feat: add scoped read-only audio preview and isolated Dify transport

This commit is contained in:
2026-10-09 16:10:59 +08:00
parent 27772bec61
commit 4d0af7f3f4
36 changed files with 1517 additions and 68 deletions
@@ -0,0 +1,41 @@
services:
bridge:
image: sha256:34386ef0cb081344d7ec1c103ba398e6e9f64e9ab3a1509accc92a4e24a07258
container_name: followup-asr-bridge-20261009
user: '1000:1000'
entrypoint: ['python', '-B', '/app/bridge.py']
working_dir: /app
restart: unless-stopped
read_only: true
cap_drop: [ALL]
security_opt: ['no-new-privileges:true']
pids_limit: 64
cpus: 0.50
mem_limit: 256m
memswap_limit: 256m
tmpfs: ['/tmp:size=16m,noexec,nosuid,nodev']
volumes:
- './bridge.py:/app/bridge.py:ro'
- './asr-key:/run/secrets/asr-key:ro'
networks:
dify:
aliases: [followup-asr-bridge]
asr: {}
healthcheck:
test: ['CMD', 'python', '-c', "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8080/health',timeout=4).read()"]
interval: 15s
timeout: 5s
retries: 3
start_period: 10s
logging:
driver: json-file
options: {max-size: 1m, max-file: '2'}
labels:
com.zyt.release: followup-dify-20261009
networks:
dify:
external: true
name: dify_v1110_eera_default
asr:
external: true
name: followup-audio-asr_default