Run the whole stack with Compose
Run Postgres, Redis, the API with the web UI and a worker together on one machine.
docker/compose.yml keeps the default services, Postgres and Redis, for make services. It also
adds a stack profile with serve --ui and one worker on the same network.
Prerequisites
- Docker, with Compose.
make.
Steps
-
Copy the environment file and fill it in:
cp .env.example .env# set AFE_API_TOKEN and OPENROUTER_API_KEY (or the key your Model names) -
Bring the stack up.
make compose-upbuildsafe:dev, starts every service and waits for the healthchecks.make compose-downstops it and removes the containers.make compose-up# UI and API on http://127.0.0.1:8765, ops on http://127.0.0.1:9464make compose-down -
Stop everything when you are done.
make downstops every development service this repository can start: the Compose stack with its Postgres and Redis, Langfuse, the OpenTelemetry Collector and the kind clusterafe. It tries every stop even when one fails, reports the failures and exits non-zero. It leaves volumes and data in place.make down -
make servicesis unchanged. It still starts only Postgres and Redis for the tests.
The Docker socket
The worker mounts /var/run/docker.sock so it can open a ticket's sandbox container. The socket is
a laptop-only choice, never a cluster one.
The container runs as a non-root user, so it needs the group that owns the socket. make compose-up
reads DOCKER_GID from .env, 0 by default. Set it to your host's Docker group when the default
is not enough:
DOCKER_GID=$(getent group docker | cut -d: -f3)
The configuration lives in deploy/kind/config/, mounted at /config. It holds a Runtime that
reads the store DSN and the broker URL from the environment, and a demo flow.
Resource limits
Every container sets a CPU and a memory limit, so a busy service cannot starve the machine. The
values live in docker/compose.yml and are a prudent starting point for a shared machine. Lower
them on a small host, raise them when a service is throttled.
Troubleshooting
Symptom: afe serve -c /config in the serve container keeps restarting.
Cause: AFE_API_TOKEN is empty in .env, so the server refuses to start.
Fix: set AFE_API_TOKEN in .env and run make compose-up again.
Symptom: the worker logs a permission error opening the sandbox container.
Cause: DOCKER_GID in .env does not match the group that owns /var/run/docker.sock on the
host.
Fix: set DOCKER_GID with the command above, then restart the stack.
Symptom: make compose-up fails because port 8765 or 9464 is already in use.
Cause: another afe serve process, or a previous stack, is already bound to that port.
Fix: stop it first, for example with make down, then run make compose-up again.