Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c7f06b35fa |
@@ -57,6 +57,9 @@ services:
|
|||||||
# share this anchor and ignore it — they don't run uwsgi.
|
# share this anchor and ignore it — they don't run uwsgi.
|
||||||
UWSGI_PROCESSES: "1"
|
UWSGI_PROCESSES: "1"
|
||||||
UWSGI_THREADS: "2"
|
UWSGI_THREADS: "2"
|
||||||
|
# Same lever for oz-celery: unset, the worker forks one process per CPU (22 on the lab node,
|
||||||
|
# ~225 MB each), which OOM-killed the shared runner mid-verify-stack. Only celery reads it.
|
||||||
|
CELERY_WORKER_CONCURRENCY: "2"
|
||||||
DJANGO_SETTINGS_MODULE: openzaak.conf.docker
|
DJANGO_SETTINGS_MODULE: openzaak.conf.docker
|
||||||
SECRET_KEY: ${OZ_SECRET_KEY:-dev-only-not-for-production}
|
SECRET_KEY: ${OZ_SECRET_KEY:-dev-only-not-for-production}
|
||||||
DB_HOST: oz-db
|
DB_HOST: oz-db
|
||||||
@@ -144,6 +147,8 @@ services:
|
|||||||
# 1 uWSGI worker, not the image default of 4×4 (#147) — see the oz-env note above.
|
# 1 uWSGI worker, not the image default of 4×4 (#147) — see the oz-env note above.
|
||||||
UWSGI_PROCESSES: "1"
|
UWSGI_PROCESSES: "1"
|
||||||
UWSGI_THREADS: "2"
|
UWSGI_THREADS: "2"
|
||||||
|
# Two celery workers, not one per CPU — see the oz-env note above.
|
||||||
|
CELERY_WORKER_CONCURRENCY: "2"
|
||||||
DJANGO_SETTINGS_MODULE: nrc.conf.docker
|
DJANGO_SETTINGS_MODULE: nrc.conf.docker
|
||||||
SECRET_KEY: ${NRC_SECRET_KEY:-dev-only-not-for-production}
|
SECRET_KEY: ${NRC_SECRET_KEY:-dev-only-not-for-production}
|
||||||
DB_HOST: nrc-db
|
DB_HOST: nrc-db
|
||||||
|
|||||||
@@ -76,6 +76,7 @@ envGroups:
|
|||||||
oz:
|
oz:
|
||||||
UWSGI_PROCESSES: "1"
|
UWSGI_PROCESSES: "1"
|
||||||
UWSGI_THREADS: "2"
|
UWSGI_THREADS: "2"
|
||||||
|
CELERY_WORKER_CONCURRENCY: "2"
|
||||||
DJANGO_SETTINGS_MODULE: openzaak.conf.docker
|
DJANGO_SETTINGS_MODULE: openzaak.conf.docker
|
||||||
SECRET_KEY: dev-only-not-for-production
|
SECRET_KEY: dev-only-not-for-production
|
||||||
DB_HOST: oz-db
|
DB_HOST: oz-db
|
||||||
@@ -98,6 +99,7 @@ envGroups:
|
|||||||
nrc:
|
nrc:
|
||||||
UWSGI_PROCESSES: "1"
|
UWSGI_PROCESSES: "1"
|
||||||
UWSGI_THREADS: "2"
|
UWSGI_THREADS: "2"
|
||||||
|
CELERY_WORKER_CONCURRENCY: "2"
|
||||||
DJANGO_SETTINGS_MODULE: nrc.conf.docker
|
DJANGO_SETTINGS_MODULE: nrc.conf.docker
|
||||||
SECRET_KEY: dev-only-not-for-production
|
SECRET_KEY: dev-only-not-for-production
|
||||||
DB_HOST: nrc-db
|
DB_HOST: nrc-db
|
||||||
@@ -275,11 +277,6 @@ workloads:
|
|||||||
# this issuer back, which is what browser tokens carry (infra/host-browser.yml).
|
# this issuer back, which is what browser tokens carry (infra/host-browser.yml).
|
||||||
KC_HOSTNAME: '{{ include "big.keycloakUrl" . }}'
|
KC_HOSTNAME: '{{ include "big.keycloakUrl" . }}'
|
||||||
KC_HOSTNAME_BACKCHANNEL_DYNAMIC: "true"
|
KC_HOSTNAME_BACKCHANNEL_DYNAMIC: "true"
|
||||||
# Behind a TLS proxy (keycloakUrl) the dynamic backchannel URLs — token,
|
|
||||||
# userinfo, certs — take their scheme from the request, which reaches Keycloak
|
|
||||||
# as plain http; trusting X-Forwarded-Proto keeps them https so the browser
|
|
||||||
# doesn't block them as mixed content. In-cluster calls send no such header.
|
|
||||||
KC_PROXY_HEADERS: xforwarded
|
|
||||||
ports: [{ name: http, port: 8080 }]
|
ports: [{ name: http, port: 8080 }]
|
||||||
# TCP, not /health/ready on the management port: nothing here gates on realm
|
# TCP, not /health/ready on the management port: nothing here gates on realm
|
||||||
# import, and a wrong health path would leave the Service with no endpoints.
|
# import, and a wrong health path would leave the Service with no endpoints.
|
||||||
|
|||||||
Reference in New Issue
Block a user