Files
pig/docker-compose.yml
T
karti 45b70b17f0
CI / verify (push) Successful in 3m32s
CI / publish (push) Has been skipped
Redesign Learn, and give it five real videos in Karti's voice
THE PAGE. The anonymous route rendered outside Shell, so it sat flush against
the viewport edge and read as a form rather than a product — which is the first
thing anyone at Prime Intellect sees when the link is shared. It now brings its
own chrome and leads with a hero; the platform track is a numbered course, the
concept tracks are a poster grid, and admin add/archive moved behind one Manage
toggle so they stop competing with the content. Verified in Chrome at 1440 and
393, light and dark: horizontal overflow is 0 in all three access states.

THE VIDEOS. Five ~30s walkthroughs, narrated in Karti's cloned voice through
Chatterbox and cut against real screen capture of the seeded demo book. The
audio is rendered FIRST and its measured duration drives the capture, because a
shot list that runs short leaves the narrator talking over a frozen frame and
one that runs long gets cut mid-sentence. Levels are loudness-normalised so
clips do not jump between videos.

Cap cannot take a programmatic upload — video.karti.ai needs an interactive
login — so PIG serves these itself. A native <video> on this origin needs no
iframe and therefore no CSP frame-src at all; Karti's own Cap recordings still
render through the existing iframe path, which is why the resolver is now a
discriminated union.

THREE THINGS THE VERIFIERS CAUGHT, all of which shipped green:

  - createMediaRoutes was never mounted. Every layer landed — migration, seed,
    both feeds, the bind mount, the docs — except the one that serves the bytes,
    so /media/learn/* fell through to the SPA fallback and answered HTTP 200
    text/html. The player showed a black box with working controls and no error.
    The tests certified the route factory in isolation, which proves the handler
    and says nothing about whether it is wired in. There is now an assertion
    against the ASSEMBLED app, and it fails loudly on content-type — the failure
    mode is a 200, not a 404.
  - A symlink in the media directory escaped the root. resolve() is lexical and
    stat() follows links, so the containment check this file's own header
    promised did not hold. realpath before the check closes it.
  - Vite proxied only /api, so self-hosted playback broke for anyone running the
    app the documented way — in the same invisible 200-text/html manner.

Also: a duplicate media slug used to throw from the middle of seedDemo() and
take out every later section; it now reports and skips that one entry. And the
player has an onError state, because content-addressed filenames mean a
re-render deliberately leaves the old row pointing at a file that is gone.

The three DEMO platform rows are dropped — five real recordings supersede them,
and placeholders sitting under real ones made the page read as half-finished to
the audience it is meant to convince. The supply and demand concept rows stay:
there are no real recordings for those tracks yet, and an empty track hides the
shape of the page.

Tests 275, typecheck clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-13 17:30:08 -07:00

119 lines
4.9 KiB
YAML

# PIG — self-hosted deployment.
#
# docker compose -p pig up -d --build
#
# The project name matters. Use something PIG-specific (`-p pig`) so this stack
# never adopts another application's volumes — a compose project silently
# inheriting a neighbouring database is a genuinely nasty way to lose data.
services:
db:
image: postgres:16-alpine
restart: unless-stopped
environment:
POSTGRES_USER: ${POSTGRES_USER:-pig}
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?POSTGRES_PASSWORD must be set}
POSTGRES_DB: ${POSTGRES_DB:-pig}
volumes:
- pig-pgdata:/var/lib/postgresql/data
# Not published to the host. The application reaches it over the compose
# network; exposing Postgres publicly is never what you want.
expose:
- '5432'
healthcheck:
test: ['CMD-SHELL', 'pg_isready -U ${POSTGRES_USER:-pig} -d ${POSTGRES_DB:-pig}']
interval: 10s
timeout: 5s
retries: 5
app:
# `image` alongside `build` means one file serves both paths: with no
# PIG_IMAGE set, `compose build` tags the local build `pig:local` and
# nothing changes; with PIG_IMAGE set to a published tag, `compose pull`
# fetches exactly that image and never builds. scripts/deploy.sh picks.
#
# app and piggy MUST carry the same reference. They are the same image
# running two commands, and a piggy left on an older release talks to the
# new schema with the old code.
image: ${PIG_IMAGE:-pig:local}
build: .
restart: unless-stopped
depends_on:
db:
condition: service_healthy
environment:
DATABASE_URL: postgres://${POSTGRES_USER:-pig}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB:-pig}
NODE_ENV: production
PIG_PORT: 8920
PIG_PUBLIC_URL: ${PIG_PUBLIC_URL:?PIG_PUBLIC_URL must be set}
SUPABASE_URL: ${SUPABASE_URL:?SUPABASE_URL must be set in production}
SUPABASE_ANON_KEY: ${SUPABASE_ANON_KEY}
SUPABASE_SERVICE_KEY: ${SUPABASE_SERVICE_KEY:-}
PIG_ADMIN_EMAILS: ${PIG_ADMIN_EMAILS:-}
PIG_INVITE_CODE: ${PIG_INVITE_CODE:-}
PRIME_API_KEY: ${PRIME_API_KEY:-}
PRIME_SYNC_ENABLED: ${PRIME_SYNC_ENABLED:-false}
PIGGY_ENABLED: ${PIGGY_ENABLED:-false}
PIGGY_INTERNAL_URL: http://piggy:8931
PIGGY_INTERNAL_TOKEN: ${PIGGY_INTERNAL_TOKEN:-}
SLACK_BOT_TOKEN: ${SLACK_BOT_TOKEN:-}
SLACK_SIGNING_SECRET: ${SLACK_SIGNING_SECRET:-}
BUZZ_RELAY_URL: ${BUZZ_RELAY_URL:-}
NOTION_CLIENT_ID: ${NOTION_CLIENT_ID:-}
NOTION_CLIENT_SECRET: ${NOTION_CLIENT_SECRET:-}
NOTION_REDIRECT_URI: ${NOTION_REDIRECT_URI:-}
BUZZ_PRIVATE_KEY: ${BUZZ_PRIVATE_KEY:-}
BUZZ_AUTH_TAG: ${BUZZ_AUTH_TAG:-}
# Where the Learn videos are, INSIDE the container. Always this path; the
# host side of the mount is what varies. Named separately from
# PIG_MEDIA_HOST_DIR so the two never get swapped — one is a path in this
# filesystem, the other a path on yours.
PIG_MEDIA_DIR: /app/media
volumes:
# The Learn videos PIG serves itself.
#
# READ-ONLY, and that is the point: the application only ever reads these
# files, so nothing it could be tricked into doing can write to, replace
# or delete a video. Uploads are deliberately not a feature — a file gets
# here by being copied onto the host, which keeps the write path outside
# anything reachable over HTTP.
#
# The host directory must EXIST before `compose up`. Docker creates a
# missing bind source as an empty directory owned by root, which then
# serves 404s for every video and cannot be written to without sudo.
- ${PIG_MEDIA_HOST_DIR:-./media}:/app/media:ro
# Bound to loopback: TLS termination belongs to the reverse proxy in front,
# not to this container.
ports:
- '127.0.0.1:${PIG_HOST_PORT:-8920}:8920'
piggy:
profiles: ['piggy']
# Same reference as `app`, deliberately — see the note there.
image: ${PIG_IMAGE:-pig:local}
build: .
restart: unless-stopped
depends_on:
db:
condition: service_healthy
command: ['npx', 'tsx', 'apps/piggy/src/main.ts']
environment:
DATABASE_URL: postgres://${POSTGRES_USER:-pig}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB:-pig}
PIGGY_INFERENCE_API_KEY: ${PIGGY_INFERENCE_API_KEY:-}
PIGGY_INFERENCE_BASE: ${PIGGY_INFERENCE_BASE:-https://api.pinference.ai/api/v1}
PIGGY_MODEL: ${PIGGY_MODEL:-nvidia/nemotron-3-nano-30b-a3b}
PIGGY_LEASE_SECONDS: ${PIGGY_LEASE_SECONDS:-300}
PIGGY_INTERNAL_TOKEN: ${PIGGY_INTERNAL_TOKEN:-}
PIGGY_CHAT_HOST: 0.0.0.0
PIGGY_CHAT_PORT: 8931
PIGGY_CHAT_ALLOW_NON_LOOPBACK: 'true'
# Private to the Compose network. There is deliberately no `ports` entry.
expose:
- '8931'
volumes:
pig-pgdata:
# Named explicitly so it is obvious which volume holds the data, and so a
# `docker compose down -v` mistake is at least a legible one.
name: pig-pgdata