Files
Maven/docker-compose.yml
T
kami 94a1c8e979 deploy: fix image build — trixie/go1.24 base, rename off the maven collision
Three fixes found bringing the stack up on the host daemon:

- base was golang:1.23-bookworm: bookworm's glibc 2.36 / GLIBCXX 3.4.30 is too
  old to link the prebuilt deps/lib/*.so (built on Arch against glibc 2.38 /
  GLIBCXX 3.4.32). Moved build+runtime to trixie (glibc 2.40). golang trixie
  images start at 1.24, which builds the go 1.23 module fine.
- builder now installs libvulkan-dev — libggml-vulkan.so needs libvulkan.so.1
  at link time.
- image renamed maven:latest -> mavenai:latest with pull_policy:never. "maven"
  is Apache Maven on Docker Hub; compose was silently pulling it, so every
  container ran mvn-entrypoint.sh and exited 127.

Verified on the host: all six build, five-service stack stays up, mavend opens
the encrypted db, mavweb GET :9201 -> 200.
2026-07-03 22:00:19 +04:00

77 lines
2.7 KiB
YAML

name: maven
# One image (built once), one container per daemon. Only mavend holds the key
# and the db volume; the modules mount just the shared socket dir + models.
# IPC stays unix-domain over the shared `sockets` volume — no code change from
# the bare-metal setup, only paths move to /run/maven.
x-image: &image
# NOT "maven" — that's Apache Maven on Docker Hub and compose will happily
# pull it, giving every container `mvn-entrypoint.sh` and exit 127.
image: mavenai:latest
pull_policy: never # only ever the locally-built image
restart: unless-stopped
services:
mavend:
<<: *image
build: .
command: ["mavend", "-config", "/opt/maven/config/mavend.json"]
# the key lives ONLY here. deploy/db_key.env holds MAVEN_DB_KEY=<base64-32B>.
env_file: [./deploy/db_key.env]
volumes:
- dbdata:/var/lib/maven # encrypted db at rest
- sockets:/run/maven # IPC socket dir
- ./deploy/mavend.json:/opt/maven/config/mavend.json:ro
- ./models:/opt/maven/models:ro
# the decrypted working copy lives in RAM (see db_tmpfs in mavend.json).
tmpfs:
- /dev/shm
mavsttd:
<<: *image
command: ["mavsttd", "-socket", "/run/maven/stt.sock", "-model", "/opt/maven/models/stt/ggml-small.bin"]
depends_on: [mavend]
# whisper uses libggml-vulkan → needs the GPU render node.
devices:
- "/dev/dri:/dev/dri"
volumes:
- sockets:/run/maven
- ./models:/opt/maven/models:ro
mavttsd:
<<: *image
command: ["mavttsd", "-socket", "/run/maven/tts.sock",
"-piper", "/opt/maven/piper/piper",
"-model", "/opt/maven/models/tts/ru_RU-irina-medium.onnx",
"-espeak_data", "/opt/maven/piper/espeak-ng-data"]
depends_on: [mavend]
volumes:
- sockets:/run/maven
- ./models:/opt/maven/models:ro
mavweb:
<<: *image
# NOTE: -voice must reach mavend's voice TCP server cross-container. That
# requires mavend to BIND its voice server on 0.0.0.0:9100 (Voice config,
# currently unset). Until that's configured, voice-over-web is inert — the
# rest of mavweb (/tools, passkey, dash) works over the core socket.
command: ["mavweb", "-addr", ":9201", "-voice", "mavend:9100", "-core", "/run/maven/mavend.sock"]
depends_on: [mavend]
ports: ["9201:9201"]
volumes:
- sockets:/run/maven
mavpoll:
<<: *image
command: ["mavpoll", "-socket", "/run/maven/mavend.sock", "-netdata", "http://host.docker.internal:19999"]
depends_on: [mavend]
extra_hosts:
- "host.docker.internal:host-gateway" # reach netdata on the host
volumes:
- sockets:/run/maven
volumes:
dbdata:
sockets: