refactor(komodo): periphery outside核心 stack (komodo-periphery/)

Per komodo discussion #223: periphery executes deploys; compose child
recreating its own parent dies mid-deploy. Core stack = mongo+core+mcp;
periphery = separate project on the same external komodo-internal network.
Renovate disabled for komodo-periphery/; update-stacks procedure excludes
both komodo stacks (manual host deploys).
This commit is contained in:
Arnout van Westen committed 2026-10-05 08:44:45 +02:00
1 parent 10e9a09a4a
commit e658b49fd7
3 files changed
+58 -34

No files matched your search

+43
View File
@@ -0,0 +1,43 @@
# Komodo periphery for Atlas — deliberately SEPARATE from the komodo stack:
# the periphery executes deploys, and a compose child that recreates its own
# parent dies mid-deploy leaving half-created containers
# (see moghtech/komodo discussion #223). Deploys for this stack are manual
# (host docker compose), renovate is disabled for this folder, and the
# update-stacks procedure does not include it.
# Joins the komodo stack's private network so core can resolve "periphery"
name: komodo-periphery
services:
periphery:
image: ghcr.io/moghtech/komodo-periphery:2
container_name: komodo-periphery
restart: unless-stopped
init: true
networks:
- komodo-internal
logging:
driver: local
env_file: ../komodo/.env
environment:
PERIPHERY_REPO_DIR: ${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}/repos
PERIPHERY_STACK_DIR: ${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}/stacks
PERIPHERY_SSL_KEY_FILE: ${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}/ssl/key.pem
PERIPHERY_SSL_CERT_FILE: ${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}/ssl/cert.pem
volumes:
## Mount external docker socket
- /var/run/docker.sock:/var/run/docker.sock
## Allow Periphery to see processes outside of container
- /proc:/proc
## Specify the Periphery agent root directory - must be the same inside and outside the container.
- ${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}:${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}
## Custom location for docker compose repo
- /mnt/user/compose:/mnt/user/compose
## v2 PKI private keys (persist)
- /etc/komodo/keys:/config/keys
labels:
komodo.skip: # Prevent Komodo from stopping with StopAllContainers
networks:
komodo-internal:
external: true
name: komodo_komodo-internal
+9 -34
View File
@@ -1,9 +1,13 @@
# Komodo (mongo, core, periphery for Atlas, MCP proxy) — moved off Unraid
# compose-manager into the repo so Renovate tracks it.
# komodo.skip labels prevent Komodo StopAllContainers from taking itself
# down; deploys DO recreate core (brief UI outage is expected and harmless).
# Komodo (mongo, core, MCP proxy) — moved off Unraid compose-manager into the
# repo so Renovate tracks it. Periphery deliberately lives OUTSIDE this stack
# (komodo-periphery/): the periphery executes deploys, and a compose child
# that recreates its own parent dies mid-deploy leaving orphaned containers
# (see moghtech/komodo discussion #223 — periphery must not be in the Core
# stack). komodo.skip labels prevent StopAllContainers from taking it down.
# Renovate bumps are NOT auto-deployed for this stack — update via host:
# cd /etc/komodo/repos/compose-files/komodo && docker compose up -d
# Exposed via atlas-traefik (LAN) + pangolin primary (internet) blueprint
# labels. .env lives next to this file (env_file for core/periphery).
# labels. .env lives next to this file (env_file for core).
name: komodo
networks:
@@ -80,35 +84,6 @@ services:
- pangolin.proxy-resources.komodo.rules[3].action=deny
- pangolin.proxy-resources.komodo.rules[3].value=ALL
periphery:
image: ghcr.io/moghtech/komodo-periphery:${COMPOSE_KOMODO_IMAGE_TAG:-2}
container_name: komodo-periphery
restart: unless-stopped
init: true
networks:
- komodo-internal
logging:
driver: ${COMPOSE_LOGGING_DRIVER:-local}
env_file: ./.env
environment:
PERIPHERY_REPO_DIR: ${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}/repos
PERIPHERY_STACK_DIR: ${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}/stacks
PERIPHERY_SSL_KEY_FILE: ${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}/ssl/key.pem
PERIPHERY_SSL_CERT_FILE: ${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}/ssl/cert.pem
volumes:
## Mount external docker socket
- /var/run/docker.sock:/var/run/docker.sock
## Allow Periphery to see processes outside of container
- /proc:/proc
## Specify the Periphery agent root directory - must be the same inside and outside the container.
- ${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}:${PERIPHERY_ROOT_DIRECTORY:-/etc/komodo}
## Custom location for docker compose repo
- /mnt/user/compose:/mnt/user/compose
## v2 PKI private keys (persist)
- /etc/komodo/keys:/config/keys
labels:
komodo.skip: # Prevent Komodo from stopping with StopAllContainers
komodo-mcp:
image: ghcr.io/myrikld/komodo-mcp:latest
container_name: komodo-mcp
+6
View File
@@ -24,6 +24,12 @@
"patch"
],
"automerge": true
},
{
"matchPaths": [
"komodo-periphery/**"
],
"enabled": false
}
]
}