claude-code-proxy/docker-entrypoint.dev.sh

87 lines
2.7 KiB
Bash
Raw Permalink Normal View History

Local fork: hardening + ops improvements (timeout knob, demotion, /livez, drain) This commit captures both the prior accumulated work-in-progress (framework migration web/→svelte/, postgres storage, conversation viewer, dashboard auth, OpenAPI spec, integration tests) AND today's operational improvements layered on top. History wasn't checkpointed incrementally; happy to split it via interactive rebase if a reviewer wants smaller commits. Today's changes (in addition to the older WIP): 1. Configurable upstream response-header timeout - ANTHROPIC_RESPONSE_HEADER_TIMEOUT env (default 300s) - Replaces hardcoded 300s in provider/anthropic.go that was firing on opus + 1M-context + extended thinking non-streaming requests - Files: internal/config/config.go, internal/provider/anthropic.go 2. Structured forward-error diagnostic logging - When a forward to Anthropic fails, log a single key=value line with request_id, model, stream, body_bytes, has_thinking, anthropic_beta, query, elapsed, ctx_err — alongside the existing human-readable error line for back-compat - Files: internal/handler/handlers.go (logForwardFailure) 3. Full SSE protocol passthrough + Flusher fix - handler/handlers.go: forward all SSE lines verbatim (event:, id:, retry:, : comments, blank-line terminators), not only data:. Previous code produced malformed SSE for strict parsers. - middleware/logging.go: explicit Flush() method on responseWriter. Embedding http.ResponseWriter (interface) does not auto-promote Flush(), so every w.(http.Flusher) check in the streaming handler was returning ok=false and SSE writes buffered in net/http until the body closed. 4. Non-streaming → streaming demotion (feature-flagged) - ANTHROPIC_DEMOTE_NONSTREAMING env (default false) - When enabled and the routed provider is anthropic, force stream=true upstream for clients that asked for stream=false. Receive SSE, accumulate via accumulateSSEToMessage (handles text, tool_use with partial_json reassembly, thinking, signature, citations_delta, usage merge), and synthesize a single non-streaming JSON response. - Eliminates the ResponseHeaderTimeout class of failure entirely. - Body rewrite uses json.Decoder + UseNumber() to preserve integer precision in unknown nested fields (tool inputs from prior turns). - Files: internal/config/config.go, internal/handler/handlers.go, cmd/proxy/main.go, cmd/proxy/main_test.go 5. Live operational state: /livez gauge + graceful drain - New internal/runtime package: atomic in-flight counter + draining flag - New middleware/inflight.go: increments runtime gauge, applied to /v1/* subrouter so Messages, ChatCompletions, and ProxyPassthrough are all counted - /v1/* moved to a gorilla/mux subrouter so the InFlight middleware applies surgically; /health, /livez, /openapi.* remain on parent router (unauthenticated, uncounted) - Health handler returns 503 draining when runtime.IsDraining() is true, so Traefik stops routing to a slot before drain begins - New /livez handler returns {status, in_flight, draining, timestamp} - SIGTERM handler in main.go: SetDraining(true), poll for in_flight==0 with 32-min ceiling and 1s tick (logs every 10s), then srv.Shutdown - Auth bypass list extended with /livez - Files: internal/runtime/runtime.go (new), internal/middleware/inflight.go (new), internal/middleware/auth.go, internal/handler/handlers.go (Health, Livez, runtime import), cmd/proxy/main.go (subrouter, drain loop) 6. OpenAPI spec updates - Document Health 503 response and new DrainingResponse schema - Add /livez path with LivezResponse schema - Files: internal/handler/openapi.go Verified: go build ./... clean, go test ./... all pass, go vet clean. Three rounds of codex peer review across changes 1-5; all feedback addressed (citations_delta, json.Number precision, drain-loop logging via lastLog timestamp, PathPrefix tightened to "/v1/").
2026-05-02 15:15:58 -06:00
#!/bin/sh
# Dev entrypoint - runs all services with hot-reload
set -e
PUID=${PUID:-1000}
PGID=${PGID:-1000}
if [ "$(id -u)" = "0" ]; then
if [ "$PUID" != "1000" ] || [ "$PGID" != "1000" ]; then
deluser node 2>/dev/null || true
delgroup node 2>/dev/null || true
addgroup -g "$PGID" -S node
adduser -S -u "$PUID" -G node -h /home/node -s /bin/sh node
fi
# Fix data dir ownership
chown "$PUID:$PGID" /app/data 2>/dev/null || true
chown "$PUID:$PGID" /app/data/requests.db* 2>/dev/null || true
# Install/update deps as root (named volumes are root-owned)
cd /app/proxy && go mod download
cd /app/svelte && npm install --loglevel=warn 2>&1 || true
cd /app
# Fix ownership on everything the node user needs to write to
chown -R "$PUID:$PGID" /app/svelte/node_modules 2>/dev/null || true
# Pre-create .svelte-kit and fix ownership so vite dev can write type definitions
mkdir -p /app/svelte/.svelte-kit/types
chown -R "$PUID:$PGID" /app/svelte/.svelte-kit /app/svelte/build 2>/dev/null || true
# Ensure Go cache/tmp dirs are writable by the node user
# Use a dedicated dir for the proxy binary so CompileDaemon can overwrite it
mkdir -p /home/node/.cache/go-build /tmp/go-build /tmp/proxy-bin
chown -R "$PUID:$PGID" /home/node/.cache /tmp/go-build /tmp/proxy-bin /go/pkg 2>/dev/null || true
# Re-exec this script as the node user
exec su-exec "$PUID:$PGID" "$0" "$@"
fi
echo "=== DEV MODE (uid=$(id -u)) ==="
echo "Proxy Server: http://0.0.0.0:${PORT} (CompileDaemon hot-reload)"
echo "Svelte Dashboard: http://0.0.0.0:${SVELTE_PORT} (vite HMR)"
echo "================"
cleanup() {
echo "Shutting down dev services..."
kill $PROXY_PID $SVELTE_PID 2>/dev/null || true
exit 0
}
trap cleanup SIGTERM SIGINT
# Start Go proxy with CompileDaemon for hot-reload
cd /app/proxy
HOME=/home/node CompileDaemon -build="go build -o /tmp/proxy-bin/proxy cmd/proxy/main.go" -command="/tmp/proxy-bin/proxy" -graceful-kill=true -graceful-timeout=10 -pattern="(.+\\.go|.+\\.yaml)$" &
PROXY_PID=$!
cd /app
# Wait for Go proxy to be ready (up to 120s for first compile)
echo "Waiting for proxy to be ready..."
i=0
while [ $i -lt 120 ]; do
if wget -qO /dev/null "http://localhost:${PORT}/health" 2>/dev/null; then
echo "Proxy is ready!"
break
fi
sleep 2
i=$((i + 2))
done
if [ $i -ge 120 ]; then
echo "Warning: proxy not ready after 120s, starting frontends anyway"
fi
# Start SvelteKit dev server (Vite HMR)
cd /app/svelte
PORT=${SVELTE_PORT} HOST=0.0.0.0 DASHBOARD_PASSWORD="${DASHBOARD_PASSWORD}" npm run dev -- --host 0.0.0.0 --port ${SVELTE_PORT} &
SVELTE_PID=$!
cd /app
echo ""
echo "All dev services started. Watching for file changes..."
echo ""
wait