mirror of
https://github.com/taylanbakircioglu/haproxy-openmanager.git
synced 2026-09-12 05:48:58 +00:00
23257b02cf
A user running the API on a 2-core/4GB host reported slow-feeling API responses (Issue #35 follow-up). Review of the hot paths found no pathological defect; the dominant factors are the single uvicorn worker (one core serves all requests) and the constant agent-poll baseline (4 requests per agent every 30s). Two zero-risk improvements: - backend/Dockerfile: CMD now honors UVICORN_WORKERS, falling back to WEB_CONCURRENCY and then 1. Flagless uvicorn natively honors WEB_CONCURRENCY, so the fallback keeps any deployment that relied on it byte-for-byte compatible; with the final default of 1 worker uvicorn runs in-process exactly as before. >1 enables the multiprocess supervisor so multi-core hosts can use all cores. Background tasks are already multi-replica safe (FOR UPDATE SKIP LOCKED / advisory locks), as exercised by the k8s HPA deployment (2-10 replicas). `exec` keeps uvicorn as PID 1 (clean SIGTERM, verified ~1s docker stop with 2 workers). docker-compose.yml passes UVICORN_WORKERS through as empty-when-unset so a user-set WEB_CONCURRENCY is never overridden; .env.template documents it. - routers/agent.py heartbeat (by-name endpoint): the agent's status/version/upgrade_status were read with three separate single-column SELECTs against the same row; now one SELECT. Identical values and None semantics (single consistent snapshot instead of three reads); saves two round-trips per heartbeat per agent every 30s. The legacy by-id heartbeat endpoint is untouched; the heartbeat API contract is unchanged for agents of every version. - README: new "Performance Tuning" section (worker/replica scaling, and how to use the X-Response-Time header plus "Slow request detected" logs to pinpoint slow endpoints). Verification: full backend suite in docker green (1063 passed, 151 skipped; also re-run by the runtime image build); worker-count expansion matrix (unset->1, UVICORN_WORKERS=2->2, WEB_CONCURRENCY=3->3, both->UVICORN_WORKERS, empty->fallback) all correct; default run confirmed single-process with uvicorn as PID 1 and healthy API; UVICORN_WORKERS=2 confirmed parent + 2 workers, healthy API, clean shutdown; live heartbeats verified for register + existing-agent paths AND degraded agents (no stats socket / haproxy stopped / garbage stats CSV / unknown backend in server_statuses): all return 200, agent row updates correctly, zero backend errors. No schema, API, or agent changes.
49 lines
1.8 KiB
Docker
49 lines
1.8 KiB
Docker
FROM python:3.11-slim
|
|
|
|
WORKDIR /app
|
|
|
|
# Install system dependencies
|
|
RUN apt-get update && apt-get install -y \
|
|
gcc \
|
|
postgresql-client \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Create non-root user for OpenShift compatibility
|
|
RUN groupadd --gid 1001 appgroup && \
|
|
useradd --uid 1001 --gid appgroup --shell /bin/bash --create-home appuser
|
|
|
|
# Copy requirements and install Python dependencies
|
|
COPY requirements.txt requirements-test.txt ./
|
|
RUN pip install --no-cache-dir -r requirements.txt && \
|
|
pip install --no-cache-dir -r requirements-test.txt
|
|
|
|
# Copy application code
|
|
COPY . .
|
|
|
|
# Run unit tests during build (fails build if tests fail)
|
|
RUN python -m pytest tests/ -v --tb=short --disable-warnings || \
|
|
(echo "❌ UNIT TESTS FAILED - Build aborted" && exit 1)
|
|
|
|
# Remove test dependencies to reduce image size
|
|
RUN pip uninstall -y pytest pytest-asyncio pytest-mock pytest-cov httpx
|
|
|
|
# Create haproxy config directory and set permissions
|
|
RUN mkdir -p /etc/haproxy && \
|
|
chown -R appuser:appgroup /app /etc/haproxy
|
|
|
|
# Switch to non-root user
|
|
USER appuser
|
|
|
|
# Expose port
|
|
EXPOSE 8000
|
|
|
|
# Run the application in production mode (without --reload).
|
|
# UVICORN_WORKERS (default 1) opts into multiple worker processes on multi-core
|
|
# hosts; with 1 worker uvicorn runs in-process, identical to the flagless CMD
|
|
# this replaces. Falls back to WEB_CONCURRENCY when UVICORN_WORKERS is unset
|
|
# because flagless uvicorn honored WEB_CONCURRENCY (uvicorn config.py) — this
|
|
# keeps any deployment that relied on it byte-for-byte compatible. Background
|
|
# tasks are multi-replica safe (FOR UPDATE SKIP LOCKED / advisory locks), as
|
|
# already exercised by the k8s HPA deployment. `exec` keeps uvicorn as PID 1
|
|
# so signal handling is unchanged.
|
|
CMD ["sh", "-c", "exec uvicorn main:app --host 0.0.0.0 --port 8000 --workers ${UVICORN_WORKERS:-${WEB_CONCURRENCY:-1}}"] |