Commit Graph
44 Commits
Author SHA1 Message Date
Asep HaryanaandClaude Opus 5 f681e624b3 chore(infra): bump llm-api flake rev to b636496
Deploys the generation-flow refactor (unified generate, streaming fixes,
tool-calling, strict model validation, AddBos::Never).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-03 09:50:23 +07:00
Asep HaryanaandClaude Opus 5 fdbdcbc1ec fix(ci): trigger nix deploy on every push to main
GitHub path filters do not match submodule gitlink changes, so the
`paths: apps/**` filter meant a submodule pointer update never triggered
the deploy. Drop the filter so any push to main deploys (matches the
documented "Push to main -> nix build -> systemctl restart").

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-03 09:35:56 +07:00
Asep HaryanaandClaude Opus 5 b7b60e9125 chore(ci): remove legacy Docker workflows (moved to Nix)
Docker was decommissioned 2026-08-02 but docker-build-push.yml and
deploy-docker.yml were left behind. They still listened to
repository_dispatch: [submodule-updated], so every app push queued a
redundant Docker build alongside the intended Nix deploy.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-03 09:13:38 +07:00
Asep Haryana d20643fbbd fix(infra): ship next.config.ts into Nix store for hub
next start re-reads next.config.ts at runtime; the OLD store had only
.next/public/package.json/node_modules, so images.maximumDiskCacheSize
fell back to defaults (undefined) and the image-optimizer disk LRU did
mkdir(<store>/.next/cache/images) -> EACCES on every optimized image.
Also now that next.config.ts sets maximumDiskCacheSize:0 +
isrFlushToDisk:false, shipping the file makes runtime match the baked
build config, eliminating the EACCES spike.
2026-08-03 04:33:46 +07:00
Asep Haryana 7da1727603 fix(firewall): accept IPv6 MLD/ND multicast (ff02::1, ff02::2, ff02::fb)
Neighbor multicast to ff02::1 (MLDv2 reports from other hosts) was
hitting the LOG+DROP tail — ~1800 FW6-DROP lines/6h in journald,
i.e. ~5/min of pure log spam from ICMPv6 layer-2 discovery. Accept
link-local multicast ranges before the logging rule.
2026-08-03 04:06:32 +07:00
Asep Haryana 9e9fd229d0 chore(infra): bump hub flake rev to 6829c7e (image disk cache fix) 2026-08-03 04:05:23 +07:00
Asep Haryana 40095f75f4 chore(infra): bump hub submodule to 6829c7efe2a735d249f5135bff4a0fc28411a295 (disable Next image disk cache) 2026-08-03 04:05:15 +07:00
Asep Haryana e280d196f9 chore: update llm-api to 344bc195fa95 2026-08-02 17:02:59 +07:00
Asep Haryana 4927338c98 docs: sync infra docs to Caddy+Nix 4000s (Traefik/Docker legacy) 2026-08-02 16:54:17 +07:00
Asep Haryana 35cbcdcc92 chore(infra): add tuned Caddyfile.prod reference 2026-08-02 16:37:05 +07:00
Asep Haryana e171201b1c chore: sync port references and docs to 4000s infra 2026-08-02 16:16:40 +07:00
Asep Haryana ec1394bdc5 chore: bump tools submodule (ports 4007/4008) 2026-08-02 14:31:47 +07:00
Asep Haryana 5d21848e87 perf(infra): traefik response speed - HTTP/3 + backend conn pooling
- entryPoints.websecure.http3: enable QUIC (UDP 443, alt-svc h3)
- serversTransport maxIdleConnsPerHost 2->100: reuse backend keep-alive
- forwardingTimeouts.dialTimeout 30s->3s: fail fast on dead backends
- disable version-check/anonymous-usage network chatter
2026-08-01 13:12:50 +07:00
Asep Haryana b96548bffa fix(infra): raise upload-buffer response cap to 2GB
Chunked file streaming (TeleUploader) serves multi-part bodies up to
120MB+; 10MB maxResponseBodyBytes made every big download 500.
2026-08-01 12:52:34 +07:00
Asep Haryana e19fa76dc3 fix(infra): add teleuploader traefik router for upload hostnames
Restore upload.asepharyana.my.id/.web.id routing lost during Nix migration
(docker label router removed with container). Upload chain uses 2GB body
buffer + dedicated 300/100 rate limit, service targets bun on host:3000.
2026-08-01 12:34:22 +07:00
Asep Haryana c535ee7858 ci(otel): add logs pipeline to otel-collector (OTLP /v1/logs 404 fix) 2026-07-31 14:13:56 +07:00
Asep Haryana 80b5161630 ci(infra): traefik dynamic config path -> /home/code (drop /root dependency) 2026-07-31 14:02:07 +07:00
Asep Haryana 1ccc0355ac ci(traefik): add hermes dashboard route via file provider 2026-07-31 13:50:46 +07:00
asepharyana 12aed642a9 ci(traefik): add zeavis routes via file provider (Nix migration) 2026-07-31 12:42:14 +07:00
asepharyana f8e3dccb44 ci(traefik): lidm routes -> host ports 3100/3101 (3000/3001 occupied by teleuploader+gmw) 2026-07-31 11:37:13 +07:00
asepharyana 1811c6adc2 ci(traefik): add lidm frontend+backend routes via file provider (Nix migration) 2026-07-31 11:29:47 +07:00
Asep Haryana d0c9f16d5d chore(infra): disable Docker compose for Nix-migrated services (hub, scraper, tools, llm-api) 2026-07-30 22:29:20 +07:00
Asep Haryana 6cbafbfe2e fix(flake): update scraper pinned rev for config fix 2026-07-30 22:28:24 +07:00
Asep Haryana 60a1af436f fix(infra): llm-api port 8080→8082 (conflict with gmw-proxy nginx) 2026-07-30 22:18:56 +07:00
Asep Haryana 2459541677 fix(scraper): update submodule - config list_separator fix 2026-07-30 22:18:03 +07:00
Asep Haryana 33b999d2b7 fix(ci): disable Determinate Nix / FlakeHub (no flakehub flakes used)
DeterminateSystems/nix-installer-action defaults to determinate:true
which tries to auth with FlakeHub via GitHub JWT. We don't use any
FlakeHub flakes, so disable it — skipping the auth entirely.
2026-07-30 22:05:41 +07:00
Asep Haryana 59f131f951 fix(ci): combine build+deploy per-service, pass exact store path
Separate deploy job failed because it used ls to find store paths
by name, finding OLD local paths instead of the freshly copied CI
paths. Now each service builds, copies, and updates its profile
in a single job using the exact store path from the build output.
No more guessing which path is the right one.
2026-07-30 21:42:39 +07:00
Asep Haryana cc8c5088a4 fix(ci): use SSH_PRIVATE_KEY secret, sanitize key format
- Ganti secret name: VPS_SSH_KEY → SSH_PRIVATE_KEY (nama yg ada)
- Fix nix copy URL: ***@ → $VPS_USER@
- Sanitize SSH key: strip \r\n, validasi dengan ssh-keygen
- Cegah libcrypto error dari key format broken
2026-07-30 21:32:40 +07:00
Asep Haryana d15e8621a9 fix(ci): proper SSH user in nix copy, deploy job structure
- Fix nix copy URL: ***@ → $VPS_USER@
- Store path from build output, passed across jobs
- Deploy job waits for all builds via needs: build
- SSH key setup in its own step, guarded by main branch
- Only deploy on main branch pushes
- Remote deploy script fetches from VPS nix store
2026-07-30 21:14:20 +07:00
Asep Haryana 33d5b12ec6 fix: tools-workers install path (no cd backend in installPhase) 2026-07-30 20:11:31 +07:00
Asep Haryana b5596e1398 feat(infra): full Nix migration — all 6 services + CI/CD
- flake.nix: 6 derivations (hub, scraper, tools-gateway, tools-workers, tools-frontend, llm-api)
- Fetch submodule source via builtins.fetchGit with pinned revs
- Fix cargo HOME/TMPDIR for Nix sandbox permission issues
- Fix llm-api: CMake/Clang deps for llama.cpp-sys2 bindgen
- Add LIBCLANG_PATH, LD_LIBRARY_PATH for Rust bindgen builds
- Systemd units: tools-gateway (3501), tools-frontend (3500), tools-workers, llm-api (8080)
- tools.target for grouped management
- Env configs: /etc/tools/env, /etc/llm-api/env
- GitHub Actions: nix-build.yml — matrix build + nix copy + deploy
- Update Traefik apps.yaml: tools/host.docker.internal:3500, llm-api/host.docker.internal:8080
- iptables: allow Docker→host on 3099, 4091, 3500, 3501, 8080
- Add scripts/nix-deploy.sh for CI/CD deploy step
2026-07-30 19:45:43 +07:00
Asep Haryana 46730ec07d feat(infra): Nix build for scraper, GitHub Actions workflow
- Build scraper (Rust) with Nix — cargo build --release
- Create scraper systemd unit (port 4091), env from Docker config
- Fix HOME/CARGO_HOME for Rust/cargo in Nix sandbox
- Update Traefik apps.yaml: scraper -> host.docker.internal:4091
- Add iptables rules for port 4091 (Docker->host)
- Add GitHub Actions workflow: nix-build.yml (determinate-nix + deploy)
- Save iptables rules persistently
2026-07-30 18:46:45 +07:00
Asep Haryana 1ae8a53cd4 chore: ignore Nix build result symlink 2026-07-30 18:33:52 +07:00
Asep Haryana ff52f8841c feat(infra): Nix build for hub app, systemd deployment
- Add flake.nix with derivations for hub (Next.js), scraper, tools, llm-api
- Create hub systemd unit (port 3099)
- Update Traefik dynamic config to point to host hub service
- Add iptables rule for Docker-to-host communication
- Use fetchGit for submodule source resolution
2026-07-30 18:33:43 +07:00
asepharyana be7348a27d fix(infra): remove buffer/compress from llm-api for real SSE streaming
- llm-api uses llm-chain instead of common-chain
- llm-chain excludes buffer & compress middlewares
- Prevents Traefik from buffering streaming SSE responses
- Each token is now flushed immediately
2026-07-26 19:14:52 +07:00
asepharyana 43f0df4493 fix(infra): remove buffer/compress from llm-api middleware chain
- Buffer middleware causes SSE stream buffering
- Compress middleware breaks real-time streaming
- Added llm-chain with only secure-headers + retry + rate-limit
- llm-api router now uses llm-chain@file instead of common-chain@file
2026-07-26 19:13:08 +07:00
asepharyana a4687c9d5b fix(llm-api): update submodule - reasoning/content stream separation 2026-07-26 19:04:36 +07:00
asepharyana d99bc06df3 fix(llm-api): update submodule to 6ff31b5 — Jinja template via minijinja
- Replaced llama-cpp-2 apply_chat_template with minijinja rendering
- reasoning_content separate from content in API response
- Works with MiniCPM5 thinking model natively
2026-07-26 18:21:43 +07:00
asepharyana 10aeda4d4b fix: update llm-api MODEL_PATH for new MiniCPM5 GGUF
Updates MODEL_PATH to MiniCPM5-1B-Claude-Opus-Fable5-V2-Thinking-Q8_0.gguf
2026-07-26 15:40:14 +07:00
asepharyana 05d6b4a055 chore: update llm-api submodule to e1f5195 (SSE streaming) 2026-07-25 11:34:30 +07:00
asepharyana 8fc4a15e0c feat(llm-api): add MiniCPM-V LLM API service with Traefik routing 2026-07-25 11:20:15 +07:00
Asepharyana 1e10973c86 ci: trigger fresh run for updated security.yml 2026-07-24 01:39:57 +07:00
Asepharyana b7e4203a15 fix(security): checkout git submodules for CodeQL Rust analysis 2026-07-24 01:36:17 +07:00
asepharyana 45ab3c8792 test: pr-agent v3 with model fix 2026-07-17 08:03:26 +07:00