feat(provisioner): make sandbox container port configurable (#3928)

* feat(provisioner): make sandbox container port configurable

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Willem Jiang <willem.jiang@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
This commit is contained in:
Zheng Feng 2026-07-04 11:01:57 +08:00 committed by GitHub
parent 94c852ac4a
commit a59f9d42e8
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -62,6 +62,17 @@ SKILLS_HOST_PATH = os.environ.get("SKILLS_HOST_PATH", "/skills")
THREADS_HOST_PATH = os.environ.get("THREADS_HOST_PATH", "/.deer-flow/threads") THREADS_HOST_PATH = os.environ.get("THREADS_HOST_PATH", "/.deer-flow/threads")
SKILLS_PVC_NAME = os.environ.get("SKILLS_PVC_NAME", "") SKILLS_PVC_NAME = os.environ.get("SKILLS_PVC_NAME", "")
USERDATA_PVC_NAME = os.environ.get("USERDATA_PVC_NAME", "") USERDATA_PVC_NAME = os.environ.get("USERDATA_PVC_NAME", "")
SANDBOX_CONTAINER_PORT_RAW = os.environ.get("SANDBOX_CONTAINER_PORT", "8080")
try:
SANDBOX_CONTAINER_PORT = int(SANDBOX_CONTAINER_PORT_RAW)
except ValueError as exc:
raise RuntimeError(
f"Invalid SANDBOX_CONTAINER_PORT={SANDBOX_CONTAINER_PORT_RAW!r}; expected an integer TCP port"
) from exc
if not (1 <= SANDBOX_CONTAINER_PORT <= 65535):
raise RuntimeError(
f"Invalid SANDBOX_CONTAINER_PORT={SANDBOX_CONTAINER_PORT}; expected a value in [1, 65535]"
)
SAFE_THREAD_ID_PATTERN = r"^[A-Za-z0-9_\-]+$" SAFE_THREAD_ID_PATTERN = r"^[A-Za-z0-9_\-]+$"
SAFE_USER_ID_PATTERN = r"^[A-Za-z0-9_\-]+$" SAFE_USER_ID_PATTERN = r"^[A-Za-z0-9_\-]+$"
DEFAULT_USER_ID = "default" DEFAULT_USER_ID = "default"
@ -320,14 +331,14 @@ def _build_pod(sandbox_id: str, thread_id: str, user_id: str = DEFAULT_USER_ID)
ports=[ ports=[
k8s_client.V1ContainerPort( k8s_client.V1ContainerPort(
name="http", name="http",
container_port=8080, container_port=SANDBOX_CONTAINER_PORT,
protocol="TCP", protocol="TCP",
) )
], ],
readiness_probe=k8s_client.V1Probe( readiness_probe=k8s_client.V1Probe(
http_get=k8s_client.V1HTTPGetAction( http_get=k8s_client.V1HTTPGetAction(
path="/v1/sandbox", path="/v1/sandbox",
port=8080, port=SANDBOX_CONTAINER_PORT,
), ),
initial_delay_seconds=5, initial_delay_seconds=5,
period_seconds=5, period_seconds=5,
@ -337,7 +348,7 @@ def _build_pod(sandbox_id: str, thread_id: str, user_id: str = DEFAULT_USER_ID)
liveness_probe=k8s_client.V1Probe( liveness_probe=k8s_client.V1Probe(
http_get=k8s_client.V1HTTPGetAction( http_get=k8s_client.V1HTTPGetAction(
path="/v1/sandbox", path="/v1/sandbox",
port=8080, port=SANDBOX_CONTAINER_PORT,
), ),
initial_delay_seconds=10, initial_delay_seconds=10,
period_seconds=10, period_seconds=10,
@ -387,8 +398,8 @@ def _build_service(sandbox_id: str) -> k8s_client.V1Service:
ports=[ ports=[
k8s_client.V1ServicePort( k8s_client.V1ServicePort(
name="http", name="http",
port=8080, port=SANDBOX_CONTAINER_PORT,
target_port=8080, target_port=SANDBOX_CONTAINER_PORT,
protocol="TCP", protocol="TCP",
# nodePort omitted → K8s auto-allocates from the range # nodePort omitted → K8s auto-allocates from the range
) )