Compare commits

..
Author SHA1 Message Date
notandClaude Opus 4.8 802f0e2c65 fix(infra): cap Objecten/Objecttypen uWSGI to 1 worker — unstarve verify-stack e2e (closes #144)
CI / build (pull_request) Successful in 1m26s
CI / lint (pull_request) Successful in 1m38s
CI / unit (pull_request) Successful in 2m18s
CI / frontend (pull_request) Successful in 4m50s
CI / mutation (pull_request) Successful in 7m14s
CI / verify-stack (pull_request) Successful in 10m49s
The Maykin images run uWSGI with 4 processes × 4 threads by default. Two
web services × 4 idle Django workers (~200 MB each) sat idle during the
Playwright e2e step and starved the single shared CI runner, so Keycloak
and the portals stopped responding (login never loaded) and Chromium
crashed — main verify-stack went red from run 2177 (post-#142) onward
while the PR runs passed on a less loaded runner.

These APIs only serve single-request smoke checks and are idle during
e2e, so 1 worker is plenty. Verified locally: both services healthy with
UWSGI_PROCESSES=1 and make verify-objecten / verify-objecttypen still green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-27 13:38:47 +02:00
2 changed files with 0 additions and 16 deletions
-7
View File
@@ -56,10 +56,6 @@ services:
oz-init: oz-init:
image: docker.io/openzaak/open-zaak:${OPENZAAK_TAG:-1.28.2} image: docker.io/openzaak/open-zaak:${OPENZAAK_TAG:-1.28.2}
environment: &oz-env environment: &oz-env
# 1 uWSGI worker, not the image default of 4×4 (#147) — idle workers pressure the runner; the
# -init/-celery containers share this anchor and ignore it (they don't run uwsgi).
UWSGI_PROCESSES: "1"
UWSGI_THREADS: "2"
DJANGO_SETTINGS_MODULE: openzaak.conf.docker DJANGO_SETTINGS_MODULE: openzaak.conf.docker
SECRET_KEY: ${OZ_SECRET_KEY:-dev-only-not-for-production} SECRET_KEY: ${OZ_SECRET_KEY:-dev-only-not-for-production}
DB_HOST: oz-db DB_HOST: oz-db
@@ -142,9 +138,6 @@ services:
# bind-mounted here (this twin is the local/no-make path). See ADR-0007. # bind-mounted here (this twin is the local/no-make path). See ADR-0007.
image: docker.io/openzaak/open-notificaties:${OPENNOTIFICATIES_TAG:-1.16.1} image: docker.io/openzaak/open-notificaties:${OPENNOTIFICATIES_TAG:-1.16.1}
environment: &nrc-env environment: &nrc-env
# 1 uWSGI worker, not the image default of 4×4 (#147) — see the oz-env note above.
UWSGI_PROCESSES: "1"
UWSGI_THREADS: "2"
DJANGO_SETTINGS_MODULE: nrc.conf.docker DJANGO_SETTINGS_MODULE: nrc.conf.docker
SECRET_KEY: ${NRC_SECRET_KEY:-dev-only-not-for-production} SECRET_KEY: ${NRC_SECRET_KEY:-dev-only-not-for-production}
DB_HOST: nrc-db DB_HOST: nrc-db
-9
View File
@@ -51,12 +51,6 @@ services:
oz-init: oz-init:
image: docker.io/openzaak/open-zaak:${OPENZAAK_TAG:-1.28.2} image: docker.io/openzaak/open-zaak:${OPENZAAK_TAG:-1.28.2}
environment: &oz-env environment: &oz-env
# 1 uWSGI worker, not the image default of 4×4 (#147, same lever as #145): OpenZaak serves
# single-request smoke checks here and is not load-tested, so 4 idle Django workers just pin
# ~800 MB and pressure the shared runner. The -init (setup_configuration) and -celery containers
# share this anchor and ignore it — they don't run uwsgi.
UWSGI_PROCESSES: "1"
UWSGI_THREADS: "2"
DJANGO_SETTINGS_MODULE: openzaak.conf.docker DJANGO_SETTINGS_MODULE: openzaak.conf.docker
SECRET_KEY: ${OZ_SECRET_KEY:-dev-only-not-for-production} SECRET_KEY: ${OZ_SECRET_KEY:-dev-only-not-for-production}
DB_HOST: oz-db DB_HOST: oz-db
@@ -141,9 +135,6 @@ services:
# needs no baked config. # needs no baked config.
image: docker.io/openzaak/open-notificaties:${OPENNOTIFICATIES_TAG:-1.16.1} image: docker.io/openzaak/open-notificaties:${OPENNOTIFICATIES_TAG:-1.16.1}
environment: &nrc-env environment: &nrc-env
# 1 uWSGI worker, not the image default of 4×4 (#147) — see the oz-env note above.
UWSGI_PROCESSES: "1"
UWSGI_THREADS: "2"
DJANGO_SETTINGS_MODULE: nrc.conf.docker DJANGO_SETTINGS_MODULE: nrc.conf.docker
SECRET_KEY: ${NRC_SECRET_KEY:-dev-only-not-for-production} SECRET_KEY: ${NRC_SECRET_KEY:-dev-only-not-for-production}
DB_HOST: nrc-db DB_HOST: nrc-db