 拉代码 →(webui/ 有改动时)重建前端 → 重启容器。前端产物 api/webui 是 gitignore 的,git pull 带不过来,必须在服务器上重建一次 - Dockerfile: 补 npm 包。corepack 只管 yarn/pnpm 不管 npm,而前端要在服务器上重建;这样服务器只需要 Docker,不必另配 Node 环境
34 lines
1.3 KiB
YAML
34 lines
1.3 KiB
YAML
services:
|
|
mediacrawler:
|
|
build: .
|
|
image: mediacrawler:latest
|
|
container_name: mediacrawler
|
|
restart: unless-stopped
|
|
|
|
# Run as the user that owns this checkout. Without it the container is root,
|
|
# and every file it writes into the mounted tree -- the crawler's per-run
|
|
# jsonl output above all -- comes out root-owned. That does not break the app,
|
|
# but it does lock the operator out of moving or deleting their own
|
|
# deployment, which is exactly what happened the first time this was deployed.
|
|
user: "1000:1000"
|
|
|
|
# host networking is a requirement, not a convenience: the crawler attaches
|
|
# to the operator's Chrome at 127.0.0.1:9222, and inside a bridge network
|
|
# that loopback is the container's own, where no browser is listening.
|
|
# It also puts the app port directly on the host, so `ports:` is not used.
|
|
network_mode: host
|
|
|
|
env_file:
|
|
- .env
|
|
environment:
|
|
MC_HOST: 0.0.0.0
|
|
MC_PORT: "18051"
|
|
TZ: Asia/Shanghai
|
|
|
|
volumes:
|
|
# The code is mounted rather than baked in, so shipping a change is
|
|
# "git pull, restart" instead of an image rebuild. Only the dependencies
|
|
# live in the image, because those are the expensive part and they change
|
|
# rarely -- rebuild only when requirements.txt or the Dockerfile changes.
|
|
- ./:/app
|