# Dev overlay for the LAN dev server (deploy/deploy-dev.sh): # # docker compose -f docker-compose.yml -f docker-compose.dev.yml up -d # # Split-repo adaptation: the monorepo's docker-compose.dev.yml (see # thermograph/docker-compose.dev.yml) overlaid a base file where backend and # frontend had `build: .` -- dev's whole point there was `--build` in place from # the working checkout. This infra repo holds no Dockerfile at all (each service's # lives in its own app repo, thermograph-backend / thermograph-frontend), so the # base docker-compose.yml already has NO `build:` for either service, only # `image: .../${BACKEND_IMAGE_PATH}:${BACKEND_IMAGE_TAG}` (and the frontend # equivalent) -- same registry-pull model as prod/beta, just pointed at a dev tag # by deploy-dev.sh. This overlay must NOT reintroduce `build:`; it only relaxes # resource caps and LAN-exposes a port, same as the monorepo overlay did. # # Differences from the prod stack (unchanged intent from the monorepo overlay): # 1. backend is published on ALL interfaces (0.0.0.0:8137), not loopback, so # phones and other devices on the Wi-Fi can reach the dev server directly -- # dev has no Caddy in front (prod does, which is why the base file binds # 127.0.0.1 only). # 2. frontend's port publish is dropped entirely -- dev has no Caddy to reach it # directly, so it stays compose-internal-only, reached solely through # backend's own reverse-proxy fallback (THERMOGRAPH_FRONTEND_BASE_INTERNAL, # see backend/web/app.py's _proxy_to_frontend in the backend repo). This # keeps the dev stack serving the one URL it always has, at :8137. # 3. The CPU caps are removed -- dev runs UNCAPPED (no thread/CPU limits), unlike # prod's backend=4 / frontend=2 / db=2 allocation. `!reset` drops the base # value (both the top-level `cpus:` and the Swarm-style `deploy.resources` # block the base file carries for parity). # 4. backend/daemon/lake get a second env_file entry pointing at a copy of the # render under $APP_DIR (deploy-dev.sh sets THERMOGRAPH_SECRETS_ENV_FILE_MIRROR # to produce it). This box's Docker is the snap package, confined to $HOME -- # it can't see /etc/thermograph.env at all (not a permissions error, it just # doesn't exist as far as snap-confined Docker is concerned), so the base # file's env_file entry silently loads nothing here. compose appends env_file # lists across overlays (last-wins on duplicate keys), so this is additive: # prod/beta never set the mirror var, so they only ever get the base entry. services: backend: ports: !override - "8137:8137" cpus: !reset null deploy: !reset null env_file: - path: ./deploy/dev-secrets.env required: false frontend: ports: !reset null cpus: !reset null deploy: !reset null # Same uncapped-on-dev treatment for the daemon; it has no ports to touch # (outbound-only in every environment). daemon: cpus: !reset null deploy: !reset null env_file: - path: ./deploy/dev-secrets.env required: false db: cpus: !reset null deploy: !reset null lake: cpus: !reset null deploy: !reset null # Uncapped memory on dev too (prod ceilings it at 8g). The Postgres/DuckDB # memory *budget* is still the ~8 GB derived by deploy/db/init/20-tuning.sh from # the default DB_MEMORY (raise DB_MEMORY to give dev more); shm_size stays (it's # required shared memory for parallel query, not a limit). mem_limit: !reset null env_file: - path: ./deploy/dev-secrets.env required: false