Files
zyt/deployment/followup-audio-dify/README.md
T

4.3 KiB

Isolated Dify ASR deployment — 2026-10-09

This directory adds only a CPU-only fixed-upstream bridge, a new speech2text model/default, and an independent Dify chat App. Do not apply its compose file to the old Dify or ASR project. The two networks are external and must not be deleted.

  • AI host deployment root: /home/www/qwen-vllm/dify-integration-20261009
  • Public API base: https://ai.zhenyangtang.com.cn/v1
  • New App: ea0d7293-3d89-425d-a236-015fac7e2470
  • App mode chat; public site disabled; API enabled; max active chat requests 1.
  • ASR: Qwen/Qwen3-ASR-1.7B; extraction: existing qwen3.6-35b.
  • App max_tokens 8192, temperature 0, enable_thinking false; JSON requested in the system/query prompts, not native JSON-schema enforcement. Existing Qwen model has strict compatibility/not_supported thinking; SDK may filter the explicit false parameter. The existing Qwen server's --default-chat-template-kwargs {"enable_thinking":false} is the effective server control, verified without changing it.
  • Binding revision: followup-dify-20261009-v1-99ebe159aef4dce6. Any App/provider/default/model-serving/bridge change requires a new revision and new acceptance. This is a version binding, not an automatic remote drift monitor.
  • Bridge: existing pinned Python 3.12 image, two Docker networks, no host port, no GPU, UID1000, read-only root, all capabilities dropped, no-new-privileges, 256MiB/0.5CPU/64PIDs; in-flight 1, token bucket 120/min burst4, 30MiB+64KiB multipart limit, 180s fixed-upstream timeout, no redirects or POST retry.
  • Secrets exist only in private 0600 host files and encrypted Dify credentials. Never print resources.private.json, asr-key, dify-runtime.env, or operator-error.private.log.
  • Provisioning uses deployed ModelProviderService, AppService, model-config and key controllers, including provider validation/encryption. It never handcrafts encrypted provider rows. Provision is single-use; inspect exact state after any failure before resuming.

Validation

Run python3 test_bridge.py locally for eight synthetic mock-server tests. public_probe.py PRIVATE_ENV SYNTHETIC_WAV [all|asr|chat] [EXPECTED_CANARIES_JSON] always verifies HTTPS certificates/hostname, never emits keys, and sends canary strings only in audio, not in ASR form prompts. Optional expected canaries are verifier inputs only. Preserve failures; passing connection tests do not establish full transcription accuracy.

Initial ASR fixture reproduced a homophone error: 红色石榴 became 红色石流; its strict four-canary result remains failed even though the other three unique canaries match and HTTPS ASR returns 200. This release is for synthetic/preview-only validation, not clinical writeback or an assertion of complete accuracy.

Webhost Python/OpenSSL validates this TLS endpoint. Webhost legacy PHP/cURL NSS certificate-key-usage behavior requires independent acceptance; do not disable TLS verification or infer PHP success from Python success.

Exact rollback

On AI host, execute only this release's /home/www/qwen-vllm/dify-integration-20261009/ROLLBACK.sh:

  • --quiesce: disable only the new App API and stop only its recorded bridge container; verified live.
  • --restore: start the same new bridge, check health, re-enable only the new App API; verified live.
  • --remove-new-objects: revoke the precise new key, delete the precise new App, remove this newly introduced non-secret speech2text default and credential through guarded ORM/service operations, and remove only this bridge. This final removal is packaged, not exercised against the live desired deployment. It aborts if another App now uses speech2text or resource IDs differ.

No command deletes shared networks, old providers/models/apps, model files, or old containers. Apply rollback before removing the private resource manifest; preserve it for identity checks. No old source files or global configuration are edited.

After live quiesce/restore, a separate 13.03075s synthetic fixture (蓝色风筝/绿色森林/白色帆船/黑色雨伞) passed all four audio-only canaries through the Webhost's fully verified HTTPS Python/OpenSSL route (ASR 200, 1.284s); the JSON chat canary also passed (200, 0.539s). This additional successful connection case does not overwrite the retained first fixture's homophone failure.