说明设计停止条件和容器资源配置

This commit is contained in:
Lihatoo 2026-07-26 17:14:19 +08:00
parent 30cdd05914
commit eb7033c496
4 changed files with 85 additions and 26 deletions

View file

@ -16,6 +16,77 @@ The service listens on port `18765`. The current local deployment is reverse pro
Traefik only performs TLS termination, compression, and reverse proxying for `npt`; authentication is enforced by this application.
## Deploying the independent np instance
`np.lihato.icu` runs independently on `100.64.0.11`. Do not copy the `npt`
OIDC values unchanged. In the `np-replica` service of the
`docker-compose.yml` deployed on `.11`, use:
```yaml
ports:
- "100.64.0.11:18765:18765"
environment:
NP_AUTH_REQUIRED: 1
NP_OIDC_ISSUER: https://auth.lihato.icu/application/o/nupack-account/
NP_OIDC_CLIENT_ID: np-replica-web
NP_OIDC_REDIRECT_URI: https://np.lihato.icu/auth/callback
NP_OIDC_POST_LOGOUT_URI: https://np.lihato.icu/
```
The `NP_OIDC_*` variables belong on the web service (`np-replica`); the
worker does not perform browser login. Preserve the existing calculation
settings, including `NP_WORKER_CONCURRENCY=16`,
`NP_PER_JOB_THREAD_LIMIT=4`, and `NP_NUPACK_CACHE_GB=8.0`.
After editing the Compose file on `.11`, recreate the web container:
```bash
docker compose up -d --force-recreate np-replica
```
If the deployed image predates the account/OIDC changes, rebuild both
application containers instead:
```bash
docker compose up -d --build --force-recreate np-replica np-worker
```
Verify the result:
```bash
curl -I https://np.lihato.icu/
curl -I 'https://np.lihato.icu/auth/login?next=%2F'
```
The first response should redirect to `/auth/login?next=%2F`. The second
`Location` header must contain all of the following:
- `client_id=np-replica-web`
- `redirect_uri=https%3A%2F%2Fnp.lihato.icu%2Fauth%2Fcallback`
- `code_challenge_method=S256`
If it contains `npt-replica-web` or `npt.lihato.icu`, the `.11` container
is still running with the wrong environment and must be recreated.
## 容器资源配置
当前 `docker-compose.yml` 面向 64 核 / 64 GB 级别的服务器配置,服务拆成三个容器:
- `redis`:只保存实时队列、运行状态和会话缓存,限制为 `mem_limit: 3g`。Redis 开启 AOF数据写入 `./runtime/redis`
- `np-replica`Web/API 容器,限制为 `mem_limit: 4g`,负责页面、登录、历史记录、任务提交和状态查询。它不应该承担大规模计算。
- `np-worker`:后台计算容器,限制为 `mem_limit: 56g`,负责实际 NUPACK 计算。大任务应该由这个容器消耗 CPU 和内存。
计算相关环境变量需要在 `np-replica``np-worker` 中保持一致:
- `NP_WORKER_CONCURRENCY=16`:最多同时执行 16 个后台任务,超过后进入 Redis 队列等待。
- `NP_PER_JOB_THREAD_LIMIT=4`:单个任务最多使用 4 个 native 计算线程,同时写入 `OMP_NUM_THREADS``OPENBLAS_NUM_THREADS``MKL_NUM_THREADS``NUMEXPR_NUM_THREADS``VECLIB_MAXIMUM_THREADS``GOTO_NUM_THREADS`,并设置 `nupack.config.threads`
- `NP_NUPACK_CACHE_GB=8.0`:单个 NUPACK 进程可使用的缓存上限。
- `NP_JOB_TTL_SECONDS=3600`Redis 中实时任务状态的保留时间;长期历史记录写入 SQLite。
理论上当前峰值为 `16 * 4 = 64` 个 native 计算线程。若机器被压满,优先把 `NP_WORKER_CONCURRENCY``16` 降到 `8``4`;如果单任务仍过重,再把 `NP_PER_JOB_THREAD_LIMIT``4` 降到 `2``1``np-replica` 的内存不建议调高来跑计算,应该把计算压力留给 `np-worker`
设计任务默认使用官方行为:固定序列 target 也参与 `tube_design` / `complex_design`。如果确认某些 target 完全固定、只需要展示结果、不需要参与优化,可在页面中把 “固定目标策略” 改为 “剥离固定目标以提速”,这样会减少 off-target 集合和优化搜索量。
## Endpoints
- `GET /`
@ -52,18 +123,3 @@ Live jobs and sessions are stored in Redis when `NP_REDIS_URL` is enabled. Accou
- For the independent `np` deployment on `100.64.0.11`, set `NP_OIDC_ISSUER=https://auth.lihato.icu/application/o/nupack-account/`, `NP_OIDC_CLIENT_ID=np-replica-web`, `NP_OIDC_REDIRECT_URI=https://np.lihato.icu/auth/callback`, and `NP_OIDC_POST_LOGOUT_URI=https://np.lihato.icu/`.
- Redis stores the live queue and login sessions. SQLite WAL at `/data/np-replica.sqlite3` stores users, owned jobs, compressed inputs/results/errors, usage totals, and durable share links.
- History and job APIs enforce ownership by the Authentik OIDC subject. Public share links expose only the selected record and can be disabled or given an expiry by its owner.
现在 `docker-compose.yml` 面向 64 核 / 64G WSL 服务器的并发策略是:
- 最多同时跑 16 个任务
- 每个任务最多用 4 个计算线程
- 后续任务进入队列等待
- 每个任务的 NUPACK 缓存上限为 8 GB
- 理论上最多占用约 64 个 native 计算线程
如果后面你发现机器还会被压满,最直接的调法就是在 docker-compose.yml 里继续压:
- 把 NP_WORKER_CONCURRENCY 改小
- 或保持并发不变,把 NP_PER_JOB_THREAD_LIMIT 改成 2 或 1