Two silent failures making the watchdog's circuit-breaker checks
toothless:
1) The Alpine runtime image had no sqlite3 binary, so every
`kubectl exec -- sqlite3 …` call inside the watchdog returned empty.
$JS/$TIN/$JOK/$JFL/$JCB all defaulted to 0 → every "soft cap" /
"tokens > 30M" / "circuit broke but still firing" check trivially
passed regardless of real state. apk add sqlite (≈700KB).
2) The "today usage" query filtered to owner_id='2' only, but dream
jobs run for any owner (we just saw a clean owner_id=1 dispatch).
Replace with SUM across all rows for date=date('now'); the caps
are intentionally global, not per-owner.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
28 lines
799 B
Docker
28 lines
799 B
Docker
# Stage 1: Build web frontend
|
|
FROM node:20-alpine AS web-builder
|
|
WORKDIR /app/web
|
|
COPY web/package*.json ./
|
|
RUN npm install --legacy-peer-deps
|
|
COPY web/ ./
|
|
RUN npm run build
|
|
|
|
# Stage 2: Build Go binary
|
|
FROM golang:1.25-alpine AS go-builder
|
|
ARG VERSION=dev
|
|
RUN apk add --no-cache tzdata
|
|
WORKDIR /app
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
COPY --from=web-builder /app/web/build internal/web/dist/
|
|
RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w -X main.version=${VERSION}" -o /synapbus ./cmd/synapbus/
|
|
|
|
# Stage 3: Runtime
|
|
FROM alpine:3.19
|
|
RUN apk add --no-cache ca-certificates tzdata sqlite && touch /.dockerenv
|
|
COPY --from=go-builder /synapbus /synapbus
|
|
EXPOSE 8080
|
|
VOLUME ["/data"]
|
|
ENTRYPOINT ["/synapbus"]
|
|
CMD ["serve", "--host", "0.0.0.0", "--port", "8080", "--data", "/data"]
|