From eb7033c49695fd6841405f6882e71c619b1f10da Mon Sep 17 00:00:00 2001
From: Lihatoo <1747565629@gmail.com>
Date: Sun, 26 Jul 2026 17:14:19 +0800
Subject: [PATCH 1/2] =?UTF-8?q?=E8=AF=B4=E6=98=8E=E8=AE=BE=E8=AE=A1?=
=?UTF-8?q?=E5=81=9C=E6=AD=A2=E6=9D=A1=E4=BB=B6=E5=92=8C=E5=AE=B9=E5=99=A8?=
=?UTF-8?q?=E8=B5=84=E6=BA=90=E9=85=8D=E7=BD=AE?=
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
---
README.md | 86 ++++++++++++++++++++++++++++++++++++++--------
docker-compose.yml | 2 +-
service/index.html | 17 +++++----
service/server.py | 6 ++--
4 files changed, 85 insertions(+), 26 deletions(-)
diff --git a/README.md b/README.md
index 3c5042c..41f1606 100644
--- a/README.md
+++ b/README.md
@@ -16,6 +16,77 @@ The service listens on port `18765`. The current local deployment is reverse pro
Traefik only performs TLS termination, compression, and reverse proxying for `npt`; authentication is enforced by this application.
+## Deploying the independent np instance
+
+`np.lihato.icu` runs independently on `100.64.0.11`. Do not copy the `npt`
+OIDC values unchanged. In the `np-replica` service of the
+`docker-compose.yml` deployed on `.11`, use:
+
+```yaml
+ports:
+ - "100.64.0.11:18765:18765"
+environment:
+ NP_AUTH_REQUIRED: 1
+ NP_OIDC_ISSUER: https://auth.lihato.icu/application/o/nupack-account/
+ NP_OIDC_CLIENT_ID: np-replica-web
+ NP_OIDC_REDIRECT_URI: https://np.lihato.icu/auth/callback
+ NP_OIDC_POST_LOGOUT_URI: https://np.lihato.icu/
+```
+
+The `NP_OIDC_*` variables belong on the web service (`np-replica`); the
+worker does not perform browser login. Preserve the existing calculation
+settings, including `NP_WORKER_CONCURRENCY=16`,
+`NP_PER_JOB_THREAD_LIMIT=4`, and `NP_NUPACK_CACHE_GB=8.0`.
+
+After editing the Compose file on `.11`, recreate the web container:
+
+```bash
+docker compose up -d --force-recreate np-replica
+```
+
+If the deployed image predates the account/OIDC changes, rebuild both
+application containers instead:
+
+```bash
+docker compose up -d --build --force-recreate np-replica np-worker
+```
+
+Verify the result:
+
+```bash
+curl -I https://np.lihato.icu/
+curl -I 'https://np.lihato.icu/auth/login?next=%2F'
+```
+
+The first response should redirect to `/auth/login?next=%2F`. The second
+`Location` header must contain all of the following:
+
+- `client_id=np-replica-web`
+- `redirect_uri=https%3A%2F%2Fnp.lihato.icu%2Fauth%2Fcallback`
+- `code_challenge_method=S256`
+
+If it contains `npt-replica-web` or `npt.lihato.icu`, the `.11` container
+is still running with the wrong environment and must be recreated.
+
+## 容器资源配置
+
+当前 `docker-compose.yml` 面向 64 核 / 64 GB 级别的服务器配置,服务拆成三个容器:
+
+- `redis`:只保存实时队列、运行状态和会话缓存,限制为 `mem_limit: 3g`。Redis 开启 AOF,数据写入 `./runtime/redis`。
+- `np-replica`:Web/API 容器,限制为 `mem_limit: 4g`,负责页面、登录、历史记录、任务提交和状态查询。它不应该承担大规模计算。
+- `np-worker`:后台计算容器,限制为 `mem_limit: 56g`,负责实际 NUPACK 计算。大任务应该由这个容器消耗 CPU 和内存。
+
+计算相关环境变量需要在 `np-replica` 和 `np-worker` 中保持一致:
+
+- `NP_WORKER_CONCURRENCY=16`:最多同时执行 16 个后台任务,超过后进入 Redis 队列等待。
+- `NP_PER_JOB_THREAD_LIMIT=4`:单个任务最多使用 4 个 native 计算线程,同时写入 `OMP_NUM_THREADS`、`OPENBLAS_NUM_THREADS`、`MKL_NUM_THREADS`、`NUMEXPR_NUM_THREADS`、`VECLIB_MAXIMUM_THREADS`、`GOTO_NUM_THREADS`,并设置 `nupack.config.threads`。
+- `NP_NUPACK_CACHE_GB=8.0`:单个 NUPACK 进程可使用的缓存上限。
+- `NP_JOB_TTL_SECONDS=3600`:Redis 中实时任务状态的保留时间;长期历史记录写入 SQLite。
+
+理论上当前峰值为 `16 * 4 = 64` 个 native 计算线程。若机器被压满,优先把 `NP_WORKER_CONCURRENCY` 从 `16` 降到 `8` 或 `4`;如果单任务仍过重,再把 `NP_PER_JOB_THREAD_LIMIT` 从 `4` 降到 `2` 或 `1`。`np-replica` 的内存不建议调高来跑计算,应该把计算压力留给 `np-worker`。
+
+设计任务默认使用官方行为:固定序列 target 也参与 `tube_design` / `complex_design`。如果确认某些 target 完全固定、只需要展示结果、不需要参与优化,可在页面中把 “固定目标策略” 改为 “剥离固定目标以提速”,这样会减少 off-target 集合和优化搜索量。
+
## Endpoints
- `GET /`
@@ -52,18 +123,3 @@ Live jobs and sessions are stored in Redis when `NP_REDIS_URL` is enabled. Accou
- For the independent `np` deployment on `100.64.0.11`, set `NP_OIDC_ISSUER=https://auth.lihato.icu/application/o/nupack-account/`, `NP_OIDC_CLIENT_ID=np-replica-web`, `NP_OIDC_REDIRECT_URI=https://np.lihato.icu/auth/callback`, and `NP_OIDC_POST_LOGOUT_URI=https://np.lihato.icu/`.
- Redis stores the live queue and login sessions. SQLite WAL at `/data/np-replica.sqlite3` stores users, owned jobs, compressed inputs/results/errors, usage totals, and durable share links.
- History and job APIs enforce ownership by the Authentik OIDC subject. Public share links expose only the selected record and can be disabled or given an expiry by its owner.
-
-
-
- 现在 `docker-compose.yml` 面向 64 核 / 64G WSL 服务器的并发策略是:
-
- - 最多同时跑 16 个任务
- - 每个任务最多用 4 个计算线程
- - 后续任务进入队列等待
- - 每个任务的 NUPACK 缓存上限为 8 GB
- - 理论上最多占用约 64 个 native 计算线程
-
- 如果后面你发现机器还会被压满,最直接的调法就是在 docker-compose.yml 里继续压:
-
- - 把 NP_WORKER_CONCURRENCY 改小
- - 或保持并发不变,把 NP_PER_JOB_THREAD_LIMIT 改成 2 或 1
diff --git a/docker-compose.yml b/docker-compose.yml
index 3232cf3..d06382d 100644
--- a/docker-compose.yml
+++ b/docker-compose.yml
@@ -3,7 +3,7 @@ services:
image: redis:7.4.8-bookworm
container_name: np-redis
restart: always
- mem_limit: 2g
+ mem_limit: 3g
command: ["redis-server", "--appendonly", "yes", "--appendfsync", "everysec", "--save", "60", "1"]
volumes:
- ./runtime/redis:/data
diff --git a/service/index.html b/service/index.html
index d6257f4..2990eb5 100644
--- a/service/index.html
+++ b/service/index.html
@@ -1687,6 +1687,7 @@ A+B