Repository navigation
Expand file tree
/
Copy pathrender.yaml
More file actions
94 lines (91 loc) · 4.01 KB
/
Copy pathrender.yaml
File metadata and controls
94 lines (91 loc) · 4.01 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
# Render Blueprint — one-click deploy of the omadia minimal core
# (middleware + admin UI + Postgres/pgvector) into the deployer's OWN
# Render workspace. This file backs the "Deploy to Render" button:
#
# https://render.com/deploy?repo=https://github.com/byte5ai/omadia
#
# Mirrors docker-compose.yaml's minimal core; the optional overlays
# (MinIO, Kroki, Ollama) are not part of the blueprint.
#
# No secrets to paste: VAULT_KEY and CREDENTIAL_KEYCHAIN_KEY are generated
# by Render on first sync (the GHCR image bakes NODE_ENV=production, which
# makes both keys mandatory at boot — see README "Deployment"). The
# first-admin /setup wizard asks for the one-time setup token the middleware
# prints to its log on first boot (or set ADMIN_SETUP_TOKEN), and the LLM key
# is connected in the admin UI afterwards and stored encrypted in the vault.
# DEV_ENDPOINTS_ENABLED stays unset: these services are publicly reachable,
# and the dev mounts expose raw KG + memory state without auth.
#
# Costs: the middleware needs a persistent disk, which requires paid
# instance types — `starter` for both services plus `basic-256mb`
# Postgres. Everything is pinned to one region (frankfurt) so the
# database connection string resolves over the private network.
services:
# --- Omadia middleware (TypeScript kernel + plugin runtime) ---------------
- type: web
name: omadia-middleware
runtime: image
image:
url: ghcr.io/byte5ai/omadia-middleware:latest
plan: starter
region: frankfurt
healthCheckPath: /health
envVars:
- key: DATABASE_URL
fromDatabase:
name: omadia-postgres
property: connectionString
# Vault master key. Generated once by Render; losing it makes vault
# entries unrecoverable, so never rotate it casually. Rotating LLM /
# plugin credentials happens inside the app (Admin → Runtime →
# Secrets), not by regenerating this key.
- key: VAULT_KEY
generateValue: true
# Credential-keychain master key (#578/#778). Deliberately a DIFFERENT
# key than VAULT_KEY — separate trust domain. Also mandatory at boot
# under NODE_ENV=production since v0.115; same "never rotate casually"
# rule applies.
- key: CREDENTIAL_KEYCHAIN_KEY
generateValue: true
# Persist vault, installed.json, builder drafts.db, and uploaded
# plugin packages on the disk below instead of the image layer.
- key: PLATFORM_DATA_DIR
value: /data
# Password sign-in limiter: AUTH_LOGIN_CLIENT_ADDRESS is left at its
# default `socket` (docs/upgrading.md, middleware/.env.example). web-ui
# reaches the middleware through its public URL, so a browser's request
# passes more proxies than one sent to the middleware directly, and no
# single `xff:<n>` picks the browser's address on both paths. Every
# browser then shares one key, which the limiter treats as shared;
# browsers that have signed in before keep a budget of their own.
disk:
name: omadia-data
mountPath: /data
sizeGB: 1
# --- Admin UI (Next.js, talks to middleware over /bot-api) ----------------
- type: web
name: omadia-web-ui
runtime: image
image:
url: ghcr.io/byte5ai/omadia-web-ui:latest
plan: starter
region: frankfurt
envVars:
# Server-side base URL the admin UI uses to reach the middleware.
# RENDER_EXTERNAL_URL is the middleware's public https URL, injected
# by Render — a full URL with scheme, which MIDDLEWARE_URL requires.
- key: MIDDLEWARE_URL
fromService:
name: omadia-middleware
type: web
envVarKey: RENDER_EXTERNAL_URL
databases:
# --- Postgres + pgvector (knowledge graph, routines, verifier store) -----
# Migrations run automatically on the middleware's first boot, including
# CREATE EXTENSION IF NOT EXISTS vector (supported on Render Postgres).
- name: omadia-postgres
plan: basic-256mb
region: frankfurt
postgresMajorVersion: "17"
databaseName: omadia
user: omadia