feat: 权限与日志治理完善,MinIO 独立部署与 tiktoken 离线打包适配

- 后端:强化平台/审批/资源/系统接口权限校验与操作日志,更新权限设计文档与测试用例
- 存储:新增 MinIO 独立部署适配(端口 19000/19001),外部端点与 host-gateway 互通
- 离线:打包 tiktoken cl100k_base 词表进镜像,避免无网环境联网下载
- 其他:算力节点接口微调,前端微调创建页小修,忽略 MinIO 运行时数据

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
wuyongtao
2026-08-12 15:21:23 +08:00
parent 2f64086177
commit 5ecca9f0bc
26 changed files with 101600 additions and 129 deletions

View File

@@ -50,10 +50,14 @@ COMPUTE_POLL_BATCH_SIZE=100
COMPUTE_REQUEST_TIMEOUT_SECONDS=5
# MinIO object storage. Enable after the MinIO service is reachable.
MINIO_ENABLED=false
MINIO_ENDPOINT=http://minio:9000
MINIO_API_PORT=19000
MINIO_CONSOLE_PORT=19001
MINIO_ENABLED=true
# For split-server deployment, replace host.docker.internal with the MinIO
# server address, for example http://10.10.20.30:19000.
MINIO_ENDPOINT=http://172.25.179.69:19000
MINIO_ACCESS_KEY=minioadmin
MINIO_SECRET_KEY=minioadmin
MINIO_SECRET_KEY=change_me_minio_secret
MINIO_BUCKET=yg-ft-resources
MINIO_SECURE=false
STORAGE_WAIT_SECONDS=300

View File

@@ -63,7 +63,9 @@ services:
COMPUTE_POLL_BATCH_SIZE: ${COMPUTE_POLL_BATCH_SIZE:-100}
COMPUTE_REQUEST_TIMEOUT_SECONDS: ${COMPUTE_REQUEST_TIMEOUT_SECONDS:-5}
MINIO_ENABLED: ${MINIO_ENABLED:-false}
MINIO_ENDPOINT: ${MINIO_ENDPOINT:-http://minio:9000}
# Use the storage server's externally reachable address. Do not use a
# MinIO container name because storage is deployed independently.
MINIO_ENDPOINT: ${MINIO_ENDPOINT:-http://host.docker.internal:19000}
MINIO_ACCESS_KEY: ${MINIO_ACCESS_KEY:-minioadmin}
MINIO_SECRET_KEY: ${MINIO_SECRET_KEY:-minioadmin}
MINIO_BUCKET: ${MINIO_BUCKET:-yg-ft-resources}
@@ -75,6 +77,8 @@ services:
- ../../backend:/app:ro
- ../../runtime/app/logs/backend:/opt/yg-ft/logs/backend
- ../../runtime/app/data:/data/yg-ft
extra_hosts:
- "host.docker.internal:host-gateway"
networks:
- yg-ft-app
healthcheck:

100256
docker/app/tiktoken/cl100k_base Normal file

File diff suppressed because it is too large Load Diff