netanalyzer/docker/remote-agent/docker-compose.yml
Joseph McQueen b3c37bd7df feat: st command suite, Webex phone + Atlas AV integrations, dockerized remote agent
Rebrand NetAnalyzer -> StoreHealthAnalyzer and consolidate the store
reporting surface into a single `st [number]` command with focused
sub-modes.

Commands
- st [number]                - general info (SIW + brands + Meraki net link)
- st [number] network        - switches, APs, store server
- st [number] pos            - registers, payment terminals, customer display
- st [number] ios            - MDM-tracked iOS hardware
- st [number] phone          - wired 78xx + DECT basestations/handsets with
                               registration state, extensions and main DID
- st [number] av             - Atlas AMPs + MDM-tracked Apple TVs, video
                               walls, music players, LED displays
- Removed `analyze` in favor of the unified `st` surface

Integrations
- integrations/webex: Service App OAuth with rotating refresh tokens,
  seed + cleanup scripts, tokens/ storage (git-ignored)
- integrations/atlas: Xyte client + cached device discovery keyed on
  zero-padded 6-digit store numbers, cold-cache failure -> unavailable
  banner instead of a misleading empty result
- services/webexPhone, services/webexService, services/avService: shape
  raw upstream data into the report layer's contract
- utils/merakiMatcher: FQDN hostname extraction so payment terminals
  match Meraki descriptions; case-insensitive lookup
- utils/chunkReport: split long markdown replies at 7000-char boundaries

Reliability / ops
- server.js: awaited framework.stop() + 8s hard-kill timer so nodemon /
  Docker restarts don't leak WDM device registrations ("excessive device
  registrations")
- nodemon.json: SIGINT so the graceful path always runs
- scripts/cleanupWebexDevices.js: one-shot WDM cleanup utility
- Group-space routing: hears() regexes tolerate the leading @BotName
  prefix Webex prepends to mentions
- Replaced HTML-unsafe <number> placeholders with [number] in all help
  strings

Remote agent containerization
- docker/remote-agent/: multi-stage node:22-alpine image, non-root user,
  tini for signal handling, minimal deps (ws/axios/dotenv)
- docker/remote-agent/package.sh: docker buildx build defaulting to
  linux/amd64 (with override), saves image + assembles deploy/ + writes
  SHA256 + zips for offline transfer
- docker/remote-agent/deploy/: runtime docker-compose.yml, install.sh
  with platform sanity check, remote-host README
- .dockerignore + .gitignore updates for build artifacts and dist bundles
- npm run agent:package convenience script

Cleanup
- Dropped storeHealth.js / HealthReport.js and their tests/mocks in favor
  of the shared storeDetail pipeline
- Store model handles null SIW records gracefully; toSummary always
  ends with a newline so the Meraki link sits on its own line

Tests
- 144 tests across 14 suites passing; new coverage for atlasClient,
  atlasDevices, avService, avCategory classification, webexPhone,
  webexServiceAppAuth, storeDetail integration, siw, chunkReport and
  the updated meraki matcher

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-06 09:54:41 -04:00

43 lines
1.5 KiB
YAML

# Compose file for the StoreHealthAnalyzer remote agent.
#
# Run from the REPOSITORY ROOT so the build context can pick up
# remoteAgent.js:
#
# docker compose -f docker/remote-agent/docker-compose.yml up -d --build
#
# Environment values come from docker/remote-agent/.env (copy the .env.example
# next to it). Set WS_URL to the main StoreHealthAnalyzer server's public
# websocket endpoint, and WS_TOKEN to the shared secret.
services:
remote-agent:
build:
context: ../..
dockerfile: docker/remote-agent/Dockerfile
image: sha-remote-agent:latest
container_name: sha-remote-agent
restart: unless-stopped
env_file:
- .env
# The agent is a websocket client — it doesn't listen on any port, so
# there's nothing to publish. It just needs outbound network access to:
# - the main StoreHealthAnalyzer server (WS_URL)
# - the internal APIs it proxies for (SIW, MDM, whatever else).
#
# If those live on the host's Docker network, uncomment `network_mode:
# host` (Linux only) or attach to a shared user-defined network.
#
# network_mode: host
# Stop signal + timeout tuning: the agent handles SIGTERM cleanly via
# tini, so the default 10s grace period is plenty.
stop_signal: SIGTERM
stop_grace_period: 10s
# Send stdout/stderr to json-file with sensible rotation so a long-lived
# container doesn't fill the disk with reconnect chatter.
logging:
driver: json-file
options:
max-size: '10m'
max-file: '3'